HjT- loki. Voisiko joku kattoo läpi. Kiitos

Discussion in 'Virukset ja haittaohjelmat - HijackThis -logit' started by Zaans, Apr 2, 2007.

  1. Zaans

    Zaans Member

    Joined:
    Jul 20, 2006
    Messages:
    16
    Likes Received:
    0
    Trophy Points:
    11
    Logfile of HijackThis v1.99.1
    Scan saved at 12:38:48, on 2.4.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    D:\Sami II\Sygate Firewall\smc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    C:\WINDOWS\system32\spoolsv.exe
    D:\Sami II\Avast 4\aswUpdSv.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    D:\Sami II\Avast 4\ashServ.exe
    D:\Sami II\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    F:\sami\Spyware Terminator\sp_rsser.exe
    F:\sami\Alcohol 120\StarWind\StarWindService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\CNAB4RPK.EXE
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    D:\Sami II\Avast 4\ashMaiSv.exe
    D:\Sami II\Avast 4\ashWebSv.exe
    C:\WINDOWS\CTHELPER.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\QuickTime\qttask.exe
    F:\sami\iPod\iTunes\iTunesHelper.exe
    F:\sami\iPod\bin\iPodService.exe
    D:\Sami II\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Java\jre1.6.0\bin\jusched.exe
    D:\SAMIII~1\AVAST4~1\ashDisp.exe
    D:\Sami II\Power Iso v.3.6\PWRISOVM.EXE
    C:\WINDOWS\system32\ctfmon.exe
    E:\Program Files\MSN Messenger\msnmsgr.exe
    C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    F:\sami\Winamp\winamp.exe
    F:\Opera\Opera.exe
    D:\Sami II\HijackThis_v1.99.1.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
    O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "F:\sami\iPod\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Sami II\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    O4 - HKLM\..\Run: [SmcService] D:\SAMIII~1\SYGATE~1\smc.exe -startgui
    O4 - HKLM\..\Run: [avast!] D:\SAMIII~1\AVAST4~1\ashDisp.exe
    O4 - HKLM\..\Run: [PWRISOVM.EXE] D:\Sami II\Power Iso v.3.6\PWRISOVM.EXE
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
    O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O11 - Options group: [INTERNATIONAL] International*
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\Sami II\Avast 4\aswUpdSv.exe
    O23 - Service: Automaattinen LiveUpdate-ajastustoiminto - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: avast! Antivirus - Unknown owner - D:\Sami II\Avast 4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - D:\Sami II\Avast 4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - D:\Sami II\Avast 4\ashWebSv.exe" /service (file missing)
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Sami II\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - F:\sami\iPod\bin\iPodService.exe
    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - D:\Sami II\Sygate Firewall\smc.exe
    O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - F:\sami\Spyware Terminator\sp_rsser.exe
    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - F:\sami\Alcohol 120\StarWind\StarWindService.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
     
  2. tomato71

    tomato71 Regular member

    Joined:
    Apr 30, 2006
    Messages:
    1,151
    Likes Received:
    0
    Trophy Points:
    46
    Moi !
    Koneella kaksi virustorjuntaohjelmaa Avast ja Norton poista toinen
    Jos jätit koneelle Nortonin,niin onko se Anti-Virus vai Internet Security
    Jos Internet Security niin poista Sygate Personal Firewall,pysyitkö mukana :D (kysy jos epäselvää)
    Ja poistot tapahtuu lisää/poista sovelluksen kautta ohjauspanelissa

    Loki muuten OK !

    tarkistetaan vielä...

    Skannaa koneesi Kaspersky Online Skannerilla
    Käytä Internet Explorer
    Sinulta kysytään sallitko ActiveX -komponentin asentamisen Kasperskyltä, klikkaa Kyllä.
    • Ohjelma käynnistyy ja aloittaa viimeisimpien tunnistetiedostojen lataamisen.
    • Kun skanneri on asennettu ja tunnistetiedot ladattu, klikkaa Next.
    • Klikkaa nyt asetuksia, Scan Settings
    • Tarkista asetuksista, että seuraavat ovat valittuina:

      o Scan using the following Anti-Virus database:

      + Extended (Jos valittavissa, muuten valitse Standard)

      o Scan Options:

