Kone takkuilee. HJT-Logi

Discussion in 'Virukset ja haittaohjelmat - HijackThis -logit' started by Tikkuneq, Dec 8, 2006.

Thread Status:
Not open for further replies.
  1. Tikkuneq

    Tikkuneq Regular member

    Joined:
    Jan 9, 2006
    Messages:
    585
    Likes Received:
    0
    Trophy Points:
    26
    Elikkäs kone nyt on aikas hidas. Esim. nettiin menee aika hitaasti ja ku
    menee Omaan Tietokoneeseen niin se semmonen "keltanen lamppu" tulee heiluun aina vähäks aikaa siihen. Ja muutenkin on hyvä tehä tarkastus onko pöpöjä.

    Voiko noista Error Safe yms. semmosista sivuista tulla jotain pöpöi?
    Ja onko Spyware Blaster hyvä käyttää ja viekö se tehoja? Entä joku haittaohjelmien poistokalu? Ja kaiken lisäks mulla on kaks Javaa Lisää ja Poista valikossa: 5.0 Update 4 ja Update 9.

    Logfile of HijackThis v1.99.1
    Scan saved at 14:49:03, on 8.12.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0011)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\brsvc01a.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\brss01a.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Norman\bin\ZLH.EXE
    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\Program Files\Brother\ControlCenter2\brctrcen.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
    C:\Program Files\Winamp\winampa.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\Norman\Bin\Zanda.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Norman\Nvc\BIN\NIP.EXE
    C:\Norman\Nvc\BIN\NVCSCHED.EXE
    C:\Norman\Nvc\BIN\nipsvc.exe
    C:\Norman\bin\NJEEVES.EXE
    C:\Norman\Nvc\bin\nvcoas.exe
    C:\WINDOWS\System32\alg.exe
    C:\Documents and Settings\Tikki\Omat tiedostot\mIRC\mirc.exe
    C:\Norman\Nvc\bin\cclaw.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\HJT\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl05a\BrStDvPt.exe
    O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1163540775687
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe
    O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE
    O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\Bin\Zanda.exe
    O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe
    O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
     
  2. fixeri

    fixeri Regular member

    Joined:
    Oct 5, 2006
    Messages:
    381
    Likes Received:
    0
    Trophy Points:
    26
    Ajaseppas tuo läpi ja lähetä sen raportti.

    Ohje AVG Anti-Spyware 7.5:n käyttöön
    Huom! Tässä ohjeessa sammutetaan tuo reaaliaikasuojaus (Shield). Näin vältetään tilanteet joissa suojaus estäisi esim HijackThis työkalun toimintaa.

    Tallenna nämä ohjeet tekstitiedostoon tai tulosta nämä, muuten et pääse niihin käsiksi vikasietotilasta

    Lataa AVG Anti-Spyware 7.5 http://www.ewido.net/en/download/
    ja tallenna ohjelma työpöydällesi.
    • Kun olet ladannut ohjelman, kaksoisklikkaa asennuohjelman pikakuvaketta työpöydälläsi, asennus alkaa.
    • Asennuksen jälkeen täytyy ohjelma käynnistää ja sen tunnisteet päivittää.
    • Käynnistä AVG Anti-Spyware.
    • Klikkaa "Update" kuvaketta päävalikossa. Sen jälkeen klikkaa "Update now" painiketta.

    o Sitten klikkaa "Start Update" kuvaketta jolloin päivitys alkaa.

