Ilmeisesti Smitfraud

Discussion in 'Virukset ja haittaohjelmat' started by mikkeli, Jun 17, 2006.

  1. mikkeli

    mikkeli Member

    Joined:
    Jan 7, 2004
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    11
    koneeseeni pesi jokin "koijari". Kun explorerin avaa, kotisivua ei voi muuttaa vaan se on jokin "safetyupdate.net"joka kertoo että koneessani on mato tms. ja kehoittaa klikkaamaan kuvaketta jonka kautta voi ostaa siihen poistoohjelman.Mikään haittapoisto-ohjelma ei ole kyennyt matoa poistamaan koneestani ja keinoni alkaa loppumaan. Voisiko joku kertoa mitä pitäisi tehdä?

    Säännöllisesti koneen oikeaan alalaitaan ilmestyi keltainen kolmio ja teksi että kone on saastunut. Lisäksi välillä tuli pop-uppeja vaikka selain ei ollut auki.Sain ne pois kun tyhjensin regeditillä explorerin history-rekisterit tyhjäksi. Joku haittapoisto ohjelma läysi jonkin smitfraud-systeemin ja ei kuitenkaan sitä poistanut. Mikä lie ollut? Mutta millä tuon exploreri-ongelman saisi pois?
     
  2. Jurppis

    Jurppis Regular member

    Joined:
    Feb 22, 2006
    Messages:
    659
    Likes Received:
    0
    Trophy Points:
    26
  3. mikkeli

    mikkeli Member

    Joined:
    Jan 7, 2004
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    11
    Joo, palataan illemmalla asiaan kunhan pääsen töistä kotiin.
     
  4. mikkeli

    mikkeli Member

    Joined:
    Jan 7, 2004
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    11
    Logfile of HijackThis v1.99.1
    Scan saved at 16:21:11, on 18.6.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\atmclk.exe
    C:\WINDOWS\system32\dcomcfg.exe
    C:\ATI-CPanel\atiptaxx.exe
    C:\Norman\bin\ZLH.EXE
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
    C:\Program Files\Logitech\Profiler\lwemon.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\WinTV\Ir.exe
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    C:\Program Files\Logitech\SetPoint\KEM.exe
    C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
    C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Norman\Bin\Zanda.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\wdfmgr.exe
    C:\Norman\Nvc\BIN\NIP.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    C:\Norman\Nvc\bin\nvcoas.exe
    C:\Norman\bin\NJEEVES.EXE
    C:\Norman\Nvc\BIN\NVCSCHED.EXE
    C:\Norman\Nvc\BIN\nipsvc.exe
    C:\WINDOWS\System32\alg.exe
    C:\Norman\Nvc\bin\cclaw.exe
    C:\WINDOWS\System32\msiexec.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Vilma\Omat tiedostot\Ylläpito\Haittaohjelmien poisto\Hijack\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.fi
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Nothing - {686a161d-5bd1-4999-8832-6393f41e564c} - C:\WINDOWS\system32\hp100.tmp
    O4 - HKLM\..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe
    O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH
    O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
    O4 - HKLM\..\Run: [ToniArts EasyCleaner] "C:\Program Files\ToniArts\EasyCleaner\EasyClea.exe" -s -startup
    O4 - HKCU\..\Run: [Start WingMan Profiler] "C:\Program Files\Logitech\Profiler\lwemon.exe" /noui
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1132952094024
    O18 - Protocol: bw+0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw+0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw-0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw-0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw00 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw00s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw10 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw10s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw20 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw20s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw30 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw30s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw40 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw40s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw50 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw50s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw60 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw60s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw70 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw70s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw80 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw80s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw90 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw90s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwa0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwa0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwb0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwb0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwc0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwc0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwd0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwd0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwe0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwe0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwf0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwf0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - (no file)
    O18 - Protocol: bwg0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwg0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwh0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwh0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwi0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwi0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwj0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwj0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwk0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwk0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwl0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwl0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwm0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwm0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwn0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwn0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwo0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwo0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwp0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwp0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwq0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwq0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwr0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwr0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bws0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bws0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwt0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwt0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwu0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwu0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwv0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwv0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bww0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bww0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwx0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwx0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwy0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwy0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwz0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwz0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: offline-8876480 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe
    O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE
    O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\Bin\Zanda.exe
    O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe
    O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe

    ################33

    tässä tämä minun logitiedosto. Vastauksia odotellen.....
     
