1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

jotkut ohjelmat sammuvat itsestään tässä hjt loki

Discussion in 'Virukset ja haittaohjelmat - HijackThis -logit' started by sod77, Sep 16, 2008.

  1. sod77

    sod77 Member

    Joined:
    Feb 19, 2008
    Messages:
    90
    Likes Received:
    0
    Trophy Points:
    16
    tässä lista..

    7-Zip 4.57
    Acrobat.com
    Acrobat.com
    Adobe AIR
    Adobe AIR
    Adobe Flash Player ActiveX
    Adobe Flash Player Plugin
    Adobe Reader 9
    AGEIA PhysX v7.09.13
    Ask Toolbar
    Atheros Communications Inc.(R) AR8121/AR8113 Gigabit/Fast Ethernet Driver
    avast! Antivirus
    AVG Anti-Spyware 7.5
    Battlefield 2(TM)
    BitComet 1.03
    BitTornado 0.3.18
    BS.Player PRO
    Call of Duty(R) 4 - Modern Warfare(TM)
    CDDRV_Installer
    CleanMyPC - Registry Cleaner
    Crysis(R)
    DAEMON Tools Toolbar
    DC++ 0.707
    DigitalTV
    DVD Suite
    EPU-6 Engine
    EVEREST Ultimate Edition v4.50
    ffdshow [rev 2073] [2008-08-11]
    FileZilla (remove only)
    FileZilla Server (remove only)
    GRID
    HijackThis 2.0.2
    HydraVision
    Java(TM) 6 Update 7
    LG ODD Auto Firmware Update
    LiveUpdate (Symantec Corporation)
    LiveUpdate (Symantec Corporation)
    Logitech Desktop Messenger
    Logitech SetPoint
    Malwarebytes' Anti-Malware
    marvell 61xx
    MediaPortal 0.2.3.0
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB929729)
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2005 Redistributable
    Mozilla Firefox (3.0.1)
    MpcStar 3.1
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB941833)
    MyTheatre
    Nero 7 Essentials
    neroxml
    OpenAL
    OpenMG Limited Patch 4.7-07-14-05-01
    OpenMG Secure Module 4.7.00
    OpenOffice.org Installer 1.0
    PowerDVD
    PowerProducer
    PunkBuster Services
    Realtek High Definition Audio Driver
    RivaTuner v2.09
    SonicStage 4.3
    SpeedFan (remove only)
    Uniblue PowerSuite
    Unreal Tournament 3
    WinAce Archiver
    Winamp
    Windows Live installer
    Windows Live Messenger
    Zultrax P2P

     
  2. Hujo

    Hujo Guest

    Poista lisää poista sovelutuksesta

    Ask Toolbar
    AVG Anti-Spyware 7.5
    LiveUpdate (Symantec Corporation)
    LiveUpdate (Symantec Corporation)
    Logitech Desktop Messenger


    Poista kansiot vikasietotilassa

    C:\Program Files (x86)\Grisoft
    C:\Program Files (x86)\AskSBar
    C:\Program Files (x86)\Symantec

    Pysäytä serviset

    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files (x86)\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_4.EXE

    tuplalikkaa laita Seis alasvetovalikosta ei käytössä
    Käytä ja Ok
     
    Last edited by a moderator: Sep 21, 2008
  3. sod77

    sod77 Member

    Joined:
    Feb 19, 2008
    Messages:
    90
    Likes Received:
    0
    Trophy Points:
    16
    tässä uusi hjt:n loki..