    • Kun päivitykset on ladattu, klikkaa "Scanner" kuvaketta ikkunan ylälaidassa. Valitse sitten "Settings" välilehti.
    • Kun "Settings" valikko on auennut, klikkaa "Recommended actions" ja sitten valitse "Quarantine".
    • Sitten "Reports" valikon alta:

    o Laita täppi kohtaan "Automatically generate report after every scan"
    o Ota täppi pois kohdasta"Only if threats were found"

    • Sitten klikkaa "Shield" kuvaketta ikkunan ylälaidassa
    • "Resident shield is", muuta tila active:sta inactive:ksi
    • Sulje ohjelma, ÄLÄ skannaa vielä.
    Käynnistä koneesi vikasietotilaan,

    sammuta ja käynnistä
    käynnistyksen yhteydessä naputtele F8
    valitse nuoli näppäimellä vikasietotila
    paina enter ja enter

    HUOM! Älä käytä muita ohjelmia AVG skannauksen aikana, tämä saattaa häiritä skannausta.
    • Kun vikasietotilassa, käynnistä AVG Anti-Spyware.
    • Klikkaa "Scanner" kuvaketta ikkunan ylälaidassa ja valitse "Scan" välilehti. Sitten klikkaa "Complete System Scan".
    • Ewido aloittaa nyt tietokoneen skannaamisen, ole kärsivällinen sillä skannaus vie aikaa.

    Kun skannaus on valmis:
    TÄRKEÄÄ : Älä klikkaa "Save Scan Report" ennen kuin klikkaat "Apply all Actions"
    • Varmistu, että Set all elements to: näyttää Quarantine (1), jos ei, klikkaa linkkiä ja valitse Quarantine popup-valikosta.
    • Sinulta kysytään mitä tehdä jos infektioita löytyi, valitse silloin "Apply all actions"

    • Sitten klikkaa "Reports" kuvaketta ohjelma yläosasta.
    • Klikkaa "Save report as" painiketta ikkunan vasemmassa alalaidassa ja tallenna raportti työpöydälle.

    • Sulje ohjelma, käynnistä kone normaalisti ja lähetä AVG:n raportti viestikejuusi.
     
  3. Tikkuneq

    Tikkuneq Regular member

    Joined:
    Jan 9, 2006
    Messages:
    585
    Likes Received:
    0
    Trophy Points:
    26
    Joo eli tehtyä tuli:

    ---------------------------------------------------------
    AVG Anti-Spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 19:29:42 8.12.2006

    + Scan result:



    :mozilla.156:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
    :mozilla.157:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
    :mozilla.158:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
    :mozilla.159:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
    :mozilla.160:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
    :mozilla.257:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
    C:\Documents and Settings\Tikki\Cookies\tikki@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
    C:\Documents and Settings\Ville\Cookies\ville@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
    :mozilla.73:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
    :mozilla.74:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
    :mozilla.21:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
    :mozilla.22:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
    C:\Documents and Settings\Tikki\Cookies\tikki@adtech[2].txt -> TrackingCookie.Adtech : No action taken.
    :mozilla.125:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
    :mozilla.126:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
    C:\Documents and Settings\Tikki\Cookies\tikki@advertising[1].txt -> TrackingCookie.Advertising : No action taken.
    :mozilla.58:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
    C:\Documents and Settings\Tikki\Cookies\tikki@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
    C:\Documents and Settings\Ville\Cookies\ville@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
    :mozilla.205:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
    C:\Documents and Settings\Tikki\Cookies\tikki@burstnet[2].txt -> TrackingCookie.Burstnet : No action taken.
    C:\Documents and Settings\Tikki\Cookies\tikki@www.burstnet[1].txt -> TrackingCookie.Burstnet : No action taken.
    :mozilla.196:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
    :mozilla.197:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
    :mozilla.198:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
    :mozilla.199:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
    :mozilla.76:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Clickhype : No action taken.
    :mozilla.77:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Clickhype : No action taken.
    :mozilla.10:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
    :mozilla.7:C:\Documents and Settings\Iskä ja Äiti\Application Data\Mozilla\Firefox\Profiles\nl5dnz58.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
    C:\Documents and Settings\Tikki\Cookies\tikki@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
    C:\Documents and Settings\Ville\Cookies\ville@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
    :mozilla.119:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
    :mozilla.120:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
    :mozilla.121:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
    :mozilla.122:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
    :mozilla.123:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
    :mozilla.124:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
    :mozilla.100:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
    :mozilla.223:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
    :mozilla.224:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
    :mozilla.37:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
    :mozilla.38:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
    :mozilla.25:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Ivwbox : No action taken.
    :mozilla.258:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Overture : No action taken.
    :mozilla.164:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
    :mozilla.165:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
    :mozilla.166:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
    :mozilla.167:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
    :mozilla.225:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
    :mozilla.226:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
    :mozilla.227:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
    :mozilla.228:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
    :mozilla.209:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
    :mozilla.210:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
    :mozilla.211:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
    :mozilla.212:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
    :mozilla.213:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
    :mozilla.147:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Sitestat : No action taken.
    :mozilla.148:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Sitestat : No action taken.
    :mozilla.136:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
    :mozilla.265:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
    :mozilla.266:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
    :mozilla.54:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
    :mozilla.55:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
    :mozilla.56:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
    :mozilla.57:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
    :mozilla.89:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
    :mozilla.90:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
    :mozilla.91:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
    :mozilla.92:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
    :mozilla.93:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
    :mozilla.144:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Trafic : No action taken.
    :mozilla.195:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
    :mozilla.208:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Valueclick : No action taken.
    :mozilla.133:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Weborama : No action taken.
    :mozilla.259:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Webtrendslive : No action taken.
    C:\Documents and Settings\Tikki\Cookies\tikki@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : No action taken.
    :mozilla.69:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
    :mozilla.70:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
    :mozilla.71:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
    :mozilla.86:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
    :mozilla.87:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
    :mozilla.88:C:\Documents and Settings\Ville\Application Data\Mozilla\Firefox\Profiles\h8b92qn7.default\cookies.txt -> TrackingCookie.Zedo : No action taken.


