Kone menee netissä automaattisesti jollekkin finnistoggle sivustolle.

Discussion in 'Virukset ja haittaohjelmat - HijackThis -logit' started by Gatherine, Feb 14, 2011.

  1. Gatherine

    Gatherine Member

    Joined:
    Feb 3, 2011
    Messages:
    9
    Likes Received:
    0
    Trophy Points:
    11
    Logfile of HijackThis v1.99.1
    Scan saved at 23:53:20, on 14.2.2011
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\Program Files\EeePC\CapsHook\CapsHook.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\EeePC\ACPI\AsTray.exe
    C:\Program Files\EeePC\ACPI\AsEPCMon.exe
    C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\F-Secure\Common\FSM32.EXE
    C:\WINDOWS\system32\igfxext.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
    C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    C:\Program Files\F-Secure\Common\FSMA32.EXE
    C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\F-Secure\Common\FSHDLL32.EXE
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\WINDOWS\system32\tcpsvcs.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\F-Secure\Common\FNRB32.EXE
    C:\Program Files\F-Secure\Common\FIH32.EXE
    C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
    C:\WINDOWS\system32\wbem\wmiapsrv.exe
    C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Skype\Plugin Manager\skypePM.exe
    C:\Documents and Settings\oppilas13\Omat tiedostot\Jotai Scheissea\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
    O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: LitmusBHO - {C6867EB7-8350-4856-877F-93CF8AE3DC9C} - C:\Program Files\F-Secure\NRS\iescript\baselitmus.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Browsing Protection Toolbar - {265EEE8E-3228-44D3-AEA5-F7FDF5860049} - C:\Program Files\F-Secure\NRS\iescript\baselitmus.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [LiveUpdate] C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe auto
    O4 - HKLM\..\Run: [SynAsusAcpi] %ProgramFiles%\Synaptics\SynTP\SynAsusAcpi.exe
    O4 - HKLM\..\Run: [EeeSplendidAgent] C:\Program Files\ASUS\EPC\EeeSplendid\AsAgent.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [CapsHook] C:\Program Files\EeePC\CapsHook\CapsHook.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe
    O4 - HKLM\..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe
    O4 - HKLM\..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
    O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Eee Docking] C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - Global Startup: SuperHybridEngine.lnk = ?
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
    O8 - Extra context menu item: Lähetä &Bluetooth-laitteeseen... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O8 - Extra context menu item: Lähetä Bluetooth-laitteeseen - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O8 - Extra context menu item: V&ie Microsoft Exceliin - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Lisää tämä blogiin - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Lisää tämä blogiin tuotteessa Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Lähetä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: Läh&etä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
    O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\oppilas13\Käynnistä-valikko\Ohjelmat\IMVU\Run IMVU.lnk
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International
    O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} (WRC Class) - http://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
    O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
    O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
    O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program Files\F-Secure\ORSP Client\fsorsp.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
     
  2. kalminen

    kalminen Regular member

    Joined:
    May 4, 2007
    Messages:
    3,915
    Likes Received:
    0
    Trophy Points:
    46
    .
    Ei täällä finnish togglea näy ???

    Lataa työpöydälle => TÄMÄ
    * Sulje kaikki päälläolevat ikkunat ja sovellukset.
    * Tuplaklikkaa OTL.exeä käynnistääksesi OTListIt:n.
    * laita ruxit kuvanmukaan =>

    [​IMG]

    * Klikkaa Run Scan nappulaa.
    * Kun tarkistus on valmis, OTListIt luo kaksi tekstitiedostoa työpöydälle, tai alapalkkiin OTListIt.Txt ja Extras.txt
    * Kopioi ja lähetä tiedostojen sisältö tänne.
    :)
     
  3. TheJuze

    TheJuze Member

    Joined:
    Dec 5, 2010
    Messages:
    12
    Likes Received:
    0
    Trophy Points:
    11
    Itsellä oli kerran kaverilla tuo, tappelin pari tuntia että sain sen poistettua mutta tuli aina takaisin. Sain poistettua Firefoxista kun menin tuonne about:config, sieltä muokkasin ja poistin pari arvoa niin lähti lopulta pois.

    Varmaan sama toimii IE selaimella. :) Yritä nyt ainakin kalmisen ohjeita ensin.

    PS: Se asentuu toolbarina, joka vaihtaa kotisivun jatkuvasti. Ihan vaan kalmiselle. :)
     
  4. kalminen

    kalminen Regular member

    Joined:
    May 4, 2007
    Messages:
    3,915
    Likes Received:
    0
    Trophy Points:
    46
    .
    Erityiseen FireFoxissta noita lisä härpäkkäitä voi
    poistaa OTListillä. (käy IE:llekin)
    kunhan saadaan logit HI
    :)
     
  5. Gatherine

    Gatherine Member

    Joined:
    Feb 3, 2011
    Messages:
    9
    Likes Received:
    0
    Trophy Points:
    11
    OTL Extras logfile created on: 17.2.2011 1:02:53 - Run 1
    OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\oppilas13\Omat tiedostot\Lataukset
    Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 0000040B | Country: Suomi | Language: FIN | Date Format: d.M.yyyy

    1 014,00 Mb Total Physical Memory | 385,00 Mb Available Physical Memory | 38,00% Memory free
    2,00 Gb Paging File | 2,00 Gb Available in Paging File | 76,00% Paging File free
    Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 80,01 Gb Total Space | 46,88 Gb Free Space | 58,59% Space Free | Partition Type: NTFS
    Drive D: | 62,16 Gb Total Space | 62,02 Gb Free Space | 99,79% Space Free | Partition Type: NTFS

    Computer Name: PHLUKIO2010_13 | User Name: oppilas13 | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

    [HKEY_USERS\S-1-5-21-458859975-744635838-2516593720-1006\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
    exefile [open] -- "%1" %*
    http [open] -- Reg Error: Key error.
    https [open] -- Reg Error: Key error.
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- C:\Documents and Settings\oppilas13\Omat tiedostot\FileCure\FileCure_noapp.exe %1
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirstRunDisabled" = 1
    "AntiVirusDisableNotify" = 0
    "FirewallDisableNotify" = 0
    "UpdatesDisableNotify" = 0
    "AntiVirusOverride" = 0
    "FirewallOverride" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
    "Start" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
    "Start" = 2

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
    "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22007
    "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22008

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
    "5985:TCP" = 5985:TCP:*:Disabled:Windowsin etähallinta
    "80:TCP" = 80:TCP:*:Disabled:Windowsin etähallinta – yhteensopivuustila (saapuva HTTP)
    "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22007
    "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22008

