Kone suht jumissa, tässä HJT-loki

Discussion in 'Virukset ja haittaohjelmat - HijackThis -logit' started by veijo62, Nov 1, 2008.

  1. veijo62

    veijo62 Member

    Joined:
    Nov 1, 2008
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    11
    Kone on suhteellisen jumissa.
    Mesen kautta tulee erilaisia linkkejä ja pop-uppeja avautuu.

    Tässä tämä loki:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 14:39:12, on 1.11.2008
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16757)
    Boot mode: Normal

    Running processes:
    C:\Windows\System32\smss.exe
    C:\Windows\system32\csrss.exe
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\csrss.exe
    C:\Windows\system32\services.exe
    C:\Windows\system32\lsass.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\winlogon.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe
    C:\Program Files\Norman\Npm\bin\ELOGSVC.EXE
    C:\Program Files\Norman\Npm\Bin\Zanda.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Program Files\Norman\Npm\bin\NJEEVES.EXE
    C:\Program Files\Norman\nse\bin\NSESVC.EXE
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Norman\Nvc\BIN\NVCSCHED.EXE
    C:\Program Files\Norman\Nvc\bin\nvcoas.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Windows\System32\rundll32.exe
    C:\Windows\RtHDVCpl.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Norman\Npm\Bin\Zlh.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Norman\Nvc\BIN\NIP.EXE
    C:\Program Files\Norman\Nvc\bin\cclaw.exe
    F:\PhoneConnectorVMC.exe
    F:\VMC.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Windows\system32\conime.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Program Files\Internet Explorer\IEUser.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Internet Explorer\iexplore.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Adobe PDF Reader -linkkiavustaja - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [recinfo801] c:\RecInfo\RecInfo.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [recinfo] RecInfo.exe
    O4 - HKLM\..\Run: [Norman ZANDA] "C:\Program Files\Norman\Npm\bin\ZLH.EXE" /LOAD /SPLASH
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [VMCL] C:\Program Files\vodafone\vmclite\DongleEnumerator.exe
    O4 - HKCU\..\Run: [REGSMODE] "C:\ProgramData\log delete delete.6p0cto"
    O4 - HKCU\..\Run: [Amok Mode Dupe Platform] "C:\ProgramData\Locks Bold Second.zpvyr"
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Paikallinen palvelu')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'Paikallinen palvelu')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Verkkopalvelu')
    O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: V&ie Microsoft Exceliin - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
    O9 - Extra button: Lähetä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: Läh&etä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O13 - Gopher Prefix:
    O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{5052D141-6B53-48E2-B092-7FEAF5B2A393}: NameServer = 195.226.224.72 195.226.224.76
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:\Program Files\Norman\Npm\bin\ELOGSVC.EXE
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: Norman NJeeves - Norman ASA - C:\Program Files\Norman\Npm\bin\NJEEVES.EXE
    O23 - Service: Norman ZANDA - Norman ASA - C:\Program Files\Norman\Npm\Bin\Zanda.exe
    O23 - Service: Norman Scanner Engine Service (nsesvc) - Norman ASA - C:\Program Files\Norman\nse\bin\NSESVC.EXE
    O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Program Files\Norman\Nvc\bin\nvcoas.exe
    O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman ASA - C:\Program Files\Norman\Nvc\BIN\NVCSCHED.EXE
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe

    --
    End of file - 9594 bytes
     
  2. veijo62

    veijo62 Member

    Joined:
    Nov 1, 2008
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    11
    löytyykö mitään?
     
  3. kalminen

    kalminen Regular member

    Joined:
    May 4, 2007
    Messages:
    3,915
    Likes Received:
    0
    Trophy Points:
    46
    Toimenpiteet Vistassa suoritetaan Järjestelmänvalvojana
    (tarkista älä oleta)

    **************************************************

    Spy-Both:
    1. Käynnistä Spybot-S&D Edistyneessä tilassa
    2. Jos se ei ole Edistyneessä tilassa, mene Tila-valikkoon ja valitse Edistynyt tila
    3. Klikkaa vasemmalla Työkalut
    4. Klikkaa listassa Pysyvä suojaus
    5. Ota rasti pois kohdasta "Pysyvä TeaTimer" ja paina OK.
    6. Käynnistä kone uudelleen.

    ********************************************

    Lataa Malwarebytes' Anti-Malware työpöydällesi.

    * Tuplaklikkaa mbam-setup.exe ja seuraa ohjeita asentaaksesi ohjelman.
    * Lopuksi varmistu, että seuraavat on valittu: Update Malwarebytes' Anti-Malware ja Launch Malwarebytes' Anti-Malware ja sen jälkeen klikkaa Finish.
    * Jos päivitys löytyy. ohjelma lataa ja asentaa uusimman version.
    * Kun ohjelma on latautunut, valitse Perform full scan ja klikkaa Scan.
    * Kun skanni on valmis, klikkaa OK ja sitten Näytä tulokset nähdäksesi tulokset.
    * Varmistu, että kaikki on merkitty ja klikkaa Poista valitut.
    * Tämän jälkeen loki avautuu muistioon. Tallenna se paikkaan, josta löydät sen helposti. Loki löytyy myös
    täältä: C:\Documents and Settings\Käyttäjänimi\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-päiväys.txt

    ------------------------------------------

    Poista ne rivit jotka on jäljellä:
    Kun käynnistät HijackThis =(HJT) ohjelman tee se hiiren oikealla napilla
    ja valitset Suorita Järjestelmänvalvojana
    Sammuta selain ja muut ohjelmat Fixin ajaksi. (ei virustorjuntaa)
    Käynnistä HijackThis (HJT):ja Scan ja ruksaa seuraavat punaisella listatut tiedostot sekä poista ne.(fix Chekked)

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [recinfo801] c:\RecInfo\RecInfo.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [recinfo] RecInfo.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKCU\..\Run: [REGSMODE] "C:\ProgramData\log delete delete.6p0cto"
    O4 - HKCU\..\Run: [Amok Mode Dupe Platform] "C:\ProgramData\Locks Bold Second.zpvyr"
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'Paikallinen palvelu')
    O13 - Gopher Prefix:
    O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{5052D141-6B53-48E2-B092-7FEAF5B2A393}: NameServer = 195.226.224.72 195.226.224.76
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

    Tyhjennä roskakori ja käynnistä koneesi uudelleen.