    ::Report end

    Mitäs sitte?
     
  4. Hujo

    Hujo Guest

    lataa tuolta http://www.ccleaner.com/download/builds.aspx
    CCleaner v1.34.407 - Basic, joka EI sisällä Yahoo toolbaria !

    laita asetukset näin:
    Valinnat --> Lisäasetukset --> Ota ruksi pois kohdasta Poista vain yli 48 tuntia vanhat tilapäistiedostot.

    aja puhistaja > tutki > putsaa oikea alakulma
    aja virheet > etsi rekisteri virheitä > Korjaa rekisteri virheet.
     
  5. Tikkuneq

    Tikkuneq Regular member

    Joined:
    Jan 9, 2006
    Messages:
    585
    Likes Received:
    0
    Trophy Points:
    26
    Joo hommat tehty, tossa vielä uusi HJT-Logi

    Logfile of HijackThis v1.99.1
    Scan saved at 23:17:41, on 9.12.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0011)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\brsvc01a.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\brss01a.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\Norman\Bin\Zanda.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Norman\Nvc\BIN\NVCSCHED.EXE
    C:\Norman\Nvc\bin\nvcoas.exe
    C:\Norman\bin\NJEEVES.EXE
    C:\Norman\Nvc\BIN\nipsvc.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Norman\bin\ZLH.EXE
    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\Program Files\Brother\ControlCenter2\brctrcen.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Norman\Nvc\BIN\NIP.EXE
    C:\Norman\Nvc\bin\cclaw.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Documents and Settings\Tikki\Omat tiedostot\mIRC\mirc.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Norman\bin\ZLH.EXE
    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\Program Files\Brother\ControlCenter2\brctrcen.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Norman\Nvc\BIN\NIP.EXE
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Norman\Nvc\bin\cclaw.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Documents and Settings\Ville\Omat tiedostot\mIRC\mirc.exe
    C:\Program Files\Brother\Brmfcmon\brmfcwnd.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\HJT\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    F2 - REG:system.ini: Shell=explorer.exe ,svchost.exe
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl05a\BrStDvPt.exe
    O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1163540775687
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe
    O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE
    O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\Bin\Zanda.exe
    O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe
    O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


    Onko kaikki nyt OK?
     
