HJT-logi+kun menee 1.6:sta pelaamaan/pelissä niin IE alkaa heittämään pop-uppeja.

Discussion in 'Virukset ja haittaohjelmat - HijackThis -logit' started by Mestaus, Apr 12, 2007.

  1. Mestaus

    Mestaus Regular member

    Joined:
    Dec 21, 2005
    Messages:
    1,141
    Likes Received:
    0
    Trophy Points:
    46
    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 21:40:33, on 12.4.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    F:\WINDOWS\System32\smss.exe
    F:\WINDOWS\system32\winlogon.exe
    F:\WINDOWS\system32\services.exe
    F:\WINDOWS\system32\lsass.exe
    F:\WINDOWS\system32\svchost.exe
    F:\WINDOWS\System32\svchost.exe
    F:\Program Files\Sygate\SPF\smc.exe
    F:\WINDOWS\Explorer.EXE
    F:\WINDOWS\system32\spoolsv.exe
    F:\WINDOWS\SOUNDMAN.EXE
    F:\Program Files\MessengerPlus! 3\MsgPlus.exe
    F:\Program Files\Logitech\SetPoint\SetPoint.exe
    F:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
    F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    F:\WINDOWS\system32\nvsvc32.exe
    F:\WINDOWS\system32\svchost.exe
    F:\WINDOWS\system32\wscntfy.exe
    F:\Program Files\Mozilla Firefox\firefox.exe
    F:\Program Files\MSN Messenger\msnmsgr.exe
    F:\Program Files\Winamp\winamp.exe
    C:\HiJackThis_v2.0.0.0\HiJackThis_v2.0.0.0.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [NeroFilterCheck] F:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [MessengerPlus3] "F:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [SmcService] F:\PROGRA~1\Sygate\SPF\smc.exe -startgui
    O4 - HKCU\..\Run: [MessengerPlus3] "F:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [msnmsgr] "F:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Logitech SetPoint.lnk = F:\Program Files\Logitech\SetPoint\SetPoint.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - F:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - F:\WINDOWS\system32\browseui.dll
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Loogisen levyn hallinnan valvontapalvelu (dmadmin) - Unknown owner - F:\WINDOWS\System32\dmadmin.exe
    O23 - Service: Tapahtumaloki (Eventlog) - Unknown owner - F:\WINDOWS\system32\services.exe
    O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu (ImapiService) - Unknown owner - F:\WINDOWS\system32\imapi.exe
    O23 - Service: NetMeeting etätyöpöydän jakaminen (mnmsrvc) - Unknown owner - F:\WINDOWS\system32\mnmsrvc.exe
    O23 - Service: NBService - Nero AG - F:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - F:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Plug and Play (PlugPlay) - Unknown owner - F:\WINDOWS\system32\services.exe
    O23 - Service: Älykortti (SCardSvr) - Unknown owner - F:\WINDOWS\System32\SCardSvr.exe
    O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - F:\Program Files\Sygate\SPF\smc.exe
    O23 - Service: Resurssilokit ja -hälytykset (SysmonLog) - Unknown owner - F:\WINDOWS\system32\smlogsvc.exe
    O23 - Service: WMI resurssisovitin (WmiApSrv) - Unknown owner - F:\WINDOWS\system32\wbem\wmiapsrv.exe

    --
    End of file - 4488 bytes
     
  2. Auttaja

    Auttaja Guest

    http://www.majorgeeks.com/download3155.html

    Lataa vaikka tuolta viimeisin vakaa versio..

    **********



    1. Lataa combofix.exe työpöydällesi jommastakummasta linkistä:
    http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    2. Tuplaklikkaa combofix.exe tiedostoa ja seuraa ohjeistuksia.
    3. Kun työkalu on valmis, se tuottaa lokin. (C:\ComboFix.txt) Lähetä tämä loki viesti ketjuusi.
    Huom! Älä klikkaile combofixin ikkunaa käytön aikana. Tämä saattaa aiheuttaa ohjelman jumiutumisen.

    Uusi hjtlogi
     
    Last edited by a moderator: Apr 12, 2007
  3. Mestaus

    Mestaus Regular member

    Joined:
    Dec 21, 2005
    Messages:
    1,141
    Likes Received:
    0
    Trophy Points:
    46
    "Omistaja" - 07-04-13 2:57:23 Service Pack 2
    ComboFix 07-04-05 - Running from: "F:\Documents and Settings\Omistaja.-.001\Ty”p”yt„"


    (((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


    F:\WINDOWS\system32\taskmgr.com
    F:\WINDOWS\regedit.com


    ((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


    -------\LEGACY_MCHINJDRV


    ((((((((((((((((((((((((((((((( Files Created from 2007-03-13 to 2007-04-13 ))))))))))))))))))))))))))))))))))