      + Scan Archives
      + Scan Mail Bases
    • Klikkaa OK
    • Nyt valitse "select a target to scan" otsikon alta Oma Tietokone, My Computer
    • Skannaus vie aikaa, joten ole kärsivällinen. Kun skannaus on valmis saat ilmoituksen, jos koneesi on saastunut.
    • Klikkaa nyt Save as Text-painiketta.
    • Tallenna tiedosto työpöydällesi.
    • Kopioi ja Liitä tiedoston sisältö seuraavaan vastaukseesi.

      ja päivitä java

      Javan päivitys ja välimuistin tyhjennys:

      1. Klikkaa Käynnistä -> Ohjauspaneeli ja tupla-klikkaa Lisää tai poista sovellus Ohjauspaneelissa.
      2. Etsi listasta kaikki entiset Java versiosi. (J2SE Runtime Environment.... )
      Niissä pitäisi olla seuraava kuva vieressä: [​IMG]
      3. Valitse kaikki entiset Java versiosi ja valitse Poista.
      4. Asenna uusin Java päivitys seuraavasta linkistä..
      5. Käynnistä kone uudelleen asennuksen jälkeen:

      http://java.sun.com/javase/downloads/index.jsp

      Rullaa alas kohteeseen Java Runtime Environment (JRE) 6u1

      Paina Download

      Ruksaa Accept, ota offline installation, tallenna vaikka työpöydälle ja asenna se.

      6. Käynnistyksen jälkeen, mene takaisin Ohjauspaneeliin ja avaa Java asetuksesi (Muita Ohjauspaneelin asetuksia -> Java kahvikuppi).

      7. General Settings -osion alla, vedä liukusäädintä (Disk Space) pienemmälle, ja klikkaa Delete Files -nappia.

      (Jotkut javapohjaiset ohjelmat saattavat tarvita enemmän levytilaa.
      Jos huomaat säädön pienentämisen jälkeen koneessa hitautta, siirrä liukusäädintä isommalle
      ).

      8. Varmista että kaikki kaksi valintaa ovat rastitettuja:

      *Applications and Applets

      *Trace and Log Files



      Ja paina OK -nappia

      9. Klikkaa OK "Temporary Files Settings" -ikkunassasi.
      Huomaa: Tämä poistaa kaikki ladatut sovellukset ja appletit VÄLIMUISTISTA.

      10. Klikkaa OK jättääksesi Java asetusikkunasi.


      Lähetä uusi hjt-loki ja kasperskyn-loki ja kerro mitä jätit ja mitä poistit
     
  3. Zaans

    Zaans Member

    Joined:
    Jul 20, 2006
    Messages:
    16
    Likes Received:
    0
    Trophy Points:
    11
    Tässä tulis näitä lokeja. Toivottavasti joku viittis kattoa läpi, kiitos.

    Kaspersky Online Scan:

    -------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER REPORT
    Monday, April 16, 2007 6:09:09 PM
    Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.93.0
    Kaspersky Anti-Virus database last update: 16/04/2007
    Kaspersky Anti-Virus database records: 298086
    -------------------------------------------------------------------------------

    Scan Settings:
    Scan using the following antivirus database: extended
    Scan Archives: true
    Scan Mail Bases: true

    Scan Target - My Computer:
    A:\
    C:\
    D:\
    E:\
    F:\
    G:\
    H:\
    I:\
    J:\

    Scan Statistics:
    Total number of scanned objects: 96950
    Number of viruses found: 10
    Number of infected objects: 19
    Number of suspicious objects: 0
    Duration of the scan process: 02:00:06