  6. Hujo

    Hujo Guest

    Avg Anti-spyware

    laita asennus näin

    • Kun päivitykset on ladattu, klikkaa "Scanner" kuvaketta ikkunan ylälaidassa. Valitse sitten "Settings" välilehti.
    • Kun "Settings" valikko on auennut, klikkaa "Recommended actions" ja sitten valitse "Quarantine".


    scannaa uudestaan
     
  7. Tikkuneq

    Tikkuneq Regular member

    Joined:
    Jan 9, 2006
    Messages:
    585
    Likes Received:
    0
    Trophy Points:
    26
    On jo. Mitäs sitten tehdään :D
     
  8. Hujo

    Hujo Guest

    Lataa SDFix by AndyManchesta http://downloads.andymanchesta.com/RemovalTools/SDFix.zip ja tallenna se työpöydällesi.

    Käynnistä koneesi vikasietotilaan ja valitse tavallinen käyttäjätilisi:
    • Käynnistä tietokone
    • Kun kuulet koneen piippaavan, paina F8, kuitenkin ennen Windowsin logon esiintuloa
    • Seuraavaksi pitäisi ilmestyä valikko
    • Valitse valikosta vikasietotila.

    • Kun vikasietotilassa, pura tiedoston SDFix.zip sisältö (SDFix kansio) työpöydällesi. Työpöydälle pitäisi ilmestyä kansio nimeltä SDFix.
    • Avaa SDFix-kansio ja tuplaklikkaa tiedostoa RunThis.bat käynnistääksesi ohjelman.
    • Paina Y käynnistääksesi skriptin.
    • Työkalu puhdistaa troijalaisen palvelut ja tekee myös joitakin korjauksia rekisteriin. Lopuksi se pyytää käynnistämään koneen uudelleen, "Press any key to Reboot".
    • Paina mitä tahansa näppäintä ja kone käynnistyy uudelleen.
    • Käynnistyminen kestää normaalia kauemmin sillä SDFix puhdistaa konetta.
    • Kun kone on käynnistynyt ja työpöytä latautunut, SDFix kertoo että puhdistus on suoritettu, "Finished".
    • Paina sitten mitä tahansa näppäintä sulkeaksesi skriptin ja ladataksesi pikakuvakkeet työpöydälle.
    • Lopuksi avaa SDFix kansio (työpöydällä) ja kopioi & liitä tiedoston Report.txt sisältö viestiketjuusi uuden HijackThis lokin kera.
     
  9. Tikkuneq

    Tikkuneq Regular member

    Joined:
    Jan 9, 2006
    Messages:
    585
    Likes Received:
    0
    Trophy Points:
    26
    Tehty


    SDFix: Version 1.46
    ****************

    ma 11.12.2006 - 19:08:37,46

    Microsoft Windows XP [versio 5.1.2600]

    Running From: C:\DOCUME~1\Tikki\TYPYT~1\SDFix

    Stage One - Safe Mode

    Checking For Trojan Services...

    Service Name:


    File Path:



    Starting Registry Repairs...

    Restoring Default Hosts File...

    Stage One Complete

    Rebooting...

    Stage Two - Normal Mode

    Checking For Malware:
    --------------------


    Backing Up and Removing any Files Found...

    Final Check:

    Services:
    ---------


    Authorized Applications Key Export:

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019"
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
    "C:\\Program Files\\DC++\\DCPlusPlus.exe"="C:\\Program Files\\DC++\\DCPlusPlus.exe:*:Enabled:DC++"
    "C:\\Program Files\\BitComet\\BitComet.exe"="C:\\Program Files\\BitComet\\BitComet.exe:*:Enabled:BitComet"
    "C:\\Documents and Settings\\Ville\\Omat tiedostot\\mIRC\\mirc.exe"="C:\\Documents and Settings\\Ville\\Omat tiedostot\\mIRC\\mirc.exe:*:Enabled:mIRC"
    "C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Mozilla Firefox"
    "C:\\Norman\\Bin\\Niu.exe"="C:\\Norman\\Bin\\Niu.exe:*:Enabled:Internet-päivitys"
    "C:\\Program Files\\Winamp\\winamp.exe"="C:\\Program Files\\Winamp\\winamp.exe:*:Enabled:Winamp"
    "C:\\Program Files\\Futuremark\\3DMark03\\3DMark03.exe"="C:\\Program Files\\Futuremark\\3DMark03\\3DMark03.exe:*:Enabled:3DMark03"
    "C:\\Documents and Settings\\Tikki\\Omat tiedostot\\mIRC\\mirc.exe"="C:\\Documents and Settings\\Tikki\\Omat tiedostot\\mIRC\\mirc.exe:*:Enabled:mIRC"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000"