    2007-04-13 00:30 <KANSIO> d-------- F:\Program Files\Rockstar Games
    2007-04-13 00:26 <KANSIO> d-------- F:\Program Files\PowerISO
    2007-04-12 21:18 83,096 --a------ F:\WINDOWS\system32\SSSensor.dll
    2007-04-12 21:18 60,496 --a------ F:\WINDOWS\system32\drivers\Teefer.sys
    2007-04-12 21:18 21,075 --a------ F:\WINDOWS\system32\drivers\wpsdrvnt.sys
    2007-04-12 21:18 14,568 --a------ F:\WINDOWS\system32\drivers\wg6n.sys
    2007-04-12 21:18 14,568 --a------ F:\WINDOWS\system32\drivers\wg5n.sys
    2007-04-12 21:18 14,568 --a------ F:\WINDOWS\system32\drivers\wg4n.sys
    2007-04-12 21:18 14,568 --a------ F:\WINDOWS\system32\drivers\wg3n.sys
    2007-04-12 21:18 <KANSIO> d-------- F:\Program Files\Sygate
    2007-04-12 18:07 5,632 --a------ F:\WINDOWS\system32\ptpusb.dll
    2007-04-12 18:07 159,232 --a------ F:\WINDOWS\system32\ptpusd.dll
    2007-04-12 18:07 15,104 --a------ F:\WINDOWS\system32\drivers\usbscan.sys
    2007-04-11 13:02 86,016 --a------ F:\WINDOWS\unvise32.exe
    2007-04-11 13:00 <KANSIO> d-------- F:\Program Files\Postal2
    2007-04-09 16:33 <KANSIO> d-------- F:\Program Files\AusLogics Disk Defrag
    2007-04-09 13:44 <KANSIO> d-------- F:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Acid stupid mfcd axis
    2007-04-09 13:43 <KANSIO> d-------- F:\DOCUME~1\ANALCO~1.001\APPLIC~1\BlahMailType
    2007-04-08 22:03 <KANSIO> d-------- F:\Program Files\Steam
    2007-04-08 01:10 <KANSIO> d-------- F:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Messenger Plus!
    2007-04-08 01:09 <KANSIO> d-------- F:\Program Files\MessengerPlus! 3
    2007-04-07 17:34 255,848 --a------ F:\WINDOWS\system32\xactengine2_6.dll
    2007-04-07 17:34 251,672 --a------ F:\WINDOWS\system32\xactengine2_5.dll
    2007-04-07 04:04 <KANSIO> d-a------ F:\WINDOWS\zts2.exe
    2007-04-07 04:04 <KANSIO> d-a------ F:\WINDOWS\system32\vcmgcd32.dll
    2007-04-07 04:04 <KANSIO> d-a------ F:\WINDOWS\system32\iifgfgf.dll
    2007-04-07 04:04 <KANSIO> d-a------ F:\WINDOWS\rundll16.exe
    2007-04-07 04:04 <KANSIO> d-a------ F:\WINDOWS\rundl132.dll
    2007-04-07 04:04 <KANSIO> d-a------ F:\WINDOWS\logo1_.exe
    2007-04-07 03:55 146,944 --a------ F:\WINDOWS\R.COM
    2007-04-07 03:55 138,240 --a------ F:\WINDOWS\system32\T.COM
    2007-04-05 20:04 <KANSIO> d-------- F:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Windows Genuine Advantage
    2007-04-05 19:37 <KANSIO> d-------- F:\Program Files\ToniArts
    2007-04-05 18:47 <KANSIO> d-------- F:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\TEMP
    2007-04-03 20:59 3,968 --a------ F:\WINDOWS\system32\drivers\AvgAsCln.sys
    2007-04-03 20:06 <KANSIO> d-------- F:\DOCUME~1\LOCALS~1.002\APPLIC~1\Ahead
    2007-04-02 23:55 68,888 --a------ F:\WINDOWS\system32\xinput1_3.dll
    2007-04-02 23:55 62,744 --a------ F:\WINDOWS\system32\xinput1_2.dll
    2007-04-02 23:55 237,848 --a------ F:\WINDOWS\system32\xactengine2_4.dll
    2007-04-02 23:55 236,824 --a------ F:\WINDOWS\system32\xactengine2_3.dll
    2007-04-02 23:55 2,414,360 --a------ F:\WINDOWS\system32\d3dx9_31.dll
    2007-04-02 23:55 15,128 --a------ F:\WINDOWS\system32\x3daudio1_1.dll
    2007-04-02 23:48 <KANSIO> d-------- F:\Program Files\Ubisoft
    2007-04-02 23:48 <KANSIO> d-------- F:\DOCUME~1\ANALCO~1.001\APPLIC~1\InstallShield
    2007-04-02 21:32 <KANSIO> d-------- F:\DOCUME~1\ANALCO~1.001\APPLIC~1\Ahead
    2007-04-02 21:30 <KANSIO> d-------- F:\Program Files\Nero
    2007-04-02 21:30 <KANSIO> d-------- F:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Nero
    2007-04-02 14:59 <KANSIO> d-------- F:\Program Files\Lavasoft
    2007-04-02 14:59 <KANSIO> d-------- F:\DOCUME~1\ANALCO~1.001\APPLIC~1\Lavasoft
    2007-04-01 20:47 <KANSIO> d-------- F:\DOCUME~1\ANALCO~1.001\APPLIC~1\Opera
    2007-04-01 19:45 <KANSIO> d-------- F:\DOCUME~1\ANALCO~1.001\APPLIC~1\DivX
    2007-04-01 15:02 25,992 --a------ F:\WINDOWS\system32\pgdfgsvc.exe
    2007-04-01 04:16 <KANSIO> d-------- F:\Program Files\DivX
    2007-03-31 20:15 2,297,552 --a------ F:\WINDOWS\system32\d3dx9_26.dll
    2007-03-31 03:24 1,168 --a------ F:\WINDOWS\mozver.dat
    2007-03-31 02:41 <KANSIO> d-------- F:\DOCUME~1\ANALCO~1.001\APPLIC~1\Command & Conquer 3 Tiberium Wars
    2007-03-31 00:53 <KANSIO> d-------- F:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Spybot - Search & Destroy
    2007-03-31 00:45 <KANSIO> d-------- F:\Program Files\CCleaner
    2007-03-31 00:31 <KANSIO> d-------- F:\DOCUME~1\ANALCO~1.001\APPLIC~1\Logitech
    2007-03-31 00:28 89,088 --a------ F:\WINDOWS\system32\atl71.dll
    2007-03-31 00:28 68,992 --a------ F:\WINDOWS\system32\drivers\LMouKE.Sys
    2007-03-31 00:28 52,992 --a------ F:\WINDOWS\system32\drivers\L8042MOU.SYS
    2007-03-31 00:28 499,712 --a------ F:\WINDOWS\system32\msvcp71.dll
    2007-03-31 00:28 49,152 --a------ F:\WINDOWS\KHALMNPR.Exe
    2007-03-31 00:28 36,480 --a------ F:\WINDOWS\system32\drivers\LHidUsbK.sys
    2007-03-31 00:28 348,160 --a------ F:\WINDOWS\system32\msvcr71.dll
    2007-03-31 00:28 24,704 --a------ F:\WINDOWS\system32\drivers\LHidKE.Sys
    2007-03-31 00:28 13,056 --a------ F:\WINDOWS\system32\drivers\L8042Kbd.SYS
    2007-03-31 00:28 1,060,864 --a------ F:\WINDOWS\system32\MFC71.dll
    2007-03-31 00:28 1,047,552 --a------ F:\WINDOWS\system32\MFC71u.dll
