HJT-loki siivouksen päätteeksi

Discussion in 'Virukset ja haittaohjelmat - HijackThis -logit' started by saamu, Feb 26, 2008.

Thread Status:
Not open for further replies.
  1. saamu

    saamu Regular member

    Joined:
    Oct 21, 2003
    Messages:
    180
    Likes Received:
    0
    Trophy Points:
    26
    Kone hidastunut jonkun verran ja skannailin nyt AVG-antispywaren ja EScanin läpi. Löisivät joitakin tiedostoja. Tässä olis vielä HJT-loki, josko siinä näkyis jotain vai joko on puhdasta.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 16:01:36, on 26.2.2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    G:\WINDOWS\System32\smss.exe
    G:\WINDOWS\system32\winlogon.exe
    G:\WINDOWS\system32\services.exe
    G:\WINDOWS\system32\lsass.exe
    G:\WINDOWS\system32\svchost.exe
    G:\WINDOWS\System32\svchost.exe
    G:\WINDOWS\system32\spoolsv.exe
    G:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    G:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    G:\WINDOWS\ATKKBService.exe
    G:\Program Files\Comodo Firewall\cmdagent.exe
    G:\WINDOWS\system32\nvsvc32.exe
    G:\WINDOWS\system32\svchost.exe
    G:\WINDOWS\Explorer.EXE
    G:\Program Files\Unlocker\UnlockerAssistant.exe
    G:\Program Files\DAEMON Tools\daemon.exe
    G:\Program Files\Comodo Firewall\cfp.exe
    G:\Program Files\Windows Live\Messenger\usnsvc.exe
    I:\Program Files\Opera 9.5 beta\opera.exe
    I:\HJT\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: Adobe PDF Reader -linkkiavustaja - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - G:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE G:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [UnlockerAssistant] "G:\Program Files\Unlocker\UnlockerAssistant.exe"
    O4 - HKCU\..\Run: [DAEMON Tools] "G:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - i:\c\program files\messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - i:\c\program files\messenger\msmsgs.exe (file missing)
    O20 - AppInit_DLLs: G:\WINDOWS\system32\guard32.dll
    O20 - Winlogon Notify: !SASWinLogon - I:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - G:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - G:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - G:\WINDOWS\ATKKBService.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - I:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - G:\Program Files\Comodo Firewall\cmdagent.exe
    O23 - Service: NetLimiter (nlsvc) - Locktime Software - I:\Program Files\NetLimiter 2 Pro\nlsvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - G:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PDAgent - Raxco Software, Inc. - I:\Program Files\Raxco\PerfectDisk\PDAgent.exe
    O23 - Service: PDEngine - Raxco Software, Inc. - I:\Program Files\Raxco\PerfectDisk\PDEngine.exe
    O23 - Service: PDExchange - Raxco Software, Inc. - I:\Program Files\Raxco\PerfectDisk\PDExchange.exe
    O23 - Service: ServiceLayer - Nokia. - G:\Program Files\PC Connectivity Solution\ServiceLayer.exe

    --
    End of file - 4090 bytes
     
Thread Status:
Not open for further replies.

Share This Page