    Infected Object Name / Virus Name / Last Action
    C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\00a82573889d16c612b9bb85c8be12d9_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\019c83f88bfb2982701c09cf6f7cf070_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0317d3faf3fac5b59a670970fd236357_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\036c2d3f008cd77aa3089fd25e7ae5cc_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\08744e7ba8cea52e887072790f9d19ed_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0c4021a8ea641739dd7d7ef06fb055b8_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0c5ed865d533fb901050794d7469b6cb_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0d0975dc23ed84b11b69e66b14aaf5d1_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0f59827d4faca5c631e97d3272e5c3c0_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\10ebb3eee9b58affd3fa9c00a8e03a70_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\158773f8713fc34a43832c2a286b1c31_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\16d082ff5f70765bd9e21658602abd0b_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\188d27c7298cefa472c78238cda5723b_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1a277469d78350b35f8ade88e14c58fd_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1ac7276b8e0d1d272e4fa55ee30b9373_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1b4aca932021a1c40a00c6df701f906b_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1c541214fb49ee3dd5ac1495866a798d_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1d65b82b38665ad6fb33eeb09fb2da61_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1df0667474cbce52376d1c85b5613341_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1e5353d76be586be6e72b1fa03f4913b_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1f5062d64b39ff62bd1e400d11651154_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1f6aa69ce307cac73206f0b7611a8bc2_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2064f237c6914b72360160a3e0a98fc3_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\20c06ab03d2fb71735f174fae5cc32f0_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2106807edf7085359bebe2f85f8084df_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\216e34e46cdf5f1b29c2490745db7533_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\220028c3424e6bd6ac82fc8807338d5d_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\230c612f5b8b6a55b5cddbb71380b9c8_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2320a9b96e3d85d8873c991d9476fcee_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\254c2474a13b51a1fede5b2e306b95dd_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\26bbf77fe2dd88bc705cc0d605b1f0df_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2727e697d51c393330f894502e1a13d8_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2890e28f18da3076fa9700bf8cca01b5_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\28924b587a5ca4491b5dba5e68eb7751_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2a933553788ec4c4eee7a78dd1fe82ca_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2adddcb80df08518d6d2a78e7d3a443b_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2b9e35c4cc01898c6b0dd7b96a9ef7b5_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2c9d5de5a9b9f29277ba1dd3a58d9d41_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2d2a655b3230c4f2dfc552725c21156e_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2e390ca5854e1abf307558b417e9dc47_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\30870f49f21a4d422919e74f57fe87e9_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\32cd4a89f6af169c0f82b9694a10802a_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\35e013043b65f611b824d50e4f672edb_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3a085df3e1afa0b757747ed9359eed60_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3b9ca6ba6c199bda35c8dcdd84ec9500_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3bb837db6d87efe397d21cb65d7cea89_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\433548e31fc636acf7c71db52f827a80_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\45ffe50f672ad9191a1ef13ef04551c0_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\465e43e3ee966f4794d889e6048d4478_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\467cf8b8f8e53c6ebb067302ec649966_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\47db7328ae0dc6f9971217a79b02f68a_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4879da52ac8004e20e45d15fc7c42088_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\497fbc9dada0e8e2b4f7e84da725902e_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4cfeeb778685221a99e4bc4165c98b99_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4eb64fb43d874f1a719acbfd071da835_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\51e816f1706ececd0b8e315aadc6661a_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\51fbd73b33e2e7ee355e6ce674019a58_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5466fa5d26a03ab30331eada90c331b1_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\54a6e8c5c34c63f0670d1a381ffc9207_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\54ea035e29df722fd4695efbf040ca2b_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\565b78edef64adc1888fd6aa4b93eca8_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\56a7762e69d76dd06e23c162a2dfa61f_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\57581666eb42834cd85689a6ec39e565_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\57a3f7c7824fd4d0102026160dbdfe80_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\59c26a558efe6e42e14b424c3b290f23_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5a140ac4e3ed2ad178ea6d355549cb5b_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5a239b27d260dd138adb3a8862e29b60_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5c67781281cc197b4991b579811ba940_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5fd7fa8a2fbc830f810993b5addd29f3_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\604ceea0afda967a7ec0db63d2ed3ed8_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\625006044a0c87dbbfe0dccf2e5e122b_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6482f799747ac645c6e98ad57129b5e6_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6597c128dcacfd98a67cfe8566b46d4a_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\66080aac0e5d768a1303e5b0ccb2a544_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6858cc44a7b3ba0f272e089695f3d721_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6