    2007-03-31 00:28 <KANSIO> d-------- F:\Program Files\Logitech
    2007-03-31 00:21 3,072 --a------ F:\WINDOWS\system32\drivers\audstub.sys
    2007-03-31 00:21 21,504 --a------ F:\WINDOWS\system32\hidserv.dll
    2007-03-31 00:20 57,216 --a------ F:\WINDOWS\system32\drivers\redbook.sys
    2007-03-31 00:19 74,240 --a------ F:\WINDOWS\system32\usbui.dll
    2007-03-31 00:19 46,464 --a------ F:\WINDOWS\system32\drivers\GAGP30KX.SYS
    2007-03-31 00:19 30,282 --a------ F:\WINDOWS\system32\drivers\pcntn5hl.sys
    2007-03-31 00:17 9,936 --a------ F:\WINDOWS\system\LZEXPAND.DLL
    2007-03-31 00:17 9,008 --a------ F:\WINDOWS\system\VER.DLL
    2007-03-31 00:17 85,020 --a------ F:\WINDOWS\system32\dgsetup.dll
    2007-03-31 00:17 82,944 --a------ F:\WINDOWS\system\OLECLI.DLL
    2007-03-31 00:17 8,704 --a------ F:\WINDOWS\system32\batt.dll
    2007-03-31 00:17 8,192 -ra------ F:\WINDOWS\system32\kbdhept.dll
    2007-03-31 00:17 74,240 --a------ F:\WINDOWS\system32\storprop.dll
    2007-03-31 00:17 7,168 -ra------ F:\WINDOWS\system32\kbdcz.dll
    2007-03-31 00:17 69,856 --a------ F:\WINDOWS\system\AVICAP.DLL
    2007-03-31 00:17 69,632 --a------ F:\WINDOWS\NOTEPAD.EXE
    2007-03-31 00:17 68,768 --a------ F:\WINDOWS\system\MMSYSTEM.DLL
    2007-03-31 00:17 6,656 -ra------ F:\WINDOWS\system32\kbdycl.dll
    2007-03-31 00:17 6,656 -ra------ F:\WINDOWS\system32\kbdsl1.dll
    2007-03-31 00:17 6,656 -ra------ F:\WINDOWS\system32\kbdsl.dll
    2007-03-31 00:17 6,656 -ra------ F:\WINDOWS\system32\kbdpl.dll
    2007-03-31 00:17 6,656 -ra------ F:\WINDOWS\system32\kbdhu.dll
    2007-03-31 00:17 6,656 -ra------ F:\WINDOWS\system32\kbdhela3.dll
    2007-03-31 00:17 6,656 -ra------ F:\WINDOWS\system32\kbdcz2.dll
    2007-03-31 00:17 6,656 -ra------ F:\WINDOWS\system32\kbdcz1.dll
    2007-03-31 00:17 6,656 -ra------ F:\WINDOWS\system32\kbdcr.dll
    2007-03-31 00:17 6,656 -ra------ F:\WINDOWS\system32\KBDAL.DLL
    2007-03-31 00:17 6,144 -ra------ F:\WINDOWS\system32\kbdtuq.dll
    2007-03-31 00:17 6,144 -ra------ F:\WINDOWS\system32\kbdtuf.dll
    2007-03-31 00:17 6,144 -ra------ F:\WINDOWS\system32\kbdlv1.dll
    2007-03-31 00:17 6,144 -ra------ F:\WINDOWS\system32\kbdlv.dll
    2007-03-31 00:17 6,144 -ra------ F:\WINDOWS\system32\kbdhela2.dll
    2007-03-31 00:17 6,144 -ra------ F:\WINDOWS\system32\kbdgkl.dll
    2007-03-31 00:17 6,144 -ra------ F:\WINDOWS\system32\kbdest.dll
    2007-03-31 00:17 5,632 -ra------ F:\WINDOWS\system32\kbdro.dll
    2007-03-31 00:17 5,632 -ra------ F:\WINDOWS\system32\kbdpl1.dll
    2007-03-31 00:17 5,632 -ra------ F:\WINDOWS\system32\kbdmon.dll
    2007-03-31 00:17 5,632 -ra------ F:\WINDOWS\system32\kbdlt1.dll
    2007-03-31 00:17 5,632 -ra------ F:\WINDOWS\system32\kbdlt.dll
    2007-03-31 00:17 5,632 -ra------ F:\WINDOWS\system32\kbdkyr.dll
    2007-03-31 00:17 5,632 -ra------ F:\WINDOWS\system32\kbdhu1.dll
    2007-03-31 00:17 5,632 -ra------ F:\WINDOWS\system32\kbdhe319.dll
    2007-03-31 00:17 5,632 -ra------ F:\WINDOWS\system32\kbdhe220.dll
    2007-03-31 00:17 5,632 -ra------ F:\WINDOWS\system32\kbdhe.dll
    2007-03-31 00:17 5,632 -ra------ F:\WINDOWS\system32\kbdazel.dll
    2007-03-31 00:17 5,120 --a------ F:\WINDOWS\system\SHELL.DLL
    2007-03-31 00:17 33,120 --a------ F:\WINDOWS\system\COMMDLG.DLL
    2007-03-31 00:17 24,661 --a------ F:\WINDOWS\system32\spxcoins.dll
    2007-03-31 00:17 24,064 --a------ F:\WINDOWS\system\OLESVR.DLL
    2007-03-31 00:17 19,200 --a------ F:\WINDOWS\system\TAPI.DLL
    2007-03-31 00:17 176,157 --a------ F:\WINDOWS\system32\dgrpsetu.dll
    2007-03-31 00:17 15,360 --a------ F:\WINDOWS\TASKMAN.EXE
    2007-03-31 00:17 13,312 --a------ F:\WINDOWS\system32\irclass.dll
    2007-03-31 00:17 126,912 --a------ F:\WINDOWS\system\MSVIDEO.DLL
    2007-03-31 00:17 11,264 --a------ F:\WINDOWS\system32\drivers\irenum.sys
    2007-03-31 00:17 109,504 --a------ F:\WINDOWS\system\AVIFILE.DLL
    2007-03-31 00:17 103,424 --a------ F:\WINDOWS\system32\EqnClass.Dll
    2007-03-31 00:17 <KANSIO> dr------- F:\DOCUME~1\DEFAUL~1.WIN\K„ynnist„-valikko
    2007-03-31 00:17 <KANSIO> dr------- F:\DOCUME~1\ALLUSE~1.WIN\Tiedostot
    2007-03-31 00:17 <KANSIO> dr------- F:\DOCUME~1\ALLUSE~1.WIN\K„ynnist„-valikko
    2007-03-31 00:17 <KANSIO> d--h----- F:\DOCUME~1\DEFAUL~1.WIN\Verkkoymp„rist”
    2007-03-31 00:17 <KANSIO> d--h----- F:\DOCUME~1\DEFAUL~1.WIN\Tulostinymp„rist”
    2007-03-31 00:17 <KANSIO> d--h----- F:\DOCUME~1\DEFAUL~1.WIN\Mallit
    2007-03-31 00:17 <KANSIO> d--h----- F:\DOCUME~1\ALLUSE~1.WIN\Mallit
    2007-03-31 00:17 <KANSIO> d-------- F:\DOCUME~1\DEFAUL~1.WIN\Ty”p”yt„
    2007-03-31 00:17 <KANSIO> d-------- F:\DOCUME~1\DEFAUL~1.WIN\Suosikit
    2007-03-31 00:17 <KANSIO> d-------- F:\DOCUME~1\ALLUSE~1.WIN\Ty”p”yt„
    2007-03-31 00:17 <KANSIO> d-------- F:\DOCUME~1\ALLUSE~1.WIN\Suosikit
    2007-03-31 00:12 <KANSIO> d-------- F:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\nView_Profiles
    2007-03-30 23:58 <KANSIO> d-------- F:\Program Files\uTorrent
    2007-03-30 23:47 22,752 --a------ F:\WINDOWS\system32\spupdsvc.exe
    2007-03-30 23:44 <KANSIO> d---s---- F:\DOCUME~1\ANALCO~1.001\UserData
    2007-03-30 23:29 3,426,072 --a------ F:\WINDOWS\system32\d3dx9_32.dll
    2007-03-30 23:22 <KANSIO> d-------- F:\Program Files\Electronic Arts
    2007-03-30 23:18 <KANSIO> d-------- F:\Program Files\Realtek AC97
