Elikkäs, joillain sivuilla missä on javasovellus itse sivun sisässä, on ongelmia (esim. aapeli). Sivu ei välttämättä lataudu kunnolla (kaikki ei näy) ja jos avaan esim. mesekeskustelun javasovelluksen ollessa auki, niin mozilla sulkeutuu automaattisesti. Apuja? Tässä loki: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 17:17:13, on 17.8.2008 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18000) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\RtHDVCpl.exe C:\Program Files\Acer\Empowering Technology\SysMonitor.exe C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Users\Tommi\Program Files\DNA\btdna.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Hamachi\hamachi.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe C:\Windows\system32\conime.exe C:\Program Files\Last.fm\LastFM.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Tommi\Program Files\BitTorrent\BitTorrent.exe C:\Program Files\Acer\Empowering Technology\NotificationCenter\Framework.NotificationCenter.exe C:\Windows\system32\SearchFilterHost.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://phnet.fi/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Adobe PDF Reader -linkkiavustaja - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Burn4Free Toolbar Helper - {D187A56B-A33F-4CBE-9D77-459FC0BAE012} - C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file) O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: Burn4Free Toolbar - {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Program Files\Acer\Empowering Technology\SysMonitor.exe O4 - HKLM\..\Run: [EmpoweringTechnology] C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe boot O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe O4 - HKLM\..\Run: [PCMMediaSharing] C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe O4 - HKLM\..\Run: [Malwarebytes Anti-Malware Reboot] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Tommi\Program Files\DNA\btdna.exe" O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Paikallinen palvelu') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'Paikallinen palvelu') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Verkkopalvelu') O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe O8 - Extra context menu item: V&ie Microsoft Exceliin - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll O9 - Extra button: Lähetä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Läh&etä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O13 - Gopher Prefix: O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: SoundMovieServer - SoundMovieServer - C:\Windows\system32\snmvtsvc.exe -- End of file - 8691 bytes
scannaa hjt:llä merkkaa paina Fix checked O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file) O4 - HKLM\..\Run: [Malwarebytes Anti-Malware Reboot] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" =================
Hoidettu. Tarvitseeko tehdä vielä jotain muuta, kun ongelma näyttäisi pysyneen (ainakaan sivut eivät näy kunnolla)?
1.Lataa combofix.exe työpöydällesi yhdestä linkistä: combofix1 combofix2 2. Tuplaklikkaa combofix.exe tiedostoa ja seuraa ohjeistuksia. 3. Kun työkalu on valmis, se tuottaa lokin. Lähetä tämä loki viesti ketjuusi. Huom! Älä klikkaile combofixin ikkunaa käytön aikana. Tämä saattaa aiheuttaa ohjelman jumiutumisen. ============ ajas tuo Malwarebytes' Anti-Malware sehän sulla on koneella. Päivitä ensin =========== Mitä siintä sivun aukeemisesta uupuu kun ei näy kunnolla..