    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019"
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000"


    Files:
    ------

    Backups Folder: - C:\DOCUME~1\Tikki\TYPYT~1\SDFix\backups\backups.zip

    Checking for files with Hidden Attributes:

    C:\Program Files\Common Files\Adobe\ESD\DLMCleanup.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\WINDOWS\system32\cdplayer.exe.manifest
    C:\WINDOWS\system32\logonui.exe.manifest
    C:\IO.SYS
    C:\MSDOS.SYS
    C:\pagefile.sys

    FINISHED!



    Logfile of HijackThis v1.99.1
    Scan saved at 19:13:42, on 11.12.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0011)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\brsvc01a.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\brss01a.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\Norman\Bin\Zanda.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Norman\bin\NJEEVES.EXE
    C:\Norman\Nvc\BIN\NVCSCHED.EXE
    C:\Norman\Nvc\BIN\nipsvc.exe
    C:\Norman\Nvc\bin\nvcoas.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\notepad.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Norman\bin\ZLH.EXE
    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\Program Files\Brother\ControlCenter2\brctrcen.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Norman\Nvc\bin\cclaw.exe
    C:\Norman\Nvc\BIN\NIP.EXE
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\HJT\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl05a\BrStDvPt.exe
    O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1163540775687
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe
    O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE
    O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\Bin\Zanda.exe
    O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe
    O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    Tarkottaako toi "Restoring Default Hosts File... " minkä toi SDfix teki, että se poisti mun HOSTS-tiedoston, minkä oon itte laittanu?

    EDIT: Nyt windows tekee sen "Uusi laite löydetty", mutta ei löydä ajureita. Sitten menee laitehallintaan: Sielä on Muut Laitteet ja siinä ku sen avaa niin sielä on "Tuntematon laite".

    Eli poistikohan toi SDFix jonkun ajurin?
     
    Last edited: Dec 11, 2006
  10. Hujo

    Hujo Guest

    Nimeäs tuo uudelleen
    C:\HJT\HijackThis.exe Skanneriksi

    ja uusi loki

    niin se poisti kun tunnisti örkiksi.
    F2 - REG:system.ini: Shell=explorer.exe ,svchost.exe
     
    Last edited by a moderator: Dec 11, 2006
  11. Tikkuneq

    Tikkuneq Regular member

    Joined:
    Jan 9, 2006
    Messages:
    585
    Likes Received:
    0
    Trophy Points:
    26
    Logfile of HijackThis v1.99.1
    Scan saved at 21:23:17, on 11.12.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0011)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\brsvc01a.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\brss01a.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\Norman\Bin\Zanda.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Norman\Nvc\BIN\NVCSCHED.EXE
    C:\Norman\Nvc\BIN\nipsvc.exe
    C:\Norman\bin\NJEEVES.EXE
    C:\Norman\Nvc\bin\nvcoas.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Norman\bin\ZLH.EXE
    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\Program Files\Brother\ControlCenter2\brctrcen.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Norman\Nvc\bin\cclaw.exe
    C:\Norman\Nvc\BIN\NIP.EXE
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Documents and Settings\Tikki\Omat tiedostot\mIRC\mirc.exe
    C:\Program Files\BitComet\BitComet.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Norman\bin\ZLH.EXE
    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\Program Files\Brother\ControlCenter2\brctrcen.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Norman\Nvc\BIN\NIP.EXE
    C:\Norman\Nvc\bin\cclaw.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Documents and Settings\Ville\Omat tiedostot\mIRC\mirc.exe
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\HJT\Skanneri.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl05a\BrStDvPt.exe
    O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1163540775687
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe
    O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE
    O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\Bin\Zanda.exe
    O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe
    O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


    Tossa logi

    Mutta edelleen tuntuu netissä olevan jotain häiskää.