    2007-03-30 23:09 0 --a------ F:\WINDOWS\nsreg.dat
    2007-03-30 23:07 <KANSIO> dr------- F:\DOCUME~1\NETWOR~1.002\Suosikit
    2007-03-30 22:41 36,528 --------- F:\WINDOWS\system32\drivers\PxHelp20.sys
    2007-03-30 22:41 2,560 --------- F:\WINDOWS\system32\drivers\cdralw2k.sys
    2007-03-30 22:41 2,432 --------- F:\WINDOWS\system32\drivers\cdr4_xp.sys
    2007-03-30 22:41 129,784 --------- F:\WINDOWS\system32\pxafs.dll
    2007-03-30 22:41 115,880 --------- F:\WINDOWS\system32\pxinsi64.exe
    2007-03-30 22:41 <KANSIO> d-------- F:\Program Files\Winamp
    2007-03-30 22:40 <KANSIO> d-------- F:\Program Files\EA GAMES
    2007-03-30 22:27 223,128 --a------ F:\WINDOWS\system32\drivers\dtscsi.sys
    2007-03-30 22:27 <KANSIO> d-------- F:\Program Files\DAEMON Tools
    2007-03-30 22:24 96,256 --a------ F:\WINDOWS\system32\drivers\sptd4381.sys
    2007-03-30 22:24 664,064 --a------ F:\WINDOWS\system32\drivers\sptd.sys
    2007-03-30 22:24 <KANSIO> d-------- F:\Program Files\MSN Messenger
    2007-03-30 22:23 306,688 --a------ F:\WINDOWS\IsUninst.exe
    2007-03-30 22:23 27,904 --a------ F:\WINDOWS\system32\drivers\VIAAGP1.SYS
    2007-03-30 22:22 <KANSIO> d-------- F:\DOCUME~1\ANALCO~1.001\WINDOWS
    2007-03-30 22:21 82,944 --a------ F:\WINDOWS\system32\drivers\wdmaud.sys
    2007-03-30 22:21 7,552 --a------ F:\WINDOWS\system32\drivers\MSKSSRV.sys
    2007-03-30 22:21 60,800 --a------ F:\WINDOWS\system32\drivers\sysaudio.sys
    2007-03-30 22:21 60,288 --a------ F:\WINDOWS\system32\drivers\drmk.sys
    2007-03-30 22:21 6,400 --a------ F:\WINDOWS\system32\drivers\splitter.sys
    2007-03-30 22:21 54,272 --a------ F:\WINDOWS\system32\drivers\swmidi.sys
    2007-03-30 22:21 52,864 --a------ F:\WINDOWS\system32\drivers\DMusic.sys
    2007-03-30 22:21 5,376 --a------ F:\WINDOWS\system32\drivers\MSPCLOCK.sys
    2007-03-30 22:21 4,992 --a------ F:\WINDOWS\system32\drivers\MSPQM.sys
    2007-03-30 22:21 4,096 --a------ F:\WINDOWS\system32\ksuser.dll
    2007-03-30 22:21 2,944 --a------ F:\WINDOWS\system32\drivers\drmkaud.sys
    2007-03-30 22:21 172,416 --a------ F:\WINDOWS\system32\drivers\kmixer.sys
    2007-03-30 22:21 145,792 --a------ F:\WINDOWS\system32\drivers\portcls.sys
    2007-03-30 22:21 142,464 --a------ F:\WINDOWS\system32\drivers\aec.sys
    2007-03-30 22:21 <KANSIO> d-------- F:\Program Files\Realtek Sound Manager
    2007-03-30 22:21 <KANSIO> d-------- F:\Program Files\AvRack
    2007-03-30 22:20 577,536 --a------ F:\WINDOWS\soundman.exe
    2007-03-30 22:20 49,152 --a------ F:\WINDOWS\system32\ChCfg.exe
    2007-03-30 22:20 4,027,456 -ra------ F:\WINDOWS\system32\drivers\alcxwdm.sys
    2007-03-30 22:20 315,392 --a------ F:\WINDOWS\alcupd.exe
    2007-03-30 22:20 217,088 --a------ F:\WINDOWS\Alcrmv.exe
    2007-03-30 22:20 147,456 --a------ F:\WINDOWS\system32\RtlCPAPI.dll
    2007-03-30 22:20 10,528,768 --a------ F:\WINDOWS\system32\RTLCPL.exe
    2007-03-30 22:18 192,512 --------- F:\WINDOWS\RtlExUpd.dll
    2007-03-30 22:17 <KANSIO> d-------- F:\DOCUME~1\ANALCO~1.001\APPLIC~1\uTorrent
    2007-03-30 22:16 5,824 --a------ F:\WINDOWS\system32\drivers\ASUSHWIO.SYS
    2007-03-30 21:44 208,896 --a------ F:\WINDOWS\system32\NVUNINST.EXE
    2007-03-30 21:44 208,896 --a------ F:\WINDOWS\system32\nvudisp.exe
    2007-03-30 21:35 3,932,160 --ah----- F:\DOCUME~1\ANALCO~1.001\NTUSER.DAT
    2007-03-30 21:35 <KANSIO> dr------- F:\DOCUME~1\ANALCO~1.001\Suosikit
    2007-03-30 21:35 <KANSIO> dr------- F:\DOCUME~1\ANALCO~1.001\Omat tiedostot
    2007-03-30 21:35 <KANSIO> dr------- F:\DOCUME~1\ANALCO~1.001\K„ynnist„-valikko
    2007-03-30 21:35 <KANSIO> d--h----- F:\DOCUME~1\ANALCO~1.001\Verkkoymp„rist”
    2007-03-30 21:35 <KANSIO> d--h----- F:\DOCUME~1\ANALCO~1.001\Tulostinymp„rist”
    2007-03-30 21:35 <KANSIO> d--h----- F:\DOCUME~1\ANALCO~1.001\Mallit
    2007-03-30 21:35 <KANSIO> d-------- F:\DOCUME~1\ANALCO~1.001\Ty”p”yt„
    2007-03-30 21:34 786,432 --ah----- F:\DOCUME~1\NETWOR~1.002\NTUSER.DAT
    2007-03-30 21:34 786,432 --ah----- F:\DOCUME~1\LOCALS~1.002\NTUSER.DAT
    2007-03-30 21:30 229,376 ---h----- F:\DOCUME~1\DEFAUL~1.WIN\NTUSER.DAT
    2007-03-30 21:27 112,128 --a------ F:\WINDOWS\system32\mapi32.dll
    2007-03-30 21:26 <KANSIO> d--hs---- F:\DOCUME~1\ALLUSE~1.WIN\DRM
    2007-03-30 21:25 86,016 --a------ F:\WINDOWS\system32\isign32.dll
    2007-03-30 21:25 81,920 --a------ F:\WINDOWS\system32\ils.dll
    2007-03-30 21:25 8,192 --a------ F:\WINDOWS\system32\bitsprx2.dll
    2007-03-30 21:25 73,728 --a------ F:\WINDOWS\system32\icwdial.dll
    2007-03-30 21:25 73,472 --a------ F:\WINDOWS\system32\drivers\sr.sys
    2007-03-30 21:25 7,168 --a------ F:\WINDOWS\system32\bitsprx3.dll
    2007-03-30 21:25 69,632 --a------ F:\WINDOWS\system32\msconf.dll
    2007-03-30 21:25 679,424 --a------ F:\WINDOWS\system32\inetcomm.dll
    2007-03-30 21:25 67,584 --a------ F:\WINDOWS\system32\srclient.dll
    2007-03-30 21:25 65,536 --a------ F:\WINDOWS\system32\icwphbk.dll
    2007-03-30 21:25 64,512 --a------ F:\WINDOWS\system32\acctres.dll
    2007-03-30 21:25 6,656 --a------ F:\WINDOWS\system32\wuauserv.dll
    2007-03-30 21:25 48,640 --a------ F:\WINDOWS\system32\inetres.dll
    2007-03-30 21:25 465,176 --a------ F:\WINDOWS\system32\wuapi.dll
    2007-03-30 21:25 45,568 --a------ F:\WINDOWS\system32\safrslv.dll
    2007-03-30 21:25 43,520 --a------ F:\WINDOWS\system32\safrcdlg.dll