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)
    "C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
    "C:\Documents and Settings\oppilas13\Omat tiedostot\Lataukset\utorrent.exe" = C:\Documents and Settings\oppilas13\Omat tiedostot\Lataukset\utorrent.exe:*:Enabled:µTorrent
    "C:\Documents and Settings\oppilas13\Omat tiedostot\Jotai Scheissea\U-Torrent\utorrent.exe" = C:\Documents and Settings\oppilas13\Omat tiedostot\Jotai Scheissea\U-Torrent\utorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
    "C:\Documents and Settings\oppilas13\Omat tiedostot\Jotai Scheissea\U-Torrent\utorrent(2).exe" = C:\Documents and Settings\oppilas13\Omat tiedostot\Jotai Scheissea\U-Torrent\utorrent(2).exe:*:Enabled:µTorrent


    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{17780F99-A9DF-450B-81B3-6781B20A17A8}" = FontResizer
    "{19F5658D-92E8-4A08-8657-D38ABB1574B2}" = Asus ACPI Driver
    "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Liven lataustyökalu
    "{2186E240-93C1-4D00-AAB2-E46A4D3DCE64}" = Windows Liven valokuvavalikoima
    "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
    "{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java(TM) 6 Update 23
    "{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program
    "{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
    "{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
    "{32DC3E9F-76CC-4867-83F1-4D039B247F91}" = Windows Live Writer
    "{350C940b-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
    "{38E5A3B1-ADF1-47E0-8024-76310A30EB36}" = LiveUpdate
    "{3C1007F9-8AC4-4053-ACCA-A162D62888CE}" = Windows Liven sähköposti
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4B5092B6-F231-4D18-83BC-2618B729CA45}" = CapsHook
    "{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
    "{587178E7-B1DF-494E-9838-FA4DD36E873C}" = ASUSUpdate for Eee PC
    "{6333FC29-BFE5-4024-AC78-958A1A7555D1}" = EeeSplendid
    "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
    "{751F4FE0-F69B-455F-A4F9-2BCD109CE7FB}" = Windows Live -perheturva
    "{7D39E592-F19F-4B4F-A786-B1DF34775E0B}" = Mobile PhoneTools
    "{7D9EF8C1-1B76-44AF-A918-86CBA6FD24C8}" = Microsoft Works
    "{88F08F98-12BC-4613-81A2-8F9B88CFC73E}" = Super Hybrid Engine
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
    "{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
    "{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Ralink RT2860 Wireless LAN Card
    "{90120000-0010-040B-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Finnish) 12
    "{90120000-0016-040B-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Finnish) 2007
    "{90120000-0016-040B-0000-0000000FF1CE}_HOMESTUDENTR_{DCB679BA-7B0C-4D8C-B443-79701F6FA01C}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0018-040B-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Finnish) 2007
    "{90120000-0018-040B-0000-0000000FF1CE}_HOMESTUDENTR_{DCB679BA-7B0C-4D8C-B443-79701F6FA01C}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001B-040B-0000-0000000FF1CE}" = Microsoft Office Word MUI (Finnish) 2007
    "{90120000-001B-040B-0000-0000000FF1CE}_HOMESTUDENTR_{DCB679BA-7B0C-4D8C-B443-79701F6FA01C}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
    "{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-040B-0000-0000000FF1CE}" = Microsoft Office Proof (Finnish) 2007
    "{90120000-001F-040B-0000-0000000FF1CE}_HOMESTUDENTR_{8C00DF3E-E8BD-4C6A-B86F-0135E11DAF1C}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-041D-0000-0000000FF1CE}" = Microsoft Office Proof (Swedish) 2007
    "{90120000-001F-041D-0000-0000000FF1CE}_HOMESTUDENTR_{43722AA8-ACEA-4F54-9B83-2467D376EF8A}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-0020-040B-0000-0000000FF1CE}" = 2007 Office Systemin yhteensopivuuspaketti
    "{90120000-002C-040B-0000-0000000FF1CE}" = Microsoft Office Proofing (Finnish) 2007
    "{90120000-006E-040B-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Finnish) 2007
    "{90120000-006E-040B-0000-0000000FF1CE}_HOMESTUDENTR_{06921DF8-773B-45F8-9464-6BB1C56FEF21}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00A1-040B-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Finnish) 2007
    "{90120000-00A1-040B-0000-0000000FF1CE}_HOMESTUDENTR_{DCB679BA-7B0C-4D8C-B443-79701F6FA01C}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{9012040B-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
    "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
    "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
    "{95120000-00AF-040B-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (Finnish)
    "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{998152E5-B605-4BBB-9853-E749AEE02B21}" = Windows Liven kirjautumisavustaja
    "{9B5C9072-939F-4249-A7E4-A197BA3A5746}" = Windows Live Sync
    "{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack
    "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
    "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
    "{AA4C0345-2E31-4D99-B4E6-7351975E06F6}" = Windows Liven asennustyökalu
    "{AC76BA86-7AD7-1035-7B44-A94000000001}" = Adobe Reader 9.4.2 - Suomi
    "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
    "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
    "{C1C441C4-57FA-4950-BDBA-BABFBAA2AA39}" = ParetoLogic FileCure
    "{C72CA49A-9237-4810-8449-45DA3BD26D64}" = EzMessenger
    "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{D802DD00-16A8-4A58-AFC9-020C2380ECDA}" = EeeSplendid
    "{D806E63B-0C11-4061-8DA9-1E980FB9A9EB}" = Data Sync
    "{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
    "{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}" = USB2.0 UVC VGA WebCam
    "{E11274EB-B35F-4A35-BC5B-98823FFE7519}" = Windows Live Messenger
    "{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
    "{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1
    "{EDBD7706-300C-43BE-9DDC-3B1C2DF4244C}" = Windows Live Toolbar
    "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
    "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{F3D2DEDC-4732-4188-8A3A-1A3FFBD4D6C8}" = ebi.BookReader3J
    "{F7875264-810A-4ABB-B185-2C5A332E483B}" = F-Secure PSC Prerequisites
    "{FEA3BE8A-67DB-4834-A2A8-D25A9D7F426D}" = Windows Live Call
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
    "ASUS VIBE" = ASUS VIBE
    "AVGAntiSpyware75" = AVG Anti-Spyware 7.5
    "Deer Hunter 2005 Demo_is1" = Deer Hunter - The 2005 Season Demo
    "Eee Docking_is1" = Eee Docking 1.3.12.0
    "F-Secure Anti-Virus" = F-Secure Client Security - Virus- ja vakoilusuojaus
    "F-Secure E-mail Scanning" = F-Secure Client Security - Sähköpostin tarkistus
    "F-Secure ExploitShield" = F-Secure Client Security - Selaussuojaus
    "F-Secure HIPS" = F-Secure Client Security - DeepGuard
    "F-Secure Internet Shield" = F-Secure Client Security - Internet-suojaus
    "F-Secure Protocol Scanner" = F-Secure Client Security - Web-liikenteen tarkistus
    "HDMI" = Intel(R) Graphics Media Accelerator Driver
    "HijackThis" = HijackThis 1.99.1
    "HOMESTUDENTR" = Tuotteen Microsoft Office Home and Student 2007 kokeiluversio
    "ie8" = Windows Internet Explorer 8
    "InstallShield_{17780F99-A9DF-450B-81B3-6781B20A17A8}" = FontResizer
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
    "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
    "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
    "PeerGuardian_is1" = PeerGuardian 2.0
    "Picasa 3" = Picasa 3
    "SubDownloader2" = SubDownloader2
    "SynTPDeinstKey" = Synaptics Pointing Device Driver
    "uTorrent" = µTorrent
    "Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
    "Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
    "Windows Media Format Runtime" = Windows Media Format 11 runtime
    "Windows Media Player" = Windows Media Player 11
    "WinGimp-2.0_is1" = GIMP 2.6.11
    "WinLiveSuite_Wave3" = Windows Liven asennustyökalu
    "WMFDist11" = Windows Media Format 11 runtime
    "wmp11" = Windows Media Player 11
    "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

