hidasteleva kone - hijackthis logi

Discussion in 'Virukset ja haittaohjelmat - HijackThis -logit' started by bomble, Dec 1, 2008.

  1. bomble

    bomble Regular member

    Joined:
    Apr 17, 2007
    Messages:
    278
    Likes Received:
    0
    Trophy Points:
    26
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 23:37:13, on 1.12.2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\nvsvc32.exe
    E:\medal of honor airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Microsoft IntelliType Pro\itype.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wbem\wmiapsrv.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Winamp\winamp.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - AppInit_DLLs: avgrsstx.dll
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
    O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PunkBuster (PnkBstrA) - Unknown owner - E:\medal of honor airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe

    --
    End of file - 7913 bytes


    kone saattaa jumittua yht äkkiä hetkeks aikaa ja käynistävalikko sun muut vähän väliä
     
  2. bomble

    bomble Regular member

    Joined:
    Apr 17, 2007
    Messages:
    278
    Likes Received:
    0
    Trophy Points:
    26
    vastauksia :)?
     
  3. Hujo

    Hujo Guest

    scannaa hjt:llä merkkaa paina Fix checked

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

    ==============

    Poista lisää poista sovelutuksesta

    Logitech Desktop Messenger

    Poista vikasiedossa kansio

    C:\Program Files\Logitech\Desktop Messenger

    =============

    Jos koneella on Malwarebytes' Anti-Malware ennestään suorita ensin päivitys aja sen jälkeen.

    Lataa Malwarebytes' Anti-Malware työpöydällesi.

    1. Tuplaklikkaa mbam-setup.exe ja seuraa ohjeita asentaaksesi ohjelman.
    2. Lopuksi varmistu, että seuraavat on valittu: Update Malwarebytes', Anti-Malwareja
    Launch Malwarebytes' Anti-Malware ja sen jälkeen klikkaaFinish.
    3. Jos päivitys löytyy. ohjelma lataa ja asentaa uusimman version.
    4. Kun ohjelma on latautunut, valitse Perform full scan ja klikkaa Scan.
    5. Kun skanni on valmis, klikkaa OK ja sitten Show Results nähdäksesi tulokset.
    6. Varmistu, että kaikki on merkitty ja klikkaa Remove Selected.
    7. Tämän jälkeen loki avautuu muistioon. Tallenna se paikkaan, josta löydät sen helposti. Loki
    löytyy myös täältä: C:\Documents and Settings\Käyttäjänimi\Application
    Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-päiväys.txt
    8. Lähetä lokin sisältö seuraavassa viestissäsi
     
  4. bomble

    bomble Regular member

    Joined:
    Apr 17, 2007
    Messages:
    278
    Likes Received:
    0
    Trophy Points:
    26
    alwarebytes' Anti-Malware 1.30
    Tietokantaversio: 1450
    Windows 5.1.2600 Service Pack 3

    2.12.2008 23:40:44
    mbam-log-2008-12-02 (23-40-44).txt

    Tarkistustyyppi: Täysi tarkistus (C:\|E:\|)
    Tarkistetut kohteet: 78251
    Kulunut aika: 30 minute(s), 20 second(s)

    Saastuneita muistiprosesseja: 0
    Saastuneita muistimoduuleja: 0
    Saastuneita rekisteriavaimia: 0
    Saastuneita rekisteriarvoja: 0
    Saastuneita rekisterikohteita: 0
    Saastuneita hakemistoja: 0
    Saastuneita tiedostoja: 0

    Saastuneita muistiprosesseja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita muistimoduuleja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita rekisteriavaimia:
    (Haitallisia kohteita ei löydetty)

    Saastuneita rekisteriarvoja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita rekisterikohteita:
    (Haitallisia kohteita ei löydetty)

    Saastuneita hakemistoja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita tiedostoja:
    (Haitallisia kohteita ei löydetty)

    eipä taida olla mitään
     
  5. Hujo

    Hujo Guest

    1.Lataa Combofix.exe työpöydällesi yhdestä linkistä:
    Combofix1
    Combofix2

    2. Tuplaklikkaa Combofix.exe tiedostoa ja seuraa ohjeistuksia.
    3. Kun työkalu on valmis, se tuottaa lokin. Lähetä tämä loki viesti ketjuusi.
    Huom! Älä klikkaile combofixin ikkunaa käytön aikana. Tämä saattaa aiheuttaa ohjelman jumiutumisen.
     
