kone on välillä hidas ja kaatuile ja ie ei avaa tota sivua http://windowsupdate.microsoft.com/ Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 0:56:47, on 16.5.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe D:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE d:\Program Files\a-squared Free\a2service.exe D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\Explorer.EXE d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe D:\Program Files\Sonera Internet Tietoturva\Common\FSM32.EXE d:\PROGRA~1\SONERA~1\backweb\4436233\Program\SERVIC~1.EXE d:\Program Files\Sonera Internet Tietoturva\Anti-Virus\fsgk32st.exe D:\Program Files\Sonera Internet Tietoturva\FSGUI\ispnews.exe d:\Program Files\Sonera Internet Tietoturva\Anti-Virus\FSGK32.EXE C:\WINDOWS\system32\LVCOMSX.EXE d:\Program Files\Sonera Internet Tietoturva\backweb\4436233\program\fsbwsys.exe D:\Program Files\ThreatFire\TFTray.exe d:\Program Files\Sonera Internet Tietoturva\Anti-Virus\fssm32.exe C:\WINDOWS\system32\Rundll32.exe d:\Program Files\Sonera Internet Tietoturva\Common\FSMA32.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\system32\NOTEPAD.EXE D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe d:\Program Files\Sonera Internet Tietoturva\Common\FSMB32.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\NOTEPAD.EXE d:\Program Files\Sonera Internet Tietoturva\Common\FCH32.EXE d:\Program Files\Sonera Internet Tietoturva\backweb\4436233\Program\fspex.exe d:\PROGRA~1\SPYWAR~1\sp_rsser.exe C:\WINDOWS\System32\svchost.exe d:\Program Files\ThreatFire\TFService.exe d:\Program Files\Sonera Internet Tietoturva\Common\FAMEH32.EXE C:\WINDOWS\system32\wdfmgr.exe d:\Program Files\Sonera Internet Tietoturva\Anti-Virus\fsrw.exe D:\Program Files\VMware\VMware Workstation\vmware-authd.exe C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe C:\WINDOWS\system32\vmnat.exe C:\WINDOWS\system32\vmnetdhcp.exe d:\Program Files\Sonera Internet Tietoturva\Anti-Virus\fsav32.exe d:\Program Files\Sonera Internet Tietoturva\FWES\Program\fsdfwd.exe d:\PROGRA~1\SONERA~1\ANTI-S~1\fsaw.exe C:\WINDOWS\System32\alg.exe d:\Program Files\Sonera Internet Tietoturva\FSGUI\fsguidll.exe D:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe D:\Program Files\ThreatFire\TFGui.exe D:\Program Files\Spybot - Search & Destroy\SpybotSD.exe D:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe C:\WINDOWS\System32\wbem\wmiprvse.exe D:\Program Files\Spybot - Search & Destroy\SpybotSD.exe D:\Program Files\Spybot - Search & Destroy\SpybotSD.exe D:\Program Files\Spybot - Search & Destroy\SpybotSD.exe D:\Program Files\Spybot - Search & Destroy\SpybotSD.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file) O2 - BHO: (no name) - {2AA0726C-95B7-4216-AA43-B5BDD524892F} - C:\WINDOWS\system32\rqRHbCrq.dll O2 - BHO: (no name) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - (no file) O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {6FE4B40D-80B2-4247-B8B0-86D6659660E6} - (no file) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {AE402173-05B5-408D-B757-B0833B6A0DB1} - (no file) O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O2 - BHO: (no name) - {C7D8C2CD-F5A9-4B58-8F06-DA83153F6DD4} - (no file) O2 - BHO: {eff701a6-6787-4b4a-91b4-58541813041d} - {d1403181-4585-4b19-a4b4-78766a107ffe} - (no file) O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O4 - HKLM\..\Run: [F-Secure Manager] "d:\Program Files\Sonera Internet Tietoturva\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [F-Secure TNB] "d:\Program Files\Sonera Internet Tietoturva\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKLM\..\Run: [F-Secure Startup Wizard] "d:\Program Files\Sonera Internet Tietoturva\FSGUI\FSSW.EXE" /reboot O4 - HKLM\..\Run: [News Service] "d:\Program Files\Sonera Internet Tietoturva\FSGUI\ispnews.exe" O4 - HKLM\..\Run: [swcpshell] C:\Windows\System32\csharpshell.exe O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [StartupDelayer] "d:\Program Files\r2 Studios\Startup Delayer\Startup Launcher.exe" O4 - HKLM\..\Run: [TrojanScanner] d:\Program Files\Trojan Remover\Trjscan.exe O4 - HKLM\..\Run: [ThreatFire] d:\Program Files\ThreatFire\TFTray.exe O4 - HKLM\..