  5. Jurppis

    Jurppis Regular member

    Joined:
    Feb 22, 2006
    Messages:
    659
    Likes Received:
    0
    Trophy Points:
    26
    Lataa SmitfraudFix © S!Ri
    http://siri.urz.free.fr/Fix/SmitfraudFix.zip
    Pura sisältö (kansio nimeltä SmitfraudFix) työpöydällesi:

    Avaa SmitfraudFix kansio ja tupla-klikkaa smitfraudfix.cmd
    Valitse optio #1 - Search kirjoittamalla 1 ja painamalla "Enter"; tekstitiedosto avautuu, joka listaa tarttuneet tiedostot (jos olemassa).
    Postita tämän tekstitiedoston sisältö viestiketjuusi.
     
  6. mikkeli

    mikkeli Member

    Joined:
    Jan 7, 2004
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    11
    SmitFraudFix v2.61

    Scan done at 17:46:50,04, su 18.06.2006
    Run from C:\Documents and Settings\Vilma\Omat tiedostot\Yll„pito\Haittaohjelmien poisto\SmitfraudFix\SmitfraudFix
    OS: Microsoft Windows XP [versio 5.1.2600] - Windows_NT
    Fix ran in normal mode

    »»»»»»»»»»»»»»»»»»»»»»»» C:\


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

    C:\WINDOWS\system32\atmclk.exe FOUND !
    C:\WINDOWS\system32\dcomcfg.exe FOUND !
    C:\WINDOWS\system32\hp???.tmp FOUND !
    C:\WINDOWS\system32\hp????.tmp FOUND !
    C:\WINDOWS\system32\ld????.tmp FOUND !
    C:\WINDOWS\system32\simpole.tlb FOUND !
    C:\WINDOWS\system32\stdole3.tlb FOUND !

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Vilma\Application Data


    »»»»»»»»»»»»»»»»»»»»»»»» Start Menu


    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Vilma\Suosikit

    C:\DOCUME~1\Vilma\Suosikit\Antivirus Test Online.url FOUND !

    »»»»»»»»»»»»»»»»»»»»»»»» Desktop


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


    »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


    »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
    "Source"="About:Home"
    "SubscribedURL"="About:Home"
    "FriendlyName"="Nykyinen kotisivu"


    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{8dc1f789-e073-4363-b40d-07376bc5ecc5}"="articulation"

    [HKEY_CLASSES_ROOT\CLSID\{8dc1f789-e073-4363-b40d-07376bc5ecc5}\InProcServer32]
    [HKEY_CURRENT_USER\Software\Classes\CLSID\{8dc1f789-e073-4363-b40d-07376bc5ecc5}\InProcServer32]

    »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


    »»»»»»»»»»»»»»»»»»»»»»»» End


    siinähän se....
     
  7. Jurppis

    Jurppis Regular member

    Joined:
    Feb 22, 2006
    Messages:
    659
    Likes Received:
    0
    Trophy Points:
    26
    Avaa HijackThis, paina do a system scan only ja merkkaa nämä:

    O18 - Protocol: bw+0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw+0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw-0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw-0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw00 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw00s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw10 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw10s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw20 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw20s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw30 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw30s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw40 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw40s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw50 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw50s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw60 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw60s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw70 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw70s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw80 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw80s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw90 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bw90s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwa0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwa0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwb0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwb0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwc0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwc0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwd0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwd0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwe0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwe0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwf0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwf0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - (no file)
    O18 - Protocol: bwg0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwg0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwh0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwh0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwi0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwi0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwj0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwj0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwk0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwk0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwl0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwl0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwm0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwm0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwn0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwn0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwo0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwo0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwp0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwp0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwq0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwq0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwr0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwr0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bws0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bws0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwt0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwt0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwu0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwu0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwv0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwv0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bww0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bww0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwx0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwx0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwy0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwy0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwz0 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: bwz0s - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)
    O18 - Protocol: offline-8876480 - {2AF979B6-3DF2-4DD6-8CD4-34295A21A71F} - (no file)

    sulje kaikki ikkunat ja paina fix cheked

    Käynnistä koneesi vikasietotilaan ja valitse tavallinen käyttäjätilisi
    http://www.pchell.com/support/safemode.shtml

    Kun vikasietotilassa, avaa SmitfraudFix kansio ja tupla-klikkaa smitfraudfix.cmd
    Valitse optio #2 - Clean kirjoittamalla 2 ja painamalla "Enter" poistaaksesi tarttuneet tiedostot.

    Sinulta kysytään: "Registry cleaning - Do you want to clean the registry ?"; vastaa "Yes" kirjoittamalla Y ja paina "Enter" poistaaksesi työpöydän taustakuvan ja puhdistaaksesi tarttuneet rekisteriavaimet.