    Postita tänne seuraavat lokit:
    * Tuore HijackThis loki (Otetaan viimeisenä ennen postitusta)
    * Malwarebytes' Anti-Malware\Logs\log-päiväys.txt
    *
    *
     
  4. veijo62

    veijo62 Member

    Joined:
    Nov 1, 2008
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    11
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 14:39:12, on 1.11.2008
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16757)
    Boot mode: Normal

    Running processes:
    C:\Windows\System32\smss.exe
    C:\Windows\system32\csrss.exe
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\csrss.exe
    C:\Windows\system32\services.exe
    C:\Windows\system32\lsass.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\winlogon.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe
    C:\Program Files\Norman\Npm\bin\ELOGSVC.EXE
    C:\Program Files\Norman\Npm\Bin\Zanda.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Program Files\Norman\Npm\bin\NJEEVES.EXE
    C:\Program Files\Norman\nse\bin\NSESVC.EXE
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Norman\Nvc\BIN\NVCSCHED.EXE
    C:\Program Files\Norman\Nvc\bin\nvcoas.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Windows\System32\rundll32.exe
    C:\Windows\RtHDVCpl.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Norman\Npm\Bin\Zlh.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Norman\Nvc\BIN\NIP.EXE
    C:\Program Files\Norman\Nvc\bin\cclaw.exe
    F:\PhoneConnectorVMC.exe
    F:\VMC.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Windows\system32\conime.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Program Files\Internet Explorer\IEUser.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Internet Explorer\iexplore.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Adobe PDF Reader -linkkiavustaja - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [recinfo801] c:\RecInfo\RecInfo.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [recinfo] RecInfo.exe
    O4 - HKLM\..\Run: [Norman ZANDA] "C:\Program Files\Norman\Npm\bin\ZLH.EXE" /LOAD /SPLASH
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [VMCL] C:\Program Files\vodafone\vmclite\DongleEnumerator.exe
    O4 - HKCU\..\Run: [REGSMODE] "C:\ProgramData\log delete delete.6p0cto"
    O4 - HKCU\..\Run: [Amok Mode Dupe Platform] "C:\ProgramData\Locks Bold Second.zpvyr"
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Paikallinen palvelu')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'Paikallinen palvelu')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Verkkopalvelu')
    O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: V&ie Microsoft Exceliin - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
    O9 - Extra button: Lähetä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: Läh&etä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O13 - Gopher Prefix:
    O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{5052D141-6B53-48E2-B092-7FEAF5B2A393}: NameServer = 195.226.224.72 195.226.224.76
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:\Program Files\Norman\Npm\bin\ELOGSVC.EXE
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: Norman NJeeves - Norman ASA - C:\Program Files\Norman\Npm\bin\NJEEVES.EXE
    O23 - Service: Norman ZANDA - Norman ASA - C:\Program Files\Norman\Npm\Bin\Zanda.exe
    O23 - Service: Norman Scanner Engine Service (nsesvc) - Norman ASA - C:\Program Files\Norman\nse\bin\NSESVC.EXE
    O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Program Files\Norman\Nvc\bin\nvcoas.exe
    O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman ASA - C:\Program Files\Norman\Nvc\BIN\NVCSCHED.EXE
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe

    --
    End of file - 9594 bytes


    ____________________________________________________________________


    Malwarebytes' Anti-Malware 1.30
    Tietokantaversio: 1366
    Windows 6.0.6000

    4.11.2008 23:56:50
    mbam-log-2008-11-04 (23-56-50).txt

    Tarkistustyyppi: Täysi tarkistus (C:\|D:\|)
    Tarkistetut kohteet: 121417
    Kulunut aika: 1 hour(s), 37 minute(s), 8 second(s)

    Saastuneita muistiprosesseja: 0
    Saastuneita muistimoduuleja: 0
    Saastuneita rekisteriavaimia: 0
    Saastuneita rekisteriarvoja: 0
    Saastuneita rekisterikohteita: 0
    Saastuneita hakemistoja: 0
    Saastuneita tiedostoja: 1

    Saastuneita muistiprosesseja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita muistimoduuleja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita rekisteriavaimia:
    (Haitallisia kohteita ei löydetty)

    Saastuneita rekisteriarvoja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita rekisterikohteita:
    (Haitallisia kohteita ei löydetty)

    Saastuneita hakemistoja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita tiedostoja:
    C:\ProgramData\SENDDOESDALE\sklmkuni.exe (Trojan.Swizzor) -> Quarantined and deleted successfully.
     
  5. kalminen

    kalminen Regular member

    Joined:
    May 4, 2007
    Messages:
    3,915
    Likes Received:
    0
    Trophy Points:
    46
    Tee toi mun edellinen ohje uudelleen ja
    lue ohjeet huolella.
    MB-AM:n ajoa ei tarvii uusia.
    HJT:n logi =>
     
  6. veijo62

    veijo62 Member

    Joined:
    Nov 1, 2008
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    11
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:17:07, on 5.11.2008
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16757)
    Boot mode: Normal

    Running processes:
    C:\Windows\System32\smss.exe
    C:\Windows\system32\csrss.exe
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\csrss.exe
    C:\Windows\system32\services.exe
    C:\Windows\system32\lsass.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\winlogon.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe
    C:\Program Files\Norman\Npm\bin\ELOGSVC.EXE
    C:\Program Files\Norman\Npm\Bin\Zanda.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\Program Files\Norman\Npm\bin\NJEEVES.EXE
    C:\Program Files\Norman\nse\bin\NSESVC.EXE
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Windows\RtHDVCpl.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Norman\Npm\Bin\Zlh.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    F:\PhoneConnectorVMC.exe
    C:\Program Files\Norman\Nvc\BIN\NVCSCHED.EXE
    C:\Program Files\Norman\Nvc\bin\nvcoas.exe
    C:\Program Files\Norman\Nvc\BIN\NIP.EXE
    C:\Program Files\Norman\Nvc\bin\cclaw.exe
    F:\VMC.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Windows\system32\SearchProtocolHost.exe
    \?\C:\Windows\system32\wbem\WMIADAP.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Adobe PDF Reader -linkkiavustaja - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [recinfo801] c:\RecInfo\RecInfo.exe
    O4 - HKLM\..\Run: [Norman ZANDA] "C:\Program Files\Norman\Npm\bin\ZLH.EXE" /LOAD /SPLASH
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [VMCL] C:\Program Files\vodafone\vmclite\DongleEnumerator.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Paikallinen palvelu')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Verkkopalvelu')
    O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: V&ie Microsoft Exceliin - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
    O9 - Extra button: Lähetä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: Läh&etä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{5052D141-6B53-48E2-B092-7FEAF5B2A393}: NameServer = 195.226.224.72 195.226.224.76
    O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:\Program Files\Norman\Npm\bin\ELOGSVC.EXE
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: Norman NJeeves - Norman ASA - C:\Program Files\Norman\Npm\bin\NJEEVES.EXE
    O23 - Service: Norman ZANDA - Norman ASA - C:\Program Files\Norman\Npm\Bin\Zanda.exe
    O23 - Service: Norman Scanner Engine Service (nsesvc) - Norman ASA - C:\Program Files\Norman\nse\bin\NSESVC.EXE
    O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Program Files\Norman\Nvc\bin\nvcoas.exe
    O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman ASA - C:\Program Files\Norman\Nvc\BIN\NVCSCHED.EXE
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe

    --
    End of file - 7434 bytes
     
  7. veijo62

    veijo62 Member

    Joined:
    Nov 1, 2008
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    11
    Vaihdoin koneeseeni uuden virustorjuntaohjelman ja palomuurin...
    Tässäpä siis nyt uudestaan uusin hjt-loki:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 22:51:51, on 5.11.2008
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16757)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\Explorer.EXE
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Alwil Software\Avast4\ashDisp.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    F:\PhoneConnectorVMC.exe
    F:\VMC.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Adobe PDF Reader -linkkiavustaja - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [recinfo801] c:\RecInfo\RecInfo.exe
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [VMCL] C:\Program Files\vodafone\vmclite\DongleEnumerator.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Paikallinen palvelu')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Verkkopalvelu')
    O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: V&ie Microsoft Exceliin - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
    O9 - Extra button: Lähetä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: Läh&etä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{5052D141-6B53-48E2-B092-7FEAF5B2A393}: NameServer = 195.226.224.72 195.226.224.76
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
    O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe

    --
    End of file - 6141 bytes
     
  8. kalminen

    kalminen Regular member

    Joined:
    May 4, 2007
    Messages:
    3,915
    Likes Received:
    0
    Trophy Points:
    46
    * Lataa Otmoveit3 by OldTimer.
    * Tallenna se työpöydällesi.
    * Tuplaklikkaa OTMoveIt3.exe käynnistääksesi sen.
    * Kopioi (CTRL+C) alla olevasta laatikosta kaikki teksti.[/list]
    Code:
    :files
    c:\RecInfo 
    
    * Palaa takaisin OtmoveIt3, paina oikeanpuoleista hiiren nappia Paste Instructions for Items to be Move-ikkunassa (Keltaisen palkin alla) ja paina Liitä.
    * Paina punaista MoveIt! -nappia.
    * Kopioi (CTRL+C) ja liitä (CTRL+V) Results-ikkunaan (Vihreän palkin alla) tullut teksti seuraavaan viestiisi.
    * Sulje OTMoveIt3.

    Jos jotain tiedostoa/kansiota ei voitu siirtää heti, ohjelma ehdottaa koneen uudelleenkäynnistystä. Vastaa ehdotukseen Yes, jolloin OtMoveIt käynnistää koneesi uudelleen.

    --------------------------------------------------------

    On suositeltavaa ottaa virustorjunnan reaaliaikainen tarkistus pois päältä
    ettei se häiritse Lop S&D:n toimintaa; voit laittaa sen
    takaisin päälle tarkistuksen jälkeen


    Lataa Lop S&D TÄÄLTÄ

    Tuplaklikkaa Lop S&D.exeä
    Valitse Suomi kieleksi painamalla U ja Enter.
    Tämän jälkeen valitse Optio 1 (Etsi) painamalla 1 ja Enter
    Odota, kunnes tarkistus on valmis
    Loki avautuu muistioon. Lähetä se seuraavassa viestissäsi. Se löytyy myös sijainnista
    C:\lopR.txt

    ---------------------------------------------------

    Toimenpiteet Vistassa suoritetaan Järjestelmänvalvojana
    (tarkista älä oleta)

    **************************************************

    Poista ne rivit jotka on jäljellä:
    Kun käynnistät HijackThis =(HJT) ohjelman tee se hiiren oikealla napilla
    ja valitset Suorita Järjestelmänvalvojana
    Sammuta selain ja muut ohjelmat Fixin ajaksi. (ei virustorjuntaa)
    Käynnistä HijackThis (HJT):ja Scan ja ruksaa seuraavat punaisella listatut tiedostot sekä poista ne.(fix Chekked)

    O4 - HKLM\..\Run: [recinfo801] c:\RecInfo\RecInfo.exe

    Tyhjennä roskakori ja käynnistä koneesi uudelleen.

    Postita tänne seuraavat lokit:
    * Tuore HijackThis loki (Otetaan viimeisenä ennen postitusta)
    * OTMoveIt logi. C:\lopR.txt
    *
     
  9. veijo62

    veijo62 Member

    Joined:
    Nov 1, 2008
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    11
    Otmoveit3:

    ========== FILES ==========
    c:\RecInfo moved successfully.

    OTMoveIt3 by OldTimer - Version 1.0.7.0 log created on 11062008_135455


    _______________________________________________________________________

    Lop S&D loki:


    --------------------\\ Lop S&D 4.2.4-9c XP/Vista

    Microsoft® Windows Vista™ Home Premium ( v6.0.6000 )
    X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor 5000+ )
    BIOS : )Phoenix - Award WorkstationBIOS v6.00PG
    USER : Minja ( Administrator )
    BOOT : Normal boot
    Antivirus : avast! antivirus 4.8.1229 [VPS 081105-0] 4.8.1229 (Not Activated)
    Firewall : Sunbelt Personal Firewall 4.6.1845 T (Activated)
    C:\ (Local Disk) - NTFS - Total:303 Go (Free:228 Go)
    D:\ (Local Disk) - NTFS - Total:150 Go (Free:150 Go)
    E:\ (CD or DVD)
    F:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
    G:\ (USB)
    H:\ (USB)
    I:\ (USB)
    J:\ (USB)
    K:\ (USB)

    "C:\Lop SD" ( MAJ : 01-11-2008|16:30 )
    Option : [1] ( to 06.11.2008|14:06 )

    [ UAC => 1 ]