915da8dd52e0d1484355af6cd098963_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6d980e99315e6732adc40fd87c09ca4a_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6eabf93056022d4ff3be7c1a5c834ae3_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6fa39533afd1674285247cf6f37045ad_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6feddcfc8f4120d5e7e48e48eb51c2fe_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\717888e8df113b8b92646e792e6f5073_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\73efbaa6bb4d5aa524d644ca78206559_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\757352f321da9ead901c91ca6e3f0b2a_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\76139a39bc21ee1e4c67a1c1904335c0_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\782d8fd358a17795632557cb31b0282e_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7b29dd43f903f049f8578f7a1fe65a99_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7bb65a95b9e11e2fbb25d1eabb103aca_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7c2206369316dfeed3c3d111541176e3_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7dfb77b99bdffa94a20aab4597a66f59_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8448371b76c7ba9296e5310cf583847c_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\882c25a225df61050a2364741ea3f9fa_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\89b52ab5903d17a2f07b9eafe9a0f0b2_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8a92ae8481e573a21b288ba9ddda5f4e_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8b14892bc6e21a2ba51b5842107fea8b_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8e7c44391642adfbe9575f0ca2dee1f9_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\977be33ae6bb7c7c46b68523b559bd0c_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9935f02162960fedc00d622d89f67dfb_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\999e78489542bdd722a91bd83184ebb5_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9a571fd0093dc432e33f049515cce99a_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9cb8dc32276e7456f8f50edf9416071b_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9cecebff93fd84cdb9611e25810ebf5d_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a0292685dcf238f05336f2c25711f356_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a14ea4803d66c2eeb501d19b7b99a72a_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a36c78664ca2cb30c0ed503d011e1eb0_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a470dd55a53e555f33801e31ccf0667d_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a620fa6ed8b5e0d0688529ed45f1e77c_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a76127792e79ca5b75ae21c6022c1baa_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a7778786deb67950a46399a81eb53510_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a86cc307ec58f002dad49497c7dabcbc_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aa1808510a1b5e5916869562ea9fcc58_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aaba4a3fa655c4cf0362a18408da0658_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ab8c482878c6b2b7d6c79bf5df3babf7_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ac9de4222947ca14ea11e29dfd420ab1_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ad2a450176030269295334755b800059_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ae8faebf8156bee823b034a11710c141_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b0862238c48faae2a91482cd5d6a46ac_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b2a7d0784e2edeeb84b72bcabcb690f1_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b62552f91c6c89776895d7ffaf72fec6_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b71da3f894cc3de2dfc4d6dc3b834d71_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b74486a5d79896833e218f0ff4090a7f_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b83d4c0c909c514558db81ee6c297828_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ba1a152a0ba8fb902c6b6343d6796ca4_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bc7aecd7b102693222c9eac2d20f401d_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c1fe64684a3b2df87ebf9ffb799773ee_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c2b15138731530245579b0b07c020719_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c42450a4a0a484a10c5a32c4df675141_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c5f99b5a3557e12f4639764ccaff6c27_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c9b0629cc9be06e47d69f2cc3a4f5af1_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cc18fd12963f404f96778b9bc682e22e_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cdd67fe14fc59708ed6012b021e5ccaa_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ce864c339713797923f9352990263ef9_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d017761d611b2fb750d85ef7a2593c18_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d02badcaca592ba2dfb0fc18e6e01f99_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d58b5aecff36113fe00306f158183823_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d64f2394638f4159669cdbe38d007c80_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d7f42bf82fd75c4225a1ee5223b8d767_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d94e9299ee58e521b681c3af7a6bbe44_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\db4d5ba55db1ca2147f3af2853b0887c_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\df411193733c12a9f8a86805dd7b0424_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\df87c86703e00932f41012447a8e3353_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e42defad567b11ac9d955ef9e2f80164_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e5306892790fa1c420dc60601fb50bd5_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eaeaec815c0a19b363131a6439001880_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eaeef02a9334309f750a9119315ad16d_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ed3036f7d3b2da6b1d5959086ec49010_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\edb1f86ee5eecfce8194e8702b73dda7_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f031e6d97a3ed894e64bdf773231fda5_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f1127d1f4410ef62defb796f55031c84_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f657c3f35a701c1d8bd4875d13fb4de7_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f7d607d9b26ee3c406a89aa60d227af4_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fc3302b6cad15d6be729202cd7ff0870_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ff6df714b6a9c6cffa4e578126e10707_77dd04b3-fa7d-4c52-bf15-4140ffec41e9 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-01092007-144258.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Spyware Terminator\setup.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Application Data\Spyware Terminator\setup.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Sivuhistoria\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\Seppo\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\Seppo\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