  6. bomble

    bomble Regular member

    Joined:
    Apr 17, 2007
    Messages:
    278
    Likes Received:
    0
    Trophy Points:
    26
    ComboFix 08-12-02.02 - kimmo 2008-12-03 22:19:20.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1035.18.2373 [GMT 2:00]
    Sijainti: c:\documents and settings\kimmo\Työpöytä\ComboFix.exe
    * Uusi palautuspiste luotu
    .

    ((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-11-03 to 2008-12-03 )))))))))))))))))
    .

    2008-12-02 23:09 . 2008-12-02 23:09 <KANSIO> d-------- c:\program files\Malwarebytes' Anti-Malware
    2008-12-02 23:09 . 2008-12-02 23:09 <KANSIO> d-------- c:\documents and settings\kimmo\Application Data\Malwarebytes
    2008-12-02 23:09 . 2008-12-02 23:09 <KANSIO> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
    2008-12-02 23:09 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
    2008-12-02 23:09 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
    2008-12-01 23:35 . 2008-12-01 23:35 <KANSIO> d-------- c:\program files\Trend Micro
    2008-12-01 22:43 . 2008-12-01 22:43 <KANSIO> d-------- c:\program files\Lavasoft
    2008-12-01 22:43 . 2008-12-01 22:45 <KANSIO> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
    2008-12-01 22:21 . 2008-12-01 23:28 <KANSIO> d-------- c:\program files\Spybot - Search & Destroy
    2008-12-01 22:21 . 2008-12-01 23:32 <KANSIO> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2008-12-01 22:04 . 2008-12-01 22:05 <KANSIO> d-------- c:\program files\Winamp
    2008-12-01 22:04 . 2008-12-02 00:53 <KANSIO> d-------- c:\documents and settings\kimmo\Application Data\Winamp
    2008-12-01 20:36 . 2008-12-01 20:36 21,840 --a------ c:\windows\system32\SIntfNT.dll
    2008-12-01 20:36 . 2008-12-01 20:36 17,212 --a------ c:\windows\system32\SIntf32.dll
    2008-12-01 20:36 . 2008-12-01 20:36 12,067 --a------ c:\windows\system32\SIntf16.dll
    2008-12-01 18:45 . 2008-12-01 18:45 94,208 --a------ c:\windows\DIIUnin.exe
    2008-12-01 18:45 . 2008-12-01 20:37 35,731 --a------ c:\windows\DIIUnin.dat
    2008-12-01 18:45 . 2008-12-01 18:45 2,829 --a------ c:\windows\DIIUnin.pif
    2008-12-01 18:39 . 2008-12-01 20:38 <KANSIO> d-------- c:\program files\Diablo II
    2008-12-01 18:17 . 2008-12-01 18:17 <KANSIO> d-------- c:\program files\Java
    2008-12-01 18:17 . 2008-12-01 18:17 410,976 --a------ c:\windows\system32\deploytk.dll
    2008-12-01 18:17 . 2008-12-01 18:17 73,728 --a------ c:\windows\system32\javacpl.cpl
    2008-12-01 08:59 . 2008-12-01 19:20 <KANSIO> d--h----- C:\$AVG8.VAULT$
    2008-11-30 20:43 . 2008-12-02 23:48 <KANSIO> d-------- c:\documents and settings\kimmo\Application Data\LimeWire
    2008-11-30 19:25 . 2008-11-04 09:35 499,712 --a------ c:\windows\system32\msvcp71.dll
    2008-11-30 19:25 . 2008-11-04 09:35 348,160 --a------ c:\windows\system32\msvcr71.dll
    2008-11-30 19:24 . 2008-11-30 19:25 <KANSIO> d-------- c:\windows\system32\Adobe
    2008-11-30 19:20 . 2008-12-01 15:55 <KANSIO> dr------- c:\documents and settings\Vieras\Omat tiedostot
    2008-11-30 19:20 . 2008-11-30 19:20 <KANSIO> d-------- c:\documents and settings\Vieras\Application Data\Logitech
    2008-11-30 19:19 . 2008-11-28 02:02 <KANSIO> d--h----- c:\documents and settings\Vieras\Verkkoympäristö
    2008-11-30 19:19 . 2008-11-30 19:24 <KANSIO> d-------- c:\documents and settings\Vieras\Työpöytä
    2008-11-30 19:19 . 2008-11-28 02:02 <KANSIO> d--h----- c:\documents and settings\Vieras\Tulostinympäristö
    2008-11-30 19:19 . 2008-11-30 19:20 <KANSIO> dr------- c:\documents and settings\Vieras\Suosikit
    2008-11-30 19:19 . 2008-11-28 18:10 <KANSIO> d--h----- c:\documents and settings\Vieras\Mallit
    2008-11-30 19:19 . 2008-11-28 02:02 <KANSIO> dr------- c:\documents and settings\Vieras\Käynnistä-valikko
    2008-11-30 19:19 . 2008-11-30 19:20 <KANSIO> d-------- c:\documents and settings\Vieras
    2008-11-30 18:44 . 2008-11-28 18:25 223 --ahs---- C:\BOOT.BKK
    2008-11-30 18:43 . 2008-11-30 18:43 <KANSIO> d-------- c:\program files\TGTSoft
    2008-11-30 18:38 . 2008-04-25 19:41 218,624 --a--c--- c:\windows\system32\dllcache\uxtheme.dll
    2008-11-29 16:27 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
    2008-11-29 16:27 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
    2008-11-29 16:27 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
    2008-11-29 14:14 . 2008-11-29 14:14 <KANSIO> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
    2008-11-28 23:41 . 2008-12-01 18:47 <KANSIO> d-------- c:\program files\Lavalys
    2008-11-28 23:32 . 2008-11-28 23:32 <KANSIO> d-------- c:\documents and settings\kimmo\Contacts
    2008-11-28 23:31 . 2008-11-28 23:32 <KANSIO> d-------- c:\program files\LimeWire
    2008-11-28 23:28 . 2008-11-28 23:31 <KANSIO> d-------- c:\program files\Windows Live
    2008-11-28 23:28 . 2008-11-28 23:29 <KANSIO> d--hsc--- c:\program files\Common Files\WindowsLiveInstaller
    2008-11-28 23:28 . 2008-11-28 23:28 <KANSIO> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
    2008-11-28 23:23 . 2008-11-28 23:23 <KANSIO> d-------- c:\program files\Yahoo!
    2008-11-28 23:23 . 2008-11-28 23:23 <KANSIO> d-------- c:\program files\uTorrent
    2008-11-28 23:23 . 2008-12-03 21:46 <KANSIO> d-------- c:\documents and settings\kimmo\Application Data\uTorrent
    2008-11-28 23:22 . 2008-11-28 23:23 <KANSIO> d-------- c:\program files\CCleaner
    2008-11-28 22:26 . 2008-11-28 22:26 <KANSIO> dr-h----- c:\documents and settings\kimmo\Application Data\SecuROM
    2008-11-28 22:26 . 2008-11-28 22:26 107,888 --a------ c:\windows\system32\CmdLineExt.dll
    2008-11-28 22:25 . 2008-11-28 22:25 <KANSIO> d-------- c:\windows\system32\LogFiles
    2008-11-28 21:58 . 2006-09-28 16:05 2,414,360 --a------ c:\windows\system32\d3dx9_31.dll
    2008-11-28 21:58 . 2006-09-28 16:04 68,888 --a------ c:\windows\system32\xinput1_3.dll
    2008-11-28 21:57 . 2008-11-28 21:57 <KANSIO> d-------- c:\windows\system32\AGEIA
