Elikkäs kun kone on päällä jonki aikaa (vaihtelee n.5 minuutista pariin tuntiin) niin jossain vaihees jumittaa niin et ne ohjelmat jotka on auki toimii, mut [bold]uusia ei saa käynnistettyä käynnitsä-valikosta, eikä työpöydältä.[/bold] Tähän vikaa tuntuu auttavan vaan koneen reset-namiska, mutte huvittais miljoonaa kertaa päiväs... Oliskos kellään ideoita millä saisin tämän kuntoon?
Virukset ja haittaohjelmat tarkistettu? Laita varoiksi HjT-loki, ohjelman saat täältä -> http://koti.mbnet.fi/pattaya1/HijackThis.exe . Tallenna hakemistoon c:\hjt, käynnistä, klikkaa do a system scan and save a logfile ja lähetä loki tänne.
Oot tehnyt levyneheytykset yms? skannannut koneet haittaphjelmien varalta? Ajappa läpi spybotit ja adwaret yms, jos ne ei helpi katotaan hjtlogi.
Logfile of HijackThis v1.99.1 Scan saved at 15:43:48, on 30.10.2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\bin\ZLH.EXE C:\Program Files\BELKIN USB Wireless Monitor\InfoMyCa.exe C:\Program Files\Logitech\MediaLife\MediaLifeService.exe C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\System32\ctfmon.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe C:\Program Files\Logitech\SetPoint\KEM.exe C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE C:\Program Files\BELKIN USB Wireless Monitor\WLService.exe C:\Program Files\Nvc\BIN\NPFSVICE.EXE C:\Program Files\BELKIN USB Wireless Monitor\WLanCfgG.exe C:\Program Files\Bin\Zanda.exe C:\WINDOWS\System32\wdfmgr.exe C:\Program Files\Nvc\BIN\NIP.EXE C:\Program Files\Npf\BIN\npfmsg2.exe C:\Program Files\Nvc\BIN\NVCSCHED.EXE C:\Program Files\bin\NJEEVES.EXE C:\Program Files\Nvc\bin\nvcoas.exe C:\Program Files\Nvc\BIN\nipsvc.exe C:\Program Files\Nvc\bin\cclaw.exe C:\WINDOWS\System32\wuauclt.exe C:\Program Files\Teamspeak2_RC2\server_windows.exe C:\Program Files\Teamspeak2_RC2\TeamSpeak.exe C:\Program Files\Opera\Opera.exe C:\HjT\HijackThis.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [Norman ZANDA] C:\Program Files\bin\ZLH.EXE /LOAD /SPLASH O4 - HKLM\..\Run: [Getca] C:\Program Files\BELKIN USB Wireless Monitor\InfoMyCa.exe O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Logitech\MediaLife\MediaLifeService.exe" O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O18 - Protocol: bw+0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw+0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O18 - Protocol: bwg0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwg0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O18 - Protocol: offline-8876480 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Belkin 54Mbps Wireless USB Network Service (Belkin 54Mbps Wireless USB) - Unknown owner - C:\Program Files\BELKIN USB Wireless Monitor\WLService.exe O23 - Service: Mouse Cursor Monitor (mousecrm) - Unknown owner - C:\WINDOWS\System32\mousecrm.exe (file missing) O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Program Files\Nvc\BIN\nipsvc.exe O23 - Service: Norman NJeeves - Unknown owner - C:\Program Files\bin\NJEEVES.EXE O23 - Service: Norman Type-R - Unknown owner - C:\Program Files\Nvc\BIN\NPFSVICE.EXE O23 - Service: Norman ZANDA - Unknown owner - C:\Program Files\Bin\Zanda.exe O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Program Files\Nvc\bin\nvcoas.exe O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Program Files\Nvc\BIN\NVCSCHED.EXE
Hae täältä -> http://www.atribune.org/downloads/rdrivrem.zip rdrivrem ja pura työpöydälle. Hae täältä -> http://www.ewido.net/en/download ewido, asenna ja päivitä, muttä ÄLÄ skannaa vielä! Hae Cleanup -> http://www.stevengould.org/software/cleanup/download.html ja asenna se. Käynnistä vikasietotilaan (F8 käynnistyksen yhteydessä) Avaa rdriv-kansio työpöydältä ja tuplaklikkaa rdrivRem.bat. Seuraa ohjeita. Seuraavaksi skannaa ewidolla, anna poistaa kaikki mitä löytää ja tallenna raportti. Fixaa HjT:llä (do a system scan only, merkkaa ja paina fix checked): O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O23 - Service: Mouse Cursor Monitor (mousecrm) - Unknown owner - C:\WINDOWS\System32\mousecrm.exe (file missing) Sitten käynnistä -> suorita -> services.msc -> ok -> etsi listalta Mouse Cursor Monitor -> tuplaklikkaa ja valitse käynnistymistavaksi "ei käytössä". Käynnistä Cleanup! Klikkaa asetukset. Mene kohtaan "Custom CleanUp!" Valitse nämä kohdat: * Empty Recycle Bins * Delete Cookies * Delete Prefetch files * Cleanup! All Users Click OK Paina CleanUp!. Paina no, jos Cleanup! haluaa käynnistää koneen. Käynnistä normaalitilaan ja lähetä rdriv.txt-tiedoston sisältö (löytyy rdriv-kansiosta), ewidon raportti ja uusi HjT-loki.
