Avast kotisivu ei aukea

Discussion in 'Virukset ja haittaohjelmat - HijackThis -logit' started by Firefox07, Mar 11, 2007.

  1. Firefox07

    Firefox07 Member

    Joined:
    Feb 28, 2005
    Messages:
    41
    Likes Received:
    0
    Trophy Points:
    16
    Epäilyttää kun avast.com aikakatkeaa eli onkohan kaikki kunnossa?

    Tässä kuva herjauksesta logia tehdessä:
    http://img236.imageshack.us/my.php?image=kuva1mg4.jpg

    Logi:

    Logfile of HijackThis v1.99.1
    Scan saved at 19:21:41, on 11.3.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
    C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    C:\Program Files\CyberLink\Shared files\RichVideo.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\carpserv.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\BUFFALO\Client Manager 2\ClientMgr2.exe
    C:\HijackThis.exe
    C:\Program Files\HyperSnap 6\HprSnap6.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O1 - Hosts: 108.112.42.206 ad.doubleclick.net
    O1 - Hosts: 178.95.95.213 ad.fastclick.net
    O1 - Hosts: 107.116.117.138 ads.fastclick.net
    O1 - Hosts: 174.15.27.94 ar.atwola.com
    O1 - Hosts: 115.27.183.221 atdmt.com
    O1 - Hosts: 108.15.197.227 awaps.net
    O1 - Hosts: 180.66.164.240 banner.fastclick.net
    O1 - Hosts: 112.56.109.230 banners.fastclick.net
    O1 - Hosts: 180.140.140.115 click.atdmt.com
    O1 - Hosts: 104.148.31.185 clicks.atdmt.com
    O1 - Hosts: 111.57.62.146 engine.awaps.net
    O1 - Hosts: 100.178.73.135 fastclick.net
    O1 - Hosts: 109.92.142.185 media.fastclick.net
    O1 - Hosts: 109.170.21.186 spd.atdmt.com
    O1 - Hosts: 186.54.74.45 www.awaps.net
    O1 - Hosts: 105.116.161.207 www.fastclick.net
    O1 - Hosts: 108.51.94.92 awaps.net
    O1 - Hosts: 102.35.134.158 fastclick.net
    O1 - Hosts: 102.158.3.18 akamai.net
    O1 - Hosts: 179.147.199.183 www.antivir.de
    O1 - Hosts: 105.108.119.104 antivir.de
    O1 - Hosts: 181.87.27.164 drweb.com
    O1 - Hosts: 110.60.112.152 www.drweb.com
    O1 - Hosts: 173.72.89.247 drweb.ru
    O1 - Hosts: 111.9.106.84 www.clamav.net
    O1 - Hosts: 179.134.219.18 clamav.net
    O1 - Hosts: 104.145.107.4 www.bitdefender.ru
    O1 - Hosts: 186.223.18.161 bitdefender.ru
    O1 - Hosts: 100.125.216.116 open.by
    O1 - Hosts: 175.210.118.4 vba32.de
    O1 - Hosts: 106.43.202.48 www.open.by
    O1 - Hosts: 176.168.161.132 rs01.avast.com
    O1 - Hosts: 113.196.23.53 sm01.avast.com
    O1 - Hosts: 173.85.201.82 rs02.avast.com
    O1 - Hosts: 100.83.75.234 sm02.avast.com
    O1 - Hosts: 178.94.124.98 rs03.avast.com
    O1 - Hosts: 115.115.189.31 sm03.avast.com
    O1 - Hosts: 179.82.30.213 rs04.avast.com
    O1 - Hosts: 108.6.5.208 sm04.avast.com
    O1 - Hosts: 184.166.75.163 rs05.avast.com
    O1 - Hosts: 109.98.190.168 sm05.avast.com
    O1 - Hosts: 185.166.221.212 rs06.avast.com
    O1 - Hosts: 101.71.169.118 sm06.avast.com
    O1 - Hosts: 183.68.192.179 rs07.avast.com
    O1 - Hosts: 113.156.186.65 sm07.avast.com
    O1 - Hosts: 173.216.20.157 rs08.avast.com
    O1 - Hosts: 115.25.97.195 sm08.avast.com
    O1 - Hosts: 185.172.91.117 rs09.avast.com
    O1 - Hosts: 103.56.26.4 sm09.avast.com
    O1 - Hosts: 187.21.191.24 rs10.avast.com
    O1 - Hosts: 106.135.126.37 sm10.avast.com
    O1 - Hosts: 186.92.191.182 rs11.avast.com
    O1 - Hosts: 101.151.218.40 sm11.avast.com
    O1 - Hosts: 182.12.173.157 rs12.avast.com
    O1 - Hosts: 102.44.86.6 sm12.avast.com
    O1 - Hosts: 187.177.109.41 rs13.avast.com
    O1 - Hosts: 100.135.39.7 sm13.avast.com
    O1 - Hosts: 183.4.26.28 rs14.avast.com
    O1 - Hosts: 109.152.56.132 sm14.avast.com
    O1 - Hosts: 174.22.52.47 rs15.avast.com
    O1 - Hosts: 112.44.76.101 sm15.avast.com
    O1 - Hosts: 176.24.2.108 rs16.avast.com
    O1 - Hosts: 104.88.100.68 sm16.avast.com
    O1 - Hosts: 175.209.96.55 rs17.avast.com
    O1 - Hosts: 108.136.54.58 sm17.avast.com
    O1 - Hosts: 182.81.75.62 rs18.avast.com
    O1 - Hosts: 100.132.172.31 sm18.avast.com
    O1 - Hosts: 183.224.68.115 rs19.avast.com
    O1 - Hosts: 103.144.191.113 sm19.avast.com
    O1 - Hosts: 184.193.195.14 rs20.avast.com
    O1 - Hosts: 103.69.72.110 sm20.avast.com
    O1 - Hosts: 176.169.145.194 rs21.avast.com
    O1 - Hosts: 105.200.223.248 sm21.avast.com
    O1 - Hosts: 176.72.49.72 rs22.avast.com
    O1 - Hosts: 105.200.136.24 sm22.avast.com
    O1 - Hosts: 184.106.33.253 rs23.avast.com
    O1 - Hosts: 112.106.95.4 sm23.avast.com
    O1 - Hosts: 176.15.175.146 rs24.avast.com
    O1 - Hosts: 115.172.124.52 sm24.avast.com
    O1 - Hosts: 174.173.108.253 rs25.avast.com
    O1 - Hosts: 111.199.132.183 sm25.avast.com
    O1 - Hosts: 181.141.199.236 rs26.avast.com
    O1 - Hosts: 108.110.4.67 sm26.avast.com
    O1 - Hosts: 187.38.57.188 rs27.avast.com
    O1 - Hosts: 110.153.170.218 sm27.avast.com
    O1 - Hosts: 184.120.97.180 rs28.avast.com
    O1 - Hosts: 104.221.204.97 sm28.avast.com
    O1 - Hosts: 184.87.84.126 rs29.avast.com
    O1 - Hosts: 113.158.156.12 sm29.avast.com
    O1 - Hosts: 175.137.116.58 rs30.avast.com
    O1 - Hosts: 106.89.171.42 sm30.avast.com
    O1 - Hosts: 181.63.155.14 downloadhosting.core.ignum.cz
    O1 - Hosts: 108.171.61.165 download25.avast.com
    O1 - Hosts: 180.78.122.242 www.avast.com
    O1 - Hosts: 105.94.46.61 avast.com
    O1 - Hosts: 101.219.196.161 www.clamwin.com
    O1 - Hosts: 177.93.131.172 clamwin.com
    O1 - Hosts: 113.178.206.30 213.219.245.4
    O1 - Hosts: 178.169.49.160 files.referats.net
    O1 - Hosts: 104.83.9.105 database.clamav.net
    O1 - Hosts: 173.153.208.24 213.248.60.121
    O2 - BHO: Adobe PDF Reader -linkkiavustaja - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [CARPService] carpserv.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\ZoneAlarm\zlclient.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: ClientManager2.lnk = C:\Program Files\BUFFALO\Client Manager 2\ClientMgr2.exe
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O8 - Extra context menu item: Liitä aiemmin luotuun PDF-tiedostoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Muunna Adobe PDF -muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Muunna linkin kohde Adobe PDF -muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Muunna linkin kohde nykyiseen PDF-muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Muunna valinta Adobe PDF -muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Muunna valinta nykyiseen PDF-muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Muunna valitut linkit Adobe PDF -muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Muunna valitut linkit nykyiseen PDF-muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.euchannels.net/update/KooPlayer.ocx
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1145693771670
    O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
    O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Unknown owner - C:\Program Files\ewido anti-spyware 4.0\guard.exe (file missing)
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod-palvelu (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: MS Common Service - Unknown owner - C:\WINDOWS\system32\mscomserv.exe (file missing)
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: Neth - Unknown owner - C:\WINDOWS\system32\netid.exe (file missing)
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NMSAccess - Unknown owner - C:\Program Files\Cheetah Burner\Cheetah DVD Burner\NMSAccess.exe (file missing)
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: Win PPPe - Unknown owner - C:\WINDOWS\system32\winser.exe (file missing)
     
  2. Auttaja

    Auttaja Guest

  3. Firefox07

    Firefox07 Member

    Joined:
    Feb 28, 2005
    Messages:
    41
    Likes Received:
    0
    Trophy Points:
    16
    ComboFix Logi:

    "OMA NIMI FIXATTU" - 07-03-11 21:04:12 Service Pack 2
    ComboFix 07-03-09.3 - Running from: "C:\Documents and Settings\Juha Kirjalainen\Ty”p”yt„"

    ((((((((((((((((((((((((((((((( Files Created from 2007-02-11 to 2007-03-11 ))))))))))))))))))))))))))))))))))


    2007-03-11 20:38 988,270 --a------ C:\ComboFix.exe
    2007-03-11 18:44 218,112 --a------ C:\HijackThis.exe
    2007-03-11 18:20 75,512 --a------ C:\WINDOWS\zllsputility.exe
    2007-03-11 18:20 1,087,216 --a------ C:\WINDOWS\system32\zpeng24.dll
    2007-03-11 18:20 <KANSIO> d-------- C:\WINDOWS\system32\ZoneLabs
    2007-03-11 18:20 <KANSIO> d-------- C:\Program Files\ZoneAlarm
    2007-03-11 18:18 <KANSIO> d-------- C:\Program Files\PALOMUURI
    2007-03-11 12:35 <KANSIO> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\AntiVir PersonalEdition Classic
    2007-03-10 06:09 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
    2007-03-08 10:09 <KANSIO> d-------- C:\Program Files\Motherboard Monitor 5
    2007-03-07 12:06 <KANSIO> d-------- C:\Program Files\uTorrent
    2007-03-07 12:06 <KANSIO> d-------- C:\DOCUME~1\JUHAKI~1\APPLIC~1\uTorrent
    2007-03-06 10:19 33,824 --a------ C:\WINDOWS\system32\drivers\oreans32.sys
    2007-03-06 10:18 974,848 --a------ C:\WINDOWS\system32\mfc70.dll
    2007-03-06 10:18 638,976 --a------ C:\WINDOWS\system32\divx.dll
    2007-03-06 10:18 524,288 --a------ C:\WINDOWS\system32\xvidcore.dll
    2007-03-06 10:18 487,424 --a------ C:\WINDOWS\system32\msvcp70.dll
    2007-03-06 10:18 413,760 --a------ C:\WINDOWS\system32\mpg4c32.dll
    2007-03-06 10:18 261,632 --a------ C:\WINDOWS\system32\mcdvd_32.dll
    2007-03-06 10:18 139,264 --a------ C:\WINDOWS\system32\xvidvfw.dll
    2007-03-06 10:18 <KANSIO> d-------- C:\Program Files\Common Files\AVSMedia
    2007-03-06 10:18 <KANSIO> d-------- C:\Program Files\AVSMedia
    2007-03-06 10:01 <KANSIO> d-------- C:\Program Files\iTunes
    2007-03-06 10:01 <KANSIO> d-------- C:\Program Files\iPod
    2007-03-04 13:49 <KANSIO> d-------- C:\Program Files\Common Files\Macrovision Shared
    2007-03-04 13:49 <KANSIO> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\FLEXnet
    2007-03-02 08:35 <KANSIO> d-------- C:\Program Files\HHD Software
    2007-02-25 14:40 <KANSIO> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avg7
    2007-02-20 21:11 0 --a------ C:\WINDOWS\system32\drivers\svchost.exe
    2007-02-20 20:43 45,056 --a------ C:\WINDOWS\system32\WNASPI32.DLL
    2007-02-20 20:43 16,512 --a------ C:\WINDOWS\system32\drivers\ASPI32.SYS
    2007-02-20 19:54 <KANSIO> d-------- C:\Program Files\Xilisoft
    2007-02-17 22:49 <KANSIO> d-------- C:\SYSTEMTOOLS
    2007-02-17 22:46 <KANSIO> d-------- C:\Program Files\Diskeeper Corporation
    2007-02-17 13:33 24,072 --a------ C:\WINDOWS\system32\uxtuneup.dll
    2007-02-17 13:32 <KANSIO> d-------- C:\Program Files\TuneUp Utilities 2007
    2007-02-17 13:32 <KANSIO> d-------- C:\DOCUME~1\JUHAKI~1\APPLIC~1\TuneUp Software
    2007-02-17 13:00 23 --ahs---- C:\WINDOWS\system32\fdacaf2_r.dll