    --------------------\\ Listaa hakemistoja sijainnissa Local

    [08.03.2008|17:00] C:\Users\Minja\AppData\Local\Adobe
    [17.10.2008|19:24] C:\Users\Minja\AppData\Local\Ahead
    [18.02.2008|19:12] C:\Users\Minja\AppData\Local\Apple
    [08.08.2008|11:25] C:\Users\Minja\AppData\Local\Apple Computer
    [16.02.2008|10:36] C:\Users\Minja\AppData\Local\Application Data
    [02.11.2008|15:34] C:\Users\Minja\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [28.08.2008|15:19] C:\Users\Minja\AppData\Local\GDIPFONTCACHEV1.DAT
    [05.11.2008|22:38] C:\Users\Minja\AppData\Local\IconCache.db
    [28.08.2008|15:20] C:\Users\Minja\AppData\Local\Microsoft
    [18.02.2008|18:58] C:\Users\Minja\AppData\Local\Microsoft Games
    [02.03.2008|19:07] C:\Users\Minja\AppData\Local\Microsoft Help
    [16.02.2008|14:51] C:\Users\Minja\AppData\Local\Mozilla
    [16.02.2008|10:44] C:\Users\Minja\AppData\Local\Seven Zip
    [16.02.2008|10:36] C:\Users\Minja\AppData\Local\Sivuhistoria
    [06.11.2008|14:00] C:\Users\Minja\AppData\Local\Temp
    [16.02.2008|10:36] C:\Users\Minja\AppData\Local\Temporary Internet Files
    [18.02.2008|18:32] C:\Users\Minja\AppData\Local\VirtualStore
    [3|tiedosto(a)] C:\Users\Minja\AppData\Local\tavua
    [16|kansio(ta)] C:\Users\Minja\AppData\Local\tavua vapaana

    --------------------\\ Ajoitetut tehtävät sijaitsee C:\Windows\Tasks

    [16.02.2008 17:27][--a------] C:\Windows\tasks\Tarkistetaan Windows Live -ty”kalurivin p„ivitykset.job
    [06.11.2008 13:34][--ah-----] C:\Windows\tasks\SA.DAT
    [05.11.2008 23:39][--a------] C:\Windows\tasks\SCHEDLGU.TXT

    --------------------\\ Listaa hakemistoja sijainnissa C:\ProgramData

    [16.02.2008|10:44] C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
    [08.03.2008|22:55] C:\ProgramData\Adobe
    [18.02.2008|19:11] C:\ProgramData\Apple
    [18.02.2008|19:12] C:\ProgramData\Apple Computer
    [02.11.2006|15:02] C:\ProgramData\Application Data
    [02.11.2006|15:02] C:\ProgramData\Desktop
    [02.11.2006|15:02] C:\ProgramData\Documents
    [02.11.2006|15:02] C:\ProgramData\Favorites
    [16.02.2008|10:44] C:\ProgramData\fsc-reg
    [02.09.2008|14:48] C:\ProgramData\Hold Trust Amok Mode
    [02.09.2008|14:48] C:\ProgramData\Locks Bold Second.zpvyr
    [09.08.2008|12:21] C:\ProgramData\log delete delete.33knc
    [08.09.2008|20:27] C:\ProgramData\log delete delete.5g52b
    [08.09.2008|21:55] C:\ProgramData\log delete delete.6p0cto
    [08.09.2008|21:33] C:\ProgramData\log delete delete.a6zyfyz
    [27.05.2008|21:23] C:\ProgramData\log delete delete.dgm4l4
    [08.09.2008|17:11] C:\ProgramData\log delete delete.dhwmr
    [08.09.2008|16:49] C:\ProgramData\log delete delete.i0xb9
    [08.09.2008|21:11] C:\ProgramData\log delete delete.j5lna1e
    [08.09.2008|18:16] C:\ProgramData\log delete delete.jkth9
    [08.09.2008|19:00] C:\ProgramData\log delete delete.jqfiv
    [08.09.2008|20:49] C:\ProgramData\log delete delete.ndurm
    [08.09.2008|19:22] C:\ProgramData\log delete delete.p257vux
    [08.09.2008|18:38] C:\ProgramData\log delete delete.pquczco
    [02.09.2008|14:47] C:\ProgramData\log delete delete.q2mmxoj
    [05.05.2008|14:03] C:\ProgramData\log delete delete.sm6oi
    [08.09.2008|17:32] C:\ProgramData\log delete delete.t7tql5
    [08.09.2008|17:54] C:\ProgramData\log delete delete.ubj9puf
    [01.04.2008|19:16] C:\ProgramData\log delete delete.ul9ohj
    [02.09.2008|14:47] C:\ProgramData\log delete delete.xupks
    [08.09.2008|19:43] C:\ProgramData\log delete delete.yteeynb
    [08.09.2008|20:05] C:\ProgramData\log delete delete.ywojbo2
    [04.11.2008|21:09] C:\ProgramData\Malwarebytes
    [27.10.2008|22:21] C:\ProgramData\Messenger Plus!
    [28.08.2008|15:08] C:\ProgramData\Microsoft
    [16.10.2008|19:47] C:\ProgramData\Microsoft Help
    [16.02.2008|10:39] C:\ProgramData\Nero
    [04.11.2008|23:56] C:\ProgramData\SENDDOESDALE
    [02.05.2008|22:35] C:\ProgramData\Spybot - Search & Destroy
    [02.11.2006|15:02] C:\ProgramData\Start Menu
    [02.11.2006|15:02] C:\ProgramData\Templates
    [18.02.2008|10:35] C:\ProgramData\WLInstaller
    [22|tiedosto(a)] C:\ProgramData\tavua
    [22|kansio(ta)] C:\ProgramData\tavua vapaana