rdriv kansiosta ei löytynyt muuta ku tämä: ~~~~~~~~~~~~~ Pre-run File Check ~~~~~~~~~~~~~ ~~~~~~~~~~~~~ Pre-run File Check ~~~~~~~~~~~~~ ~~~~~~~~~~~~~ Post run File Check ~~~~~~~~~~~~~ ~~~~~~~~~~~~~ Pre-run File Check ~~~~~~~~~~~~~ ~~~~~~~~~~~~~ Post run File Check ~~~~~~~~~~~~~ ~~~~~~~~~~~~~ Pre-run File Check ~~~~~~~~~~~~~ ~~~~~~~~~~~~~ Post run File Check ~~~~~~~~~~~~~ ewidon raportti: --------------------------------------------------------- ewido security suite - Scan report --------------------------------------------------------- + Created on: 16:37:29, 30.10.2005 + Report-Checksum: 1CED6604 + Scan result: :mozilla.14:C:\Documents and Settings\Jani Peltoniemi\Application Data\Mozilla\Firefox\Profiles\w7vxlzy1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned without backup :mozilla.15:C:\Documents and Settings\Jani Peltoniemi\Application Data\Mozilla\Firefox\Profiles\w7vxlzy1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned without backup :mozilla.16:C:\Documents and Settings\Jani Peltoniemi\Application Data\Mozilla\Firefox\Profiles\w7vxlzy1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned without backup :mozilla.17:C:\Documents and Settings\Jani Peltoniemi\Application Data\Mozilla\Firefox\Profiles\w7vxlzy1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned without backup :mozilla.18:C:\Documents and Settings\Jani Peltoniemi\Application Data\Mozilla\Firefox\Profiles\w7vxlzy1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned without backup :mozilla.19:C:\Documents and Settings\Jani Peltoniemi\Application Data\Mozilla\Firefox\Profiles\w7vxlzy1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned without backup :mozilla.20:C:\Documents and Settings\Jani Peltoniemi\Application Data\Mozilla\Firefox\Profiles\w7vxlzy1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned without backup :mozilla.21:C:\Documents and Settings\Jani Peltoniemi\Application Data\Mozilla\Firefox\Profiles\w7vxlzy1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned without backup :mozilla.22:C:\Documents and Settings\Jani Peltoniemi\Application Data\Mozilla\Firefox\Profiles\w7vxlzy1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned without backup :mozilla.23:C:\Documents and Settings\Jani Peltoniemi\Application Data\Mozilla\Firefox\Profiles\w7vxlzy1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned without backup :mozilla.24:C:\Documents and Settings\Jani Peltoniemi\Application Data\Mozilla\Firefox\Profiles\w7vxlzy1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned without backup :mozilla.25:C:\Documents and Settings\Jani Peltoniemi\Application Data\Mozilla\Firefox\Profiles\w7vxlzy1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned without backup :mozilla.26:C:\Documents and Settings\Jani Peltoniemi\Application Data\Mozilla\Firefox\Profiles\w7vxlzy1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned without backup :mozilla.27:C:\Documents and Settings\Jani Peltoniemi\Application Data\Mozilla\Firefox\Profiles\w7vxlzy1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned without backup :mozilla.28:C:\Documents and Settings\Jani Peltoniemi\Application Data\Mozilla\Firefox\Profiles\w7vxlzy1.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned without backup :mozilla.33:C:\Documents and Settings\Jani Peltoniemi\Application Data\Mozilla\Firefox\Profiles\w7vxlzy1.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned without backup :mozilla.34:C:\Documents and Settings\Jani Peltoniemi\Application Data\Mozilla\Firefox\Profiles\w7vxlzy1.