Kone on hidas Hjt-Logi

Discussion in 'Virukset ja haittaohjelmat' started by NaabKilla, Jul 21, 2006.

  1. NaabKilla

    NaabKilla Member

    Joined:
    Jan 5, 2006
    Messages:
    64
    Likes Received:
    0
    Trophy Points:
    16
    Kone on ihan hidas ja AntiVir ilmoittaa jostain Key.exe:stä mutta ei suostu poistamaan sitä




    Logfile of HijackThis v1.99.1
    Scan saved at 14:49:21, on 21.7.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Winamp\winampa.exe
    C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
    C:\Program Files\Prevx1\PXConsole.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Valve\Steam\Steam.exe
    C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
    C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    C:\WINDOWS\System32\cisvc.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\Prevx1\PXAgent.exe
    C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\snmp.exe
    C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    C:\Program Files\Winamp\winamp.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Työpöytä\HjT\HijackThis_v1.99.1.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    F2 - REG:system.ini: UserInit=userinit.exe
    O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users.WINDOWS\Application Data\Prevx\pxbho.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fi\msntb.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fi\msntb.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
    O4 - HKLM\..\Run: [!1_pgaccount] "C:\Program Files\ProcessGuard\pgaccount.exe"
    O4 - HKLM\..\Run: [PrevxOne] C:\Program Files\Prevx1\PXConsole.exe
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\Steam.exe -silent
    O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1152471901816
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1152543597453
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: geedc - C:\WINDOWS\
    O23 - Service: AntiVir Scheduler (AntiVirScheduler) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: DiamondCS Process Guard Service v3.000 (DCSPGSRV) - Unknown owner - C:\Program Files\ProcessGuard\dcsuserprot.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
    O23 - Service: Windows Update Manager Tool (UpdateManagerTool) - Unknown owner - C:\WINDOWS\update\updmangr.exe (file missing)
     
  2. Marku2

    Marku2 Regular member

    Joined:
    Dec 7, 2005
    Messages:
    1,259
    Likes Received:
    0
    Trophy Points:
    46
    Käynnistä->Suorita->Kirjoita siihen:
    sc stop UpdateManagerTool ja enter
    sc delete UpdateManagerTool ja enter

    [bold]Fixaa HjT:llä[/bold] (do a system scan only->merkkaa seuraavat ja paina fix checked)
    [bold]O20 - Winlogon Notify: geedc - C:\WINDOWS\
    23 - Service: Windows Update Manager Tool (UpdateManagerTool) - Unknown owner - C:\WINDOWS\update\updmangr.exe (file missing)[/bold]

    Poista: (jos ei lähe kokeile vikasietotilassa, F8 käynnistyksen yhteydessä ja valitset vikasietotilan)
    C:\WINDOWS\[bold]==>update<--[/bold]

    Onko sulla vielä ProcessGuard asenettuna koneelle, vai oletko poistanu sen?
     
    Last edited: Jul 21, 2006
  3. NaabKilla

    NaabKilla Member

    Joined:
    Jan 5, 2006
    Messages:
    64
    Likes Received:
    0
    Trophy Points:
    16
    Olen poistanut sen
     
  4. Marku2

    Marku2 Regular member

    Joined:
    Dec 7, 2005
    Messages:
    1,259
    Likes Received:
    0
    Trophy Points:
    46
    Jatketaan puhdistusta...

    Käynnistä->suorita->Kirjoita siihen:
    sc stop [bold]DCSPGSRV[/bold] ja enter
    sc delete [bold]DCSPGSRV[/bold] ja enter

    [bold]Poista:[/bold]
    C:\Program Files\[bold]==>ProcessGuard<--[/bold]

    Hommaa ewido: http://aaxxeell.googlepages.com/ewido4
    Päivitä, scannaa, poista löydöt ja lähetä raportti tänne, sekä uusi HjT-loki.


     
  5. NaabKilla

    NaabKilla Member

    Joined:
    Jan 5, 2006
    Messages:
    64
    Likes Received:
    0
    Trophy Points:
    16
    ---------------------------------------------------------
    ewido anti-spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 13:58:16 22.7.2006

    + Scan result:



    C:\Program Files\BitComet\Downloads\steam cd key generator\steamkeygen.exe/SERVER~1.EXE -> Backdoor.Ciadoor.13 : No action taken.
    C:\Program Files\BitComet\Downloads\steam cd key generator\steamkeygen.exe/STEAMA~1.EXE -> Dropper.Small : No action taken.
    C:\Program Files\EMCO Malware Destroyer\MalwareDestroyer.exe -> Logger.Delf.28 : No action taken.
    :mozilla.129:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
    :mozilla.67:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
    :mozilla.71:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
    :mozilla.68:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
    :mozilla.69:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
    :mozilla.70:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
    :mozilla.72:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
    :mozilla.134:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
    :mozilla.107:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Bluestreak : No action taken.
    :mozilla.124:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
    :mozilla.125:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
    :mozilla.126:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
    :mozilla.117:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
    :mozilla.118:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
    :mozilla.119:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
    :mozilla.120:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
    :mozilla.121:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
    :mozilla.122:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
    :mozilla.123:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
    :mozilla.101:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
    :mozilla.127:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Euroclick : No action taken.
    :mozilla.128:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Euroclick : No action taken.
    :mozilla.110:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
    :mozilla.140:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Overture : No action taken.
    :mozilla.141:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Overture : No action taken.
    :mozilla.111:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Qksrv : No action taken.
    :mozilla.114:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Qksrv : No action taken.
    :mozilla.96:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Sitestat : No action taken.
    :mozilla.97:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Sitestat : No action taken.
    :mozilla.17:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
    :mozilla.18:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
    :mozilla.65:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
    :mozilla.66:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
    :mozilla.81:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
    :mozilla.82:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
    :mozilla.83:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
    :mozilla.84:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
    :mozilla.85:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
    :mozilla.86:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
    :mozilla.87:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
    :mozilla.16:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
    :mozilla.19:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.


