Kone on ihan hidas ja AntiVir ilmoittaa jostain Key.exe:stä mutta ei suostu poistamaan sitä Logfile of HijackThis v1.99.1 Scan saved at 14:49:21, on 21.7.2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Winamp\winampa.exe C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE C:\Program Files\Prevx1\PXConsole.exe C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Valve\Steam\Steam.exe C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe C:\Program Files\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe C:\WINDOWS\System32\cisvc.exe C:\WINDOWS\System32\nvsvc32.exe C:\Program Files\Prevx1\PXAgent.exe C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\snmp.exe C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe C:\Program Files\Winamp\winamp.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Työpöytä\HjT\HijackThis_v1.99.1.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users.WINDOWS\Application Data\Prevx\pxbho.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fi\msntb.dll O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fi\msntb.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup O4 - HKLM\..\Run: [!1_pgaccount] "C:\Program Files\ProcessGuard\pgaccount.exe" O4 - HKLM\..\Run: [PrevxOne] C:\Program Files\Prevx1\PXConsole.exe O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\Steam.exe -silent O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1152471901816 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1152543597453 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: geedc - C:\WINDOWS\ O23 - Service: AntiVir Scheduler (AntiVirScheduler) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: DiamondCS Process Guard Service v3.000 (DCSPGSRV) - Unknown owner - C:\Program Files\ProcessGuard\dcsuserprot.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing) O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: Windows Update Manager Tool (UpdateManagerTool) - Unknown owner - C:\WINDOWS\update\updmangr.exe (file missing)
Käynnistä->Suorita->Kirjoita siihen: sc stop UpdateManagerTool ja enter sc delete UpdateManagerTool ja enter [bold]Fixaa HjT:llä[/bold] (do a system scan only->merkkaa seuraavat ja paina fix checked) [bold]O20 - Winlogon Notify: geedc - C:\WINDOWS\ 23 - Service: Windows Update Manager Tool (UpdateManagerTool) - Unknown owner - C:\WINDOWS\update\updmangr.exe (file missing)[/bold] Poista: (jos ei lähe kokeile vikasietotilassa, F8 käynnistyksen yhteydessä ja valitset vikasietotilan) C:\WINDOWS\[bold]==>update<--[/bold] Onko sulla vielä ProcessGuard asenettuna koneelle, vai oletko poistanu sen?
Jatketaan puhdistusta... Käynnistä->suorita->Kirjoita siihen: sc stop [bold]DCSPGSRV[/bold] ja enter sc delete [bold]DCSPGSRV[/bold] ja enter [bold]Poista:[/bold] C:\Program Files\[bold]==>ProcessGuard<--[/bold] Hommaa ewido: http://aaxxeell.googlepages.com/ewido4 Päivitä, scannaa, poista löydöt ja lähetä raportti tänne, sekä uusi HjT-loki.
--------------------------------------------------------- ewido anti-spyware - Scan Report --------------------------------------------------------- + Created at: 13:58:16 22.7.2006 + Scan result: C:\Program Files\BitComet\Downloads\steam cd key generator\steamkeygen.exe/SERVER~1.EXE -> Backdoor.Ciadoor.13 : No action taken. C:\Program Files\BitComet\Downloads\steam cd key generator\steamkeygen.exe/STEAMA~1.EXE -> Dropper.Small : No action taken. C:\Program Files\EMCO Malware Destroyer\MalwareDestroyer.exe -> Logger.Delf.28 : No action taken. :mozilla.129:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.67:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Adbrite : No action taken. :mozilla.71:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Adbrite : No action taken. :mozilla.68:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken. :mozilla.69:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken. :mozilla.70:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken. :mozilla.72:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken. :mozilla.134:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Atdmt : No action taken. :mozilla.107:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Bluestreak : No action taken. :mozilla.124:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Burstnet : No action taken. :mozilla.125:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Burstnet : No action taken. :mozilla.126:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Burstnet : No action taken. :mozilla.117:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.118:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.119:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.120:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.121:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.122:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.123:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.101:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken. :mozilla.127:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Euroclick : No action taken. :mozilla.128:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Euroclick : No action taken. :mozilla.110:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken. :mozilla.140:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Overture : No action taken. :mozilla.141:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Overture : No action taken. :mozilla.111:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Qksrv : No action taken. :mozilla.114:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Qksrv : No action taken. :mozilla.96:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Sitestat : No action taken. :mozilla.97:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Sitestat : No action