    ========== HKEY_USERS Uninstall List ==========

    [HKEY_USERS\S-1-5-21-458859975-744635838-2516593720-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "IMVU Avatar chat client software BETA" = IMVU Avatar Chat Software

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 8.12.2010 11:55:43 | Computer Name = PHLUKIO2010_13 | Source = Application Error | ID = 1000
    Description = Virhesovellus pg2.exe, versio 1.0.6.5, moduuli ntdll.dll, versio 5.1.2600.5755,
    osoite 0x0001b21a.

    Error - 9.12.2010 5:51:43 | Computer Name = PHLUKIO2010_13 | Source = Application Error | ID = 1000
    Description = Virhesovellus pg2.exe, versio 1.0.6.5, moduuli ntdll.dll, versio 5.1.2600.5755,
    osoite 0x0001b21a.

    Error - 16.12.2010 16:54:34 | Computer Name = PHLUKIO2010_13 | Source = Application Hang | ID = 1002
    Description = Lukkiutunut sovellus firefox.exe, versio 1.9.2.3989, lukkiutumismoduuli
    hungapp, versio 0.0.0.0, lukkiutumisosoite 0x00000000.

    Error - 20.12.2010 3:12:53 | Computer Name = PHLUKIO2010_13 | Source = Application Hang | ID = 1002
    Description = Lukkiutunut sovellus SoftwareUpdate.exe, versio 2.1.1.116, lukkiutumismoduuli
    hungapp, versio 0.0.0.0, lukkiutumisosoite 0x00000000.

    Error - 20.12.2010 12:01:35 | Computer Name = PHLUKIO2010_13 | Source = Application Hang | ID = 1002
    Description = Lukkiutunut sovellus vlc.exe, versio 1.1.4.0, lukkiutumismoduuli hungapp,
    versio 0.0.0.0, lukkiutumisosoite 0x00000000.

    Error - 24.12.2010 6:10:24 | Computer Name = PHLUKIO2010_13 | Source = Application Error | ID = 1000
    Description = Virhesovellus pg2.exe, versio 1.0.6.5, moduuli ntdll.dll, versio 5.1.2600.5755,
    osoite 0x0001b21a.

    Error - 31.12.2010 12:30:02 | Computer Name = PHLUKIO2010_13 | Source = Application Error | ID = 1000
    Description = Virhesovellus dh2005demo.exe, versio 0.0.0.0, moduuli dh2005demo.exe,
    versio 0.0.0.0, osoite 0x0016dc8a.

    Error - 4.2.2011 18:26:34 | Computer Name = PHLUKIO2010_13 | Source = F-Secure Anti-Virus | ID = 103
    Description = 1 2011-02-05 00:26:33+03:00 phlukio2010_13 PHLUKIO2010_13\oppilas13
    F-Secure Anti-Virus Crash detected. \Device\HarddiskVolume1\Documents and Settings\oppilas13\Cookies\oppilas13@atdmt[2].txt


    Error - 6.2.2011 11:51:41 | Computer Name = PHLUKIO2010_13 | Source = Application Hang | ID = 1002
    Description = Lukkiutunut sovellus Skype.exe, versio 5.0.0.156, lukkiutumismoduuli
    hungapp, versio 0.0.0.0, lukkiutumisosoite 0x00000000.

    Error - 11.2.2011 7:50:08 | Computer Name = PHLUKIO2010_13 | Source = Application Error | ID = 1000
    Description = Virhesovellus explorer.exe, versio 6.0.2900.5512, moduuli comctl32.dll,
    versio 6.0.2900.6028, osoite 0x0004dbe4.

    [ System Events ]
    Error - 4.2.2011 17:09:36 | Computer Name = PHLUKIO2010_13 | Source = Service Control Manager | ID = 7023
    Description = Palvelu Sovellusten hallinta lopetettiin virheen takia. Virhe: %%126

    Error - 4.2.2011 17:09:36 | Computer Name = PHLUKIO2010_13 | Source = Service Control Manager | ID = 7023
    Description = Palvelu Sovellusten hallinta lopetettiin virheen takia. Virhe: %%126

    Error - 4.2.2011 17:09:36 | Computer Name = PHLUKIO2010_13 | Source = Service Control Manager | ID = 7023
    Description = Palvelu Sovellusten hallinta lopetettiin virheen takia. Virhe: %%126

    Error - 4.2.2011 17:09:37 | Computer Name = PHLUKIO2010_13 | Source = Service Control Manager | ID = 7023
    Description = Palvelu Sovellusten hallinta lopetettiin virheen takia. Virhe: %%126

    Error - 4.2.2011 17:09:37 | Computer Name = PHLUKIO2010_13 | Source = Service Control Manager | ID = 7023
    Description = Palvelu Sovellusten hallinta lopetettiin virheen takia. Virhe: %%126

    Error - 4.2.2011 17:09:37 | Computer Name = PHLUKIO2010_13 | Source = Service Control Manager | ID = 7023
    Description = Palvelu Sovellusten hallinta lopetettiin virheen takia. Virhe: %%126

    Error - 4.2.2011 17:09:37 | Computer Name = PHLUKIO2010_13 | Source = Service Control Manager | ID = 7023
    Description = Palvelu Sovellusten hallinta lopetettiin virheen takia. Virhe: %%126

    Error - 4.2.2011 17:09:37 | Computer Name = PHLUKIO2010_13 | Source = Service Control Manager | ID = 7023
    Description = Palvelu Sovellusten hallinta lopetettiin virheen takia. Virhe: %%126

    Error - 4.2.2011 17:09:37 | Computer Name = PHLUKIO2010_13 | Source = Service Control Manager | ID = 7023
    Description = Palvelu Sovellusten hallinta lopetettiin virheen takia. Virhe: %%126

    Error - 15.2.2011 17:10:44 | Computer Name = PHLUKIO2010_13 | Source = Dhcp | ID = 1001
    Description = Verkon DHCP-palvelin ei voinut myöntää IP-osoitetta tietokoneen verkkokortille,
    jonka verkko-osoite on 20CF3026847C. Virhe %%1223. Tietokone jatkaa osoitteen pyytämistä
    verkon DHCP-palvelimelta.


    < End of report >
     
  6. Gatherine

    Gatherine Member

    Joined:
    Feb 3, 2011
    Messages:
    9
    Likes Received:
    0
    Trophy Points:
    11
    Tää on se OTL, toi äskeinen oli se extras.