    --------------------\\ Listaa hakemistoja sijainnissa C:\Program Files

    [16.02.2008|10:44] C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
    [08.03.2008|22:55] C:\Program Files\Adobe
    [05.11.2008|21:55] C:\Program Files\Alwil Software
    [18.02.2008|19:11] C:\Program Files\Apple Software Update
    [02.09.2008|14:46] C:\Program Files\Circle Developement
    [08.03.2008|22:55] C:\Program Files\Common Files
    [16.02.2008|20:55] C:\Program Files\DC++
    [16.02.2008|12:11] C:\Program Files\InstallShield Installation Information
    [17.10.2008|17:37] C:\Program Files\Internet Explorer
    [13.08.2008|15:54] C:\Program Files\Java
    [04.11.2008|21:09] C:\Program Files\Malwarebytes' Anti-Malware
    [05.10.2008|17:20] C:\Program Files\Matroska Pack
    [02.09.2008|14:46] C:\Program Files\Messenger Plus! Live
    [28.08.2008|15:12] C:\Program Files\Microsoft Expression
    [02.11.2006|14:37] C:\Program Files\Microsoft Games
    [28.08.2008|14:59] C:\Program Files\Microsoft Office
    [28.08.2008|14:59] C:\Program Files\Microsoft Visual Studio
    [28.08.2008|14:56] C:\Program Files\Microsoft Visual Studio 8
    [16.02.2008|10:43] C:\Program Files\Microsoft Works
    [16.02.2008|10:41] C:\Program Files\Microsoft.NET
    [02.11.2006|14:42] C:\Program Files\Movie Maker
    [18.10.2008|10:05] C:\Program Files\Mozilla Firefox
    [28.08.2008|15:00] C:\Program Files\MSBuild
    [02.11.2006|14:37] C:\Program Files\MSN
    [18.01.2008|10:43] C:\Program Files\MSXML 4.0
    [16.02.2008|10:39] C:\Program Files\Nero
    [05.11.2008|22:17] C:\Program Files\Norman
    [13.08.2008|16:54] C:\Program Files\OpenOffice.org 2.4
    [18.02.2008|19:13] C:\Program Files\QuickTime
    [18.02.2008|14:01] C:\Program Files\Real
    [02.11.2006|14:37] C:\Program Files\Reference Assemblies
    [05.11.2008|19:24] C:\Program Files\Spybot - Search & Destroy
    [05.11.2008|22:14] C:\Program Files\Sunbelt Software
    [01.11.2008|14:38] C:\Program Files\Trend Micro
    [02.11.2006|15:01] C:\Program Files\Uninstall Information
    [18.02.2008|12:41] C:\Program Files\Winamp
    [02.11.2006|14:42] C:\Program Files\Windows Calendar
    [02.11.2006|14:42] C:\Program Files\Windows Collaboration
    [02.11.2006|14:42] C:\Program Files\Windows Defender
    [02.11.2006|14:42] C:\Program Files\Windows Journal
    [16.02.2008|17:14] C:\Program Files\Windows Live
    [16.02.2008|17:27] C:\Program Files\Windows Live Toolbar
    [17.10.2008|17:37] C:\Program Files\Windows Mail
    [02.11.2006|14:42] C:\Program Files\Windows Media Player
    [02.11.2006|14:37] C:\Program Files\Windows NT
    [02.11.2006|14:42] C:\Program Files\Windows Photo Gallery
    [16.02.2008|12:23] C:\Program Files\Windows Sidebar
    [03.05.2008|10:24] C:\Program Files\WinRAR
    [16.02.2008|11:02] C:\Program Files\Vodafone
    [0|tiedosto(a)] C:\Program Files\tavua
    [51|kansio(ta)] C:\Program Files\tavua vapaana

    --------------------\\ Listaa hakemistoja sijainnissa C:\Program Files\Common Files

    [08.03.2008|22:55] C:\Program Files\Common Files\Adobe
    [16.02.2008|10:39] C:\Program Files\Common Files\Ahead
    [16.02.2008|10:41] C:\Program Files\Common Files\DESIGNER
    [18.01.2008|10:54] C:\Program Files\Common Files\Fujitsu Siemens Computers
    [18.02.2008|22:11] C:\Program Files\Common Files\Java
    [28.08.2008|15:09] C:\Program Files\Common Files\microsoft shared
    [18.02.2008|14:01] C:\Program Files\Common Files\Real
    [02.11.2006|13:18] C:\Program Files\Common Files\Services
    [02.11.2006|13:18] C:\Program Files\Common Files\SpeechEngines
    [28.08.2008|14:55] C:\Program Files\Common Files\System
    [16.02.2008|17:14] C:\Program Files\Common Files\WindowsLiveInstaller
    [16.02.2008|11:02] C:\Program Files\Common Files\Wise Installation Wizard
    [18.02.2008|14:01] C:\Program Files\Common Files\xing shared
    [0|tiedosto(a)] C:\Program Files\Common Files\tavua
    [15|kansio(ta)] C:\Program Files\Common Files\tavua vapaana

    --------------------\\ Process

    ( 56 Processes )

    ... OK !

    --------------------\\ Etsii S_Lopilla

    C:\ProgramData\Locks Bold Second.zpvyr
    C:\ProgramData\log delete delete.33knc
    C:\ProgramData\log delete delete.5g52b
    C:\ProgramData\log delete delete.dhwmr
    C:\ProgramData\log delete delete.i0xb9
    C:\ProgramData\log delete delete.jkth9
    C:\ProgramData\log delete delete.jqfiv
    C:\ProgramData\log delete delete.ndurm
    C:\ProgramData\log delete delete.sm6oi
    C:\ProgramData\log delete delete.xupks
    C:\ProgramData\log delete delete.6p0cto
    C:\ProgramData\log delete delete.dgm4l4
    C:\ProgramData\log delete delete.t7tql5
    C:\ProgramData\log delete delete.ul9ohj
    C:\ProgramData\log delete delete.a6zyfyz
    C:\ProgramData\log delete delete.j5lna1e
    C:\ProgramData\log delete delete.p257vux
    C:\ProgramData\log delete delete.pquczco
    C:\ProgramData\log delete delete.q2mmxoj
    C:\ProgramData\log delete delete.ubj9puf
    C:\ProgramData\log delete delete.yteeynb
    C:\ProgramData\log delete delete.ywojbo2
    C:\Users\Minja\AppData\Local\Temp\bis4A87.exe

    --------------------\\ Etsii Lopin tiedostoja ja kansioita

    C:\ProgramData\Hold Trust Amok Mode
    C:\ProgramData\Hold Trust Amok Mode\Frag Admin.exe
    C:\Program Files\Circle Developement
    C:\Program Files\Circle Developement\Uninstall.exe
    C:\Users\Minja\AppData\Roaming\MICROS~1\Windows\Cookies\minja@www.adserver5[2].txt
    C:\Users\Minja\AppData\Roaming\MICROS~1\Windows\Cookies\minja@www.lop[1].txt

    --------------------\\ Etsii rekisterikohteita

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    ..... OK !