http://img65.imageshack.us/my.php?image=nimetnth8.jpg Tässä aika selvä esimerkki siitä. Jos tuossa samalla avaisin mesekeskustelun, ja takaisin tuon ikkunan, niin mozilla sulkeutuisi. Ja tässäpä tämä combofix-loki: ComboFix 08-08-17.05 - Tommi 2008-08-18 22:28:30.5 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1035.18.1721 [GMT 3:00] Running from: C:\Users\Tommi\Downloads\ComboFix.exe * Resident AV is active . (((((((((((((((((((((((((((((((((((((( Muut poistot )))))))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Users\Tommi\AppData\Roaming\macromedia\Flash Player\#SharedObjects\FNW65KNB\interclick.com C:\Users\Tommi\AppData\Roaming\macromedia\Flash Player\#SharedObjects\FNW65KNB\interclick.com\ud.sol C:\Users\Tommi\AppData\Roaming\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com C:\Users\Tommi\AppData\Roaming\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol . ((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-07-18 to 2008-08-18 ))))))))))))))))) . 2008-08-17 17:16 . 2008-08-17 17:16 <KANSIO> d-------- C:\Users\Tommi\AppData\Roaming\F-Secure 2008-08-15 19:48 . 2008-08-15 19:48 <KANSIO> d-------- C:\Program Files\YouTube Downloader 2008-08-14 22:17 . 2008-07-16 04:32 2,048 --a------ C:\Windows\System32\tzres.dll 2008-08-14 20:26 . 2008-08-14 20:26 <KANSIO> d-------- C:\Users\All Users\F-Secure 2008-08-14 20:26 . 2008-08-14 20:26 <KANSIO> d-------- C:\ProgramData\F-Secure 2008-08-14 20:26 . 2007-05-25 16:15 572,784 --a------ C:\Windows\System32\msvcp50.dll 2008-08-14 20:26 . 2008-08-14 20:44 60,064 --a------ C:\Windows\System32\drivers\fsdfw.sys 2008-08-14 20:26 . 2007-05-25 16:09 35,024 --a------ C:\Windows\System32\drivers\fses.sys 2008-08-14 20:25 . 2008-08-14 22:21 <KANSIO> d-------- C:\Program Files\F-Secure Internet Security 2008-08-14 20:19 . 2008-08-14 20:24 <KANSIO> d-------- C:\Users\All Users\fssg 2008-08-14 20:19 . 2008-08-14 20:24 <KANSIO> d-------- C:\ProgramData\fssg 2008-08-14 07:55 . 2008-06-27 04:55 1,383,424 --a------ C:\Windows\System32\mshtml.tlb 2008-08-14 07:55 . 2008-06-27 07:15 827,392 --a------ C:\Windows\System32\wininet.dll 2008-08-14 07:55 . 2008-06-19 06:31 361,984 --a------ C:\Windows\System32\IPSECSVC.DLL 2008-08-14 07:55 . 2008-04-18 08:48 269,312 --a------ C:\Windows\System32\es.dll 2008-08-14 07:54 . 2008-04-10 08:12 738,304 --a------ C:\Windows\System32\inetcomm.dll 2008-08-11 19:17 . 2008-08-11 19:17 <KANSIO> d-------- C:\Program Files\Xilisoft 2008-08-10 21:14 . 2008-08-10 21:16 <KANSIO> d-------- C:\Program Files\AimOne_AlltoMP3 2008-08-10 20:44 . 2008-08-10 20:44 <KANSIO> d-------- C:\Program Files\QuickTime 2008-08-01 21:53 . 2008-08-01 21:53 <KANSIO> d-------- C:\Program Files\Burn4Free Toolbar 2008-08-01 21:53 . 2008-08-01 22:12 <KANSIO> d-------- C:\Program Files\Burn4Free 2008-08-01 21:53 . 2008-08-01 21:53 232,075 --a------ C:\Windows\Burn4Free_Toolbar_Uninstaller_6675.exe 2008-07-31 22:21 . 2008-07-31 22:21 <KANSIO> d-------- C:\Users\All Users\eMule 2008-07-31 22:21 . 2008-07-31 22:21 <KANSIO> d-------- C:\ProgramData\eMule 2008-07-31 22:21 . 2008-07-31 22:21 <KANSIO> d-------- C:\Program Files\eMule 2008-07-31 00:50 . 