    OTL logfile created on: 17.2.2011 1:02:53 - Run 1
    OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\oppilas13\Omat tiedostot\Lataukset
    Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 0000040B | Country: Suomi | Language: FIN | Date Format: d.M.yyyy

    1 014,00 Mb Total Physical Memory | 385,00 Mb Available Physical Memory | 38,00% Memory free
    2,00 Gb Paging File | 2,00 Gb Available in Paging File | 76,00% Paging File free
    Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 80,01 Gb Total Space | 46,88 Gb Free Space | 58,59% Space Free | Partition Type: NTFS
    Drive D: | 62,16 Gb Total Space | 62,02 Gb Free Space | 99,79% Space Free | Partition Type: NTFS

    Computer Name: PHLUKIO2010_13 | User Name: oppilas13 | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2011.02.17 00:56:42 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\oppilas13\Omat tiedostot\Lataukset\OTL.exe
    PRC - [2011.02.02 14:12:33 | 000,918,184 | ---- | M] (F-Secure Corporation) -- C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
    PRC - [2011.02.02 14:12:32 | 000,508,584 | ---- | M] (F-Secure Corporation) -- C:\Program Files\F-Secure\Anti-Virus\fsgk32.exe
    PRC - [2011.01.05 06:08:49 | 000,372,904 | ---- | M] (F-Secure Corporation) -- C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
    PRC - [2010.12.21 00:20:26 | 000,063,992 | ---- | M] (F-Secure Corporation) -- C:\Program Files\F-Secure\ORSP Client\fsorsp.exe
    PRC - [2010.05.28 15:41:36 | 000,445,344 | ---- | M] (ASUS) -- C:\Program Files\EeePC\CapsHook\CapsHook.exe
    PRC - [2010.05.17 09:40:22 | 001,246,632 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
    PRC - [2010.03.26 11:09:30 | 000,166,576 | ---- | M] (F-Secure Corporation) -- C:\Program Files\F-Secure\common\FNRB32.exe
    PRC - [2010.03.26 11:09:30 | 000,129,712 | ---- | M] (F-Secure Corporation) -- C:\Program Files\F-Secure\common\FIH32.exe
    PRC - [2010.03.26 11:09:22 | 000,301,744 | ---- | M] (F-Secure Corporation) -- C:\Program Files\F-Secure\common\FSM32.EXE
    PRC - [2010.03.26 11:09:22 | 000,187,056 | ---- | M] (F-Secure Corporation) -- C:\Program Files\F-Secure\common\FSMA32.EXE
    PRC - [2010.03.26 11:09:20 | 000,088,752 | ---- | M] (F-Secure Corporation) -- C:\Program Files\F-Secure\common\FSHDLL32.EXE
    PRC - [2010.03.26 11:08:10 | 000,522,928 | ---- | M] (F-Secure Corporation) -- C:\Program Files\F-Secure\FWES\program\fsdfwd.exe
    PRC - [2010.03.26 11:06:54 | 000,219,824 | ---- | M] (F-Secure Corporation) -- C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    PRC - [2010.03.25 08:30:52 | 000,402,096 | ---- | M] () -- C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
    PRC - [2010.01.29 20:18:52 | 000,751,592 | ---- | M] () -- C:\Program Files\ASUS\LiveUpdate\LiveUpdate.exe
    PRC - [2009.09.28 15:59:56 | 000,172,056 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\igfxext.exe
    PRC - [2009.06.26 12:13:00 | 000,118,784 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\EeePC\ACPI\AsTray.exe
    PRC - [2009.05.08 15:54:20 | 000,098,304 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\EeePC\ACPI\AsEPCMon.exe
    PRC - [2009.04.30 19:49:42 | 000,385,024 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
    PRC - [2009.01.14 16:53:02 | 000,226,656 | ---- | M] (Microsoft Corp.) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    PRC - [2008.04.15 14:00:00 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
    PRC - [2007.05.30 14:31:10 | 000,312,880 | ---- | M] (GRISOFT s.r.o.) -- C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe


    ========== Modules (SafeList) ==========

    MOD - [2011.02.17 00:56:42 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\oppilas13\Omat tiedostot\Lataukset\OTL.exe
    MOD - [2010.08.23 18:12:31 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


    ========== Win32 Services (SafeList) ==========

    SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
    SRV - [2010.12.21 00:20:26 | 000,063,992 | ---- | M] (F-Secure Corporation) [On_Demand | Running] -- C:\Program Files\F-Secure\ORSP Client\fsorsp.exe -- (FSORSPClient)
    SRV - [2010.04.28 06:44:02 | 000,704,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
    SRV - [2010.03.26 11:09:30 | 000,166,576 | ---- | M] (F-Secure Corporation) [On_Demand | Running] -- C:\Program Files\F-Secure\Common\FNRB32.EXE -- (F-Secure Network Request Broker)
    SRV - [2010.03.26 11:09:22 | 000,187,056 | ---- | M] (F-Secure Corporation) [Auto | Running] -- C:\Program Files\F-Secure\Common\FSMA32.EXE -- (FSMA)
    SRV - [2010.03.26 11:08:10 | 000,522,928 | ---- | M] (F-Secure Corporation) [On_Demand | Running] -- C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe -- (FSDFWD)
    SRV - [2010.03.26 11:06:54 | 000,219,824 | ---- | M] (F-Secure Corporation) [Auto | Running] -- C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe -- (F-Secure Gatekeeper Handler Starter)
    SRV - [2009.01.14 16:53:02 | 000,226,656 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
    SRV - [2008.04.15 14:00:00 | 000,105,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\p2pgasvc.dll -- (p2pgasvc)
    SRV - [2008.04.15 14:00:00 | 000,034,816 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\iprip.dll -- (Iprip)
    SRV - [2007.05.30 14:31:10 | 000,312,880 | ---- | M] (GRISOFT s.r.o.) [Auto | Running] -- C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe -- (AVG Anti-Spyware Guard)