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 17:38:45, on 22.9.2008
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
    Boot mode: Normal

    Running processes:
    C:\Program Files\ASUS\Six Engine\SixEngine.exe
    C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe
    C:\Program Files (x86)\CleanMyPC\Registry Cleaner\RCHelper.exe
    C:\Program Files (x86)\PC-TV\WinManager\WinManager.exe
    C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\HJT\HiJackThis_v2.0.2.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.2.6.26.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
    O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\MSN Toolbar\01.01.2607.0\en-us\msntb.dll
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [MCE CI Console] "C:\Program Files (x86)\MCECIConsole\MCECIConsole.exe"
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files (x86)\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] C:\Program Files (x86)\Uniblue\SpeedUpMyPC 3\StartSUMP2.exe
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe" -autorun
    O4 - HKCU\..\Run: [Registry Cleaner Scheduler] "C:\Program Files (x86)\CleanMyPC\Registry Cleaner\RCHelper.exe" /startup
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Paikallinen palvelu')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'Paikallinen palvelu')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Verkkopalvelu')
    O4 - Global Startup: Logitech SetPoint.lnk = ?
    O4 - Global Startup: WinManager.lnk = C:\Program Files (x86)\PC-TV\WinManager\WinManager.exe
    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files (x86)\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files (x86)\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files (x86)\BitComet\BitComet.exe/AddAllLink.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.2.6.26.dll/206 (file missing)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O13 - Gopher Prefix:
    O17 - HKLM\System\CCS\Services\Tcpip\..\{E5E6DC90-1BC7-44D5-BB1F-73B0C02AF20C}: Domain = pp.htv.fi
    O20 - AppInit_DLLs: C:\Windows\SysWOW64\cssdll32.dll C:\Windows\SysWOW64\guard32.dll
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: ASP.NET-tilapalvelu (aspnet_state) - Unknown owner - (no file)
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\Comodo\Firewall\cmdagent.exe
    O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
    O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files (x86)\FileZilla Server\FileZilla Server.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Input Service (InputService) - and-81 - C:\Program Files (x86)\IR Server Suite\Input Service\Input Service.exe
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    --
    End of file - 9478 bytes
     
  4. Hujo

    Hujo Guest

    mites kone toimii
     
  5. sod77

    sod77 Member

    Joined:
    Feb 19, 2008
    Messages:
    90
    Likes Received:
    0
    Trophy Points:
    16
    hyvin toimii.. pitää vaan selvittää tuo IE ongelma..

    en ole varma mutta voiko tuon IE:n ongelma johtua tästä..

    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll

    tämä löytyi mikrosoftin sivuilta

    Tämä ongelma saattaa ilmetä, jos vähintään yksi seuraavista ehdoista toteutuu:
    • Internet Explorerin yhteysasetukset ovat virheelliset.
    • Hosts-tiedostossa on virheellinen merkintä.
    • Winsock.dll-, Wsock32.dll- tai Wsock.vxd-tiedosto puuttuu tai on vioittunut.
    • Winsock.dll-, Wsock32.dll- tai Wsock.vxd-tiedostosta on useita kopioita tai jokin tiedostoista on väärässä kansiossa.
    • TCP/IP:tä ei ole asennettu tai se ei toimi oikein.
    • WinSock2-rekisteriavain on vioittunut.
    • Internet-yhteyden jakaminen ei toimi tai sen asennus on vioittunut.
    • Rnr20.dll-tiedosto puuttuu tai on vioittunut, tai seuraavan rekisteriavaimen Library Path -arvo puuttuu tai sisältää väärän sijainnin:
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinSock2\ Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001


    Tässä linkki sivulle
     
    Last edited: Sep 22, 2008
  6. Hujo

    Hujo Guest

    ookos laitanut vistan palomuurin päälle

    Kun koneella on COMODO Firewall Pro

    nuo kuuluu vistalle
     
  7. sod77

    sod77 Member

    Joined:
    Feb 19, 2008
    Messages:
    90
    Likes Received:
    0
    Trophy Points:
    16
    vistan oma palomuuri on pois käytöstä ja comodo on käytösssä..
     
  8. Hujo

    Hujo Guest

    sitten suntarvii noita ruveta tarkisteleen mitä mikrosoftin sivuilta löysit.
     

Share This Page