    2007-03-30 21:25 43,520 --a------ F:\WINDOWS\system32\racpldlg.dll
    2007-03-30 21:25 41,240 --a------ F:\WINDOWS\system32\wups.dll
    2007-03-30 21:25 382,464 --a------ F:\WINDOWS\system32\qmgr.dll
    2007-03-30 21:25 34,560 --a------ F:\WINDOWS\system32\mnmdd.dll
    2007-03-30 21:25 32,768 --a------ F:\WINDOWS\system32\mnmsrvc.exe
    2007-03-30 21:25 32,768 --a------ F:\WINDOWS\system32\isrdbg32.dll
    2007-03-30 21:25 29,696 --a------ F:\WINDOWS\system32\safrdm.dll
    2007-03-30 21:25 28,672 --a------ F:\WINDOWS\system32\nmmkcert.dll
    2007-03-30 21:25 278,528 --a------ F:\WINDOWS\system32\inetcfg.dll
    2007-03-30 21:25 276,480 --a------ F:\WINDOWS\system32\mstask.dll
    2007-03-30 21:25 252,928 --a------ F:\WINDOWS\system32\msoeacct.dll
    2007-03-30 21:25 240,640 --a------ F:\WINDOWS\system32\srrstr.dll
    2007-03-30 21:25 23,040 --a------ F:\WINDOWS\system32\fltmc.exe
    2007-03-30 21:25 194,840 --a------ F:\WINDOWS\system32\wuaueng1.dll
    2007-03-30 21:25 190,976 --a------ F:\WINDOWS\system32\schedsvc.dll
    2007-03-30 21:25 18,944 --a------ F:\WINDOWS\system32\qmgrprxy.dll
    2007-03-30 21:25 173,848 --a------ F:\WINDOWS\system32\wuauclt1.exe
    2007-03-30 21:25 173,536 --a------ F:\WINDOWS\system32\wuweb.dll
    2007-03-30 21:25 170,496 --a------ F:\WINDOWS\system32\srsvc.dll
    2007-03-30 21:25 16,896 --a------ F:\WINDOWS\system32\fltlib.dll
    2007-03-30 21:25 16,384 --a------ F:\WINDOWS\system32\icfgnt5.dll
    2007-03-30 21:25 128,896 --a------ F:\WINDOWS\system32\drivers\fltmgr.sys
    2007-03-30 21:25 127,256 --a------ F:\WINDOWS\system32\wucltui.dll
    2007-03-30 21:25 124,696 --a------ F:\WINDOWS\system32\wuauclt.exe
    2007-03-30 21:25 12,288 --a------ F:\WINDOWS\system32\nmevtmsg.dll
    2007-03-30 21:25 12,288 --a------ F:\WINDOWS\system32\mstinit.exe
    2007-03-30 21:25 11,264 --a------ F:\WINDOWS\system32\atrace.dll
    2007-03-30 21:25 105,984 --a------ F:\WINDOWS\system32\msoert2.dll
    2007-03-30 21:25 1,343,768 --a------ F:\WINDOWS\system32\wuaueng.dll
    2007-03-30 21:24 97,792 --a------ F:\WINDOWS\system32\comrepl.dll
    2007-03-30 21:24 956,416 --a------ F:\WINDOWS\system32\msdtctm.dll
    2007-03-30 21:24 93,696 --a------ F:\WINDOWS\system32\tscfgwmi.dll
    2007-03-30 21:24 91,136 --a------ F:\WINDOWS\system32\mtxoci.dll
    2007-03-30 21:24 9,728 --a------ F:\WINDOWS\system32\reset.exe
    2007-03-30 21:24 87,176 --a------ F:\WINDOWS\system32\rdpwsx.dll
    2007-03-30 21:24 85,504 --a------ F:\WINDOWS\system32\catsrvps.dll
    2007-03-30 21:24 80,896 --a------ F:\WINDOWS\system32\charmap.exe
    2007-03-30 21:24 73,216 --a------ F:\WINDOWS\system32\avwav.dll
    2007-03-30 21:24 67,072 --a------ F:\WINDOWS\system32\rdshost.exe
    2007-03-30 21:24 655,360 --a------ F:\WINDOWS\system32\mstscax.dll
    2007-03-30 21:24 625,152 --a------ F:\WINDOWS\system32\catsrvut.dll
    2007-03-30 21:24 62,464 --a------ F:\WINDOWS\system32\rdpclip.exe
    2007-03-30 21:24 605,696 --a------ F:\WINDOWS\system32\getuname.dll
    2007-03-30 21:24 60,416 --a------ F:\WINDOWS\system32\remotepg.dll
    2007-03-30 21:24 60,416 --a------ F:\WINDOWS\system32\colbact.dll
    2007-03-30 21:24 6,144 --a------ F:\WINDOWS\system32\msdtc.exe
    2007-03-30 21:24 58,880 --a------ F:\WINDOWS\system32\msdtclog.dll
    2007-03-30 21:24 56,832 --a------ F:\WINDOWS\system32\sol.exe
    2007-03-30 21:24 55,296 --a------ F:\WINDOWS\system32\freecell.exe
    2007-03-30 21:24 540,160 --a------ F:\WINDOWS\system32\comuid.dll
    2007-03-30 21:24 54,272 --a------ F:\WINDOWS\system32\stclient.dll
    2007-03-30 21:24 538,624 --a------ F:\WINDOWS\system32\spider.exe
    2007-03-30 21:24 5,632 --a------ F:\WINDOWS\system32\write.exe
    2007-03-30 21:24 5,120 --a------ F:\WINDOWS\system32\dcomcnfg.exe
    2007-03-30 21:24 498,688 --a------ F:\WINDOWS\system32\clbcatq.dll
    2007-03-30 21:24 44,544 --a------ F:\WINDOWS\system32\tscupgrd.exe
    2007-03-30 21:24 44,544 --a------ F:\WINDOWS\system32\hticons.dll
    2007-03-30 21:24 426,496 --a------ F:\WINDOWS\system32\msdtcprx.dll
    2007-03-30 21:24 404,992 --a------ F:\WINDOWS\system32\mstsc.exe
    2007-03-30 21:24 4,096 --a------ F:\WINDOWS\system32\rdpcfgex.dll
    2007-03-30 21:24 4,096 --a------ F:\WINDOWS\system32\mtxex.dll
    2007-03-30 21:24 39,424 --a------ F:\WINDOWS\system32\cfgbkend.dll
    2007-03-30 21:24 35,328 --a------ F:\WINDOWS\system32\winchat.exe
    2007-03-30 21:24 348,160 --a------ F:\WINDOWS\system32\hypertrm.dll
    2007-03-30 21:24 344,064 --a------ F:\WINDOWS\system32\mspaint.exe
    2007-03-30 21:24 33,792 --a------ F:\WINDOWS\system32\regini.exe
    2007-03-30 21:24 295,424 --a------ F:\WINDOWS\system32\termsrv.dll
    2007-03-30 21:24 25,600 --a------ F:\WINDOWS\system32\comaddin.dll
    2007-03-30 21:24 25,088 --a------ F:\WINDOWS\system32\mtxlegih.dll
    2007-03-30 21:24 227,840 --a------ F:\WINDOWS\system32\avtapi.dll
    2007-03-30 21:24 225,792 --a------ F:\WINDOWS\system32\catsrv.dll
    2007-03-30 21:24 22,016 --a------ F:\WINDOWS\system32\qwinsta.exe
    2007-03-30 21:24 21,896 --a------ F:\WINDOWS\system32\drivers\tdtcp.sys
    2007-03-30 21:24 21,672 --a------ F:\WINDOWS\system32\emptyregdb.dat
    2007-03-30 21:24 21,504 --a------ F:\WINDOWS\system32\msg.exe
    2007-03-30 21:24 20,480 --a------ F:\WINDOWS\system32\qprocess.exe