    2008-11-28 21:57 . 2008-12-01 22:43 <KANSIO> d-------- c:\program files\Common Files\Wise Installation Wizard
    2008-11-28 21:57 . 2008-11-28 21:57 <KANSIO> d-------- c:\program files\AGEIA Technologies
    2008-11-28 21:51 . 2008-11-28 21:51 <KANSIO> d-------- c:\documents and settings\kimmo\Application Data\Logitech
    2008-11-28 21:51 . 2008-11-28 21:51 127,034 -r------- c:\windows\bwUnin-8.1.1.50-8876480SL.exe
    2008-11-28 21:50 . 2008-11-28 21:50 0 --ah----- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
    2008-11-28 21:50 . 2008-11-28 21:50 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
    2008-11-28 21:50 . 2008-11-28 21:50 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
    2008-11-28 21:49 . 2008-11-28 21:51 <KANSIO> d-------- c:\program files\Logitech
    2008-11-28 21:49 . 2008-11-28 21:51 <KANSIO> d-------- c:\program files\Common Files\Logishrd
    2008-11-28 21:49 . 2008-11-28 21:49 <KANSIO> d-------- c:\documents and settings\All Users\Application Data\Logitech
    2008-11-28 21:49 . 2007-11-15 10:06 301,656 --a------ c:\windows\system32\BtCoreIf.dll
    2008-11-28 21:49 . 2007-11-15 10:07 170,512 --a------ c:\windows\system32\kemutb.dll
    2008-11-28 21:49 . 2007-11-15 10:07 141,840 --a------ c:\windows\system32\KemUtil.dll
    2008-11-28 21:49 . 2007-11-15 10:07 117,264 --a------ c:\windows\system32\KemWnd.dll
    2008-11-28 21:49 . 2007-11-15 10:07 76,304 --a------ c:\windows\system32\KemXML.dll
    2008-11-28 21:48 . 2008-11-28 21:48 <KANSIO> d-------- c:\documents and settings\All Users\Application Data\LogiShrd
    2008-11-28 21:46 . 2008-11-28 21:46 <KANSIO> d-------- c:\program files\Microsoft IntelliType Pro
    2008-11-28 21:46 . 2008-11-28 21:46 0 --a------ c:\windows\nsreg.dat
    2008-11-28 21:43 . 2008-04-13 20:45 32,128 --a------ c:\windows\system32\drivers\usbccgp.sys
    2008-11-28 21:43 . 2008-04-13 20:45 32,128 --a--c--- c:\windows\system32\dllcache\usbccgp.sys
    2008-11-28 21:43 . 2008-04-14 18:11 21,504 --a------ c:\windows\system32\hidserv.dll
    2008-11-28 21:43 . 2008-04-14 18:11 21,504 --a--c--- c:\windows\system32\dllcache\hidserv.dll
    2008-11-28 21:43 . 2008-04-14 17:46 14,720 --a------ c:\windows\system32\drivers\kbdhid.sys
    2008-11-28 21:43 . 2008-04-14 17:46 14,720 --a--c--- c:\windows\system32\dllcache\kbdhid.sys
    2008-11-28 20:36 . 2008-11-28 20:36 <KANSIO> d-------- c:\windows\system32\fi
    2008-11-28 20:36 . 2008-11-28 20:36 <KANSIO> d-------- c:\windows\system32\bits
    2008-11-28 20:36 . 2008-11-28 20:36 <KANSIO> d-------- c:\windows\l2schemas
    2008-11-28 20:34 . 2008-11-28 20:34 <KANSIO> d-------- c:\windows\ServicePackFiles
    2008-11-28 20:29 . 2008-11-28 20:29 <KANSIO> d-------- c:\windows\EHome
    2008-11-28 20:19 . 2008-11-28 20:36 <KANSIO> d-------- c:\windows\system32\fi-fi
    2008-11-28 20:19 . 2008-10-03 19:12 6,066,176 -----c--- c:\windows\system32\dllcache\ieframe.dll
    2008-11-28 20:19 . 2007-04-17 11:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
    2008-11-28 20:19 . 2007-03-08 07:10 1,011,712 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
    2008-11-28 20:19 . 2008-08-26 10:12 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
    2008-11-28 20:19 . 2008-08-26 10:12 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
    2008-11-28 20:19 . 2008-08-26 10:12 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
    2008-11-28 20:19 . 2008-08-26 10:12 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
    2008-11-28 20:19 . 2008-08-26 10:12 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
    2008-11-28 20:19 . 2008-08-25 10:38 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
    2008-11-28 19:40 . 2004-08-03 22:41 1,309,184 --------- c:\windows\system32\drivers\mtlstrm.sys
    2008-11-28 19:39 . 2004-09-14 16:06 701,440 --------- c:\windows\system32\drivers\ati2mtag.sys
    2008-11-28 19:26 . 2008-06-14 19:34 272,128 --------- c:\windows\system32\drivers\bthport.sys
    2008-11-28 19:26 . 2008-06-14 19:34 272,128 -----c--- c:\windows\system32\dllcache\bthport.sys
    2008-11-28 19:26 . 2008-08-14 12:04 138,496 -----c--- c:\windows\system32\dllcache\afd.sys
    2008-11-28 19:25 . 2008-08-14 15:25 2,191,488 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
    2008-11-28 19:25 . 2008-08-14 15:25 2,147,840 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
    2008-11-28 19:25 . 2008-08-14 15:25 2,068,352 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
    2008-11-28 19:25 . 2008-08-14 15:24 2,026,496 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
    2008-11-28 19:25 . 2008-09-15 17:27 1,846,656 -----c--- c:\windows\system32\dllcache\win32k.sys
    2008-11-28 19:25 . 2008-04-11 21:05 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
    2008-11-28 19:25 . 2008-10-24 13:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
    2008-11-28 19:25 . 2008-10-15 18:37 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
    2008-11-28 19:25 . 2008-09-08 12:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
    2008-11-28 19:25 . 2008-05-08 16:02 203,136 -----c--- c:\windows\system32\dllcache\rmcast.sys
    2008-11-28 19:24 . 2008-12-03 08:38 <KANSIO> d-------- c:\windows\system32\drivers\Avg
    2008-11-28 19:24 . 2008-11-28 19:24 <KANSIO> d-------- c:\program files\AVG
    2008-11-28 19:24 . 2008-11-28 19:24 <KANSIO> d-------- c:\documents and settings\All Users\Application Data\avg8
    2008-11-28 19:24 . 2008-11-28 19:24 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys
    2008-11-28 19:24 . 2008-11-28 19:24 76,040 --a------ c:\windows\system32\drivers\avgtdix.sys
    2008-11-28 19:24 . 2008-11-28 19:24 10,520 --a------ c:\windows\system32\avgrsstx.dll
    2008-11-28 19:23 . 2008-11-30 03:00 <KANSIO> d--h----- c:\windows\$hf_mig$
    2008-11-28 19:19 . 2008-11-28 19:19 13,646 --a------ c:\windows\system32\wpa.bak
    2008-11-28 19:16 . 2008-11-28 19:16 <KANSIO> d--hs---- c:\documents and settings\kimmo\UserData