\Run: [BM330e06e5] Rundll32.exe "C:\WINDOWS\system32\ofxtykcd.dll",s O4 - HKLM\..\Run: [LexPPS.exe] C:\WINDOWS\system32\lexpps.exe O4 - HKLM\..\RunServices: [Winpower] "C:\Program Files\UpsPilot\Winpower.exe" O4 - HKCU\..\Run: [csharpshell] C:\Windows\System32\csharpshell.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [SpybotSD TeaTimer] "D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: AutorunsDisabled O4 - Global Startup: AutorunsDisabled O4 - Global Startup: Sonera Tietoturva.lnk = D:\Program Files\Sonera Internet Tietoturva\backweb\4436233\Program\fspex.exe O8 - Extra context menu item: &D&ownload &with BitComet - res://D:\Program Files3\BitComet\BitComet.exe/AddLink.htm O8 - Extra context menu item: &D&ownload all video with BitComet - res://D:\Program Files3\BitComet\BitComet.exe/AddVideo.htm O8 - Extra context menu item: &D&ownload all with BitComet - res://D:\Program Files3\BitComet\BitComet.exe/AddAllLink.htm O8 - Extra context menu item: &Estä tämä kohoikkuna - d:\Program Files\Sonera Internet Tietoturva\Anti-Spyware\blockpopups.htm O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Avaa uuteen etuvälilehteen - res://C:\Program Files\Windows Live Toolbar\Components\fi-fi\msntabres.dll.mui/230?aa946b597d1344619a0fa5b4fa7a357b O8 - Extra context menu item: Avaa uuteen taustavälilehteen - res://C:\Program Files\Windows Live Toolbar\Components\fi-fi\msntabres.dll.mui/229?aa946b597d1344619a0fa5b4fa7a357b O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Lisää tämä blogiin - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Lisää tämä blogiin tuotteessa Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: IE-suojaus - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - d:\Program Files\Sonera Internet Tietoturva\Anti-Spyware\ieshield.dll O9 - Extra 'Tools' menuitem: IE-suojaus... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - d:\Program Files\Sonera Internet Tietoturva\Anti-Spyware\ieshield.dll O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://D:\Program Files3\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing) O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll O20 - Winlogon Notify: rqRHbCrq - C:\WINDOWS\SYSTEM32\rqRHbCrq.dll O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - d:\Program Files\a-squared Free\a2service.exe O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Sonera Tietoturva (BackWeb Client - 4436233) - Sonera Tietoturva - d:\PROGRA~1\SONERA~1\backweb\4436233\Program\SERVIC~1.EXE O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - d:\Program Files\Sonera Internet Tietoturva\Anti-Virus\fsgk32st.exe O23 - Service: fsbwsys - F-Secure Corp. - d:\Program Files\Sonera Internet Tietoturva\backweb\4436233\program\fsbwsys.exe O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - d:\Program Files\Sonera Internet Tietoturva\FWES\Program\fsdfwd.exe O23 - Service: FSMA - F-Secure Corporation - d:\Program Files\Sonera Internet Tietoturva\Common\FSMA32.EXE O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Route Access Protocol Graphics (RAPG) - Unknown owner - C:\Program Files\Intel\SVCH0ST.exe (file missing) O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Program Files\WinPcap\rpcapd.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - d:\PROGRA~1\SPYWAR~1\sp_rsser.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe O23 - Service: ThreatFire - PC Tools - d:\Program Files\ThreatFire\TFService.exe O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - D:\Program Files\VMware\VMware Workstation\vmware-authd.exe O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - d:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe O23 - Service: Winpower - Zero G - C:\PROGRA~1\UpsPilot\Winpower.exe -- End of file - 12848 bytes
Koneeltasi löytyy aina 8 eri haittaohjelman poistajaa Poista nämä ohjelmat SUPERAntiSpyware Spybot - Search & Destroy Ad-Aware 2007 AVG Anti-Spyware 7.5 Windows Defender Trojan Remover a-squared Free Webroot Spy Sweeper Poistettuasi ohelmat käynnistä kone uudestaan ja lataa ja asenna Malwarebytes-Anti-Malware http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htm Päivitä ohjelma ja suorita täysi skannaus. lopuksi läheta mawarebytesin logi ja uusi hijackthis logi.