    (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


    2007-03-11 18:22 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat
    2007-03-10 18:19 -------- d-------- C:\Program Files\progdvb
    2007-03-10 10:34 -------- d--h----- C:\Program Files\installshield installation information
    2007-03-10 10:33 -------- d-------- C:\Program Files\cyberlink
    2007-03-09 21:52 -------- d-------- C:\Program Files\spywareblaster
    2007-03-08 22:19 -------- d-------- C:\DOCUME~1\JUHAKI~1\APPLIC~1\canon
    2007-03-07 14:20 99 --a------ C:\DOCUME~1\JUHAKI~1\APPLIC~1\avsdvdplayer.m3u
    2007-03-07 07:59 -------- d-------- C:\Program Files\ffdshow
    2007-03-06 12:04 -------- d-------- C:\Program Files\super internet tv
    2007-03-06 09:59 -------- d-------- C:\Program Files\quicktime
    2007-03-06 09:57 -------- d-------- C:\Program Files\apple software update
    2007-03-04 13:49 -------- d-------- C:\DOCUME~1\JUHAKI~1\APPLIC~1\adobe
    2007-03-04 13:23 -------- d-------- C:\Program Files\Common Files\adobe
    2007-02-25 14:40 -------- d---s---- C:\DOCUME~1\JUHAKI~1\APPLIC~1\microsoft
    2007-02-23 13:42 -------- d-------- C:\DOCUME~1\JUHAKI~1\APPLIC~1\officeupdate12
    2007-02-21 21:00 10752 --a------ C:\WINDOWS\system32\ff_vfw.dll
    2007-02-17 13:31 -------- d-------- C:\Program Files\Common Files\wise installation wizard
    2007-02-17 13:12 -------- d-------- C:\Program Files\winamp
    2007-02-15 19:27 -------- d-------- C:\Program Files\windows media connect 2
    2007-02-15 17:11 -------- d-------- C:\Program Files\tweaknow regcleaner std
    2007-02-14 12:47 -------- d-------- C:\Program Files\hypersnap 6
    2007-02-09 00:24 -------- d-------- C:\DOCUME~1\JUHAKI~1\APPLIC~1\bsplayer
    2007-02-02 20:45 -------- d-------- C:\DOCUME~1\JUHAKI~1\APPLIC~1\adobeum
    2007-01-28 22:11 -------- d-------- C:\Program Files\msn messenger
    2007-01-26 23:58 -------- d-------- C:\Program Files\tvuplayer
    2007-01-24 15:43 -------- d-------- C:\Program Files\Common Files\ahead
    2007-01-16 19:29 -------- d-------- C:\DOCUME~1\JUHAKI~1\APPLIC~1\pc suite
    2007-01-14 13:50 86172 --a------ C:\WINDOWS\system32\perfc00b.dat
    2007-01-14 13:50 396142 --a------ C:\WINDOWS\system32\perfh00b.dat
    2007-01-13 00:41 -------- d-------- C:\Program Files\jlgsolera
    2007-01-13 00:09 -------- d-------- C:\DOCUME~1\JUHAKI~1\APPLIC~1\tvu networks
    2007-01-12 21:02 -------- d-------- C:\DOCUME~1\JUHAKI~1\APPLIC~1\divx
    2007-01-08 19:01 17408 --a------ C:\WINDOWS\system32\corpol.dll


    (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

    *Note* empty entries & legit default entries are not shown

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
    "CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
    "CARPService"="carpserv.exe"
    "RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
    "LanguageShortcut"="\"C:\\Program Files\\CyberLink\\PowerDVD\\Language\\Language.exe\""
    "avgnt"="\"C:\\Program Files\\AntiVir PersonalEdition Classic\\avgnt.exe\" /min"
    "ZoneAlarm Client"="\"C:\\Program Files\\ZoneAlarm\\zlclient.exe\""

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
    "Installed"="1"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
    "Installed"="1"
    "NoChange"="1"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
    "Installed"="1"


    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
    "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
    "UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
    "WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
    "PcSync"="C:\\Program Files\\Nokia\\Nokia PC Suite 6\\PcSync2.exe /NoDialog"

    [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
    "PcSync"="C:\\Program Files\\Nokia\\Nokia PC Suite 6\\PcSync2.exe /NoDialog"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
    "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
    LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
    NetworkService REG_MULTI_SZ DnsCache\0\0
    rpcss REG_MULTI_SZ RpcSs\0\0
    imgsvc REG_MULTI_SZ StiSvc\0\0
    termsvcs REG_MULTI_SZ TermService\0\0
    HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
    DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
    WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
    bthsvcs REG_MULTI_SZ BthServ\0\0
    mysee2 REG_MULTI_SZ Mysee2_Runtime\0
    Usnsvc REG_MULTI_SZ usnsvc\0\0

    HKLM\software\Microsoft\Windows NT\CurrentVersion\Svchost *netsvcs*
    UxTuneUp


    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{93e9dc30-dce7-11da-8fce-000bcd368d5d}]
    Shell\AutoRun\command E:\lzext.exe

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{98d871c0-427b-11db-914a-000d0b9f63f2}]
    Shell\AutoRun\command F:\lzext.exe