    .
    (((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-12-01 18:21 --------- d--h--w c:\program files\InstallShield Installation Information
    2008-12-01 18:21 --------- d-----w c:\program files\Common Files\InstallShield
    2008-11-28 18:22 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee
    2008-11-28 16:31 --------- d-----w c:\program files\ASRock Utility
    2008-11-28 16:25 --------- d-----w c:\program files\AMD
    2008-11-28 16:25 --------- d-----w c:\documents and settings\kimmo\Application Data\InstallShield
    2008-11-28 16:23 --------- d-----w c:\program files\NVIDIA Corporation
    2008-11-28 16:20 315,392 ----a-w c:\windows\HideWin.exe
    2008-11-28 16:20 --------- d-----w c:\program files\Realtek
    2008-11-28 16:14 --------- d-----w c:\program files\microsoft frontpage
    2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
    2008-10-16 12:13 202,776 ----a-w c:\windows\system32\wuweb.dll
    2008-10-16 12:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
    2008-10-16 12:12 561,688 ----a-w c:\windows\system32\wuapi.dll
    2008-10-16 12:12 323,608 ----a-w c:\windows\system32\wucltui.dll
    2008-10-16 12:09 92,696 ----a-w c:\windows\system32\cdm.dll
    2008-10-16 12:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
    2008-10-16 12:09 43,544 ----a-w c:\windows\system32\wups2.dll
    2008-10-16 12:08 34,328 ----a-w c:\windows\system32\wups.dll
    2008-09-15 15:27 1,846,656 ----a-w c:\windows\system32\win32k.sys
    2008-09-10 01:15 1,307,648 ------w c:\windows\system32\msxml6.dll
    2008-09-04 17:16 1,106,944 ----a-w c:\windows\system32\msxml3.dll
    .