    2007-03-30 21:24 20,480 --a------ F:\WINDOWS\system32\mtxdm.dll
    2007-03-30 21:24 19,968 --a------ F:\WINDOWS\system32\rdpsnd.dll
    2007-03-30 21:24 186,368 --a------ F:\WINDOWS\system32\accwiz.exe
    2007-03-30 21:24 17,408 --a------ F:\WINDOWS\system32\tsshutdn.exe
    2007-03-30 21:24 161,280 --a------ F:\WINDOWS\system32\msdtcuiu.dll
    2007-03-30 21:24 16,896 --a------ F:\WINDOWS\system32\qappsrv.exe
    2007-03-30 21:24 16,384 --a------ F:\WINDOWS\system32\tskill.exe
    2007-03-30 21:24 16,384 --a------ F:\WINDOWS\system32\avmeter.dll
    2007-03-30 21:24 15,872 --a------ F:\WINDOWS\system32\rwinsta.exe
    2007-03-30 21:24 15,872 --a------ F:\WINDOWS\system32\cdmodem.dll
    2007-03-30 21:24 15,360 --a------ F:\WINDOWS\system32\tscon.exe
    2007-03-30 21:24 15,360 --a------ F:\WINDOWS\system32\logoff.exe
    2007-03-30 21:24 147,968 --a------ F:\WINDOWS\system32\rdchost.dll
    2007-03-30 21:24 147,456 --a------ F:\WINDOWS\system32\comsnap.dll
    2007-03-30 21:24 140,800 --a------ F:\WINDOWS\system32\sessmgr.exe
    2007-03-30 21:24 14,848 --a------ F:\WINDOWS\system32\tsdiscon.exe
    2007-03-30 21:24 14,848 --a------ F:\WINDOWS\system32\shadow.exe
    2007-03-30 21:24 139,400 --a------ F:\WINDOWS\system32\drivers\rdpwd.sys
    2007-03-30 21:24 138,752 --a------ F:\WINDOWS\system32\sndvol32.exe
    2007-03-30 21:24 131,584 --a------ F:\WINDOWS\system32\sndrec32.exe
    2007-03-30 21:24 13,824 --a------ F:\WINDOWS\system32\rdsaddin.exe
    2007-03-30 21:24 126,976 --a------ F:\WINDOWS\system32\mshearts.exe
    2007-03-30 21:24 123,392 --a------ F:\WINDOWS\system32\mplay32.exe
    2007-03-30 21:24 12,040 --a------ F:\WINDOWS\system32\drivers\tdpipe.sys
    2007-03-30 21:24 119,808 --a------ F:\WINDOWS\system32\winmine.exe
    2007-03-30 21:24 114,688 --a------ F:\WINDOWS\system32\calc.exe
    2007-03-30 21:24 110,080 --a------ F:\WINDOWS\system32\clbcatex.dll
    2007-03-30 21:24 11,776 --a------ F:\WINDOWS\system32\xolehlp.dll
    2007-03-30 21:24 11,264 --a------ F:\WINDOWS\system32\icaapi.dll
    2007-03-30 21:24 102,400 --a------ F:\WINDOWS\system32\clipbrd.exe
    2007-03-30 21:24 1,267,200 --a------ F:\WINDOWS\system32\comsvcs.dll
    2007-03-30 21:24 1,161 --a------ F:\WINDOWS\system32\usrlogon.cmd
    2007-03-30 21:23 58,880 --a------ F:\WINDOWS\system32\licwmi.dll
    2007-03-30 21:23 56,320 --a------ F:\WINDOWS\system32\servdeps.dll
    2007-03-30 21:23 40,840 --a------ F:\WINDOWS\system32\drivers\termdd.sys
    2007-03-30 21:23 196,864 --a------ F:\WINDOWS\system32\drivers\rdpdr.sys
    2007-03-30 21:23 185,344 --a------ F:\WINDOWS\system32\cmprops.dll
    2007-03-30 21:23 17,408 --a------ F:\WINDOWS\system32\mmfutil.dll
    2007-03-30 13:03 <KANSIO> d-------- F:\DOCUME~1\ANALCO~1.000\APPLIC~1\Command & Conquer 3 Tiberium Wars
    2007-03-30 12:56 <KANSIO> dr-h----- F:\DOCUME~1\ANALCO~1.000\APPLIC~1\SecuROM
    2007-03-29 23:09 <KANSIO> d-------- F:\DOCUME~1\ANALCO~1.000\APPLIC~1\BlahMailType
    2007-03-29 18:02 <KANSIO> d-------- F:\DOCUME~1\ANALCO~1.000\APPLIC~1\Adobe
    2007-03-27 10:55 524,288 --a------ F:\WINDOWS\system32\DivXsm.exe
    2007-03-27 10:55 3,596,288 --a------ F:\WINDOWS\system32\qt-dx331.dll
    2007-03-27 10:55 200,704 --a------ F:\WINDOWS\system32\ssldivx.dll
    2007-03-27 10:55 1,044,480 --a------ F:\WINDOWS\system32\libdivx.dll
    2007-03-27 10:49 73,728 --a------ F:\WINDOWS\system32\dpl100.dll
    2007-03-27 10:49 593,920 --a------ F:\WINDOWS\system32\dpuGUI11.dll
    2007-03-27 10:49 57,344 --a------ F:\WINDOWS\system32\dpv11.dll
    2007-03-27 10:49 53,248 --a------ F:\WINDOWS\system32\dpuGUI10.dll
    2007-03-27 10:49 344,064 --a------ F:\WINDOWS\system32\dpus11.dll
    2007-03-27 10:49 294,912 --a------ F:\WINDOWS\system32\dpu11.dll
    2007-03-27 10:49 294,912 --a------ F:\WINDOWS\system32\dpu10.dll
    2007-03-27 10:49 196,608 --a------ F:\WINDOWS\system32\dtu100.dll
    2007-03-27 10:48 823,296 --a------ F:\WINDOWS\system32\divx_xx0c.dll
    2007-03-27 10:48 823,296 --a------ F:\WINDOWS\system32\divx_xx07.dll
    2007-03-27 10:48 802,816 --a------ F:\WINDOWS\system32\divx_xx11.dll
    2007-03-27 10:48 639,066 --a------ F:\WINDOWS\system32\DivX.dll
    2007-03-25 16:34 <KANSIO> d-------- F:\DOCUME~1\ANALCO~1.000\APPLIC~1\Lavasoft
    2007-03-24 16:42 <KANSIO> d-------- F:\DOCUME~1\ANALCO~1.000\APPLIC~1\Logitech
    2007-03-24 15:25 <KANSIO> dr------- F:\DOCUME~1\NETWOR~1.001\Suosikit
    2007-03-23 20:19 <KANSIO> d-------- F:\DOCUME~1\ANALCO~1.000\APPLIC~1\DivX
    2007-03-23 20:16 <KANSIO> d-------- F:\DOCUME~1\ANALCO~1.000\APPLIC~1\Ahead
    2007-03-23 19:54 <KANSIO> d-------- F:\DOCUME~1\ANALCO~1.000\APPLIC~1\uTorrent
    2007-03-23 19:19 2,883,584 --ah----- F:\DOCUME~1\ANALCO~1.000\NTUSER.DAT
    2007-03-23 19:19 <KANSIO> d--h----- F:\DOCUME~1\ANALCO~1.000\Verkkoymp„rist”
    2007-03-23 19:19 <KANSIO> d--h----- F:\DOCUME~1\ANALCO~1.000\Tulostinymp„rist”
    2007-03-23 19:19 <KANSIO> d--h----- F:\DOCUME~1\ANALCO~1.000\Mallit
    2007-03-23 19:18 229,376 --ah----- F:\DOCUME~1\LOCALS~1.001\NTUSER.DAT
    2007-03-23 19:17 229,376 --ah----- F:\DOCUME~1\NETWOR~1.001\NTUSER.DAT
    2007-03-21 22:31 <KANSIO> d-------- F:\WINDOWS\nview
    2007-03-20 23:27 <KANSIO> d-------- F:\Program Files\Common Files\Raxco
    2007-03-20 15:11 <KANSIO> d-------- F:\WINDOWS\system32\oodag


    (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


    2007-04-13 00:30 -------- d--h----- F:\Program Files\installshield installation information
    2007-04-12 04:05 64812 --a------ F:\WINDOWS\system32\perfc00b.dat
    2007-04-12 04:05 354486 --a------ F:\WINDOWS\system32\perfh00b.dat
    2007-03-31 00:17 62 --ahs---- F:\DOCUME~1\ANALCO~1.001\APPLIC~1\desktop.ini
    2007-03-30 21:24 -------- d-------- F:\Program Files\messenger
    2007-03-24 16:39 -------- d-------- F:\Program Files\Common Files\logitech
    2007-03-23 18:41 -------- d-------- F:\Program Files\Common Files\wise installation wizard
    2007-03-08 18:38 578048 --a------ F:\WINDOWS\system32\user32.dll
    2007-03-08 18:37 40960 --a------ F:\WINDOWS\system32\mf3216.dll
    2007-03-08 18:37 281600 --a------ F:\WINDOWS\system32\gdi32.dll
    2007-03-08 18:34 1843840 --a------ F:\WINDOWS\system32\win32k.sys
    2007-02-16 04:40 124472 --a------ F:\WINDOWS\system32\divxcodecupdatechecker.exe


    (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

    *Note* empty entries & legit default entries are not shown

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
    "MessengerPlus3"="\"F:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe\" /WinStart"
    "msnmsgr"="\"F:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
    "NvCplDaemon"="RUNDLL32.EXE F:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
    "nwiz"="nwiz.exe /install"
    "SoundMan"="SOUNDMAN.EXE"
    "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE"
    "NeroFilterCheck"="F:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"
    "MessengerPlus3"="\"F:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe\""
    "SmcService"="F:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui"
    "PWRISOVM.EXE"="F:\\Program Files\\PowerISO\\PWRISOVM.EXE"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spywarefighterguard]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="spftray"
    "hkey"="HKLM"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="winampa"
    "hkey"="HKLM"
    "command"="F:\\Program Files\\Winamp\\winampa.exe"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "SPYWAREfighterRP"=dword:00000003


    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
    "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
    "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
    Authentication Packages REG_MULTI_SZ msv1_0\0\0
    Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
    Notification Packages REG_MULTI_SZ scecli\0\0

    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
    HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
    LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
    NetworkService REG_MULTI_SZ DnsCache\0\0
    DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
    rpcss REG_MULTI_SZ RpcSs\0\0
    imgsvc REG_MULTI_SZ StiSvc\0\0
    termsvcs REG_MULTI_SZ TermService\0\0


    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d0584add-df02-11db-bc91-806d6172696f}]
    Shell\AutoRun\command H:\Autorun.exe
    *newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_SMCSERVICE


    Contents of the 'Scheduled Tasks' folder
    F:\WINDOWS\tasks\B02603F092DDB8CC.job


    ********************************************************************

    catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
    http://www.gmer.net

    scanning hidden processes ...

    scanning hidden services ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden processes: 0
    hidden services: 0
    hidden files: 0

    ********************************************************************

    Completion time: 07-04-13 2:58:47
    F:\ComboFix-quarantined-files.txt ... 07-04-13 02:58


    HTJ-logi ->

    Logfile of HijackThis v1.99.1
    Scan saved at 2:59:34, on 13.4.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    F:\WINDOWS\System32\smss.exe
    F:\WINDOWS\system32\winlogon.exe
    F:\WINDOWS\system32\services.exe
    F:\WINDOWS\system32\lsass.exe
    F:\WINDOWS\system32\svchost.exe
    F:\WINDOWS\System32\svchost.exe
    F:\Program Files\Sygate\SPF\smc.exe
    F:\WINDOWS\Explorer.EXE
    F:\WINDOWS\system32\spoolsv.exe
    F:\WINDOWS\SOUNDMAN.EXE
    F:\Program Files\MessengerPlus! 3\MsgPlus.exe
    F:\Program Files\Logitech\SetPoint\SetPoint.exe
    F:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
    F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    F:\WINDOWS\system32\nvsvc32.exe
    F:\WINDOWS\system32\svchost.exe
    F:\WINDOWS\system32\wscntfy.exe
    F:\Program Files\MSN Messenger\msnmsgr.exe
    F:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [NeroFilterCheck] F:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [MessengerPlus3] "F:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [SmcService] F:\PROGRA~1\Sygate\SPF\smc.exe -startgui
    O4 - HKLM\..\Run: [PWRISOVM.EXE] F:\Program Files\PowerISO\PWRISOVM.EXE
    O4 - HKCU\..\Run: [MessengerPlus3] "F:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [msnmsgr] "F:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - Global Startup: Logitech SetPoint.lnk = F:\Program Files\Logitech\SetPoint\SetPoint.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "F:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: WgaLogon - F:\WINDOWS\
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: NBService - Nero AG - F:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - F:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - F:\Program Files\Sygate\SPF\smc.exe
     
    Last edited: Apr 12, 2007
  4. Auttaja

    Auttaja Guest

    Tere tehdäänpä tää seuraavaks.

    [*]Käynnistä AVG Anti-Spyware.
    [*]Klikkaa "Update" kuvaketta päävalikossa. Sen jälkeen klikkaa "Update now" painiketta.
    [*]Sitten klikkaa "Start Update" kuvaketta jolloin päivitys alkaa.
    [*]Paina hetken kuluttua uudestaan "Start Update" , jos päivitykset eivät heti onnistu
    [*]Jos automaattipäivitys ei jostain syystä toimi, niin tunnisteet voi ladata manuaalisesti http://www.ewido.net/en/download/updates/ -linkin takaa.
    [*]Kun päivitykset on ladattu, klikkaa "Scanner" kuvaketta ikkunan ylälaidassa. Valitse sitten "Settings" välilehti.
    [*]Kun "Settings" valikko on auennut, klikkaa "Recommended actions" ja sitten valitse "Quarantine".
    [*]Sitten "Reports" valikon alta:
    [*]Laita täppi kohtaan "Automatically generate report after every scan"
    [*]Ota täppi pois kohdasta"Only if threats were found"
    [*]Sitten klikkaa "Shield" kuvaketta ikkunan ylälaidassa
    [*]"Resident shield is", muuta tila active:sta inactive:ksi
    [*]Sulje ohjelma, ÄLÄ skannaa vielä.

    Käynnistä tietokone vikasietotilaan:
    1. Käynnistä tietokone uudelleen.
    2. Kun tietokone käynnistyy, paina F8-näppäintä.
    3. Näyttöön tulee erilaisia käynnistysvaihtoehtoja.
    4. Valitse näppäimistön nuolinäppäinten avulla Vikasietotila.
    5. Paina ENTER-näppäintä.

    HUOM! Älä käytä muita ohjelmia AVG skannauksen aikana, tämä saattaa häiritä skannausta.
    [*]Kun vikasietotilassa, käynnistä AVG Anti-Spyware.
    [*]Klikkaa "Scanner" kuvaketta ikkunan ylälaidassa ja valitse "Scan" välilehti. Sitten klikkaa "Complete System Scan".
    [*]AVG aloittaa nyt tietokoneen skannaamisen, ole kärsivällinen sillä skannaus vie aikaa.
    Kun skannaus on valmis:
    TÄRKEÄÄ : Älä klikkaa "Save Scan Report" ennen kuin klikkaat "Apply all Actions"
    [*]Varmistu, että Set all elements to: näyttää Quarantine (1), jos ei, klikkaa linkkiä ja valitse Quarantine popup-valikosta.
    [*]Sinulta kysytään mitä tehdä jos infektioita löytyi, valitse silloin "Apply all actions"
    [​IMG]
    [*]Sitten klikkaa "Reports" kuvaketta ohjelma yläosasta.
    [*]Klikkaa "Save report as" painiketta ikkunan vasemmassa alalaidassa ja tallenna raportti työpöydälle.
    [*]Sulje ohjelma, käynnistä kone normaalisti ja lähetä AVG:n raportti viestiketjuusi.

    *******


    Lataa ja tallenna Blacklight työpöydällesi;

    Tupla-klikkaa blbeta.exe, hyväksy sopimus, klikkaa > Scan, sitten > Next

    Näet listan kaikesta mitä löytyi. Työpöydällesi myös ilmestyy loki jonka nimi on fsbl.xxxxxxx.log (xxxxxxx;n tilalla on luultavimmin numeroita).

    Kopioi ja liitä tämä loki seuraavaan vastaukseesi. Älä valitse "Rename" optiota vielä! Haluamme nähdä login ensin, koska hyviä tiedostoja saattaa olla mukana.
     
    Last edited by a moderator: Apr 12, 2007
  5. Mestaus

    Mestaus Regular member

    Joined:
    Dec 21, 2005
    Messages:
    1,141
    Likes Received:
    0
    Trophy Points:
    46
    ---------------------------------------------------------
    AVG Anti-Spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 11:03:23 14.4.2007

    + Scan result:



    F:\System Volume Information\_restore{02AE1B92-ED6A-4A61-AF0C-0E1E2B25A9FA}\RP44\A0006386.exe -> Backdoor.Hupigon.kg : No action taken.
    :mozilla.361:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
    :mozilla.149:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
    :mozilla.152:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
    :mozilla.58:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
    :mozilla.65:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
    :mozilla.99:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
    :mozilla.112:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Cpvfeed : No action taken.
    :mozilla.118:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Cpvfeed : No action taken.
    :mozilla.119:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Cpvfeed : No action taken.
    :mozilla.120:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Cpvfeed : No action taken.
    :mozilla.14:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
    :mozilla.79:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Imrworldwide : No action taken.
    :mozilla.75:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Information : No action taken.
    :mozilla.77:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Information : No action taken.
    :mozilla.78:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Information : No action taken.
    :mozilla.68:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Live : No action taken.
    :mozilla.69:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Live : No action taken.
    :mozilla.70:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Live : No action taken.
    :mozilla.15:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Paypal : No action taken.
    :mozilla.37:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
    :mozilla.38:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
    :mozilla.39:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
    :mozilla.40:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
    :mozilla.73:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Sextracker : No action taken.
    :mozilla.74:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Sextracker : No action taken.
    :mozilla.153:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
    :mozilla.154:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
    :mozilla.155:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
    :mozilla.156:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
    :mozilla.81:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
    :mozilla.6:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Statistik-gallup : No action taken.
    F:\Documents and Settings\Omistaja.-.001\Cookies\Omistaja@statistik-gallup[1].txt -> TrackingCookie.Statistik-gallup : No action taken.
    :mozilla.22:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
    :mozilla.23:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
    :mozilla.145:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
    :mozilla.148:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
    :mozilla.33:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
    :mozilla.34:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
    :mozilla.35:F:\Documents and Settings\Omistaja.-.001\Application Data\Mozilla\Firefox\Profiles\kncl11ra.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.


    ::Report end

    Siinä oli autom jokasessa pöpön kohdassa Delete laitoin sen,eikai haittaa?Savetin ton raportin,ennen kun poistin ne..Prkl krapula pukkaa päälle.

    Tässä tää F-Securen juttu.
    04/14/07 11:07:30 [Info]: BlackLight Engine 1.0.61 initialized
    04/14/07 11:07:30 [Info]: OS: 5.1 build 2600 (Service Pack 2)
    04/14/07 11:07:30 [Note]: 7019 4
    04/14/07 11:07:30 [Note]: 7005 0
    04/14/07 11:07:33 [Note]: 7006 0
    04/14/07 11:07:33 [Note]: 7011 1316
    04/14/07 11:07:33 [Note]: 7026 0
    04/14/07 11:07:33 [Note]: 7026 0
    04/14/07 11:07:34 [Note]: FSRAW library version 1.7.1021
    04/14/07 11:08:50 [Note]: 7007 0
     
    Last edited: Apr 14, 2007
  6. Auttaja

    Auttaja Guest

    O20 - Winlogon Notify: WgaLogon - F:\WINDOWS\

    fixaa tuo rivi, laita uusin hijackthis logi

    1. Klikkaa käynnistä > Oma tietokone oikean puoleisella hiiren napilla
    2. Valitse ominaisuudet
    3. Valitse järjestelmän palauttaminen välilehti
    4. Ruksi eteen ¤ poista järjestelmän palauttaminen kaikissa asemissa
    5. Paina Käytä
    6. Paina ok
    7. Sammuta ja käynnistä
    8. Ota ruksi pois ¤ poista järjestelmän palauttaminen kaikissa asemissa
    9. Käytä ja OKa
     
  7. Mestaus

    Mestaus Regular member

    Joined:
    Dec 21, 2005
    Messages:
    1,141
    Likes Received:
    0
    Trophy Points:
    46
    Logfile of HijackThis v1.99.1
    Scan saved at 16:55:03, on 14.4.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    F:\WINDOWS\System32\smss.exe
    F:\WINDOWS\system32\winlogon.exe
    F:\WINDOWS\system32\services.exe
    F:\WINDOWS\system32\lsass.exe
    F:\WINDOWS\system32\svchost.exe
    F:\WINDOWS\System32\svchost.exe
    F:\WINDOWS\Explorer.EXE
    F:\WINDOWS\system32\spoolsv.exe
    F:\WINDOWS\SOUNDMAN.EXE
    F:\Program Files\MessengerPlus! 3\MsgPlus.exe
    F:\Program Files\Logitech\SetPoint\SetPoint.exe
    F:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
    F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    F:\WINDOWS\system32\nvsvc32.exe
    F:\Program Files\MSN Messenger\msnmsgr.exe
    F:\WINDOWS\system32\svchost.exe
    F:\WINDOWS\system32\wscntfy.exe
    F:\Program Files\Sygate\SPF\smc.exe
    F:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [NeroFilterCheck] F:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [MessengerPlus3] "F:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [SmcService] F:\PROGRA~1\Sygate\SPF\smc.exe -startgui
    O4 - HKCU\..\Run: [MessengerPlus3] "F:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [msnmsgr] "F:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - Global Startup: Logitech SetPoint.lnk = F:\Program Files\Logitech\SetPoint\SetPoint.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "F:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: NBService - Nero AG - F:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - F:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - F:\Program Files\Sygate\SPF\smc.exe

     
  8. Auttaja

    Auttaja Guest

    Tuleeko viel popuppia? Sulta puuttuu reealiaikainen virustorjunta, esim Antivir on todella hyvä siihen.

    *******

    Avaa omatietokone
    Paina hiiren oikealla napilla Paikallinen levy (C:) asemaa (Tai sitä kovalevyasemaa jota käytät, olisi suotavaa jos tekisit tämän kaikille kiintolevyillesi joita omistat esim. D, F, G)
    ->valitse ominaisuudet
    Avaa työkalut välilehti
    ->aja virheen etsintä
    *molemmat kohdat, siis etsi ja korjaa
    ->eheytä kiintolevy

    *********

    Lataa tuosta CCleaner ja asenna se: http://ccleaner.com/download/downloadpage.aspx?1
    Kun asennat tätä ohjelmaa niin älä asenna sen mukana tulevaa yahoo-toolbaria. Tämä ohjelma
    etsii ja poistaa ns. turhia tiedostoja koneeltasi eli esim: temp tiedostot ja tällä saat myös
    puhdistettua rekisterisi. -korjaa automaattisesti tiedostojärjestelmän virheet¨
    -etsi ja yritä korjata virheelliset sektorit
     
  9. Mestaus

    Mestaus Regular member

    Joined:
    Dec 21, 2005
    Messages:
    1,141
    Likes Received:
    0
    Trophy Points:
    46
    Loppu jokin aika sitten niitten tulo kun vedin koneen escannilla,juuh tuttu ohjelma toi ccleaner,sillä vetelen virheitä/siivoilen.Nii puuttuu joo toi virushommeli,tosin escannilla aina tarkastelen,sygate on mulla muurina oisko hyvä muuri?Jokin kevyt kokoonpano muuri+virustorjunta?
    Kovot on C,D,E,F,G pitää tehä.Tosin jos eheytän wintoosan niin se valittaa,että vähintää 15% tilaa pitäisi olla.Kun on noi kovot nii pirun täynnä.Oisko sulla jtn hyvää eheytyssoftaa?Ja ohjeet miten eheytetään kovo.
     
  10. Auttaja

    Auttaja Guest

    Jepjep, Sygate on hyvä palomuuri, antivir siihen rinnalle niin on hyvä kombinaatio. Eheytyssoftia on hyviä mutta ne ovat tosin maksullisia, esim. diskeeper, ja o&o defrag.
     
  11. Mestaus

    Mestaus Regular member

    Joined:
    Dec 21, 2005
    Messages:
    1,141
    Likes Received:
    0
    Trophy Points:
    46
    Jees.Mikäs kandeis ottaa toi diskleeper?Mite sillä tarkalleen eheytetään sitte..
     

Share This Page