2008-07-31 00:50 <KANSIO> d-------- C:\Program Files\Smart Projects 2008-07-29 16:32 . 2008-07-29 16:32 <KANSIO> d-------- C:\Program Files\TagRename 2008-07-28 00:02 . 2008-07-28 02:14 <KANSIO> d-------- C:\Users\Tommi\AppData\Roaming\uTorrent 2008-07-28 00:02 . 2008-07-28 00:02 <KANSIO> d-------- C:\Program Files\uTorrent 2008-07-26 18:27 . 2008-07-26 18:28 <KANSIO> d-------- C:\Users\Tommi\OngameNetwork 2008-07-19 22:49 . 2008-07-19 22:49 50 --a------ C:\Windows\MegaManager.INI 2008-07-18 18:24 . 2008-07-18 18:25 <KANSIO> d-------- C:\Program Files\Hamachi 2008-07-18 18:24 . 2008-07-18 18:24 25,280 --a------ C:\Windows\System32\drivers\hamachi.sys . (((((((((((((((((((((((((((((((((((( Find3M-raportti )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-08-18 19:32 --------- d-----w C:\Users\Tommi\AppData\Roaming\BitTorrent 2008-08-18 19:31 --------- d-----w C:\Users\Tommi\AppData\Roaming\Hamachi 2008-08-18 19:24 --------- d-----w C:\Users\Tommi\AppData\Roaming\DNA 2008-08-17 15:45 --------- d-----w C:\ProgramData\Messenger Plus! 2008-08-17 08:58 --------- d-----w C:\Users\Tommi\AppData\Roaming\mIRC 2008-08-16 23:22 --------- d-----w C:\Program Files\mIRC 2008-08-16 20:51 --------- d-----w C:\ProgramData\Soulseek 2008-08-14 19:18 --------- d-----w C:\ProgramData\Microsoft Help 2008-08-14 17:24 --------- d-----w C:\ProgramData\McAfee 2008-08-14 17:21 --------- d-----w C:\ProgramData\SiteAdvisor 2008-08-10 18:08 --------- d-----w C:\Users\Tommi\AppData\Roaming\dvdcss 2008-08-10 17:44 --------- d-----w C:\Program Files\ImTOO 2008-08-03 13:50 --------- d-----w C:\Program Files\DC++ 2008-07-19 19:49 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-07-17 19:13 --------- d-----w C:\Program Files\Java 2008-07-17 19:10 --------- d-----w C:\Program Files\Common Files\Java 2008-07-17 14:47 --------- d-----w C:\Program Files\B2BPOKER 2008-07-16 07:20 --------- d-----w C:\ProgramData\NOS 2008-07-16 07:20 --------- d-----w C:\Program Files\NOS 2008-07-15 17:34 --------- d-----w C:\Program Files\Common Files\Adobe 2008-07-15 15:04 --------- d-----w C:\Program Files\activePDF 2008-07-13 23:19 --------- d-----w C:\Program Files\Messenger Plus! Live 2008-07-12 16:45 --------- d-----w C:\Program Files\Bytescout XLS Viewer 2008-07-08 22:01 --------- d-----w C:\Users\Tommi\AppData\Roaming\DivX 2008-07-08 21:59 --------- d-----w C:\Program Files\Mozilla Thunderbird 2008-07-08 21:59 --------- d-----w C:\Program Files\DivX 2008-07-08 21:59 --------- d-----w C:\Program Files\Common Files\PX Storage Engine 2008-07-08 21:42 --------- d-----w C:\Program Files\avisplit 2008-07-08 21:05 --------- d-----w C:\Program Files\SoulseekNS 2008-07-08 10:10 --------- d-----w C:\Program Files\Windows Live Safety Center 2008-07-07 00:03 --------- d-----w C:\ProgramData\Spybot - Search & Destroy 2008-07-06 22:54 --------- d-----w C:\Program Files\Trend Micro 2008-07-06 22:23 --------- d-----w C:\Program Files\EMCO Malware Destroyer 2008-07-06 22:20 --------- d-----w C:\Users\Tommi\AppData\Roaming\Malwarebytes 2008-07-06 22:20 --------- d-----w C:\ProgramData\Malwarebytes 2008-07-06 21:55 --------- d-----w C:\Program Files\ToniArts 2008-07-06 21:20 --------- d-----w C:\ProgramData\Lavasoft 2008-07-06 21:17 --------- d-----w C:\Program Files\Lavasoft 2008-07-06 21:16 