    (((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-01-26 13508608]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-01-26 86016]
    "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-28 1261336]
    "itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2007-08-31 988584]
    "WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-04 36352]
    "RTHDCPL"="RTHDCPL.EXE" [2007-10-25 c:\windows\RTHDCPL.exe]
    "nwiz"="nwiz.exe" [2008-01-26 c:\windows\system32\nwiz.exe]
    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 c:\windows\KHALMNPR.Exe]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

    c:\documents and settings\All Users\K„ynnist„-valikko\Ohjelmat\K„ynnistys\
    Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-11-28 67128]
    Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-11-28 784912]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
    2007-11-15 10:10 72208 c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=avgrsstx.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
    @=""

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
    "e:\\medal of honor airborne\\UnrealEngine3\\Binaries\\MOHA.exe"=
    "c:\\Program Files\\uTorrent\\uTorrent.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-28 97928]
    R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-11-28 875288]
    R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-11-28 231704]
    R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-11-28 76040]

    *Newly Created Service* - PROCEXP90
    .
    'Ajoitetut tehtävät'-kansion sisältö

    2008-11-28 c:\windows\Tasks\Microsoft_Hardware_Launch_IType_exe.job
    - c:\program files\Microsoft IntelliType Pro\itype.exe [2007-08-31 21:13]
    .
    - - - - POISTETUT JÄMÄRIVIT - - - -

    HKCU-Run-ASRock OC Tuner - (no file)