    --------------------\\ Tarkistaa Hosts-tiedostoa

    Hosts-tiedosto PUHDAS


    --------------------\\ Tarkistaa Catchmella onko piilotettuja tiedostoja

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-11-06 14:08:16
    Windows 6.0.6000 NTFS
    scanning hidden processes ...
    scanning hidden files ...
    scan completed successfully
    hidden processes: 0
    hidden files: 207

    --------------------\\ Tarkistaa muita infektioita


    Muita infektiota ei löytynyt !

    [F:1935][D:27]-> C:\Users\Minja\AppData\Local\Temp
    [F:77][D:1]-> C:\Users\Minja\AppData\Roaming\MICROS~1\Windows\Cookies
    [F:1189][D:8]-> C:\Users\Minja\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
    [F:3][D:3]-> C:\$Recycle.Bin

    1 - "C:\Lop SD\LopR_1.txt" - to 06.11.2008|14:10 - Option : [1]

    --------------------\\ Tarkistus valmistui 14:10:45
    [ UAC => 1 ]

     
  10. veijo62

    veijo62 Member

    Joined:
    Nov 1, 2008
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    11
    HJT-loki:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 14:26:31, on 6.11.2008
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16757)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Windows\System32\rundll32.exe
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Alwil Software\Avast4\ashDisp.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    F:\PhoneConnectorVMC.exe
    F:\VMC.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Windows\system32\SearchFilterHost.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Adobe PDF Reader -linkkiavustaja - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [VMCL] C:\Program Files\vodafone\vmclite\DongleEnumerator.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Paikallinen palvelu')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Verkkopalvelu')
    O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: V&ie Microsoft Exceliin - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
    O9 - Extra button: Lähetä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: Läh&etä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{5052D141-6B53-48E2-B092-7FEAF5B2A393}: NameServer = 195.226.224.72 195.226.224.76
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
    O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe

    --
    End of file - 6007 bytes
     
  11. kalminen

    kalminen Regular member

    Joined:
    May 4, 2007
    Messages:
    3,915
    Likes Received:
    0
    Trophy Points:
    46
    Olihan siellä vielä.

    Käynnistä Lop S&D

    Valitse Optio 3 (Korjaa - Hosts) painamalla 3 ja Enter
    ÄLÄ sulje ikkunaa korjauksen aikana!
    Loki avautuu muistioon. Lähetä se seuraavassa viestissäsi. Se löytyy myös sijainnista C:\lopR.txt

    ---------------------------------------------------

    Toimenpiteet Vistassa suoritetaan Järjestelmänvalvojana
    (tarkista älä oleta)

    **************************************************

    Poista ne rivit jotka on jäljellä:
    Kun käynnistät HijackThis =(HJT) ohjelman tee se hiiren oikealla napilla
    ja valitset Suorita Järjestelmänvalvojana
    Sammuta selain ja muut ohjelmat Fixin ajaksi. (ei virustorjuntaa)
    Käynnistä HijackThis (HJT):ja Scan ja ruksaa seuraavat punaisella listatut tiedostot sekä poista ne.(fix Chekked)

    O17 - HKLM\System\CCS\Services\Tcpip\..\{5052D141-6B53-48E2-B092-7FEAF5B2A393}: NameServer = 195.226.224.72 195.226.224.76

    Tyhjennä roskakori ja käynnistä koneesi uudelleen.

    Postita tänne seuraavat lokit:
    * Tuore HijackThis loki (Otetaan viimeisenä ennen postitusta)
    * C:\lopR.txt raportti
    *
    *
     
  12. veijo62

    veijo62 Member

    Joined:
    Nov 1, 2008
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    11
    Lop S&D:


    --------------------\\ Lop S&D 4.2.4-9c XP/Vista

    Microsoft® Windows Vista™ Home Premium ( v6.0.6000 )
    X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor 5000+ )
    BIOS : )Phoenix - Award WorkstationBIOS v6.00PG
    USER : Minja ( Administrator )
    BOOT : Normal boot
    Antivirus : avast! antivirus 4.8.1229 [VPS 081105-0] 4.8.1229 (Activated)
    Firewall : Sunbelt Personal Firewall 4.6.1845 T (Activated)
    C:\ (Local Disk) - NTFS - Total:303 Go (Free:228 Go)
    D:\ (Local Disk) - NTFS - Total:150 Go (Free:150 Go)
    E:\ (CD or DVD)
    F:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
    G:\ (USB)
    H:\ (USB)
    I:\ (USB)
    J:\ (USB)
    K:\ (USB)

    "C:\Lop SD" ( MAJ : 01-11-2008|16:30 )
    Option : [3] ( to 06.11.2008|15:24 )

    [ UAC => 1 ]


    \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ Korjaa

    Poistettu! - C:\ProgramData\Hold Trust Amok Mode\Frag Admin.exe
    Poistettu! - C:\Program Files\Circle Developement\Uninstall.exe
    Poistettu! - C:\Users\Minja\AppData\Roaming\MICROS~1\Windows\Cookies\minja@www.adserver5[2].txt
    Poistettu! - C:\Users\Minja\AppData\Roaming\MICROS~1\Windows\Cookies\minja@www.lop[1].txt
    Poistettu! - C:\ProgramData\Locks Bold Second.zpvyr
    Poistettu! - C:\ProgramData\log delete delete.33knc
    Poistettu! - C:\ProgramData\log delete delete.5g52b
    Poistettu! - C:\ProgramData\log delete delete.dhwmr
    Poistettu! - C:\ProgramData\log delete delete.i0xb9
    Poistettu! - C:\ProgramData\log delete delete.jkth9
    Poistettu! - C:\ProgramData\log delete delete.jqfiv
    Poistettu! - C:\ProgramData\log delete delete.ndurm
    Poistettu! - C:\ProgramData\log delete delete.sm6oi
    Poistettu! - C:\ProgramData\log delete delete.xupks
    Poistettu! - C:\ProgramData\log delete delete.6p0cto
    Poistettu! - C:\ProgramData\log delete delete.dgm4l4
    Poistettu! - C:\ProgramData\log delete delete.t7tql5
    Poistettu! - C:\ProgramData\log delete delete.ul9ohj
    Poistettu! - C:\ProgramData\log delete delete.a6zyfyz
    Poistettu! - C:\ProgramData\log delete delete.j5lna1e
    Poistettu! - C:\ProgramData\log delete delete.p257vux
    Poistettu! - C:\ProgramData\log delete delete.pquczco
    Poistettu! - C:\ProgramData\log delete delete.q2mmxoj
    Poistettu! - C:\ProgramData\log delete delete.ubj9puf
    Poistettu! - C:\ProgramData\log delete delete.yteeynb
    Poistettu! - C:\ProgramData\log delete delete.ywojbo2
    Poistettu! - C:\Users\Minja\AppData\Local\Temp\bis4A87.exe
    Poistettu! - C:\ProgramData\Hold Trust Amok Mode
    Poistettu! - C:\Program Files\Circle Developement