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2008-06-29 22:03 --------- d-----w C:\Program Files\AllMusicConverter 2008-06-29 15:25 --------- d-----w C:\Users\Tommi\AppData\Roaming\Thunderbird 2008-06-29 15:21 --------- d-----w C:\Program Files\Google 2008-06-26 12:51 --------- d-----w C:\Users\Tommi\AppData\Roaming\PeerNetworking 2008-06-26 11:18 --------- d-----w C:\Program Files\Adobe(2) 2008-06-26 11:17 --------- d-----w C:\Program Files\Common Files\Adobe(3) 2008-06-26 03:29 801,280 ----a-w C:\Windows\System32\NaturalLanguage6.dll 2008-06-26 01:45 2,644,480 ----a-w C:\Windows\System32\NlsLexicons0009.dll 2008-06-26 01:45 12,240,896 ----a-w C:\Windows\System32\NlsLexicons0007.dll 2008-06-22 23:45 --------- d-----w C:\Program Files\DC++(6) 2008-06-22 23:40 --------- d-----w C:\Program Files\RevConnect(11) 2008-06-20 12:04 --------- d-----w C:\Program Files\Yahoo! 2008-06-18 17:52 161,096 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe 2008-06-11 00:07 524,288 ----a-w C:\Windows\System32\DivXsm.exe 2008-06-11 00:07 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll 2008-06-11 00:04 200,704 ----a-w C:\Windows\System32\ssldivx.dll 2008-06-11 00:04 1,044,480 ----a-w C:\Windows\System32\libdivx.dll 2008-06-04 09:05 184,320 ----a-w C:\Windows\System32\snmvtsvc.exe 2008-06-04 07:19 3,768 ----a-w C:\Windows\System32\MusCVideo32.sys 2008-06-04 07:19 23,096 ----a-w C:\Windows\System32\MusCDriverV32.sys 2008-06-04 07:19 10,936 ----a-w C:\Windows\System32\MusCVideo32.dll 2008-05-22 22:18 12,288 ----a-w C:\Windows\System32\DivXWMPExtType.dll 2008-01-21 02:43 174 --sha-w C:\Program Files\desktop.ini 2006-08-18 19:19 572,802 ----a-w C:\Users\Tommi\setup.exe . (((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet ))))))))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D187A56B-A33F-4CBE-9D77-459FC0BAE012}] 2008-08-01 21:53 806912 --a------ C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}"= "C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll" [2008-08-01 21:53 806912] [HKEY_CLASSES_ROOT\clsid\{4f11acbb-393f-4c86-a214-ff3d0d155cc3}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}"= "C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll" [2008-08-01 21:53 806912] [HKEY_CLASSES_ROOT\clsid\{4f11acbb-393f-4c86-a214-ff3d0d155cc3}] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-03-04 23:38 121392 --a------ C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-21 05:23 1233920] "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184] "BitTorrent DNA"="C:\Users\Tommi\Program Files\DNA\btdna.exe" [2008-06-13 11:16 289088] "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-21 05:25 125952] "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 05:25 202240] "AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 10:37 2321600] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Acer Empowering Technology Monitor"="C:\Program Files\Acer\Empowering Technology\SysMonitor.exe" [2008-04-25 13:31 319488] "EmpoweringTechnology"="C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe" [2008-04-25 13:31 319488] "eDataSecurity Loader"="C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-04 23:38 526896] "PCMMediaSharing"="C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2008-01-25 18:49 204908] "BkupTray"="C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-02-25 