    .
    ------- Täydentävä tarkistus -------
    .
    FireFox -: Profile - c:\documents and settings\kimmo\Application Data\Mozilla\Firefox\Profiles\z96kcm7z.default\
    FireFox -: prefs.js - STARTUP.HOMEPAGE - GOOGLE.COM
    FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
    FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
    FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
    FF -: plugin - c:\program files\Yahoo!\Common\npyaxmpb.dll
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-12-03 22:22:30
    Windows 5.1.2600 Service Pack 3 NTFS

    tarkistaa piilotettuja prosesseja ...

    tarkistaa piilotettuja käynnistysarvoja ...

    tarkistaa piilotettuja tiedostoja ...

    tarkistus on valmis
    piilotetut tiedostot: 0

    **************************************************************************
    .
    --------------------- Prosesseihin ladatut DLLt ---------------------

    - - - - - - - > 'winlogon.exe'(732)
    c:\windows\system32\avgrsstx.dll
    c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
    c:\program files\common files\logishrd\bluetooth\LBTServ.dll

    - - - - - - - > 'lsass.exe'(840)
    c:\windows\system32\avgrsstx.dll
    c:\windows\system32\nvLsp.dll
    .
    Valmistumisajankohta: 2008-12-03 22:23:08
    ComboFix-quarantined-files.txt 2008-12-03 20:23:06

    Ennen ajoa: 29 639 540 736 tavua vapaana
    Ajon jälkeen: 29,649,858,560 tavua vapaana

    WindowsXP-KB310994-SP2-Home-BootDisk-FIN.EXE
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer

    248 --- E O F --- 2008-11-30 15:51:25
     
  7. Hujo

    Hujo Guest

    Lataa OTMoveIt
    OTMoveIt ja tallenna se työpöydällesi.

    Tuplaklikkaa OTMoveIt.exe.
    Klikkaa CleanUp!.
    Valitse Yes kun kysytään "Begin cleanup Process?".
    Jos pyydetään, että saako koneen käynnistää uudeelleen, valitse Yes.OTMoveIt poistaa itsensä kun se on valmis, jos näin ei käy poista se itse.

    HUOM: Jos palomuurisi tai joku muu tietoturvaohjelma varoittaa, että OTMoveIt yrittää päästä nettin, niin anna sen päästä sinne.

    ============

    Lataa Tästä Ccleaner
    CCleaner v 2.14.750.- Standard Build, ÄLÄ aseenna Yahoo toolbaria!
    Asennuksessa poista merkki/rasti kohdasta "asenna Yahoo! toolbar/työkalupalkki".
    Asennuksen jälkeen aukaise CCleaneri.
    Valitse vasemmalta pystyrivistä Options.
    Valitse viereisestä pystyrivistä Settings.
    Language kohtaan valitse Suomi.

    Puhdistaja
    Valitse vasemmalta pystyrivistä Puhdistaja.
    Paina alhaalta Tutki.
    Nyt CCleaneri tutkii, mitä voidaan poistaa (tempit, cookiessit jne.).
    Kun tutkiminen on valmis, paina Aja CCleaner.
    Nyt CCleaneri poistaa löydetyt tempit, cookiessit jne.

    Rekisterin virheiden korjaus
    Valitse vasemmalta pystyrivistä Rekisteri.
    Paina alhaalta Etsi rekisterin virheitä.
    Kun etsintä on valmis ja olet varma, että haluat korjata ne rivit jotka ovat merkattuja, niin paina Korjaa valitut rekisterin virheet.
    Sinulta kysytään "haluatko varmuuskopioida muutokset rekisteriin", paina Kyllä. Tallenna varmuuskopio vaikka "Omat tiedostot" -kansioon.
    Klikkaa uudesta aukeavasta ikkunasta Korjaa kaikki valitut virheet.
    Saat vielä varmistus kysymyksen, paina Ok.
    Kun virheet on korjattu, paina Sulje.
    Nyt voit sulkea CCleanerin painamalla oikealta ylhäältä punaista rastia.
     
  8. bomble

    bomble Regular member

    Joined:
    Apr 17, 2007
    Messages:
    278
    Likes Received:
    0
    Trophy Points:
    26
    nojoo eipä tarvitse enään, heitti bluescreenin ja ide kovalevy tais mennä hajal, ei näkyny biosissa sitä enään. mutta kiitos kuitenki o/
     
  9. Hujo

    Hujo Guest

    Niin se teknikka sitten sanoi sopimuksen irti
     

Share This Page