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned without backup :mozilla.39:C:\Documents and Settings\Jani Peltoniemi\Application Data\Mozilla\Firefox\Profiles\w7vxlzy1.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned without backup :mozilla.41:C:\Documents and Settings\Jani Peltoniemi\Application Data\Mozilla\Firefox\Profiles\w7vxlzy1.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned without backup :mozilla.42:C:\Documents and Settings\Jani Peltoniemi\Application Data\Mozilla\Firefox\Profiles\w7vxlzy1.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned without backup C:\Documents and Settings\Jani Peltoniemi\Cookies\jani peltoniemi@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned without backup C:\Documents and Settings\Jani Peltoniemi\Cookies\jani peltoniemi@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned without backup ::Report End hjt logi: Logfile of HijackThis v1.99.1 Scan saved at 16:52:22, on 30.10.2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\bin\ZLH.EXE C:\Program Files\BELKIN USB Wireless Monitor\InfoMyCa.exe C:\Program Files\Logitech\MediaLife\MediaLifeService.exe C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\System32\ctfmon.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe C:\Program Files\Logitech\SetPoint\KEM.exe C:\Program Files\BELKIN USB Wireless Monitor\WLService.exe C:\Program Files\BELKIN USB Wireless Monitor\WLanCfgG.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\Program Files\ewido\security suite\ewidoguard.exe C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE C:\Program Files\Nvc\BIN\NPFSVICE.EXE C:\Program Files\Bin\Zanda.exe C:\WINDOWS\System32\wdfmgr.exe C:\Program Files\Nvc\BIN\NIP.EXE C:\Program Files\Nvc\BIN\NVCSCHED.EXE C:\Program Files\bin\NJEEVES.EXE C:\Program Files\Npf\BIN\npfmsg2.exe C:\Program Files\Nvc\BIN\nipsvc.exe C:\Program Files\Nvc\bin\nvcoas.exe C:\Program Files\Nvc\bin\cclaw.exe C:\WINDOWS\System32\wuauclt.exe C:\Program Files\Opera\Opera.exe C:\WINDOWS\System32\wuauclt.exe C:\HjT\HijackThis.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [Norman ZANDA] C:\Program Files\bin\ZLH.EXE /LOAD /SPLASH O4 - HKLM\..\Run: [Getca] C:\Program Files\BELKIN USB Wireless Monitor\InfoMyCa.exe O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Logitech\MediaLife\MediaLifeService.exe" O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O18 - Protocol: bw+0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw+0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O18 - Protocol: bwg0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwg0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0s - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O18 - Protocol: offline-8876480 - {62174BA4-0DC0-4A19-9B46-07FF39257AD8} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Belkin 54Mbps Wireless USB Network Service (Belkin 54Mbps Wireless USB) - Unknown owner - C:\Program Files\BELKIN USB Wireless Monitor\WLService.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Program Files\Nvc\BIN\nipsvc.exe O23 - Service: Norman NJeeves - Unknown owner - C:\Program Files\bin\NJEEVES.EXE O23 - Service: Norman Type-R - Unknown owner - C:\Program Files\Nvc\BIN\NPFSVICE.EXE O23 - Service: Norman ZANDA - Unknown owner - C:\Program Files\Bin\Zanda.exe O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Program Files\Nvc\bin\nvcoas.exe O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Program Files\Nvc\BIN\NVCSCHED.EXE
Joo, ei tossa ilm. enää ollut rdriv.syssiä. Kato vielä löytyykö tämä -> c:\windows\system32\rdriv.sys.