18:57 34040] "StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 12:17 61440] "WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 21:48 57344] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784] "F-Secure Manager"="C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" [2007-05-25 16:12 183208] "F-Secure TNB"="C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" [2007-05-25 16:11 740208] "RtHDVCpl"="RtHDVCpl.exe" [2008-03-26 08:21 5369856 C:\Windows\RtHDVCpl.exe] C:\Users\Tommi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [2008-07-18 18:24:47 624416] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.mkdmp3enc"= C:\PROGRA~1\ACERAR~1\ACERVI~1\Kernel\Burner\MKDMP3Enc.ACM [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{F437FC51-8447-4F50-A200-AB48ADA85752}"= C:\Program Files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live "{72B98891-2783-4F50-A5CF-18A6FC8E6F7D}"= C:\Program Files\Acer Arcade Live\Acer DV Magician\Acer DV Magician.exe:Acer DV Magician "{481EC971-D056-46AB-A7C2-B27E04C7DCDF}"= C:\Program Files\Acer Arcade Live\Acer SlideShow DVD\Acer SlideShow DVD.exe:Acer SlideShow DVD "{9F8B81CB-436E-4454-BAF2-282F31A9FE30}"= C:\Program Files\Acer Arcade Live\Acer VideoMagician\Acer VideoMagician.exe:Acer VideoMagician "{70AF495A-DD48-4DD5-B65C-2FD8152267F5}"= C:\Program Files\Acer Arcade Live\Acer DVDivine\Acer DVDivine.exe:Acer DVDivine "{89A83514-7802-44E6-B1CE-505EB11398A1}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia\Acer HomeMedia.exe:Acer HomeMedia "{17E28DA0-6226-404D-90FF-9478B108674D}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Acer HomeMedia Connect.exe:Acer HomeMedia Connect "{A9AA388F-5DFE-4CEE-BB6C-D0CF7C7C03C6}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:Acer HomeMedia Connect Service "{9C462EB5-87D6-4836-9DB3-F7DED0602CF9}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Trial Creator\Acer HomeMedia Trial Creator.exe:Acer HomeMedia Trial Creator "{447AD60F-F14B-4AA1-B364-55E446901A57}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{BA054699-71A1-45C8-979C-AF723553ADF2}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{15455CCB-28FF-48C8-A3DA-2CDEC00A110A}"= UDP:C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe "{B1965491-35E8-4A69-9875-7C55F1B3F124}"= UDP:C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe "{E112860F-0203-4E8E-86F5-CA337A84BE1E}"= UDP:C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe "{7BE1C121-92E6-43A1-AA34-32074866D361}"= TCP:C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe "{404163B8-B600-4FDE-8D53-A994AA8121AF}"= TCP:C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe "{F76A28F9-8EDB-492E-9A15-C890DBFDB6BB}"= TCP:C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe "{C4527736-9434-4877-B775-E2211C1E4092}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) "{C5F3AAF3-6A72-408D-BB18-E0756D6FF85F}"= UDP:C:\Program Files\DNA\btdna.exeNA "{406E801D-86B4-46E9-94B0-82F859C9DB24}"= TCP:C:\Program Files\DNA\btdna.exeNA "{77C2F6B1-55BC-4EE2-9237-0D65DF76AD7F}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent "{873FC9EC-31C0-4108-BD1A-AF3968444306}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent "{733FC620-B8CD-4262-B330-66ECF9DDC6AA}"= Disabled:UDP:C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008 "{0BCCAA60-9365-42EE-955A-AB2EEBF5ACA4}"= Disabled:TCP:C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008 "{A7378ABF-E9FC-4CAE-9A9B-9F7A00B551BD}"= UDP:C:\Users\Tommi\Documents\fm.exe:Football Manager 2008 "{DE88E7F6-51D9-462F-8C0B-CF73C1D1028C}"= TCP:C:\Users\Tommi\Documents\fm.exe:Football Manager 2008 "TCP Query User{034CCA25-1BE1-496C-BAE6-4A2955D14ECF}C:\\program files\\dc++\\dcplusplus.exe"= UDP:C:\program files\dc++\dcplusplus.exeC++ "UDP Query User{BAF93112-B5D7-4F90-AA80-2D7E71CFE64F}C:\\program files\\dc++\\dcplusplus.exe"= TCP:C:\program files\dc++\dcplusplus.exeC++ "TCP Query User{F185B79F-5496-45B1-A683-C267B180EF79}C:\\program files\\revconnect\\dcplusplus.exe"= UDP:C:\program files\revconnect\dcplusplus.exeC++ "UDP Query User{0BFAA5C1-B512-433A-B806-126702EDDB53}C:\\program files\\revconnect\\dcplusplus.exe"= TCP:C:\program files\revconnect\dcplusplus.exeC++ "TCP Query User{C69BA5DA-3836-4A4D-B087-788433E88FE4}C:\\users\\tommi\\program files\\dna\\btdna.exe"= UDP:C:\users\tommi\program files\dna\btdna.exe:btdna.exe "UDP Query User{74688A95-0DE0-41CF-89B4-CB6AB82E86A6}C:\\users\\tommi\\program files\\dna\\btdna.exe"= TCP:C:\users\tommi\program files\dna\btdna.exe:btdna.exe "TCP Query User{889AA4ED-A492-4D36-8551-D2CD764BC7D5}C:\\users\\tommi\\documents\\sports interactive\\football manager 2008\\fm.exe"= UDP:C:\users\tommi\documents\sports interactive\football manager 2008\fm.exe:fm.exe "UDP Query User{3C278A0B-8B59-42EA-9294-3B47572F70BE}C:\\users\\tommi\\documents\\sports interactive\\football manager 2008\\fm.exe"= TCP:C:\users\tommi\documents\sports interactive\football manager 2008\fm.exe:fm.exe "TCP Query User{F1EF1083-1885-4DC2-9705-DB66B646C818}C:\\program files\\videolan\\vlc\\vlc.exe"= UDP:C:\program files\videolan\vlc\vlc.exe:VLC media player "UDP Query User{02B22D37-A1A8-4DFE-8799-0B0427F91E12}C:\\program files\\videolan\\vlc\\vlc.exe"= TCP:C:\program files\videolan\vlc\vlc.exe:VLC media player "TCP Query User{CD8C1D34-F3E1-4A11-8789-7AD688E21158}C:\\program files\\emco malware destroyer\\malwaredestroyer.exe"= UDP:C:\program files\emco malware destroyer\malwaredestroyer.exe:Malware Scanner for Home User's "UDP Query User{603FCFB9-8D88-48A2-B44F-3C6ACEE5F13B}C:\\program files\\emco malware destroyer\\malwaredestroyer.exe"= TCP:C:\program files\emco malware destroyer\malwaredestroyer.exe:Malware Scanner for Home User's "TCP Query User{54A82EF6-AA27-4B0E-94B4-21744246C21F}C:\\users\\tommi\\program files\\dna\\btdna.exe"= UDP:C:\users\tommi\program files\dna\btdna.exe:btdna.exe "UDP Query User{1D6C9851-A8FA-4D0E-AB42-6E7ACCE09276}C:\\users\\tommi\\program files\\dna\\btdna.exe"= TCP:C:\users\tommi\program files\dna\btdna.exe:btdna.exe "TCP Query User{8381218E-DD56-47B7-8843-F3DA0332F6B2}C:\\program files\\mirc\\mirc.exe"= UDP:C:\program files\mirc\mirc.exe:mIRC "UDP Query User{0982D26C-EA81-42E3-853D-DE73490E4213}C:\\program files\\mirc\\mirc.exe"= TCP:C:\program files\mirc\mirc.exe:mIRC "TCP Query User{FA8F92A7-65C0-462D-88BF-74DEFA2A6EDC}C:\\program files\\bittorrent\\bittorrent.exe"= UDP:C:\program files\bittorrent\bittorrent.exe:bittorrent "UDP Query User{3A69BDBE-D1DF-427A-843C-80BDEE5A567E}C:\\program files\\bittorrent\\bittorrent.exe"= TCP:C:\program files\bittorrent\bittorrent.exe:bittorrent "TCP Query User{B84F12EF-1B4D-416E-B682-FBA3FC2FCA94}C:\\program files\\revconnect\\dcplusplus.exe"= UDP:C:\program files\revconnect\dcplusplus.exeC++ "UDP Query User{C64B66AC-E66F-4E25-90A5-574D191E2B8C}C:\\program files\\revconnect\\dcplusplus.exe"= TCP:C:\program files\revconnect\dcplusplus.exeC++ "TCP Query User{6E65BC34-CA6E-497A-B8EE-BF409DAF7FEE}C:\\program files\\soulseekns\\slsk.exe"= UDP:C:\program files\soulseekns\slsk.exe:SoulSeek "UDP Query User{2A205C96-F974-4178-8E9D-3A01E6B0C31C}C:\\program files\\soulseekns\\slsk.exe"= TCP:C:\program files\soulseekns\slsk.exe:SoulSeek "TCP Query User{1D2D4CFA-C0DA-49A0-A712-1E819274E4F3}C:\\program files\\b2bpoker\\pokerihuone\\jre\\bin\\javaw.exe"= UDP:C:\program files\b2bpoker\pokerihuone\jre\bin\javaw.exe:Java(TM) 2 Platform Standard Edition binary "UDP Query User{C7584C6B-83D7-4253-8D0A-C8022EC574B3}C:\\program files\\b2bpoker\\pokerihuone\\jre\\bin\\javaw.exe"= TCP:C:\program files\b2bpoker\pokerihuone\jre\bin\javaw.exe:Java(TM) 2 Platform Standard Edition binary "TCP Query User{0D955E2A-C20D-4767-9A1D-90C50A5EFC91}C:\\program files\\b2bpoker\\pokerihuone\\jre\\bin\\javaw.exe"= UDP:C:\program files\b2bpoker\pokerihuone\jre\bin\javaw.exe:Java(TM) 2 Platform Standard Edition binary "UDP Query User{9168F2A4-EAE8-4AF1-87CE-71DDE715D086}C:\\program files\\b2bpoker\\pokerihuone\\jre\\bin\\javaw.exe"= TCP:C:\program files\b2bpoker\pokerihuone\jre\bin\javaw.exe:Java(TM) 2 Platform Standard Edition binary "TCP Query User{FE896EBE-1591-48DE-A2C7-EF80D5AA7426}C:\\program files\\mirc\\mirc.exe"= UDP:C:\program files\mirc\mirc.exe:mIRC "UDP Query User{3A065421-77DC-40B6-9895-ABE6DCFDA4FD}C:\\program files\\mirc\\mirc.exe"= TCP:C:\program files\mirc\mirc.exe:mIRC "TCP Query User{FE3E3235-7BDC-447E-AA9D-FD94FA01D7FB}C:\\program files\\mozilla firefox\\firefox.exe"= UDP:C:\program files\mozilla firefox\firefox.exe:Firefox "UDP Query User{35BBF606-EE64-46D3-892C-FF864F6624EF}C:\\program files\\mozilla firefox\\firefox.exe"= TCP:C:\program files\mozilla firefox\firefox.exe:Firefox "TCP Query User{05C77AF1-F171-44F8-B1D7-9D8BA33A1807}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent "UDP Query User{AA6F9D10-5C0F-41FD-B54A-C8751BAC9B56}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent "TCP Query User{C1CDDB73-71ED-4B8F-A4E2-D0B0FF502357}C:\\users\\tommi\\program files\\bittorrent\\bittorrent.exe"= UDP:C:\users\tommi\program files\bittorrent\bittorrent.exe:bittorrent.exe "UDP Query User{9B300AEC-7F6B-48B1-BE09-1BCDF5957FD4}C:\\users\\tommi\\program files\\bittorrent\\bittorrent.exe"= TCP:C:\users\tommi\program files\bittorrent\bittorrent.exe:bittorrent.exe "TCP Query User{B1BC1ECC-3D31-4D08-A22F-5A48D3F1C4F9}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule "UDP Query User{54BE115C-F62B-4383-B5E1-3ADA541243CB}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule "TCP Query User{CF53ACD9-B359-44AE-AE3B-D7B6420DAD50}C:\\program files\\soulseekns\\slsk.exe"= UDP:C:\program files\soulseekns\slsk.exe:SoulSeek "UDP Query User{EF68107C-396D-4900-B589-9C58EF29CBC0}C:\\program files\\soulseekns\\slsk.exe"= TCP:C:\program files\soulseekns\slsk.exe:SoulSeek [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List] "C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent R0 