Miten tää örmelö pois koneelta?

Discussion in 'Virukset ja haittaohjelmat' started by dumppi, Jun 11, 2005.

  1. dumppi

    dumppi Regular member

    Joined:
    Mar 11, 2003
    Messages:
    232
    Likes Received:
    0
    Trophy Points:
    26
    En tiiä onko toi ees örkki mut luulisin.. Eli kun painan minkä vaan kansion päällä hiiren oikealla niin "avaa" kohdan alapuolella on kohta "javascript" ja tottakai siinä on linkki mikä on joku pornosaitti.. xD Onks tietoo miten ton sais pois..? linkki ei kuitenkaa aukee vaa tulee joku valitus että pitää ohjauspaneelista laittaa jotaa..

    Löysin etsimällä koneelta tuon linkin ja se johdatti program files kansioo ja sielä oli "johlee" niminen kansio jossa oli tää linkki ym. roskaa... poistin koko kansion.. ei kuitenkaan auttanu..

    Ad Warella ei lähteny pois, eikä spybotilla, eikä microsoftin spywarella.. eli jos joku tietää jotaa ni kertokaa kiitos.
     
  2. gerbiili

    gerbiili Active member

    Joined:
    Aug 7, 2004
    Messages:
    1,848
    Likes Received:
    0
    Trophy Points:
    66
    Sitten HiJackThis kokeiluun. Laita loki tänne. Ja jos tarkalleen muistat minkä nimisiä kansiot olivat, niin googlella oletko katsonut että onko tietoa?
     
  3. Viljam

    Viljam Regular member

    Joined:
    Apr 15, 2005
    Messages:
    363
    Likes Received:
    6
    Trophy Points:
    28
    Oletko ajanut virustorjunnan läpi...tämä oli oletuksena gerbiilillä?
     
  4. gerbiili

    gerbiili Active member

    Joined:
    Aug 7, 2004
    Messages:
    1,848
    Likes Received:
    0
    Trophy Points:
    66
    Juu, oli oletuksena kun kaveri oli kuitenkin kolmella spywaresoftalla tarkistanut :D Ei silloin kehtaa alkaa paasata virustorjunnan tärkeydestä
     
  5. dumppi

    dumppi Regular member

    Joined:
    Mar 11, 2003
    Messages:
    232
    Likes Received:
    0
    Trophy Points:
    26
    Juu mul on Norton Internet security 2005.. ei löydy viruksia.. rupeen nyt perehtymää hijackiin ja tuun taas kyselemään tyhmiä =)
     
  6. Viljam

    Viljam Regular member

    Joined:
    Apr 15, 2005
    Messages:
    363
    Likes Received:
    6
    Trophy Points:
    28
    Mulla on oletuksena että dumpin mainitsemat torj.ohj. ovat nimenomaan tarkoitettu spyware/malware torjuntaan,ja ns."vaaralliset" löytyvät jostain muualta,eli jos kunnon troijalainen yms.ilmenee ei nämä k.o. ohjelmat niitä ainakaan poista.Mutta tästä me jokainen saadaan kunnon tietoa,kun luetaan alan julkaisuja ja seurataan mm.afterdawnia.
     
  7. Viljam

    Viljam Regular member

    Joined:
    Apr 15, 2005
    Messages:
    363
    Likes Received:
    6
    Trophy Points:
    28
    dumppi ehti ennen,seurasin Montrealia.
     
  8. morsku

    morsku Guest

  9. dumppi

    dumppi Regular member

    Joined:
    Mar 11, 2003
    Messages:
    232
    Likes Received:
    0
    Trophy Points:
    26
    Täs logi, kattokaas onko jotaa ylimäärästä:

    Ainii en tiiä onko tää nyt oikeen otettu mut luulisin... =)

    Logfile of HijackThis v1.99.0
    Scan saved at 21:07:46, on 11.6.2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    D:\Norton Internet Security 2005\ISSVC.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    D:\Norton Internet Security 2005\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    D:\Daemon Tools\daemon.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    D:\Giant AntiSpyware\gcasServ.exe
    D:\SpySpot\Spybot - Search & Destroy\TeaTimer.exe
    C:\WINDOWS\system32\rundll32.exe
    D:\Giant AntiSpyware\gcasDtServ.exe
    C:\WINDOWS\system32\mmc.exe
    C:\Program Files\Common Files\Symantec Shared\NMain.exe
    D:\NORTON~1\NORTON~1\navw32.exe
    C:\WINDOWS\system32\DfrgNtfs.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
    C:\WINDOWS\system32\DfrgFat.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    D:\Asennettavat Ohjelmat\HiJackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.soneraplaza.fi/kaista
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soneraplaza.fi
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.soneraplaza.fi/kaista
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Sonera Internet
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi;<local>
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\adobe acrobat reader\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\SpySpot\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
    O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Norton Internet Security 2005\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Norton Internet Security 2005\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "D:\Daemon Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [gcasServ] "D:\Giant AntiSpyware\gcasServ.exe"
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\SpySpot\Spybot - Search & Destroy\TeaTimer.exe
    O8 - Extra context menu item: Vie Microsoft E&xceliin - res://D:\MICROS~1\Office10\EXCEL.EXE/3000
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
    O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Loogisen levyn hallinnan valvontapalvelu - Unknown - C:\WINDOWS\System32\dmadmin.exe
    O23 - Service: Tapahtumaloki - Unknown - C:\WINDOWS\system32\services.exe
    O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu - Unknown - C:\WINDOWS\System32\imapi.exe
    O23 - Service: ISSvc - Symantec Corporation - D:\Norton Internet Security 2005\ISSVC.exe
    O23 - Service: NetMeeting etätyöpöydän jakaminen - Unknown - C:\WINDOWS\System32\mnmsrvc.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service - Symantec Corporation - D:\Norton Internet Security 2005\Norton AntiVirus\navapsvc.exe
    O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Plug and Play - Unknown - C:\WINDOWS\system32\services.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Etätyöpöydän ohjeen istunnonhallinta - Unknown - C:\WINDOWS\system32\sessmgr.exe
    O23 - Service: SAVScan - Symantec Corporation - D:\Norton Internet Security 2005\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Älykortti - Unknown - C:\WINDOWS\System32\SCardSvr.exe
    O23 - Service: SmartLinkService - Unknown - slserv.exe (file missing)
    O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Resurssilokit ja -hälytykset - Unknown - C:\WINDOWS\system32\smlogsvc.exe
    O23 - Service: Aseman tilannevedos - Unknown - C:\WINDOWS\System32\vssvc.exe
    O23 - Service: WMI resurssisovitin - Unknown - C:\WINDOWS\System32\wbem\wmiapsrv.exe

     
  10. Viljam

    Viljam Regular member

    Joined:
    Apr 15, 2005
    Messages:
    363
    Likes Received:
    6
    Trophy Points:
    28
    Best,päivitys pitää muistaa;pitäisköhän lähtee baariin...
     
  11. Viljam

    Viljam Regular member

    Joined:
    Apr 15, 2005
    Messages:
    363
    Likes Received:
    6
    Trophy Points:
    28
    dumppihan taitaa olla linjalla.Ota morsku kantaa tai sitten muut gurut.
     
  12. morsku

    morsku Guest

  13. dumppi

    dumppi Regular member

    Joined:
    Mar 11, 2003
    Messages:
    232
    Likes Received:
    0
    Trophy Points:
    26
    Siinä:

    Logfile of HijackThis v1.99.1
    Scan saved at 22:29:00, on 11.6.2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    D:\Norton Internet Security 2005\ISSVC.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    D:\Norton Internet Security 2005\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    D:\Daemon Tools\daemon.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    D:\Giant AntiSpyware\gcasServ.exe
    D:\SpySpot\Spybot - Search & Destroy\TeaTimer.exe
    C:\WINDOWS\system32\rundll32.exe
    D:\Giant AntiSpyware\gcasDtServ.exe
    C:\Program Files\Common Files\Symantec Shared\NMain.exe
    D:\NORTON~1\NORTON~1\navw32.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    D:\DC ++ RevConnect\RevConnect\DCPlusPlus.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
    D:\HiJackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.soneraplaza.fi/kaista
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soneraplaza.fi
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.soneraplaza.fi/kaista
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Sonera Internet
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi;<local>
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\adobe acrobat reader\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\SpySpot\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
    O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Norton Internet Security 2005\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Norton Internet Security 2005\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "D:\Daemon Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [gcasServ] "D:\Giant AntiSpyware\gcasServ.exe"
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\SpySpot\Spybot - Search & Destroy\TeaTimer.exe
    O8 - Extra context menu item: Vie Microsoft E&xceliin - res://D:\MICROS~1\Office10\EXCEL.EXE/3000
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: ISSvc (ISSVC) - Symantec Corporation - D:\Norton Internet Security 2005\ISSVC.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - D:\Norton Internet Security 2005\Norton AntiVirus\navapsvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: SAVScan - Symantec Corporation - D:\Norton Internet Security 2005\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

     
  14. morsku

    morsku Guest

    Last edited by a moderator: Jun 12, 2005
  15. dumppi

    dumppi Regular member

    Joined:
    Mar 11, 2003
    Messages:
    232
    Likes Received:
    0
    Trophy Points:
    26
    Jep eScan päivitelty ja ajettu läpi mut ei löytyny mitää hälyttävää..

    Googlella en löytäny tästä mitää.
    Rupee jo ihmetyttämään!

    Eli edelleen jos jollain ois ratkaisu ni hyvä ois =)

     
  16. morsku

    morsku Guest

    Vähän epäilyttävä toi johlee ohjelma ootko itse sen ladannut? :D
    http://www.johlee.co.uk/ mutta kun menit poistamaan kansion.. löytyykö lisää poista sovelluksesta?
     
    Last edited by a moderator: Jun 12, 2005
  17. anak

    anak Member

    Joined:
    Apr 2, 2004
    Messages:
    46
    Likes Received:
    0
    Trophy Points:
    16
    Jep ajattelin tähän viel lisätä ku en uutta aihetta jaksanu alkaa väsää.
    Löyty ton eScan perusteella tulee aika paljon noit viruksia poistaakose mitään niist vai pitääkö kaikki poistaa ite ?? paitsi et tossa kyll lukee et "Action taken - File deleted" et poistaako se noi selvimmät?

    Ja sitt jos on noit tartunnan saaneit tiedostoja uskaltaako niitä poistaa että ne ei mitenkään aiheuta haittaa windowsin toiminnalle?
     
  18. Viljam

    Viljam Regular member

    Joined:
    Apr 15, 2005
    Messages:
    363
    Likes Received:
    6
    Trophy Points:
    28
    Kyllä se poistaa,kun siinä lukee file deleted;sehän siinä paras pointti onkin verrattuna muihin on-line scannereihin.Tartunnan saaneita tiedostoja...jaa,mulla on joskus ollut esim.system volume informationissa spywareita ja sen tietyn palautuspisteen olen poistanut käsin.
     
  19. anak

    anak Member

    Joined:
    Apr 2, 2004
    Messages:
    46
    Likes Received:
    0
    Trophy Points:
    16
    jep kiitos vaa nimittäin noit trojjalaisia löyty yllättävän paljon selittäen sen minkä takia kone vähä hidastellu viime aikana pitää ottaa logi ylös ja katella jos vois noit muitaki poistaa sitte
     
  20. dumppi

    dumppi Regular member

    Joined:
    Mar 11, 2003
    Messages:
    232
    Likes Received:
    0
    Trophy Points:
    26
    En oo Johleeta ite ladannu, eikä sitä löydy lisää/poista paikasta.
     

Share This Page