    Työkalu tarkistaa jos wininet.dll on tarttunut. Sinua saatetaan pyytää korvaamaan tarttunut .dll (jos löytyy); vastaa "Yes" kirjoittamalla Y ja painamalla "Enter".

    Työkalun saattaa tarvita käynnistää kone uudelleen; jos ei tee niin, käynnistä normaaliin Windowsiin.
    Tekstitiedosto ilmestyy, puhdistusprosessin jäljiltä; kopioi & liitä tämän raportin tulokset vastaukseesi.
    Raportti löytyy paikalliselta levyltäsi, useimmiten C:\rapport.txt. Lähetä lisäksi uusi HijackThis loki.
     
  8. mikkeli

    mikkeli Member

    Joined:
    Jan 7, 2004
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    11
    SmitFraudFix v2.61

    Scan done at 18:35:38,84, su 18.06.2006
    Run from C:\Documents and Settings\Vilma\Omat tiedostot\Yll„pito\Haittaohjelmien poisto\SmitfraudFix\SmitfraudFix
    OS: Microsoft Windows XP [versio 5.1.2600] - Windows_NT
    Fix ran in safe mode

    »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{8dc1f789-e073-4363-b40d-07376bc5ecc5}"="articulation"

    [HKEY_CLASSES_ROOT\CLSID\{8dc1f789-e073-4363-b40d-07376bc5ecc5}\InProcServer32]
    [HKEY_CURRENT_USER\Software\Classes\CLSID\{8dc1f789-e073-4363-b40d-07376bc5ecc5}\InProcServer32]

    »»»»»»»»»»»»»»»»»»»»»»»» Killing process


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

    C:\WINDOWS\system32\atmclk.exe Deleted
    C:\WINDOWS\system32\dcomcfg.exe Deleted
    C:\WINDOWS\system32\hp???.tmp Deleted
    C:\WINDOWS\system32\ld????.tmp Deleted
    C:\WINDOWS\system32\simpole.tlb Deleted
    C:\WINDOWS\system32\stdole3.tlb Deleted
    C:\DOCUME~1\Vilma\Suosikit\Antivirus Test Online.url Deleted

    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


    »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

    Registry Cleaning done.

    »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» End


    ja lisäksi uusi hijackThis logi


    Logfile of HijackThis v1.99.1
    Scan saved at 18:41:10, on 18.6.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\ATI-CPanel\atiptaxx.exe
    C:\Norman\bin\ZLH.EXE
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
    C:\Program Files\Logitech\Profiler\lwemon.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\WinTV\Ir.exe
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    C:\Program Files\Logitech\SetPoint\KEM.exe
    C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
    C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Norman\Bin\Zanda.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\wdfmgr.exe
    C:\Norman\Nvc\BIN\NIP.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    C:\WINDOWS\System32\wbem\wmiprvse.exe
    C:\Norman\Nvc\bin\nvcoas.exe
    C:\Norman\bin\NJEEVES.EXE
    C:\Norman\Nvc\BIN\nipsvc.exe
    C:\Norman\Nvc\BIN\NVCSCHED.EXE
    C:\WINDOWS\System32\alg.exe
    C:\Norman\Nvc\bin\cclaw.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\System32\wbem\wmiprvse.exe
    C:\Documents and Settings\Vilma\Omat tiedostot\Ylläpito\Haittaohjelmien poisto\Hijack\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe
    O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH
    O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
    O4 - HKLM\..\Run: [ToniArts EasyCleaner] "C:\Program Files\ToniArts\EasyCleaner\EasyClea.exe" -s -startup
    O4 - HKCU\..\Run: [Start WingMan Profiler] "C:\Program Files\Logitech\Profiler\lwemon.exe" /noui
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1132952094024
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe
    O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE
    O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\Bin\Zanda.exe
    O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe
    O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe

    siinäpä ne.....mitäs sitten seuraavaksi?

    Mutta nytpä tuo tuntuu toimivan, ei herjaa eikä tule pop-uppeja.
     
    Last edited: Jun 18, 2006
  9. Jurppis

    Jurppis Regular member

    Joined:
    Feb 22, 2006
    Messages:
    659
    Likes Received:
    0
    Trophy Points:
    26
    Loki on puhdas ja jos ei ongelmia enää ilmene niin tämä selvä :)
     
  10. mikkeli

    mikkeli Member

    Joined:
    Jan 7, 2004
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    11
    kiitos todella paljon ja hyvät kesät ja juhannukset!
     

Share This Page