    ========== Driver Services (SafeList) ==========

    DRV - [2010.12.15 19:14:34 | 000,042,664 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\Drivers\fsbts.sys -- (fsbts)
    DRV - [2010.11.30 08:01:26 | 000,130,728 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files\F-Secure\Anti-Virus\minifilter\fsgk.sys -- (F-Secure Gatekeeper)
    DRV - [2010.04.27 10:10:52 | 006,031,904 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
    DRV - [2010.03.31 03:40:20 | 000,011,520 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AsUpIO.sys -- (AsUpIO)
    DRV - [2010.03.26 11:08:54 | 000,068,144 | ---- | M] (F-Secure Corporation) [Kernel | System | Running] -- C:\Program Files\F-Secure\HIPS\drivers\fshs.sys -- (F-Secure HIPS)
    DRV - [2010.03.26 11:08:08 | 000,080,080 | ---- | M] (F-Secure Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\fsdfw.sys -- (FSFW)
    DRV - [2010.03.26 11:07:04 | 000,039,856 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Program Files\F-Secure\Anti-Virus\win2k\fsfilter.sys -- (F-Secure Filter)
    DRV - [2010.03.26 11:07:04 | 000,025,264 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Program Files\F-Secure\Anti-Virus\win2k\fsrec.sys -- (F-Secure Recognizer)
    DRV - [2010.02.11 14:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
    DRV - [2010.02.04 17:08:30 | 000,073,088 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rtsuvc.sys -- (rtsuvc)
    DRV - [2009.11.19 15:45:08 | 000,230,448 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
    DRV - [2009.11.18 01:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
    DRV - [2009.11.18 01:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
    DRV - [2009.09.24 11:55:32 | 006,301,696 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\igxpmp32.sys -- (ialm)
    DRV - [2009.08.12 01:04:30 | 001,582,624 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\athw.sys -- (AR5416)
    DRV - [2009.08.06 07:48:42 | 000,054,752 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
    DRV - [2009.07.27 09:09:52 | 000,044,032 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\l1c51x86.sys -- (L1c)
    DRV - [2009.06.04 12:43:16 | 000,330,264 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\iaStor.sys -- (iaStor)
    DRV - [2008.11.03 09:03:28 | 000,013,880 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\kbfiltr.sys -- (kbfiltr)
    DRV - [2008.04.15 14:00:00 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus) Microsoft UAA -väyläohjain (High Definition Audio)
    DRV - [2008.04.08 17:59:28 | 000,010,752 | ---- | M] (ASUSTeK Computer Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASUSACPI.SYS -- (AsusACPI)
    DRV - [2007.05.30 14:10:42 | 000,011,000 | ---- | M] () [Kernel | System | Running] -- C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys -- (AVG Anti-Spyware Driver)
    DRV - [2007.05.30 14:10:42 | 000,010,872 | ---- | M] (GRISOFT, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AvgAsCln.sys -- (AvgAsCln)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank


    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



    IE - HKU\S-1-5-21-458859975-744635838-2516593720-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://fi.msn.com/?ocid=iehp
    IE - HKU\S-1-5-21-458859975-744635838-2516593720-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fi
    IE - HKU\S-1-5-21-458859975-744635838-2516593720-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A6 FD 06 16 87 B8 CB 01 [binary data]
    IE - HKU\S-1-5-21-458859975-744635838-2516593720-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    ========== FireFox ==========

    FF - prefs.js..browser.search.defaultthis.engineName: "http://finnish.toggle.com/fi/index.php?rvs=google"
    FF - prefs.js..browser.startup.homepage: "http://fi.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fi:eek:fficial"
    FF - prefs.js..extensions.enabledItems: litmus-ff@f-secure.com:1.10
    FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
    FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
    FF - prefs.js..keyword.URL: "http://finnish.toggle.com/fi/index.php?rvs=google"
    FF - prefs.js..network.proxy.type: 0

    FF - HKLM\software\mozilla\Firefox\Extensions\\litmus-ff@f-secure.com: C:\Program Files\F-Secure\NRS\litmus-ff@f-secure.com [2010.09.30 11:45:40 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.01.20 11:53:04 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.02.11 13:46:16 | 000,000,000 | ---D | M]

    [2010.11.10 22:59:28 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\oppilas13\Application Data\Mozilla\Extensions
    [2010.11.10 22:59:28 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\oppilas13\Application Data\Mozilla\Extensions\IMVUClientXUL@imvu.com
    [2011.02.15 23:46:44 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\oppilas13\Application Data\Mozilla\Firefox\Profiles\fw87o3gx.default\extensions
    [2010.11.01 18:05:58 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\oppilas13\Application Data\Mozilla\Firefox\Profiles\fw87o3gx.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
    [2011.01.20 12:18:18 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Documents and Settings\oppilas13\Application Data\Mozilla\Firefox\Profiles\fw87o3gx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
    [2010.12.24 04:02:58 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\oppilas13\Application Data\Mozilla\Firefox\Profiles\fw87o3gx.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
    [2011.01.20 12:03:57 | 000,000,000 | ---D | M] ("CyberSearch") -- C:\Documents and Settings\oppilas13\Application Data\Mozilla\Firefox\Profiles\fw87o3gx.default\extensions\cybersearch@cybernetnews.com
    [2011.02.13 22:01:20 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
    [2010.12.20 09:06:00 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
    [2010.09.30 11:45:40 | 000,000,000 | ---D | M] ("Browsing Protection") -- C:\PROGRAM FILES\F-SECURE\NRS\LITMUS-FF@F-SECURE.COM
    [2010.12.20 09:05:42 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
    [2010.12.20 09:05:40 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
    [2010.12.03 20:02:48 | 000,002,062 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bookplus-fi.xml
    [2010.12.03 20:02:48 | 000,001,069 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\creativecommons-fi.xml
    [2010.12.03 20:02:48 | 000,002,677 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\huuto-fi.xml
    [2010.12.03 20:02:48 | 000,001,183 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-fi.xml
    [2010.12.03 20:02:48 | 000,001,100 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-fi.xml

    O1 HOSTS File: ([2011.02.03 08:53:13 | 000,623,385 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
    O1 - Hosts: 127.0.0.1 localhost
    O1 - Hosts: 127.0.0.1 fr.a2dfp.net
    O1 - Hosts: 127.0.0.1 m.fr.a2dfp.net
    O1 - Hosts: 127.0.0.1 ad.a8.net
    O1 - Hosts: 127.0.0.1 asy.a8ww.net
    O1 - Hosts: 127.0.0.1 abcstats.com
    O1 - Hosts: 127.0.0.1 a.abv.bg
    O1 - Hosts: 127.0.0.1 adserver.abv.bg
    O1 - Hosts: 127.0.0.1 adv.abv.bg
    O1 - Hosts: 127.0.0.1 bimg.abv.bg
    O1 - Hosts: 127.0.0.1 ca.abv.bg
    O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
    O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
    O1 - Hosts: 127.0.0.1 accuserveadsystem.com
    O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
    O1 - Hosts: 127.0.0.1 achmedia.com
    O1 - Hosts: 127.0.0.1 aconti.net
    O1 - Hosts: 127.0.0.1 secure.aconti.net
    O1 - Hosts: 127.0.0.1 www.aconti.net #[Dialer.Aconti]
    O1 - Hosts: 127.0.0.1 ads.active.com
    O1 - Hosts: 127.0.0.1 am1.activemeter.com
    O1 - Hosts: 127.0.0.1 www.activemeter.com #[Tracking.Cookie]
    O1 - Hosts: 127.0.0.1 ads.activepower.net
    O1 - Hosts: 127.0.0.1 stat.active24stats.nl #[Tracking.Cookie]
    O1 - Hosts: 127.0.0.1 ad2games.com
    O1 - Hosts: 16473 more lines...
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
    O2 - BHO: (Browsing Protection Class) - {C6867EB7-8350-4856-877F-93CF8AE3DC9C} - C:\Program Files\F-Secure\NRS\iescript\baselitmus.dll (F-Secure Corporation)
    O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKLM\..\Toolbar: (Browsing Protection Toolbar) - {265EEE8E-3228-44D3-AEA5-F7FDF5860049} - C:\Program Files\F-Secure\NRS\iescript\baselitmus.dll (F-Secure Corporation)
    O3 - HKU\S-1-5-21-458859975-744635838-2516593720-1006\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O4 - HKLM..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe (ASUSTeK Computer Inc.)
    O4 - HKLM..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe (ASUSTeK Computer Inc.)
    O4 - HKLM..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe (ASUSTeK Computer Inc.)
    O4 - HKLM..\Run: [CapsHook] C:\Program Files\EeePC\CapsHook\CapsHook.exe (ASUS)
    O4 - HKLM..\Run: [EeeSplendidAgent] File not found
    O4 - HKLM..\Run: [F-Secure Manager] C:\Program Files\F-Secure\Common\FSM32.EXE (F-Secure Corporation)
    O4 - HKLM..\Run: [F-Secure TNB] C:\Program Files\F-Secure\FSGUI\TNBUtil.exe (F-Secure Corporation)
    O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
    O4 - HKLM..\Run: [LiveUpdate] C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe ()
    O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
    O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
    O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
    O4 - HKLM..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe (Synaptics Incorporated)
    O4 - HKU\S-1-5-21-458859975-744635838-2516593720-1006..\Run: [Eee Docking] C:\Program Files\ASUS\Eee Docking\Eee Docking.exe ()
    O4 - Startup: C:\Documents and Settings\All Users\Käynnistä-valikko\Ohjelmat\Käynnistys\SuperHybridEngine.lnk = C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe (ASUSTeK Computer Inc.)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-21-458859975-744635838-2516593720-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
    O9 - Extra Button: Lisää tämä blogiin - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : &Lisää tämä blogiin tuotteessa Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
    O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\oppilas13\Käynnistä-valikko\Ohjelmat\IMVU\Run IMVU.lnk ()
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
    O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx (WRC Class)
    O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.78.102.50 62.78.102.10
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
    O24 - Desktop Components:0 (Nykyinen kotisivu) - About:Home
    O24 - Desktop WallPaper: C:\Documents and Settings\oppilas13\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\oppilas13\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O28 - HKLM ShellExecuteHooks: {57B86673-276A-48B2-BAE7-C6DBB3020EB8} - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll (GRISOFT s.r.o.)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2010.03.16 20:22:41 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    ========== Files/Folders - Created Within 30 Days ==========

    [2011.02.14 01:51:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
    [2011.02.01 10:16:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\oppilas13\Local Settings\Application Data\Identities
    [2011.02.01 00:12:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\oppilas13\Application Data\Grisoft
    [2011.02.01 00:12:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Käynnistä-valikko\Ohjelmat\AVG Anti-Spyware 7.5
    [2011.02.01 00:12:15 | 000,010,872 | ---- | C] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\drivers\AvgAsCln.sys
    [2011.02.01 00:12:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Grisoft
    [2011.02.01 00:12:02 | 000,000,000 | ---D | C] -- C:\Program Files\Grisoft
    [2011.01.24 11:08:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\oppilas13\Application Data\Malwarebytes
    [2011.01.24 11:08:33 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2011.01.24 11:08:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Käynnistä-valikko\Ohjelmat\Malwarebytes' Anti-Malware
    [2011.01.24 11:08:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    [2011.01.24 11:08:27 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [2011.01.24 11:08:26 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2011.01.20 23:44:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\oppilas13\Local Settings\Application Data\WMTools Downloaded Files
    [2011.01.20 12:18:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Google
    [2011.01.20 10:41:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Käynnistä-valikko\Ohjelmat\Mozilla Firefox
    [2011.01.20 10:40:35 | 008,415,184 | ---- | C] (Mozilla) -- C:\Program Files\Firefox Setup 3.6.13.exe
    [2011.01.20 08:46:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\oppilas13\Application Data\PhotoScape
    [2011.01.20 08:28:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\oppilas13\Application Data\PhotoFiltre Studio X
    [2011.01.20 08:16:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\oppilas13\Application Data\PhotoFiltre
    [2011.01.19 21:16:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sandlot Games
    [2011.01.19 21:16:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
    [2011.01.19 20:45:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\oppilas13\Käynnistä-valikko\Ohjelmat\Game Park
    [2011.01.19 20:45:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Oberon Media
    [2009.11.04 08:53:14 | 000,013,880 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\kbfiltr.sys
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2011.02.17 01:04:35 | 000,000,450 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{00C451BD-9A7E-45C1-B283-886102F13E48}.job
    [2011.02.17 01:01:17 | 000,000,705 | ---- | M] () -- C:\Documents and Settings\oppilas13\Työpöytä\OTL.lnk
    [2011.02.16 22:55:45 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2011.02.16 22:55:27 | 000,002,271 | ---- | M] () -- C:\Documents and Settings\All Users\Työpöytä\Skype.lnk
    [2011.02.16 22:55:02 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2011.02.16 00:08:15 | 000,034,304 | ---- | M] () -- C:\Documents and Settings\oppilas13\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011.02.11 13:46:16 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Työpöytä\Adobe Reader 9.lnk
    [2011.02.10 13:23:56 | 000,253,472 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2011.02.10 13:06:37 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
    [2011.02.09 23:30:26 | 000,033,807 | ---- | M] () -- C:\Documents and Settings\oppilas13\.recently-used.xbel
    [2011.02.06 18:00:00 | 000,000,452 | ---- | M] () -- C:\WINDOWS\tasks\ParetoLogic Registration3.job
    [2011.02.04 23:10:02 | 000,448,900 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2011.02.04 23:10:02 | 000,423,700 | ---- | M] () -- C:\WINDOWS\System32\perfh00B.dat
    [2011.02.04 23:10:02 | 000,088,930 | ---- | M] () -- C:\WINDOWS\System32\perfc00B.dat
    [2011.02.04 23:10:02 | 000,074,952 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2011.02.03 08:53:13 | 000,623,385 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\HOSTS.MVP
    [2011.02.03 08:53:13 | 000,623,385 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\HOSTS
    [2011.02.01 00:12:20 | 000,000,849 | ---- | M] () -- C:\Documents and Settings\All Users\Työpöytä\AVG Anti-Spyware.lnk
    [2011.01.26 11:48:32 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\oppilas13\Työpöytä\Mbam.lnk
    [2011.01.21 16:44:12 | 008,466,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shell32.dll
    [2011.01.21 16:44:12 | 000,439,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shimgvw.dll
    [2011.01.20 10:41:36 | 000,001,620 | ---- | M] () -- C:\Documents and Settings\oppilas13\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
    [2011.01.20 10:41:36 | 000,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Työpöytä\Fizilla Kettu Repolainen.lnk
    [2011.01.20 10:40:35 | 008,415,184 | ---- | M] (Mozilla) -- C:\Program Files\Firefox Setup 3.6.13.exe
    [2011.01.18 13:08:20 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\oppilas13\Omat tiedostot\~$ghj.docx
    [2011.01.18 12:08:09 | 000,010,979 | ---- | M] () -- C:\Documents and Settings\oppilas13\Omat tiedostot\ghj.docx
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2011.02.17 01:01:17 | 000,000,705 | ---- | C] () -- C:\Documents and Settings\oppilas13\Työpöytä\OTL.lnk
    [2011.02.11 13:46:16 | 000,001,729 | ---- | C] () -- C:\Documents and Settings\All Users\Työpöytä\Adobe Reader 9.lnk
    [2011.02.09 23:30:26 | 000,033,807 | ---- | C] () -- C:\Documents and Settings\oppilas13\.recently-used.xbel
    [2011.02.01 00:12:19 | 000,000,849 | ---- | C] () -- C:\Documents and Settings\All Users\Työpöytä\AVG Anti-Spyware.lnk
    [2011.01.26 11:48:32 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\oppilas13\Työpöytä\Mbam.lnk
    [2011.01.20 10:41:36 | 000,001,620 | ---- | C] () -- C:\Documents and Settings\oppilas13\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
    [2011.01.20 10:41:36 | 000,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Työpöytä\Fizilla Kettu Repolainen.lnk
    [2011.01.18 13:08:20 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\oppilas13\Omat tiedostot\~$ghj.docx
    [2010.10.23 05:33:41 | 000,034,304 | ---- | C] () -- C:\Documents and Settings\oppilas13\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2010.10.13 11:14:10 | 000,276,304 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
    [2010.10.01 15:37:01 | 000,000,085 | ---- | C] () -- C:\Documents and Settings\oppilas13\Local Settings\Application Data\FASTWiz.log
    [2010.09.30 11:42:49 | 000,006,144 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
    [2010.09.22 14:56:54 | 000,042,664 | ---- | C] () -- C:\WINDOWS\System32\drivers\fsbts.sys
    [2010.09.22 14:27:42 | 000,000,405 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2010.09.22 14:05:53 | 000,000,131 | ---- | C] () -- C:\Documents and Settings\oppilas13\Local Settings\Application Data\fusioncache.dat
    [2010.06.29 20:34:06 | 000,025,616 | ---- | C] () -- C:\WINDOWS\AsAcpiSvrLang.ini
    [2010.03.16 22:48:18 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
    [2010.03.16 21:29:00 | 000,011,520 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsUpIO.sys
    [2010.03.16 21:28:51 | 000,001,769 | ---- | C] () -- C:\WINDOWS\Language_trs.ini
    [2010.03.16 12:17:15 | 000,004,381 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
    [2010.03.16 12:10:49 | 000,005,312 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
    [2003.04.01 09:58:30 | 000,005,649 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI

    ========== LOP Check ==========

    [2010.03.16 21:41:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EBI
    [2010.09.22 14:56:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\F-Secure
    [2010.11.01 15:44:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FileCure
    [2010.09.22 14:30:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\fssg
    [2011.02.01 00:12:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grisoft
    [2010.05.10 23:12:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\OberonGameConsole
    [2010.11.01 15:44:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
    [2010.03.16 21:25:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ralink Driver
    [2010.03.16 21:41:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RSMR
    [2011.01.19 21:16:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sandlot Games
    [2011.01.19 22:30:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
    [2011.02.01 00:12:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\oppilas13\Application Data\Grisoft
    [2011.02.09 23:30:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\oppilas13\Application Data\gtk-2.0
    [2010.12.31 18:23:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\oppilas13\Application Data\IMVU
    [2010.11.11 21:15:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\oppilas13\Application Data\IMVUClient
    [2011.01.20 08:16:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\oppilas13\Application Data\PhotoFiltre
    [2011.01.20 08:28:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\oppilas13\Application Data\PhotoFiltre Studio X
    [2011.01.20 08:56:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\oppilas13\Application Data\PhotoScape
    [2011.01.15 16:07:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\oppilas13\Application Data\uTorrent
    [2010.11.11 16:01:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\oppilas13\Application Data\Vivox
    [2011.02.06 18:00:00 | 000,000,452 | ---- | M] () -- C:\WINDOWS\Tasks\ParetoLogic Registration3.job
    [2011.02.17 01:04:35 | 000,000,450 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{00C451BD-9A7E-45C1-B283-886102F13E48}.job

    ========== Purity Check ==========



    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:93DE1838

    < End of report >
     
  7. kalminen

    kalminen Regular member

    Joined:
    May 4, 2007
    Messages:
    3,915
    Likes Received:
    0
    Trophy Points:
    46
    .
    Kyllä se täällä oli !!!

    Tämän voit poistaa koneelta => AVG Anti Spyware 7.5

    -------------------------------------------------------------------

    Kopioi alla olevasta laatikosta kaikki muistiin.

    Code:
    :OTL
    FF - prefs.js..browser.search.defaultthis.engineName: "http://finnish.toggle.com/fi/index.php?rvs=google" 
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. 
    O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation) 
    O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
    O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
    O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation) 
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]
    
    Käynnistä OTL.EXE ohjelma.
    Vista - 7:ssa tee se hiiren oikealla napilla ja Suorita Järjestelmän valvojana
    Liitä muistista texti OTL:n valkoiseen laatikkoon (Custom Scans/Fixes)
    Paina sitten Run Fix nappia
    Lopuksi se pyytää koneen ReStarttia => OK
    Logi aukeaa muistioon josta kopioit sen viestiisi.

    Vieläkö selain karkailee ???
    :)
     
  8. Gatherine

    Gatherine Member

    Joined:
    Feb 3, 2011
    Messages:
    9
    Likes Received:
    0
    Trophy Points:
    11
    All processes killed
    ========== OTL ==========
    Prefs.js: "http://finnish.toggle.com/fi/index.php?rvs=google" removed from browser.search.defaultthis.engineName
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\IMJPMIG8.1 deleted successfully.
    C:\WINDOWS\ime\imjp8_1\imjpmig.exe moved successfully.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\MSPY2002 deleted successfully.
    C:\WINDOWS\system32\IME\PINTLGNT\IMSCINST.EXE moved successfully.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\PHIME2002A deleted successfully.
    C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE moved successfully.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\PHIME2002ASync deleted successfully.
    File C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE not found.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 32902 bytes

    User: Järjestelmänvalvoja
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 117608 bytes

    User: LocalService
    ->Temp folder emptied: 66016 bytes
    ->Temporary Internet Files folder emptied: 32969 bytes

    User: NetworkService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 46106536 bytes

    User: oppilas13
    ->Temp folder emptied: 304120703 bytes
    ->Temporary Internet Files folder emptied: 104826007 bytes
    ->Java cache emptied: 933000 bytes
    ->FireFox cache emptied: 54084657 bytes
    ->Flash cache emptied: 17464 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 2518 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 30788856 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 23724226 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
    RecycleBin emptied: 493551 bytes

    Total Files Cleaned = 539,00 mb


    OTL by OldTimer - Version 3.2.20.6 log created on 02172011_203340

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...