    Ei aina ekalla kerralla mee vaan joutuu refreshaa selaimella. Ja todella hitaasti toimii esim. Hotmail (ei mene sivulle ollenkaan).

    Ja voiko jotenkin estää nuo ErrorSafet ja muut semmoset niin että niitä ei hyppisi eteen?

    Ja pitäisikö se AVG:n scannaus tehdä uudestaan?
     
  12. Hujo

    Hujo Guest

    Lataa SmitfraudFix (c) S!Ri http://siri.urz.free.fr/Fix/SmitfraudFix.zip
    Pura sisältö (kansio nimeltä SmitfraudFix) työpöydällesi:

    Avaa SmitfraudFix kansio ja tupla-klikkaa smitfraudfix.cmd
    Valitse optio #1 - Search kirjoittamalla 1 ja painamalla "Enter"; tekstitiedosto avautuu, joka listaa tarttuneet tiedostot (jos olemassa).
    Postita tämän tekstitiedoston sisältö viestiketjuusi.

    Huomaa : process.exe filun tunnistaa jotkut Anti-virus ohjelmat (AntiVir, Dr.Web, Kaspersky) "Haittakaluna"; se ei ole virus, vaan ohjelma joka pysäyttää prosesseja. A/V ohjelmat eivät pysty tunnistamaan hyvän ja pahan käytön tälläisten ohjelmian väliltä, silloin ne saattavat varoittaa käyttäjää.


    Katotaan tää ensin ennen kuin ajetaan Avg uudestaan et ollut laitanut niitä menemään karanteeniin katso ohje vielä siintä
     
  13. Tikkuneq

    Tikkuneq Regular member

    Joined:
    Jan 9, 2006
    Messages:
    585
    Likes Received:
    0
    Trophy Points:
    26
    Joo kesti vähän mutta tässä olis:

    SmitFraudFix v2.130

    Scan done at 12:05:57,75, to 14.12.2006
    Run from C:\Documents and Settings\Tikki\Ty”p”yt„\SmitfraudFix\SmitfraudFix
    OS: Microsoft Windows XP [versio 5.1.2600] - Windows_NT
    The filesystem type is NTFS
    Fix run in normal mode

    »»»»»»»»»»»»»»»»»»»»»»»» C:\


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Tikki


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Tikki\Application Data


    »»»»»»»»»»»»»»»»»»»»»»»» Start Menu


    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Tikki\Suosikit


    »»»»»»»»»»»»»»»»»»»»»»»» Desktop


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


    »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


    »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
    "Source"="About:Home"
    "SubscribedURL"="About:Home"
    "FriendlyName"="Nykyinen kotisivu"


    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=""


    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "System"=""


    »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32


    »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


    »»»»»»»»»»»»»»»»»»»»»»»» End

     
  14. Hujo

    Hujo Guest

    Kyllä tee se uudestaan

    aja vielä tuollakin

    Escan

    Ohjeet tuolla sivulla.
    http://koti.mbnet.fi/pattaya1/escanmwav.htm
    lataa tuosta
    http://www.spywareinfo.dk/download/mwav.exe
    päivitä tuosta
    http://koti.mbnet.fi/pattaya1/lataus/Mwav.bat
    laita täpit merkkauksien mukaan
    http://koti.mbnet.fi/pattaya1/eScan6.jpg

    scannaa

    jos ala luukkuun tulee jotain niin kopioi se näin:
    Käytä komentoa Ctrl+A.
    Kopioi rivit komennolla Ctrl+C.
    Liitä rivit komennolla Ctrl+V.

    Laita virus log tänne.
     
    Last edited by a moderator: Dec 14, 2006
Thread Status:
Not open for further replies.

Share This Page