    \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


    --------------------\\ Listaa hakemistoja sijainnissa Local

    [08.03.2008|17:00] C:\Users\Minja\AppData\Local\Adobe
    [17.10.2008|19:24] C:\Users\Minja\AppData\Local\Ahead
    [18.02.2008|19:12] C:\Users\Minja\AppData\Local\Apple
    [08.08.2008|11:25] C:\Users\Minja\AppData\Local\Apple Computer
    [16.02.2008|10:36] C:\Users\Minja\AppData\Local\Application Data
    [02.11.2008|15:34] C:\Users\Minja\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [28.08.2008|15:19] C:\Users\Minja\AppData\Local\GDIPFONTCACHEV1.DAT
    [06.11.2008|14:21] C:\Users\Minja\AppData\Local\IconCache.db
    [28.08.2008|15:20] C:\Users\Minja\AppData\Local\Microsoft
    [18.02.2008|18:58] C:\Users\Minja\AppData\Local\Microsoft Games
    [02.03.2008|19:07] C:\Users\Minja\AppData\Local\Microsoft Help
    [16.02.2008|14:51] C:\Users\Minja\AppData\Local\Mozilla
    [16.02.2008|10:44] C:\Users\Minja\AppData\Local\Seven Zip
    [16.02.2008|10:36] C:\Users\Minja\AppData\Local\Sivuhistoria
    [06.11.2008|15:28] C:\Users\Minja\AppData\Local\Temp
    [16.02.2008|10:36] C:\Users\Minja\AppData\Local\Temporary Internet Files
    [18.02.2008|18:32] C:\Users\Minja\AppData\Local\VirtualStore
    [3|tiedosto(a)] C:\Users\Minja\AppData\Local\tavua
    [16|kansio(ta)] C:\Users\Minja\AppData\Local\tavua vapaana

    --------------------\\ Ajoitetut tehtävät sijaitsee C:\Windows\Tasks

    [16.02.2008 17:27][--a------] C:\Windows\tasks\Tarkistetaan Windows Live -ty”kalurivin p„ivitykset.job
    [06.11.2008 14:22][--ah-----] C:\Windows\tasks\SA.DAT
    [06.11.2008 14:21][--a------] C:\Windows\tasks\SCHEDLGU.TXT

    --------------------\\ Listaa hakemistoja sijainnissa C:\ProgramData

    [16.02.2008|10:44] C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
    [08.03.2008|22:55] C:\ProgramData\Adobe
    [18.02.2008|19:11] C:\ProgramData\Apple
    [18.02.2008|19:12] C:\ProgramData\Apple Computer
    [02.11.2006|15:02] C:\ProgramData\Application Data
    [02.11.2006|15:02] C:\ProgramData\Desktop
    [02.11.2006|15:02] C:\ProgramData\Documents
    [02.11.2006|15:02] C:\ProgramData\Favorites
    [16.02.2008|10:44] C:\ProgramData\fsc-reg
    [04.11.2008|21:09] C:\ProgramData\Malwarebytes
    [27.10.2008|22:21] C:\ProgramData\Messenger Plus!
    [28.08.2008|15:08] C:\ProgramData\Microsoft
    [16.10.2008|19:47] C:\ProgramData\Microsoft Help
    [16.02.2008|10:39] C:\ProgramData\Nero
    [04.11.2008|23:56] C:\ProgramData\SENDDOESDALE
    [02.05.2008|22:35] C:\ProgramData\Spybot - Search & Destroy
    [02.11.2006|15:02] C:\ProgramData\Start Menu
    [02.11.2006|15:02] C:\ProgramData\Templates
    [18.02.2008|10:35] C:\ProgramData\WLInstaller
    [0|tiedosto(a)] C:\ProgramData\tavua
    [21|kansio(ta)] C:\ProgramData\tavua vapaana

    --------------------\\ Listaa hakemistoja sijainnissa C:\Program Files

    [16.02.2008|10:44] C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
    [08.03.2008|22:55] C:\Program Files\Adobe
    [05.11.2008|21:55] C:\Program Files\Alwil Software
    [18.02.2008|19:11] C:\Program Files\Apple Software Update
    [08.03.2008|22:55] C:\Program Files\Common Files
    [16.02.2008|20:55] C:\Program Files\DC++
    [16.02.2008|12:11] C:\Program Files\InstallShield Installation Information
    [17.10.2008|17:37] C:\Program Files\Internet Explorer
    [13.08.2008|15:54] C:\Program Files\Java
    [04.11.2008|21:09] C:\Program Files\Malwarebytes' Anti-Malware
    [05.10.2008|17:20] C:\Program Files\Matroska Pack
    [02.09.2008|14:46] C:\Program Files\Messenger Plus! Live
    [28.08.2008|15:12] C:\Program Files\Microsoft Expression
    [02.11.2006|14:37] C:\Program Files\Microsoft Games
    [28.08.2008|14:59] C:\Program Files\Microsoft Office
    [28.08.2008|14:59] C:\Program Files\Microsoft Visual Studio
    [28.08.2008|14:56] C:\Program Files\Microsoft Visual Studio 8
    [16.02.2008|10:43] C:\Program Files\Microsoft Works
    [16.02.2008|10:41] C:\Program Files\Microsoft.NET
    [02.11.2006|14:42] C:\Program Files\Movie Maker
    [18.10.2008|10:05] C:\Program Files\Mozilla Firefox
    [28.08.2008|15:00] C:\Program Files\MSBuild
    [02.11.2006|14:37] C:\Program Files\MSN
    [18.01.2008|10:43] C:\Program Files\MSXML 4.0
    [16.02.2008|10:39] C:\Program Files\Nero
    [05.11.2008|22:17] C:\Program Files\Norman
    [13.08.2008|16:54] C:\Program Files\OpenOffice.org 2.4
    [18.02.2008|19:13] C:\Program Files\QuickTime
    [18.02.2008|14:01] C:\Program Files\Real
    [02.11.2006|14:37] C:\Program Files\Reference Assemblies
    [05.11.2008|19:24] C:\Program Files\Spybot - Search & Destroy
    [05.11.2008|22:14] C:\Program Files\Sunbelt Software
    [01.11.2008|14:38] C:\Program Files\Trend Micro
    [02.11.2006|15:01] C:\Program Files\Uninstall Information
    [18.02.2008|12:41] C:\Program Files\Winamp
    [02.11.2006|14:42] C:\Program Files\Windows Calendar
    [02.11.2006|14:42] C:\Program Files\Windows Collaboration
    [02.11.2006|14:42] C:\Program Files\Windows Defender
    [02.11.2006|14:42] C:\Program Files\Windows Journal
    [16.02.2008|17:14] C:\Program Files\Windows Live
    [16.02.2008|17:27] C:\Program Files\Windows Live Toolbar
    [17.10.2008|17:37] C:\Program Files\Windows Mail
    [02.11.2006|14:42] C:\Program Files\Windows Media Player
    [02.11.2006|14:37] C:\Program Files\Windows NT
    [02.11.2006|14:42] C:\Program Files\Windows Photo Gallery
    [16.02.2008|12:23] C:\Program Files\Windows Sidebar
    [03.05.2008|10:24] C:\Program Files\WinRAR
    [16.02.2008|11:02] C:\Program Files\Vodafone
    [0|tiedosto(a)] C:\Program Files\tavua
    [50|kansio(ta)] C:\Program Files\tavua vapaana