    C:\Documents and Settings\Seppo\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\Seppo\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\Seppo\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{EC757BA6-1CF8-4954-9816-DC57F1CC5DC9} Object is locked skipped
    C:\Documents and Settings\Seppo\Local Settings\Sivuhistoria\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\Seppo\Local Settings\Sivuhistoria\History.IE5\MSHist012007041620070417\index.dat Object is locked skipped
    C:\Documents and Settings\Seppo\Local Settings\Temp\~DF2545.tmp Object is locked skipped
    C:\Documents and Settings\Seppo\Local Settings\Temp\~DF2684.tmp Object is locked skipped
    C:\Documents and Settings\Seppo\Local Settings\Temp\~DFF08A.tmp Object is locked skipped
    C:\Documents and Settings\Seppo\Local Settings\Temp\~DFF0CD.tmp Object is locked skipped
    C:\Documents and Settings\Seppo\Local Settings\Temp\~ROMFN_00000E04 Object is locked skipped
    C:\Documents and Settings\Seppo\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
    C:\Documents and Settings\Seppo\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\Seppo\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\Seppo\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\Seppo\Omat tiedostot\Outlook Datafiles\Outlook.pst/Personal Folders/Deleted Items/06 Feb 2007 21:06 from Enoch X. Lake:The Long Haul/greeting postcard.exe Infected: Email-Worm.Win32.Zhelatin.r skipped
    C:\Documents and Settings\Seppo\Omat tiedostot\Outlook Datafiles\Outlook.pst Mail MS Mail: infected - 1 skipped
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    C:\System Volume Information\_restore{57BE0EF2-0224-41F4-98BE-350CF3416F9F}\RP92\change.log Object is locked skipped
    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
    C:\WINDOWS\SchedLgU.Txt Object is locked skipped
    C:\WINDOWS\SoftwareDistribution\EventCache\{D7824D61-7E76-4AD2-A67C-EE3E13897420}.bin Object is locked skipped
    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
    C:\WINDOWS\Sti_Trace.log Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
    C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\default Object is locked skipped
    C:\WINDOWS\system32\config\default.LOG Object is locked skipped
    C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
    C:\WINDOWS\system32\config\SAM Object is locked skipped
    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
    C:\WINDOWS\system32\config\software Object is locked skipped
    C:\WINDOWS\system32\config\software.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\system Object is locked skipped
    C:\WINDOWS\system32\config\system.LOG Object is locked skipped
    C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
    C:\WINDOWS\system32\h323log.txt Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
    C:\WINDOWS\Temp\Perflib_Perfdata_730.dat Object is locked skipped
    C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
    C:\WINDOWS\wiadebug.log Object is locked skipped
    C:\WINDOWS\wiaservc.log Object is locked skipped
    C:\WINDOWS\WindowsUpdate.log Object is locked skipped
    C:\WINDOWS\{00000001-00000000-00000009-00001102-00000004-20021102}.CDF Object is locked skipped
    D:\Sami II\Avast 4\DATA\aswResp.dat Object is locked skipped
    D:\Sami II\Avast 4\DATA\Avast4.db Object is locked skipped
    D:\Sami II\Avast 4\DATA\integ\avast.int Object is locked skipped
    D:\Sami II\Avast 4\DATA\log\AshWebSv.ws Object is locked skipped
    D:\Sami II\Avast 4\DATA\log\aswMaiSv.log Object is locked skipped
    D:\Sami II\Avast 4\DATA\log\nshield.log Object is locked skipped
    D:\Sami II\Avast 4\DATA\report\Resident protection.txt Object is locked skipped
    D:\Sami II\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
    D:\Sami II\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
    D:\Sami II\SmitfraudFix.exe RarSFX: infected - 2 skipped
    D:\Sami II\SmitfraudFix.exe PE_Patch.UPX: infected - 2 skipped
    D:\Sami II\Sygate Firewall\debug.log Object is locked skipped
    D:\Sami II\Sygate Firewall\rawlog.log Object is locked skipped
    D:\Sami II\Sygate Firewall\seclog.log Object is locked skipped
    D:\Sami II\Sygate Firewall\syslog.log Object is locked skipped
    D:\Sami II\Sygate Firewall\tralog.log Object is locked skipped
    D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    D:\System Volume Information\_restore{57BE0EF2-0224-41F4-98BE-350CF3416F9F}\RP93\change.log Object is locked skipped
    D:\wanha_D_asema\AGSetup0609.exe/fsg-ag.exe Infected: not-a-virus:AdWare.Win32.Gator.3102 skipped
    D:\wanha_D_asema\AGSetup0609.exe ViseMan: infected - 1 skipped
    D:\wanha_D_asema\AGSetup0609.exe ViseMan: infected - 1 skipped
    D:\wanha_D_asema\Irci-Mirci\mirc612.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.612 skipped
    D:\wanha_D_asema\Irci-Mirci\mirc612.exe mIRC: infected - 1 skipped
    E:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\725E4F5A.ani Infected: Trojan-Downloader.Win32.Ani.b skipped
    E:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\72714B45.anr Infected: Trojan-Downloader.Win32.Ani.c skipped
    E:\System Volume Information\_restore{A27EE49D-44FE-4721-86C2-48695AE96C3E}\RP1\A0000322.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped
    F:\mirc\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
    F:\sami\Alcohol 120\StarWind\logs\starwind.2007-04-16.15-27-25.log Object is locked skipped
    F:\System Volume Information\_restore{A27EE49D-44FE-4721-86C2-48695AE96C3E}\RP1\A0000324.exe Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
    F:\System Volume Information\_restore{A27EE49D-44FE-4721-86C2-48695AE96C3E}\RP1\A0000325.exe/data0014 Infected: not-a-virus:AdTool.Win32.MyWebSearch.ak skipped
    F:\System Volume Information\_restore{A27EE49D-44FE-4721-86C2-48695AE96C3E}\RP1\A0000325.exe/data0015 Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
    F:\System Volume Information\_restore{A27EE49D-44FE-4721-86C2-48695AE96C3E}\RP1\A0000325.exe NSIS: infected - 2 skipped