    Contents of the 'Scheduled Tasks' folder
    C:\WINDOWS\tasks\1-Click Maintenance.job
    C:\WINDOWS\tasks\AppleSoftwareUpdate.job


    ********************************************************************

    catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
    http://www.gmer.net

    scanning hidden processes ...

    scanning hidden services ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden processes: 0
    hidden services: 0
    hidden files: 0

    ********************************************************************

    Completion time: 07-03-11 21:07:30
    C:\ComboFix1.txt ... 07-03-11 20:56
    C:\ComboFix2.txt ... 07-03-11 20:55
     
  4. Firefox07

    Firefox07 Member

    Joined:
    Feb 28, 2005
    Messages:
    41
    Likes Received:
    0
    Trophy Points:
    16
    Logi:

    Logfile of HijackThis v1.99.1
    Scan saved at 21:15:18, on 11.3.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
    C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    C:\Program Files\CyberLink\Shared files\RichVideo.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\carpserv.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\BUFFALO\Client Manager 2\ClientMgr2.exe
    C:\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O1 - Hosts: 108.112.42.206 ad.doubleclick.net
    O1 - Hosts: 178.95.95.213 ad.fastclick.net
    O1 - Hosts: 107.116.117.138 ads.fastclick.net
    O1 - Hosts: 174.15.27.94 ar.atwola.com
    O1 - Hosts: 115.27.183.221 atdmt.com
    O1 - Hosts: 108.15.197.227 awaps.net
    O1 - Hosts: 180.66.164.240 banner.fastclick.net
    O1 - Hosts: 112.56.109.230 banners.fastclick.net
    O1 - Hosts: 180.140.140.115 click.atdmt.com
    O1 - Hosts: 104.148.31.185 clicks.atdmt.com
    O1 - Hosts: 111.57.62.146 engine.awaps.net
    O1 - Hosts: 100.178.73.135 fastclick.net
    O1 - Hosts: 109.92.142.185 media.fastclick.net
    O1 - Hosts: 109.170.21.186 spd.atdmt.com
    O1 - Hosts: 186.54.74.45 www.awaps.net
    O1 - Hosts: 105.116.161.207 www.fastclick.net
    O1 - Hosts: 108.51.94.92 awaps.net
    O1 - Hosts: 102.35.134.158 fastclick.net
    O1 - Hosts: 102.158.3.18 akamai.net
    O1 - Hosts: 179.147.199.183 www.antivir.de
    O1 - Hosts: 105.108.119.104 antivir.de
    O1 - Hosts: 181.87.27.164 drweb.com
    O1 - Hosts: 110.60.112.152 www.drweb.com
    O1 - Hosts: 173.72.89.247 drweb.ru
    O1 - Hosts: 111.9.106.84 www.clamav.net
    O1 - Hosts: 179.134.219.18 clamav.net
    O1 - Hosts: 104.145.107.4 www.bitdefender.ru
    O1 - Hosts: 186.223.18.161 bitdefender.ru
    O1 - Hosts: 100.125.216.116 open.by
    O1 - Hosts: 175.210.118.4 vba32.de
    O1 - Hosts: 106.43.202.48 www.open.by
    O1 - Hosts: 176.168.161.132 rs01.avast.com
    O1 - Hosts: 113.196.23.53 sm01.avast.com
    O1 - Hosts: 173.85.201.82 rs02.avast.com
    O1 - Hosts: 100.83.75.234 sm02.avast.com
    O1 - Hosts: 178.94.124.98 rs03.avast.com
    O1 - Hosts: 115.115.189.31 sm03.avast.com
    O1 - Hosts: 179.82.30.213 rs04.avast.com
    O1 - Hosts: 108.6.5.208 sm04.avast.com
    O1 - Hosts: 184.166.75.163 rs05.avast.com
    O1 - Hosts: 109.98.190.168 sm05.avast.com
    O1 - Hosts: 185.166.221.212 rs06.avast.com
    O1 - Hosts: 101.71.169.118 sm06.avast.com
    O1 - Hosts: 183.68.192.179 rs07.avast.com
    O1 - Hosts: 113.156.186.65 sm07.avast.com
    O1 - Hosts: 173.216.20.157 rs08.avast.com
    O1 - Hosts: 115.25.97.195 sm08.avast.com
    O1 - Hosts: 185.172.91.117 rs09.avast.com
    O1 - Hosts: 103.56.26.4 sm09.avast.com
    O1 - Hosts: 187.21.191.24 rs10.avast.com
    O1 - Hosts: 106.135.126.37 sm10.avast.com
    O1 - Hosts: 186.92.191.182 rs11.avast.com
    O1 - Hosts: 101.151.218.40 sm11.avast.com
    O1 - Hosts: 182.12.173.157 rs12.avast.com
    O1 - Hosts: 102.44.86.6 sm12.avast.com
    O1 - Hosts: 187.177.109.41 rs13.avast.com
    O1 - Hosts: 100.135.39.7 sm13.avast.com
    O1 - Hosts: 183.4.26.28 rs14.avast.com
    O1 - Hosts: 109.152.56.132 sm14.avast.com
    O1 - Hosts: 174.22.52.47 rs15.avast.com
    O1 - Hosts: 112.44.76.101 sm15.avast.com
    O1 - Hosts: 176.24.2.108 rs16.avast.com
    O1 - Hosts: 104.88.100.68 sm16.avast.com
    O1 - Hosts: 175.209.96.55 rs17.avast.com
    O1 - Hosts: 108.136.54.58 sm17.avast.com
    O1 - Hosts: 182.81.75.62 rs18.avast.com
    O1 - Hosts: 100.132.172.31 sm18.avast.com
    O1 - Hosts: 183.224.68.115 rs19.avast.com
    O1 - Hosts: 103.144.191.113 sm19.avast.com
    O1 - Hosts: 184.193.195.14 rs20.avast.com
    O1 - Hosts: 103.69.72.110 sm20.avast.com
    O1 - Hosts: 176.169.145.194 rs21.avast.com
    O1 - Hosts: 105.200.223.248 sm21.avast.com
    O1 - Hosts: 176.72.49.72 rs22.avast.com
    O1 - Hosts: 105.200.136.24 sm22.avast.com
    O1 - Hosts: 184.106.33.253 rs23.avast.com
    O1 - Hosts: 112.106.95.4 sm23.avast.com
    O1 - Hosts: 176.15.175.146 rs24.avast.com
    O1 - Hosts: 115.172.124.52 sm24.avast.com
    O1 - Hosts: 174.173.108.253 rs25.avast.com
    O1 - Hosts: 111.199.132.183 sm25.avast.com
    O1 - Hosts: 181.141.199.236 rs26.avast.com
    O1 - Hosts: 108.110.4.67 sm26.avast.com
    O1 - Hosts: 187.38.57.188 rs27.avast.com
    O1 - Hosts: 110.153.170.218 sm27.avast.com
    O1 - Hosts: 184.120.97.180 rs28.avast.com
    O1 - Hosts: 104.221.204.97 sm28.avast.com
    O1 - Hosts: 184.87.84.126 rs29.avast.com
    O1 - Hosts: 113.158.156.12 sm29.avast.com
    O1 - Hosts: 175.137.116.58 rs30.avast.com
    O1 - Hosts: 106.89.171.42 sm30.avast.com
    O1 - Hosts: 181.63.155.14 downloadhosting.core.ignum.cz
    O1 - Hosts: 108.171.61.165 download25.avast.com
    O1 - Hosts: 180.78.122.242 www.avast.com
    O1 - Hosts: 105.94.46.61 avast.com
    O1 - Hosts: 101.219.196.161 www.clamwin.com
    O1 - Hosts: 177.93.131.172 clamwin.com
    O1 - Hosts: 113.178.206.30 213.219.245.4
    O1 - Hosts: 178.169.49.160 files.referats.net
    O1 - Hosts: 104.83.9.105 database.clamav.net
    O1 - Hosts: 173.153.208.24 213.248.60.121
    O2 - BHO: Adobe PDF Reader -linkkiavustaja - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [CARPService] carpserv.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\ZoneAlarm\zlclient.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: ClientManager2.lnk = C:\Program Files\BUFFALO\Client Manager 2\ClientMgr2.exe
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O8 - Extra context menu item: Liitä aiemmin luotuun PDF-tiedostoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Muunna Adobe PDF -muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Muunna linkin kohde Adobe PDF -muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Muunna linkin kohde nykyiseen PDF-muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Muunna valinta Adobe PDF -muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Muunna valinta nykyiseen PDF-muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Muunna valitut linkit Adobe PDF -muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Muunna valitut linkit nykyiseen PDF-muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.euchannels.net/update/KooPlayer.ocx
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1145693771670
    O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
    O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Unknown owner - C:\Program Files\ewido anti-spyware 4.0\guard.exe (file missing)
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod-palvelu (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: MS Common Service - Unknown owner - C:\WINDOWS\system32\mscomserv.exe (file missing)
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: Neth - Unknown owner - C:\WINDOWS\system32\netid.exe (file missing)
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NMSAccess - Unknown owner - C:\Program Files\Cheetah Burner\Cheetah DVD Burner\NMSAccess.exe (file missing)
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: Win PPPe - Unknown owner - C:\WINDOWS\system32\winser.exe (file missing)
     