ahcix86s;ahcix86s;C:\Windows\system32\drivers\ahcix86s.sys [2007-12-19 09:45] R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-30 06:23] R1 F-Secure HIPS;F-Secure HIPS;C:\Program Files\F-Secure Internet Security\HIPS\fshs.sys [2008-08-14 20:43] R1 FSES;F-Secure Email Scanning Driver;C:\Windows\system32\drivers\fses.sys [2007-05-25 16:09] R1 FSFW;F-Secure Firewall Driver;C:\Windows\system32\drivers\fsdfw.sys [2008-08-14 20:44] R1 fsvista;F-Secure Vista Support Driver;C:\Program Files\F-Secure Internet Security\Anti-Virus\minifilter\fsvista.sys [2007-05-25 16:08] R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-01-25 18:49] R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-02-25 18:57] R2 ETService;Empowering Technology Service;C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [2008-04-25 13:30] R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-02-25 02:02] R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-02-25 18:53] R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2008-03-09 17:58] R3 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\F-Secure Internet Security\Anti-Virus\minifilter\fsgk.sys [2007-05-25 16:08] R3 MusCDriverV32;MusCDriverV32;C:\Windows\system32\drivers\MusCDriverV32.sys [2008-06-04 10:19] R3 RTL85n86;Realtek 8180/8185 Extensible 802.11 Wireless Device Driver;C:\Windows\system32\DRIVERS\RTL85n86.sys [2007-01-24 15:23] R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-12-28 05:51] S3 SoundMovieServer;SoundMovieServer;C:\Windows\system32\snmvtsvc.exe [2008-06-04 12:05] S4 ErrDev;Microsoft Hardware Error Device Driver;C:\Windows\system32\drivers\errdev.sys [2008-01-21 05:23] S4 F-Secure Filter;F-Secure File System Filter;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSfilter.sys [2007-05-25 16:09] S4 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSrec.sys [2007-05-25 16:09] S4 MegaSR;MegaSR;C:\Windows\system32\drivers\megasr.sys [2008-01-21 05:23] . - - - - ORPHANS REMOVED - - - - HKLM-Run-Malwarebytes Anti-Malware Reboot - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe . ------- Supplementary Scan ------- . FireFox -: Profile - C:\Users\Tommi\AppData\Roaming\Mozilla\Firefox\Profiles\gs2iba4m.default\ FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://phnet.fi/ FF -: plugin - C:\Program Files\DNA\plugins\npbtdna.dll FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll FF -: plugin - C:\Users\Tommi\Program Files\DNA\plugins\npbtdna.dll . . ------- File Associations (Beta) ------- . VBEFile="%SystemRoot%\System32\WScript.exe" "%1" %* VBSFile="%SystemRoot%\System32\WScript.exe" "%1" %* vbefile\shell\open\command="%SystemRoot%\System32\WScript.exe" "%1" %* vbsfile\shell\open\command="%SystemRoot%\System32\WScript.exe" "%1" %* jsefile\shell\open\command=%SystemRoot%\System32\WScript.exe "%1" %* . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-08-18 22:33:14 Windows 6.0.6001 Service Pack 1 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-08-18 22:34:59 ComboFix-quarantined-files.txt 2008-08-18 19:34:56 Pre-Run: 53,802,336,256 tavua vapaana Post-Run: 55,344,869,376 tavua vapaana 289 --- E O F --- 2008-08-16 08:51:56
kyllä tuo aapeli ihan normaalilta näyttää. firefoxsin asetuksissa saattaa olla jotain pois ... katos että hyväksyy javan olekos koittanut poistaa Firefoxsin ja asentaa uudelleen