    Scan process completed.


    Uusin HijackThis loki:

    Logfile of HijackThis v1.99.1
    Scan saved at 18:31:15, on 16.4.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    D:\Sami II\Sygate Firewall\smc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    D:\Sami II\Avast 4\aswUpdSv.exe
    D:\Sami II\Avast 4\ashServ.exe
    D:\Sami II\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\CNAB4RPK.EXE
    C:\WINDOWS\system32\PnkBstrA.exe
    F:\sami\Spyware Terminator\sp_rsser.exe
    F:\sami\Alcohol 120\StarWind\StarWindService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    D:\Sami II\Avast 4\ashMaiSv.exe
    D:\Sami II\Avast 4\ashWebSv.exe
    C:\WINDOWS\CTHELPER.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\QuickTime\qttask.exe
    F:\sami\iPod\iTunes\iTunesHelper.exe
    D:\SAMIII~1\AVAST4~1\ashDisp.exe
    D:\Sami II\Power Iso v.3.6\PowerISO\PWRISOVM.EXE
    F:\sami\iPod\bin\iPodService.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    F:\sami\WinPatrol\winpatrol.exe
    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    D:\Sami II\HijackThis_v1.99.1.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iltalehti.fi/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
    O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "F:\sami\iPod\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [SmcService] D:\SAMIII~1\SYGATE~1\smc.exe -startgui
    O4 - HKLM\..\Run: [avast!] D:\SAMIII~1\AVAST4~1\ashDisp.exe
    O4 - HKLM\..\Run: [PWRISOVM.EXE] D:\Sami II\Power Iso v.3.6\PowerISO\PWRISOVM.EXE
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [WinPatrol] F:\sami\WinPatrol\winpatrol.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
    O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\Sami II\Avast 4\aswUpdSv.exe
    O23 - Service: Automaattinen LiveUpdate-ajastustoiminto - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
    O23 - Service: avast! Antivirus - Unknown owner - D:\Sami II\Avast 4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - D:\Sami II\Avast 4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - D:\Sami II\Avast 4\ashWebSv.exe" /service (file missing)
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Sami II\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - F:\sami\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
    O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - D:\Sami II\Sygate Firewall\smc.exe
    O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - F:\sami\Spyware Terminator\sp_rsser.exe
    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - F:\sami\Alcohol 120\StarWind\StarWindService.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe



    Kiitos jo etukäteen sille joka viitsii katsoa läpi ja myöhäiset kiitoksen tomato71:lle!

    Kysyisin tässä samalla että onko sellainen ohjelma kuin NT Ydin & Järjestelmä ( ntoskrnl.exe ) haitallinen kun Sygate ilmottelee usein, että blokkaa sen toiminnan.
     