    --------------------\\ Listaa hakemistoja sijainnissa C:\Program Files\Common Files

    [08.03.2008|22:55] C:\Program Files\Common Files\Adobe
    [16.02.2008|10:39] C:\Program Files\Common Files\Ahead
    [16.02.2008|10:41] C:\Program Files\Common Files\DESIGNER
    [18.01.2008|10:54] C:\Program Files\Common Files\Fujitsu Siemens Computers
    [18.02.2008|22:11] C:\Program Files\Common Files\Java
    [28.08.2008|15:09] C:\Program Files\Common Files\microsoft shared
    [18.02.2008|14:01] C:\Program Files\Common Files\Real
    [02.11.2006|13:18] C:\Program Files\Common Files\Services
    [02.11.2006|13:18] C:\Program Files\Common Files\SpeechEngines
    [28.08.2008|14:55] C:\Program Files\Common Files\System
    [16.02.2008|17:14] C:\Program Files\Common Files\WindowsLiveInstaller
    [16.02.2008|11:02] C:\Program Files\Common Files\Wise Installation Wizard
    [18.02.2008|14:01] C:\Program Files\Common Files\xing shared
    [0|tiedosto(a)] C:\Program Files\Common Files\tavua
    [15|kansio(ta)] C:\Program Files\Common Files\tavua vapaana

    --------------------\\ Process

    ( 56 Processes )

    ... OK !

    --------------------\\ Etsii S_Lopilla

    Lopin kansioita ei löytynyt !

    --------------------\\ Etsii Lopin tiedostoja ja kansioita

    Lopin kansioita ei löytynyt !

    --------------------\\ Etsii rekisterikohteita

    ..... OK !

    --------------------\\ Tarkistaa Hosts-tiedostoa

    Hosts-tiedosto PUHDAS


    --------------------\\ Tarkistaa Catchmella onko piilotettuja tiedostoja

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-11-06 15:29:21
    Windows 6.0.6000 NTFS
    scanning hidden processes ...
    scanning hidden files ...
    scan completed successfully
    hidden processes: 0
    hidden files: 207

    --------------------\\ Tarkistaa muita infektioita


    Muita infektiota ei löytynyt !

    [F:1933][D:27]-> C:\Users\Minja\AppData\Local\Temp
    [F:75][D:1]-> C:\Users\Minja\AppData\Roaming\MICROS~1\Windows\Cookies
    [F:1190][D:8]-> C:\Users\Minja\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
    [F:3][D:3]-> C:\$Recycle.Bin

    1 - "C:\Lop SD\LopR_1.txt" - to 06.11.2008|14:10 - Option : [1]
    2 - "C:\Lop SD\LopR_2.txt" - to 06.11.2008|15:31 - Option : [3]

    --------------------\\ Tarkistus valmistui 15:31:50
    [ UAC => 1 ]

     
  13. veijo62

    veijo62 Member

    Joined:
    Nov 1, 2008
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    11
    Tässä tämä HJT-loki...
    Listassa ei ollut kohtaa 017 - HKLM\system\... jonka olisin voinut poistaa!

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 15:43:11, on 6.11.2008
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16757)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\Explorer.EXE
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Alwil Software\Avast4\ashDisp.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    F:\PhoneConnectorVMC.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Adobe PDF Reader -linkkiavustaja - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [VMCL] C:\Program Files\vodafone\vmclite\DongleEnumerator.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Paikallinen palvelu')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Verkkopalvelu')
    O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: V&ie Microsoft Exceliin - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
    O9 - Extra button: Lähetä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: Läh&etä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
    O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe

    --
    End of file - 5904 bytes
     
  14. kalminen

    kalminen Regular member

    Joined:
    May 4, 2007
    Messages:
    3,915
    Likes Received:
    0
    Trophy Points:
    46
    Tämä alkaa näyttää hyvältä !!!

    Vistan voisit päivittää SP1

    Poista kansio:
    C:\Lop SD\

    Miltä kone tuntuu ???
    D:
     
  15. veijo62

    veijo62 Member

    Joined:
    Nov 1, 2008
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    11
    Mahtavaa :) Suuret kiitokset avusta. Yksin en olisi ikipäivänä selviytynyt! "Pientä" jelppiä tarvitsin jopa ohjeiden noudattamiseen kaverilta (myönnettäköön se) ...huomaa että en ole mikään tietokonehai.

    Epämääräisiä explorerin ikkunoita ei ole tässä rupeaman aikana avautunut yhtään o/ (joista päättelin jonkin olevan vialla koneessani).
    Eiköhän tämä kone siis ole toipumaanpäin! HyväHyvä.

    Päivitys tehty ja kansiokin poistettu. Näin ainakin luulisin :'D

    Kiitokset vielä ohjeistuksesta!

    -M-
     
  16. kalminen

    kalminen Regular member

    Joined:
    May 4, 2007
    Messages:
    3,915
    Likes Received:
    0
    Trophy Points:
    46
    Oikein hyvä D:
     

Share This Page