    ::Report end

    ja




    Logfile of HijackThis v1.99.1
    Scan saved at 14:03:29, on 22.7.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
    C:\Program Files\Prevx1\PXConsole.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\a-squared Anti-Malware\a2guard.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Valve\Steam\Steam.exe
    C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
    C:\WINDOWS\System32\cisvc.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\Prevx1\PXAgent.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\snmp.exe
    C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
    C:\WINDOWS\System32\wdfmgr.exe
    C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\Program Files\ewido anti-spyware 4.0\ewido.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Winamp\winamp.exe
    C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Työpöytä\HjT\HijackThis_v1.99.1.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    F2 - REG:system.ini: UserInit=userinit.exe
    O2 - BHO: SuperAdBlockerBHO Class - {00000000-6C30-11D8-9363-000AE6309654} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABBHO.dll
    O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users.WINDOWS\Application Data\Prevx\pxbho.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fi\msntb.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fi\msntb.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Super Ad Blocker Toolbar - {B4B3001E-0F56-4E51-8250-BDE11547EC55} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\sabtb.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
    O4 - HKLM\..\Run: [PrevxOne] C:\Program Files\Prevx1\PXConsole.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe"
    O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\Steam.exe -silent
    O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
    O4 - HKCU\..\Run: [SuperAdBlocker] C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SAdBlock.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1152471901816
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1152543597453
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: SABWinLogon - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
    O23 - Service: Super Ad Blocker Service (SABSVC) - SuperAdBlocker.com - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe

     
  6. Marku2

    Marku2 Regular member

    Joined:
    Dec 7, 2005
    Messages:
    1,259
    Likes Received:
    0
    Trophy Points:
    46
    [bold]Poista:[/bold]
    C:\Program Files\[bold]==>EMCO Malware Destroyer<--[/bold]
    C:\Program Files\BitComet\Downloads\[bold]==>steam cd key generator<--[/bold]

    Avaa [bold]Lisää/Poista Sovellus[/bold] -> Poista kaikki javat ja lataa uusin täältä-> http://www.java.com/en/download/manual.jsp

    Lähetä uusi HjT-loki.
     
    Last edited: Jul 22, 2006
  7. NaabKilla

    NaabKilla Member

    Joined:
    Jan 5, 2006
    Messages:
    64
    Likes Received:
    0
    Trophy Points:
    16
    Logfile of HijackThis v1.99.1
    Scan saved at 19:53:27, on 22.7.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\System32\cisvc.exe
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Winamp\winampa.exe
    C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
    C:\Program Files\Prevx1\PXConsole.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\ewido anti-spyware 4.0\ewido.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Valve\Steam\Steam.exe
    C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\snmp.exe
    C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
    C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Prevx1\PXAgent.exe
    C:\Program Files\Winamp\winamp.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\BitComet\BitComet.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\System32\msiexec.exe
    C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Työpöytä\HjT\HijackThis_v1.99.1.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    F2 - REG:system.ini: UserInit=userinit.exe
    O2 - BHO: SuperAdBlockerBHO Class - {00000000-6C30-11D8-9363-000AE6309654} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABBHO.dll
    O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users.WINDOWS\Application Data\Prevx\pxbho.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fi\msntb.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fi\msntb.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Super Ad Blocker Toolbar - {B4B3001E-0F56-4E51-8250-BDE11547EC55} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\sabtb.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
    O4 - HKLM\..\Run: [PrevxOne] C:\Program Files\Prevx1\PXConsole.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe"
    O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\Steam.exe -silent
    O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
    O4 - HKCU\..\Run: [SuperAdBlocker] C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SAdBlock.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1152471901816
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1152543597453
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: SABWinLogon - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
    O23 - Service: Super Ad Blocker Service (SABSVC) - SuperAdBlocker.com - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe

     
  8. Marku2

    Marku2 Regular member

    Joined:
    Dec 7, 2005
    Messages:
    1,259
    Likes Received:
    0
    Trophy Points:
    46
    Loki on puhdas. Vieläkö ongelmia?
     
  9. NaabKilla

    NaabKilla Member

    Joined:
    Jan 5, 2006
    Messages:
    64
    Likes Received:
    0
    Trophy Points:
    16
    Ei ole ongelmia. Kiitos sulle!
     
  10. Marku2

    Marku2 Regular member

    Joined:
    Dec 7, 2005
    Messages:
    1,259
    Likes Received:
    0
    Trophy Points:
    46
    Oleppa hyvä. :)
     

Share This Page