  4. tomato71

    tomato71 Regular member

    Joined:
    Apr 30, 2006
    Messages:
    1,151
    Likes Received:
    0
    Trophy Points:
    46
    Jatketaan.....
    Koneella taas 2 virustorjunta ohjelmaa...... :D Avast ja AVG Free
    Poista toinen lisää/poista sovelluksen kautta,vaan 1 koneella

    Paina Käynnistä ---> Suorita -->kirjoita sc stop "Symantec Core LC" (pamauta enteriä )
    Paina Käynnistä ---> Suorita -->kirjoita sc delete "Symantec Core LC" (pamauta enteriä )


    [*]1.Napsauta Käynnistä-painiketta ja valitse Ohjauspaneeli.
    [*]2.Valitse "Kansion asetukset"
    [*]3.Siirry "Näytä välilehdelle"
    [*]4.Valitse Näytä-välilehden Piilotetut tiedostot ja kansiot -kohdassa" Näytä piilotetut tiedostot ja kansiot."


    Tallenna nämä ohjeet tekstitiedostoon työpöydälle tai tulosta nämä, muuten et pääse niihin käsiksi vikasietotilasta


    [*]Käynnistä tietokone
    [*]Kun kuulet koneen piippaavan, paina F8, kuitenkin ennen Windowsin logon esiintuloa
    [*]Seuraavaksi pitäisi ilmestyä valikko
    [*]Valitse valikosta vikasietotila.


    Poista Kansiot:

    C:\Program Files\Common Files\Symantec Shared
    E:\Program Files\Norton Internet Security


    Tyhjennä kansio(älä poista kansiota vaan tyhjennä se):

    C:\Documents and Settings\Seppo\Omat tiedostot\Outlook Datafiles\Outlook.pst/Personal Folders/Deleted Items


    Käynnistä kone uudelleen

    Tarkista tämä tiedosto D:\wanha_D_asema\AGSetup0609.exe täällä-->Virustotal
    kopioi tulos muistioon ja liitä se sitten tänne

    * Lataa Dr.Web CureIt työpöydälle:
    ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

    Tuplaklikkaa drweb-cureit.exe ja anna sen tehdä express scan
    Se skannaa käynnissä olevat ohjelmat ja jos jotain löytyy, klikkaa yes kun se kysyy haluatko poistaa sen. Tämä on vain lyhyt scan.
    Kun scan on valmis, merkkaa asemat, jotka haluat scannata.
    Valitse kaikki asemat. Punainen piste osoittaa, mitkä asemat on valittu.
    Klikaa vihreää nuolta oikealla ja scan alkaa.
    Klikkaa 'Yes to all', jos kysytään haluatko poistaa/siirtää tiedoston.
    Kun scan on valmis, katso voitko klikata next-kuvaketta löytyneiden tiedostojen vieressä: [​IMG]
    Jos asia on niin, klikkaa sitä ja sitten klikkaa next-kuvaketta oikealla alhaalla ja valitse Move incurable kuten alla olevalla kuvassa:
    [​IMG]
    Tämä siirtää sen %userprofile%\DoctorWeb\quarantine-hakemistoon.
    Tämän jälkeen klikkaa Dr.Web CureIt-valikossa file ja valitse save report list
    Tallenna raportti työpöydälle. Raportin nimi on DrWeb.csv
    Sulje Dr.Web Cureit.
    Käynnistä kone uudelleen !! Tämä siksi, että käytössä olevat tiedostot poistetaan/siirretään käynnistyksen yhteydessä.
    Käynnistyksen jälkeen liitä Dr.Web-lokin, jonka tallensit aiemmin, sisältö seuraavaan vastaukseesi.

    Ja tässä juttua tuosta ntoskrnl.exe

    lue

    lue


    Lähetä uusi hjt-loki + DrWeb-loki ja virustotalin tulos
     
    Last edited: May 5, 2007
  5. Zaans

    Zaans Member

    Joined:
    Jul 20, 2006
    Messages:
    16
    Likes Received:
    0
    Trophy Points:
    11
    Ei oikeen onnistu toi vikasietotilaan meneminen... :D Painan F8, mutta mitään ei tapahdu. Teen varmasti jotain väärin, mutta en oikeen saanut selvää mitä pitää painaa tosta ----> F8
     
  6. tomato71

    tomato71 Regular member

    Joined:
    Apr 30, 2006
    Messages:
    1,151
    Likes Received:
    0
    Trophy Points:
    46
    Moi! Ei riitä että painat F8 kerran vaan sun pitää jatkuvasti(lyhyitä painalluksia nopeeseen tahtiin) painaa sitä heti kun virrat laitat päälle
     

Share This Page