    Jep, tossa ois toi noin ja selain karkailee edellee sille sivulle. .__.
     
  9. kalminen

    kalminen Regular member

    Joined:
    May 4, 2007
    Messages:
    3,915
    Likes Received:
    0
    Trophy Points:
    46
    .
    Lopuksi poistamme kaikki käytetyt työkalut roskineen.

    * TuplaklikkaaOTL.exe.
    * Klikkaa CleanUp!.
    * Valitse Yes kun kysytään "Begin cleanup Process?".
    * Jos pyydetään, että saako koneen käynnistää uudeelleen, valitse Yes.
    * OTL.exe poistaa itsensä kun se on valmis, jos näin ei käy poista se itse.

    Tämän enempää en osaa sinua auttaa.
    :)
     
  10. Gatherine

    Gatherine Member

    Joined:
    Feb 3, 2011
    Messages:
    9
    Likes Received:
    0
    Trophy Points:
    11
    Joo ei toi auttanu :/ noh, kiitos kuitenki avusta :)
     
  11. TheJuze

    TheJuze Member

    Joined:
    Dec 5, 2010
    Messages:
    12
    Likes Received:
    0
    Trophy Points:
    11
    No niimpä niin, onneksi itse korjasin tämän kerran. Ei mitään erikoisia työkaluja tarvita.

    Avaa Firefox/IE (Kumpi tai mikä sinulla nyt onkaan). Firefoxissa ainakin käy näin näppärästi:

    Kirjoita osoitepalkkiin "about:config" ilman lainausmerkkejä. Paina "Lupaan olla varovainen."

    Sieltä etsit noita IRCFast ja Finnish Toggleja (esim. kotisivun osoite) hakutoiminnolla (Ctrl + F), jos löytyy jotain niin kerrothan. EDIT: Kannattaa ainakin noita URL päätteisiä etsiä, kuten Keyword.URL

    Muistaakseni browser.startup.homepage tulee vaihtaa... Niitä on siellä muutama.

    En ihan tarkalleen muista mitkä pitivät poistaa ja mitkä muokata, mutta katsotaan sitten, tämä ainakin auttaa minua hieman.

    EDIT: Toinen vaihtoehto saattaa olla poistaa Firefox ja asentaa uudelleen, mutta jos se on tarttunut IE:hen niin se aika varmasti tulee vain takaisin. Firefoxin rekisterin se ainakin sotkee.
    EDIT2: Ja tuossa jos haluat vielä kääntää suomeksi:
    [​IMG]
    EDIT3: Voit myös kokeilla käynnistää safe modessa, poistaa Lisää tai Poista Sovelluksista tuon Togglen, poistat Firefoxin lisäosista togglen (HUOM! Käynnistä Firefox myös sen omalla vikasietotilalla! Käynnistä-valikosta löytyy.) ja IRCFast? Sitten siivoat roskat CCleanerillä. :)

    EDIT4: Ai niin! Melkein unohdin!

    Firefoxissa avaa Työkalut -> Asetukset -> Tietosuoja. Valitse "Valitut historiatiedot", sieltä "poista evästeitä" ja poista FinnishTogglet ja IRCFastit ja kaikki sieltä. Muista myös lisätä http://*.toggle.com ja IRCFast poikkeuksiin jotta ne eivät asennu uudelleen.

    EDIT5: No tuli vielä luettua lisää, jos jaksat suomentaa: http://kb.mozillazine.org/Resetting_preferences
     
    Last edited: Feb 19, 2011
  12. Gatherine

    Gatherine Member

    Joined:
    Feb 3, 2011
    Messages:
    9
    Likes Received:
    0
    Trophy Points:
    11
    No sieltä about:config jutusta löyty ainaki tällänen:

    keyword.URL;http://finnish.toggle.com/fi/index.php?rvs=google
     
  13. TheJuze

    TheJuze Member

    Joined:
    Dec 5, 2010
    Messages:
    12
    Likes Received:
    0
    Trophy Points:
    11
    Etsitkö jo noita Toggleja ja muita muualta? about:config -> Etsi "toggle". Postaat tänne sitten kaikki togglet. :)

    Tuliko jo kokeiltua EDIT3 ja EDIT4 neuvoja?
     
    Last edited: Feb 22, 2011
  14. Gatherine

    Gatherine Member

    Joined:
    Feb 3, 2011
    Messages:
    9
    Likes Received:
    0
    Trophy Points:
    11
    Mä kokeilin noita EDIT 3 ja EDIT 4 mut siinä EDIT 3 jutussa on löytäny mitää sieltä lisäosista enkä sieltä lisää tai poista sovellus -osiosta. Ja tuo toggle hommeli, minkä postasin oli ainut mikä löyty ku etin sieltä about:config jutusta.
     
  15. TheJuze

    TheJuze Member

    Joined:
    Dec 5, 2010
    Messages:
    12
    Likes Received:
    0
    Trophy Points:
    11
    No tämän enempää en osaa nyt neuvoa kun en löydä sitä sivuakaan missä oli ohjeet. :(

    Voin vielä viimeset ohjeet antaa:

    1. Käynnistä Firefox vikasietotilassa (Käynnistävalikko -> Firefox -> Firefox (vikasietotila)). Poista kaikki käytöstä. (Ainakin 1-2 ja 4-5 ruksaat) -> Tee muutokset ja käynnistä uudelleen nappi (tai miten se nyt lukeekaan).
    2. (Tee uudelleen) Firefoxissa avaa Työkalut -> Asetukset -> Tietosuoja. Valitse "Valitut historiatiedot", sieltä "poista evästeitä" ja poista FinnishTogglet ja IRCFastit ja kaikki sieltä. Muista myös lisätä http://*.toggle.com ja IRCFast poikkeuksiin jotta ne eivät asennu uudelleen.
    3. about:config -> Vaihda tuo keyword.URL siitä Togglesta tähän: http://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=

    Katsos jos toimii, jos ei niin enempää minulta ei löydy neuvoja kuin asentaa Windows uudelleen. Jos ryhdyt tähän, muista ottaa varmuuskopiot tärkeistä tiedostoista. Onnea yritykseen! Minun neuvot loppuvat tähän (ainakin nyt).
     
    Last edited: Feb 24, 2011
  16. Gatherine

    Gatherine Member

    Joined:
    Feb 3, 2011
    Messages:
    9
    Likes Received:
    0
    Trophy Points:
    11
    hei jee kiitos, nyt menee taas suoraan sille sivulle minkä kirjotanki ^^
     
  17. TheJuze

    TheJuze Member

    Joined:
    Dec 5, 2010
    Messages:
    12
    Likes Received:
    0
    Trophy Points:
    11
    Mahtavaa! Menetin jo melkein toivoni. Hyvä että toimii! :) :)
     

Share This Page