  5. Auttaja

    Auttaja Guest

    Laita uusi HijackThis logi, koneellasi tosiaan örkkejä :)
     
  6. Firefox07

    Firefox07 Member

    Joined:
    Feb 28, 2005
    Messages:
    41
    Likes Received:
    0
    Trophy Points:
    16
    Logfile of HijackThis v1.99.1
    Scan saved at 21:27:55, on 11.3.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\carpserv.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\BUFFALO\Client Manager 2\ClientMgr2.exe
    C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
    C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    C:\Program Files\CyberLink\Shared files\RichVideo.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\wbem\wmiapsrv.exe
    C:\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O1 - Hosts: 108.112.42.206 ad.doubleclick.net
    O1 - Hosts: 178.95.95.213 ad.fastclick.net
    O1 - Hosts: 107.116.117.138 ads.fastclick.net
    O1 - Hosts: 174.15.27.94 ar.atwola.com
    O1 - Hosts: 115.27.183.221 atdmt.com
    O1 - Hosts: 108.15.197.227 awaps.net
    O1 - Hosts: 180.66.164.240 banner.fastclick.net
    O1 - Hosts: 112.56.109.230 banners.fastclick.net
    O1 - Hosts: 180.140.140.115 click.atdmt.com
    O1 - Hosts: 104.148.31.185 clicks.atdmt.com
    O1 - Hosts: 111.57.62.146 engine.awaps.net
    O1 - Hosts: 100.178.73.135 fastclick.net
    O1 - Hosts: 109.92.142.185 media.fastclick.net
    O1 - Hosts: 109.170.21.186 spd.atdmt.com
    O1 - Hosts: 186.54.74.45 www.awaps.net
    O1 - Hosts: 105.116.161.207 www.fastclick.net
    O1 - Hosts: 108.51.94.92 awaps.net
    O1 - Hosts: 102.35.134.158 fastclick.net
    O1 - Hosts: 102.158.3.18 akamai.net
    O1 - Hosts: 179.147.199.183 www.antivir.de
    O1 - Hosts: 105.108.119.104 antivir.de
    O1 - Hosts: 181.87.27.164 drweb.com
    O1 - Hosts: 110.60.112.152 www.drweb.com
    O1 - Hosts: 173.72.89.247 drweb.ru
    O1 - Hosts: 111.9.106.84 www.clamav.net
    O1 - Hosts: 179.134.219.18 clamav.net
    O1 - Hosts: 104.145.107.4 www.bitdefender.ru
    O1 - Hosts: 186.223.18.161 bitdefender.ru
    O1 - Hosts: 100.125.216.116 open.by
    O1 - Hosts: 175.210.118.4 vba32.de
    O1 - Hosts: 106.43.202.48 www.open.by
    O1 - Hosts: 176.168.161.132 rs01.avast.com
    O1 - Hosts: 113.196.23.53 sm01.avast.com
    O1 - Hosts: 173.85.201.82 rs02.avast.com
    O1 - Hosts: 100.83.75.234 sm02.avast.com
    O1 - Hosts: 178.94.124.98 rs03.avast.com
    O1 - Hosts: 115.115.189.31 sm03.avast.com
    O1 - Hosts: 179.82.30.213 rs04.avast.com
    O1 - Hosts: 108.6.5.208 sm04.avast.com
    O1 - Hosts: 184.166.75.163 rs05.avast.com
    O1 - Hosts: 109.98.190.168 sm05.avast.com
    O1 - Hosts: 185.166.221.212 rs06.avast.com
    O1 - Hosts: 101.71.169.118 sm06.avast.com
    O1 - Hosts: 183.68.192.179 rs07.avast.com
    O1 - Hosts: 113.156.186.65 sm07.avast.com
    O1 - Hosts: 173.216.20.157 rs08.avast.com
    O1 - Hosts: 115.25.97.195 sm08.avast.com
    O1 - Hosts: 185.172.91.117 rs09.avast.com
    O1 - Hosts: 103.56.26.4 sm09.avast.com
    O1 - Hosts: 187.21.191.24 rs10.avast.com
    O1 - Hosts: 106.135.126.37 sm10.avast.com
    O1 - Hosts: 186.92.191.182 rs11.avast.com
    O1 - Hosts: 101.151.218.40 sm11.avast.com
    O1 - Hosts: 182.12.173.157 rs12.avast.com
    O1 - Hosts: 102.44.86.6 sm12.avast.com
    O1 - Hosts: 187.177.109.41 rs13.avast.com
    O1 - Hosts: 100.135.39.7 sm13.avast.com
    O1 - Hosts: 183.4.26.28 rs14.avast.com
    O1 - Hosts: 109.152.56.132 sm14.avast.com
    O1 - Hosts: 174.22.52.47 rs15.avast.com
    O1 - Hosts: 112.44.76.101 sm15.avast.com
    O1 - Hosts: 176.24.2.108 rs16.avast.com
    O1 - Hosts: 104.88.100.68 sm16.avast.com
    O1 - Hosts: 175.209.96.55 rs17.avast.com
    O1 - Hosts: 108.136.54.58 sm17.avast.com
    O1 - Hosts: 182.81.75.62 rs18.avast.com
    O1 - Hosts: 100.132.172.31 sm18.avast.com
    O1 - Hosts: 183.224.68.115 rs19.avast.com
    O1 - Hosts: 103.144.191.113 sm19.avast.com
    O1 - Hosts: 184.193.195.14 rs20.avast.com
    O1 - Hosts: 103.69.72.110 sm20.avast.com
    O1 - Hosts: 176.169.145.194 rs21.avast.com
    O1 - Hosts: 105.200.223.248 sm21.avast.com
    O1 - Hosts: 176.72.49.72 rs22.avast.com
    O1 - Hosts: 105.200.136.24 sm22.avast.com
    O1 - Hosts: 184.106.33.253 rs23.avast.com
    O1 - Hosts: 112.106.95.4 sm23.avast.com
    O1 - Hosts: 176.15.175.146 rs24.avast.com
    O1 - Hosts: 115.172.124.52 sm24.avast.com
    O1 - Hosts: 174.173.108.253 rs25.avast.com
    O1 - Hosts: 111.199.132.183 sm25.avast.com
    O1 - Hosts: 181.141.199.236 rs26.avast.com
    O1 - Hosts: 108.110.4.67 sm26.avast.com
    O1 - Hosts: 187.38.57.188 rs27.avast.com
    O1 - Hosts: 110.153.170.218 sm27.avast.com
    O1 - Hosts: 184.120.97.180 rs28.avast.com
    O1 - Hosts: 104.221.204.97 sm28.avast.com
    O1 - Hosts: 184.87.84.126 rs29.avast.com
    O1 - Hosts: 113.158.156.12 sm29.avast.com
    O1 - Hosts: 175.137.116.58 rs30.avast.com
    O1 - Hosts: 106.89.171.42 sm30.avast.com
    O1 - Hosts: 181.63.155.14 downloadhosting.core.ignum.cz
    O1 - Hosts: 108.171.61.165 download25.avast.com
    O1 - Hosts: 180.78.122.242 www.avast.com
    O1 - Hosts: 105.94.46.61 avast.com
    O1 - Hosts: 101.219.196.161 www.clamwin.com
    O1 - Hosts: 177.93.131.172 clamwin.com
    O1 - Hosts: 113.178.206.30 213.219.245.4
    O1 - Hosts: 178.169.49.160 files.referats.net
    O1 - Hosts: 104.83.9.105 database.clamav.net
    O1 - Hosts: 173.153.208.24 213.248.60.121
    O2 - BHO: Adobe PDF Reader -linkkiavustaja - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [CARPService] carpserv.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\ZoneAlarm\zlclient.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: ClientManager2.lnk = C:\Program Files\BUFFALO\Client Manager 2\ClientMgr2.exe
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O8 - Extra context menu item: Liitä aiemmin luotuun PDF-tiedostoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Muunna Adobe PDF -muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Muunna linkin kohde Adobe PDF -muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Muunna linkin kohde nykyiseen PDF-muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Muunna valinta Adobe PDF -muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Muunna valinta nykyiseen PDF-muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Muunna valitut linkit Adobe PDF -muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Muunna valitut linkit nykyiseen PDF-muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.euchannels.net/update/KooPlayer.ocx
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1145693771670
    O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
    O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Unknown owner - C:\Program Files\ewido anti-spyware 4.0\guard.exe (file missing)
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod-palvelu (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: MS Common Service - Unknown owner - C:\WINDOWS\system32\mscomserv.exe (file missing)
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: Neth - Unknown owner - C:\WINDOWS\system32\netid.exe (file missing)
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NMSAccess - Unknown owner - C:\Program Files\Cheetah Burner\Cheetah DVD Burner\NMSAccess.exe (file missing)
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: Win PPPe - Unknown owner - C:\WINDOWS\system32\winser.exe (file missing)
     
  7. Auttaja

    Auttaja Guest

    -Lataa tämä ohjelma!
    http://www.funkytoad.com/download/HostsXpert.zip
    - Tee uusi kansio: C:\HostsXpert
    - Pura kansioon C:\HostsXpert
    Täältä englanniksi lisäohjeita:
    http://metallica.geekstogo.com/xpcompressedexplanation.html
    - Paina HostsXpert.exe ajaaksesi sen (sen pitää siis olla tuolla C:\HostsXpert kansiossa)

    - Paina "Make Hosts Writable?" oikeassa yläkulmassa (jos toiminnassa)
    - Klikkaa "Restore Microsoft's Hosts File" ja sitten OK
    - Paina X lopettaaksesi

    ***********

    Lataa SDFix by AndyManchesta http://downloads.andymanchesta.com/RemovalTools/SDFix.zip ja tallenna se työpöydällesi.

    Käynnistä koneesi vikasietotilaan ja valitse tavallinen käyttäjätilisi:

    * Käynnistä tietokone
    * Kun kuulet koneen piippaavan, paina F8, kuitenkin ennen Windowsin logon esiintuloa
    * Seuraavaksi pitäisi ilmestyä valikko
    * Valitse valikosta vikasietotila.


    * Kun vikasietotilassa, pura tiedoston SDFix.zip sisältö (SDFix.exe) työpöydälle. Tuplakilikkaa työpöydälle ilmestynyttä sdfix.exe tiedostoa. Tiedosto purkaantuu ja asentaa itsensä siihen levyasemaan, minne on käyttöjärjestelmä on asennettu ja juureen ilmestyy kansio SDFix, ESIM C:\SDFix
    * Avaa SDFix-kansio ja tuplaklikkaa tiedostoa RunThis.bat käynnistääksesi ohjelman.
    * Paina Y käynnistääksesi skriptin.
    * Työkalu puhdistaa troijalaisen palvelut ja tekee myös joitakin korjauksia rekisteriin. Lopuksi se pyytää käynnistämään koneen uudelleen, "Press any key to Reboot".
    * Paina mitä tahansa näppäintä ja kone käynnistyy uudelleen.
    * Käynnistyminen kestää normaalia kauemmin sillä SDFix puhdistaa konetta.
    * Kun kone on käynnistynyt ja työpöytä latautunut, SDFix kertoo että puhdistus on suoritettu, "Finished".
    * Paina sitten mitä tahansa näppäintä sulkeaksesi skriptin ja ladataksesi pikakuvakkeet työpöydälle.
    * Lopuksi avaa SDFix kansio ja kopioi & liitä tiedoston Report.txt sisältö viestiketjuusi uuden HijackThis lokin kera.


     
  8. Firefox07

    Firefox07 Member

    Joined:
    Feb 28, 2005
    Messages:
    41
    Likes Received:
    0
    Trophy Points:
    16
    Suuret kiitokset... ( laitan vielä login )

    Logfile of HijackThis v1.99.1
    Scan saved at 22:29:27, on 11.3.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
    C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    C:\Program Files\CyberLink\Shared files\RichVideo.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\wbem\wmiapsrv.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\carpserv.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\BUFFALO\Client Manager 2\ClientMgr2.exe
    C:\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: Adobe PDF Reader -linkkiavustaja - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [CARPService] carpserv.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\ZoneAlarm\zlclient.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: ClientManager2.lnk = C:\Program Files\BUFFALO\Client Manager 2\ClientMgr2.exe
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O8 - Extra context menu item: Liitä aiemmin luotuun PDF-tiedostoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Muunna Adobe PDF -muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Muunna linkin kohde Adobe PDF -muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Muunna linkin kohde nykyiseen PDF-muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Muunna valinta Adobe PDF -muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Muunna valinta nykyiseen PDF-muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Muunna valitut linkit Adobe PDF -muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Muunna valitut linkit nykyiseen PDF-muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.euchannels.net/update/KooPlayer.ocx
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1145693771670
    O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
    O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Unknown owner - C:\Program Files\ewido anti-spyware 4.0\guard.exe (file missing)
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod-palvelu (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: MS Common Service - Unknown owner - C:\WINDOWS\system32\mscomserv.exe (file missing)
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NMSAccess - Unknown owner - C:\Program Files\Cheetah Burner\Cheetah DVD Burner\NMSAccess.exe (file missing)
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
     
  9. Auttaja

    Auttaja Guest

    Äläs vielä hätäile, tää oli vasta alkua :)

    Avaa hijackthis merkkaa ja paina fix checked näille:

    O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
    O23 - Service: MS Common Service - Unknown owner - C:\WINDOWS\system32\mscomserv.exe (file missing)

    Avaa suorita rivi ja kirjota siihen

    sc delete "MS Common Service"

    *****************
    laita piilotiedostot näkyviin

    * Avaa Oma Tietokone.
    * Valitse Työkalut ylämenusta ja klikkaa Kansion asetukset.
    * Valitse Näytä välilehti.
    * Piilotiedostot/kansiot kohdalla valitse Näytä piilotetut tiedostot ja kansiot.
    * Poista rasti ruudusta -> Piilota suojatut käyttöjärjestelmätiedostot
    * Klikkaa Kyllä varmistaaksesi muutokset.
    * Klikkaa OK.

    ***************

    Poista jos löytyy:
    C:\WINDOWS\system32\mscomserv.exe

    ****************

    Laita piilotiedostot piiloon
    *********************

    Lataa SmitfraudFix (by S!Ri) http://siri.urz.free.fr/Fix/SmitfraudFix.zip työpöydällesi.

    Printtaa ohjeet ulos tai tallenna nämä tekstitiedostoon.

    Käynnistä koneesi vikasietotilaan ja valitse tavallinen käyttäjätilisi.

    Vikasietotilaan pääset painamalla F8 käynnistyksen alussa piippauksen kuultuasi.


    Kun vikasietotilassa, tuplaklikkaa tiedostoa SmitfraudFix.exe
    Valitse optio #2 - Clean kirjoittamalla 2 ja painamalla "Enter" poistaaksesi tarttuneet tiedostot.

    Sinulta kysytään: "Registry cleaning - Do you want to clean the registry ?"; vastaa "Yes" kirjoittamalla Y ja paina "Enter" poistaaksesi työpöydän taustakuvan ja puhdistaaksesi tarttuneet rekisteriavaimet.

    Työkalu tarkistaa jos wininet.dll on tarttunut. Sinua saatetaan pyytää korvaamaan tarttunut .dll (jos löytyy); vastaa "Yes" kirjoittamalla Y ja painamalla "Enter".

    Työkalun saattaa tarvita käynnistää kone uudelleen; jos ei tee niin, käynnistä normaaliin Windowsiin.
    Tekstitiedosto ilmestyy, puhdistusprosessin jäljiltä; kopioi & liitä tämän raportin tulokset vastaukseesi.
    Raportti löytyy paikalliselta levyltäsi, useimmiten C:\rapport.txt.

    ***************

    [*]Käynnistä AVG Anti-Spyware.
    [*]Klikkaa "Update" kuvaketta päävalikossa. Sen jälkeen klikkaa "Update now" painiketta.
    [*]Sitten klikkaa "Start Update" kuvaketta jolloin päivitys alkaa.
    [*]Kun päivitykset on ladattu, klikkaa "Scanner" kuvaketta ikkunan ylälaidassa. Valitse sitten "Settings" välilehti.
    [*]Kun "Settings" valikko on auennut, klikkaa "Recommended actions" ja sitten valitse "Quarantine".
    [*]Sitten "Reports" valikon alta:
    [*]Laita täppi kohtaan "Automatically generate report after every scan"
    [*]Ota täppi pois kohdasta"Only if threats were found"
    [*]Sitten klikkaa "Shield" kuvaketta ikkunan ylälaidassa
    [*]"Resident shield is", muuta tila active:sta inactive:ksi
    [*]Sulje ohjelma, ÄLÄ skannaa vielä.

    Käynnistä tietokone vikasietotilaan:
    1. Käynnistä tietokone uudelleen.
    2. Kun tietokone käynnistyy, paina F8-näppäintä.
    3. Näyttöön tulee erilaisia käynnistysvaihtoehtoja.
    4. Valitse näppäimistön nuolinäppäinten avulla Vikasietotila.
    5. Paina ENTER-näppäintä.

    HUOM! Älä käytä muita ohjelmia AVG skannauksen aikana, tämä saattaa häiritä skannausta.
    [*]Kun vikasietotilassa, käynnistä AVG Anti-Spyware.
    [*]Klikkaa "Scanner" kuvaketta ikkunan ylälaidassa ja valitse "Scan" välilehti. Sitten klikkaa "Complete System Scan".
    [*]AVG aloittaa nyt tietokoneen skannaamisen, ole kärsivällinen sillä skannaus vie aikaa.
    Kun skannaus on valmis:
    TÄRKEÄÄ : Älä klikkaa "Save Scan Report" ennen kuin klikkaat "Apply all Actions"
    [*]Varmistu, että Set all elements to: näyttää Quarantine (1), jos ei, klikkaa linkkiä ja valitse Quarantine popup-valikosta.
    [*]Sinulta kysytään mitä tehdä jos infektioita löytyi, valitse silloin "Apply all actions"
    [​IMG]
    [*]Sitten klikkaa "Reports" kuvaketta ohjelma yläosasta.
    [*]Klikkaa "Save report as" painiketta ikkunan vasemmassa alalaidassa ja tallenna raportti työpöydälle.
    [*]Sulje ohjelma, käynnistä kone normaalisti ja lähetä AVG:n raportti viestiketjuusi.

    *******************

    Laita uusin HJT-logi
     
    Last edited by a moderator: Mar 11, 2007
  10. Firefox07

    Firefox07 Member

    Joined:
    Feb 28, 2005
    Messages:
    41
    Likes Received:
    0
    Trophy Points:
    16
    SmitFraudFix v2.148

    Scan done at 0:55:59,10, ma 12.03.2007
    Run from C:\Documents and Settings\xxxxxxxxxxxxxx\Ty”p”yt„\SmitfraudFix\SmitfraudFix
    OS: Microsoft Windows XP [versio 5.1.2600] - Windows_NT
    The filesystem type is NTFS
    Fix run in safe mode

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Killing process


    »»»»»»»»»»»»»»»»»»»»»»»» hosts

    127.0.0.1 localhost

    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "System"=""


    »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

    Registry Cleaning done.

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» End

    AVG Anti-Spyware ei löytänyt mitään...( siksi ei raporttia )

    Logfile of HijackThis v1.99.1
    Scan saved at 16:35:37, on 12.3.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\carpserv.exe
    C:\Program Files\ZoneAlarm\zlclient.exe
    C:\PROGRA~1\VIRUTO~1\ashDisp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\BUFFALO\Client Manager 2\ClientMgr2.exe
    C:\Program Files\Virutorjuntaohjelma\aswUpdSv.exe
    C:\Program Files\Virutorjuntaohjelma\ashServ.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
    C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    C:\Program Files\CyberLink\Shared files\RichVideo.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Virutorjuntaohjelma\ashMaiSv.exe
    C:\Program Files\Virutorjuntaohjelma\ashWebSv.exe
    C:\WINDOWS\System32\wbem\wmiapsrv.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: Adobe PDF Reader -linkkiavustaja - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [CARPService] carpserv.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\VIRUTO~1\ashDisp.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: ClientManager2.lnk = C:\Program Files\BUFFALO\Client Manager 2\ClientMgr2.exe
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O8 - Extra context menu item: Liitä aiemmin luotuun PDF-tiedostoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Muunna Adobe PDF -muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Muunna linkin kohde Adobe PDF -muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Muunna linkin kohde nykyiseen PDF-muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Muunna valinta Adobe PDF -muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Muunna valinta nykyiseen PDF-muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Muunna valitut linkit Adobe PDF -muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Muunna valitut linkit nykyiseen PDF-muotoon - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.euchannels.net/update/KooPlayer.ocx
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1145693771670
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Virutorjuntaohjelma\aswUpdSv.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Virutorjuntaohjelma\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Virutorjuntaohjelma\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Virutorjuntaohjelma\ashWebSv.exe" /service (file missing)
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
    O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Unknown owner - C:\Program Files\ewido anti-spyware 4.0\guard.exe (file missing)
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod-palvelu (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NMSAccess - Unknown owner - C:\Program Files\Cheetah Burner\Cheetah DVD Burner\NMSAccess.exe (file missing)
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
     
  11. Auttaja

    Auttaja Guest

    Nonii lokis on kunnossa :)
     
  12. Firefox07

    Firefox07 Member

    Joined:
    Feb 28, 2005
    Messages:
    41
    Likes Received:
    0
    Trophy Points:
    16
    Kovasti kiitoksia......

    Rautainen ammattitaito teillä täällä ja
    vastaisuudessa yritän olla varovaisempi koska
    totuushan yleensä on että käyttäjän
    oman tunaroinnin seurauksena tälle osastolle päädytään...
     

Share This Page