taken. :mozilla.17:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken. :mozilla.18:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken. :mozilla.65:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken. :mozilla.66:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken. :mozilla.81:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Valuead : No action taken. :mozilla.82:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Valuead : No action taken. :mozilla.83:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Valuead : No action taken. :mozilla.84:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Valuead : No action taken. :mozilla.85:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Valuead : No action taken. :mozilla.86:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Valuead : No action taken. :mozilla.87:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Valuead : No action taken. :mozilla.16:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.19:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. ::Report end ja Logfile of HijackThis v1.99.1 Scan saved at 14:03:29, on 22.7.2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Winamp\winampa.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE C:\Program Files\Prevx1\PXConsole.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\a-squared Anti-Malware\a2guard.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Valve\Steam\Steam.exe C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe C:\WINDOWS\System32\cisvc.exe C:\WINDOWS\System32\nvsvc32.exe C:\Program Files\Prevx1\PXAgent.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\snmp.exe C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe C:\WINDOWS\System32\wdfmgr.exe C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\ewido anti-spyware 4.0\guard.exe C:\Program Files\ewido anti-spyware 4.0\ewido.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Winamp\winamp.exe C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Työpöytä\HjT\HijackThis_v1.99.1.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: SuperAdBlockerBHO Class - {00000000-6C30-11D8-9363-000AE6309654} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABBHO.dll O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users.WINDOWS\Application Data\Prevx\pxbho.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fi\msntb.dll O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fi\msntb.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: Super Ad Blocker Toolbar - {B4B3001E-0F56-4E51-8250-BDE11547EC55} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\sabtb.dll O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup O4 - HKLM\..\Run: [PrevxOne] C:\Program Files\Prevx1\PXConsole.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\Steam.exe -silent O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O4 - HKCU\..\Run: [SuperAdBlocker] C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SAdBlock.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1152471901816 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1152543597453 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: SABWinLogon - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing) O23 - Service: Super Ad Blocker Service (SABSVC) - SuperAdBlocker.com - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
[bold]Poista:[/bold] C:\Program Files\[bold]==>EMCO Malware Destroyer<--[/bold] C:\Program Files\BitComet\Downloads\[bold]==>steam cd key generator<--[/bold] Avaa [bold]Lisää/Poista Sovellus[/bold] -> Poista kaikki javat ja lataa uusin täältä-> http://www.java.com/en/download/manual.jsp Lähetä uusi HjT-loki.
Logfile of HijackThis v1.99.1 Scan saved at 19:53:27, on 22.7.2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\System32\cisvc.exe C:\Program Files\ewido anti-spyware 4.0\guard.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Winamp\winampa.exe C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE C:\Program Files\Prevx1\PXConsole.exe C:\WINDOWS\System32\nvsvc32.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\ewido anti-spyware 4.0\ewido.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Valve\Steam\Steam.exe C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\snmp.exe C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Prevx1\PXAgent.exe C:\Program Files\Winamp\winamp.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\BitComet\BitComet.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\System32\msiexec.exe C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Työpöytä\HjT\HijackThis_v1.99.1.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: SuperAdBlockerBHO Class - {00000000-6C30-11D8-9363-000AE6309654} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABBHO.dll O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users.WINDOWS\Application Data\Prevx\pxbho.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fi\msntb.dll O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fi\msntb.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: Super Ad Blocker Toolbar - {B4B3001E-0F56-4E51-8250-BDE11547EC55} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\sabtb.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup O4 - HKLM\..\Run: [PrevxOne] C:\Program Files\Prevx1\PXConsole.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\Steam.exe -silent O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O4 - HKCU\..\Run: [SuperAdBlocker] C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SAdBlock.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1152471901816 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1152543597453 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: SABWinLogon - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing) O23 - Service: Super Ad Blocker Service (SABSVC) - SuperAdBlocker.com - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe