Ongelmia javan kanssa. HJT-loki

Discussion in 'Virukset ja haittaohjelmat - HijackThis -logit' started by lurtsifan, Aug 17, 2008.

  1. lurtsifan

    lurtsifan Member

    Joined:
    Jan 3, 2008
    Messages:
    37
    Likes Received:
    0
    Trophy Points:
    16
    Elikkäs, joillain sivuilla missä on javasovellus itse sivun sisässä, on ongelmia (esim. aapeli). Sivu ei välttämättä lataudu kunnolla (kaikki ei näy) ja jos avaan esim. mesekeskustelun javasovelluksen ollessa auki, niin mozilla sulkeutuu automaattisesti. Apuja?

    Tässä loki:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 17:17:13, on 17.8.2008
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\Acer\Empowering Technology\SysMonitor.exe
    C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe
    C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
    C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Users\Tommi\Program Files\DNA\btdna.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Hamachi\hamachi.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe
    C:\Windows\system32\conime.exe
    C:\Program Files\Last.fm\LastFM.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Users\Tommi\Program Files\BitTorrent\BitTorrent.exe
    C:\Program Files\Acer\Empowering Technology\NotificationCenter\Framework.NotificationCenter.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://phnet.fi/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: Adobe PDF Reader -linkkiavustaja - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
    O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Burn4Free Toolbar Helper - {D187A56B-A33F-4CBE-9D77-459FC0BAE012} - C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Burn4Free Toolbar - {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Program Files\Acer\Empowering Technology\SysMonitor.exe
    O4 - HKLM\..\Run: [EmpoweringTechnology] C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe boot
    O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
    O4 - HKLM\..\Run: [PCMMediaSharing] C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
    O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
    O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
    O4 - HKLM\..\Run: [Malwarebytes Anti-Malware Reboot] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Tommi\Program Files\DNA\btdna.exe"
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Paikallinen palvelu')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'Paikallinen palvelu')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Verkkopalvelu')
    O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
    O8 - Extra context menu item: V&ie Microsoft Exceliin - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
    O9 - Extra button: Lähetä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: Läh&etä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O13 - Gopher Prefix:
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
    O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
    O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
    O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
    O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
    O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: SoundMovieServer - SoundMovieServer - C:\Windows\system32\snmvtsvc.exe

    --
    End of file - 8691 bytes
     
  2. Hujo

    Hujo Guest

    scannaa hjt:llä merkkaa paina Fix checked

    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O4 - HKLM\..\Run: [Malwarebytes Anti-Malware Reboot] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"

    =================

     
  3. lurtsifan

    lurtsifan Member

    Joined:
    Jan 3, 2008
    Messages:
    37
    Likes Received:
    0
    Trophy Points:
    16
    Hoidettu. Tarvitseeko tehdä vielä jotain muuta, kun ongelma näyttäisi pysyneen (ainakaan sivut eivät näy kunnolla)?
     
  4. Hujo

    Hujo Guest

    1.Lataa combofix.exe työpöydällesi yhdestä linkistä:
    combofix1
    combofix2

    2. Tuplaklikkaa combofix.exe tiedostoa ja seuraa ohjeistuksia.
    3. Kun työkalu on valmis, se tuottaa lokin. Lähetä tämä loki viesti ketjuusi.
    Huom! Älä klikkaile combofixin ikkunaa käytön aikana. Tämä saattaa aiheuttaa ohjelman jumiutumisen.


    ============

    ajas tuo Malwarebytes' Anti-Malware sehän sulla on koneella.
    Päivitä ensin

    ===========

    Mitä siintä sivun aukeemisesta uupuu kun ei näy kunnolla..
     
  5. lurtsifan

    lurtsifan Member

    Joined:
    Jan 3, 2008
    Messages:
    37
    Likes Received:
    0
    Trophy Points:
    16
    http://img65.imageshack.us/my.php?image=nimetnth8.jpg

    Tässä aika selvä esimerkki siitä. Jos tuossa samalla avaisin mesekeskustelun, ja takaisin tuon ikkunan, niin mozilla sulkeutuisi.

    Ja tässäpä tämä combofix-loki:

    ComboFix 08-08-17.05 - Tommi 2008-08-18 22:28:30.5 - NTFSx86
    Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1035.18.1721 [GMT 3:00]
    Running from: C:\Users\Tommi\Downloads\ComboFix.exe
    * Resident AV is active

    .

    (((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Users\Tommi\AppData\Roaming\macromedia\Flash Player\#SharedObjects\FNW65KNB\interclick.com
    C:\Users\Tommi\AppData\Roaming\macromedia\Flash Player\#SharedObjects\FNW65KNB\interclick.com\ud.sol
    C:\Users\Tommi\AppData\Roaming\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
    C:\Users\Tommi\AppData\Roaming\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol

    .
    ((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-07-18 to 2008-08-18 )))))))))))))))))
    .

    2008-08-17 17:16 . 2008-08-17 17:16 <KANSIO> d-------- C:\Users\Tommi\AppData\Roaming\F-Secure
    2008-08-15 19:48 . 2008-08-15 19:48 <KANSIO> d-------- C:\Program Files\YouTube Downloader
    2008-08-14 22:17 . 2008-07-16 04:32 2,048 --a------ C:\Windows\System32\tzres.dll
    2008-08-14 20:26 . 2008-08-14 20:26 <KANSIO> d-------- C:\Users\All Users\F-Secure
    2008-08-14 20:26 . 2008-08-14 20:26 <KANSIO> d-------- C:\ProgramData\F-Secure
    2008-08-14 20:26 . 2007-05-25 16:15 572,784 --a------ C:\Windows\System32\msvcp50.dll
    2008-08-14 20:26 . 2008-08-14 20:44 60,064 --a------ C:\Windows\System32\drivers\fsdfw.sys
    2008-08-14 20:26 . 2007-05-25 16:09 35,024 --a------ C:\Windows\System32\drivers\fses.sys
    2008-08-14 20:25 . 2008-08-14 22:21 <KANSIO> d-------- C:\Program Files\F-Secure Internet Security
    2008-08-14 20:19 . 2008-08-14 20:24 <KANSIO> d-------- C:\Users\All Users\fssg
    2008-08-14 20:19 . 2008-08-14 20:24 <KANSIO> d-------- C:\ProgramData\fssg
    2008-08-14 07:55 . 2008-06-27 04:55 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
    2008-08-14 07:55 . 2008-06-27 07:15 827,392 --a------ C:\Windows\System32\wininet.dll
    2008-08-14 07:55 . 2008-06-19 06:31 361,984 --a------ C:\Windows\System32\IPSECSVC.DLL
    2008-08-14 07:55 . 2008-04-18 08:48 269,312 --a------ C:\Windows\System32\es.dll
    2008-08-14 07:54 . 2008-04-10 08:12 738,304 --a------ C:\Windows\System32\inetcomm.dll
    2008-08-11 19:17 . 2008-08-11 19:17 <KANSIO> d-------- C:\Program Files\Xilisoft
    2008-08-10 21:14 . 2008-08-10 21:16 <KANSIO> d-------- C:\Program Files\AimOne_AlltoMP3
    2008-08-10 20:44 . 2008-08-10 20:44 <KANSIO> d-------- C:\Program Files\QuickTime
    2008-08-01 21:53 . 2008-08-01 21:53 <KANSIO> d-------- C:\Program Files\Burn4Free Toolbar
    2008-08-01 21:53 . 2008-08-01 22:12 <KANSIO> d-------- C:\Program Files\Burn4Free
    2008-08-01 21:53 . 2008-08-01 21:53 232,075 --a------ C:\Windows\Burn4Free_Toolbar_Uninstaller_6675.exe
    2008-07-31 22:21 . 2008-07-31 22:21 <KANSIO> d-------- C:\Users\All Users\eMule
    2008-07-31 22:21 . 2008-07-31 22:21 <KANSIO> d-------- C:\ProgramData\eMule
    2008-07-31 22:21 . 2008-07-31 22:21 <KANSIO> d-------- C:\Program Files\eMule
    2008-07-31 00:50 . 2008-07-31 00:50 <KANSIO> d-------- C:\Program Files\Smart Projects
    2008-07-29 16:32 . 2008-07-29 16:32 <KANSIO> d-------- C:\Program Files\TagRename
    2008-07-28 00:02 . 2008-07-28 02:14 <KANSIO> d-------- C:\Users\Tommi\AppData\Roaming\uTorrent
    2008-07-28 00:02 . 2008-07-28 00:02 <KANSIO> d-------- C:\Program Files\uTorrent
    2008-07-26 18:27 . 2008-07-26 18:28 <KANSIO> d-------- C:\Users\Tommi\OngameNetwork
    2008-07-19 22:49 . 2008-07-19 22:49 50 --a------ C:\Windows\MegaManager.INI
    2008-07-18 18:24 . 2008-07-18 18:25 <KANSIO> d-------- C:\Program Files\Hamachi
    2008-07-18 18:24 . 2008-07-18 18:24 25,280 --a------ C:\Windows\System32\drivers\hamachi.sys

    .
    (((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-08-18 19:32 --------- d-----w C:\Users\Tommi\AppData\Roaming\BitTorrent
    2008-08-18 19:31 --------- d-----w C:\Users\Tommi\AppData\Roaming\Hamachi
    2008-08-18 19:24 --------- d-----w C:\Users\Tommi\AppData\Roaming\DNA
    2008-08-17 15:45 --------- d-----w C:\ProgramData\Messenger Plus!
    2008-08-17 08:58 --------- d-----w C:\Users\Tommi\AppData\Roaming\mIRC
    2008-08-16 23:22 --------- d-----w C:\Program Files\mIRC
    2008-08-16 20:51 --------- d-----w C:\ProgramData\Soulseek
    2008-08-14 19:18 --------- d-----w C:\ProgramData\Microsoft Help
    2008-08-14 17:24 --------- d-----w C:\ProgramData\McAfee
    2008-08-14 17:21 --------- d-----w C:\ProgramData\SiteAdvisor
    2008-08-10 18:08 --------- d-----w C:\Users\Tommi\AppData\Roaming\dvdcss
    2008-08-10 17:44 --------- d-----w C:\Program Files\ImTOO
    2008-08-03 13:50 --------- d-----w C:\Program Files\DC++
    2008-07-19 19:49 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-07-17 19:13 --------- d-----w C:\Program Files\Java
    2008-07-17 19:10 --------- d-----w C:\Program Files\Common Files\Java
    2008-07-17 14:47 --------- d-----w C:\Program Files\B2BPOKER
    2008-07-16 07:20 --------- d-----w C:\ProgramData\NOS
    2008-07-16 07:20 --------- d-----w C:\Program Files\NOS
    2008-07-15 17:34 --------- d-----w C:\Program Files\Common Files\Adobe
    2008-07-15 15:04 --------- d-----w C:\Program Files\activePDF
    2008-07-13 23:19 --------- d-----w C:\Program Files\Messenger Plus! Live
    2008-07-12 16:45 --------- d-----w C:\Program Files\Bytescout XLS Viewer
    2008-07-08 22:01 --------- d-----w C:\Users\Tommi\AppData\Roaming\DivX
    2008-07-08 21:59 --------- d-----w C:\Program Files\Mozilla Thunderbird
    2008-07-08 21:59 --------- d-----w C:\Program Files\DivX
    2008-07-08 21:59 --------- d-----w C:\Program Files\Common Files\PX Storage Engine
    2008-07-08 21:42 --------- d-----w C:\Program Files\avisplit
    2008-07-08 21:05 --------- d-----w C:\Program Files\SoulseekNS
    2008-07-08 10:10 --------- d-----w C:\Program Files\Windows Live Safety Center
    2008-07-07 00:03 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
    2008-07-06 22:54 --------- d-----w C:\Program Files\Trend Micro
    2008-07-06 22:23 --------- d-----w C:\Program Files\EMCO Malware Destroyer
    2008-07-06 22:20 --------- d-----w C:\Users\Tommi\AppData\Roaming\Malwarebytes
    2008-07-06 22:20 --------- d-----w C:\ProgramData\Malwarebytes
    2008-07-06 21:55 --------- d-----w C:\Program Files\ToniArts
    2008-07-06 21:20 --------- d-----w C:\ProgramData\Lavasoft
    2008-07-06 21:17 --------- d-----w C:\Program Files\Lavasoft
    2008-07-06 21:16 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
    2008-06-29 22:03 --------- d-----w C:\Program Files\AllMusicConverter
    2008-06-29 15:25 --------- d-----w C:\Users\Tommi\AppData\Roaming\Thunderbird
    2008-06-29 15:21 --------- d-----w C:\Program Files\Google
    2008-06-26 12:51 --------- d-----w C:\Users\Tommi\AppData\Roaming\PeerNetworking
    2008-06-26 11:18 --------- d-----w C:\Program Files\Adobe(2)
    2008-06-26 11:17 --------- d-----w C:\Program Files\Common Files\Adobe(3)
    2008-06-26 03:29 801,280 ----a-w C:\Windows\System32\NaturalLanguage6.dll
    2008-06-26 01:45 2,644,480 ----a-w C:\Windows\System32\NlsLexicons0009.dll
    2008-06-26 01:45 12,240,896 ----a-w C:\Windows\System32\NlsLexicons0007.dll
    2008-06-22 23:45 --------- d-----w C:\Program Files\DC++(6)
    2008-06-22 23:40 --------- d-----w C:\Program Files\RevConnect(11)
    2008-06-20 12:04 --------- d-----w C:\Program Files\Yahoo!
    2008-06-18 17:52 161,096 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe
    2008-06-11 00:07 524,288 ----a-w C:\Windows\System32\DivXsm.exe
    2008-06-11 00:07 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
    2008-06-11 00:04 200,704 ----a-w C:\Windows\System32\ssldivx.dll
    2008-06-11 00:04 1,044,480 ----a-w C:\Windows\System32\libdivx.dll
    2008-06-04 09:05 184,320 ----a-w C:\Windows\System32\snmvtsvc.exe
    2008-06-04 07:19 3,768 ----a-w C:\Windows\System32\MusCVideo32.sys
    2008-06-04 07:19 23,096 ----a-w C:\Windows\System32\MusCDriverV32.sys
    2008-06-04 07:19 10,936 ----a-w C:\Windows\System32\MusCVideo32.dll
    2008-05-22 22:18 12,288 ----a-w C:\Windows\System32\DivXWMPExtType.dll
    2008-01-21 02:43 174 --sha-w C:\Program Files\desktop.ini
    2006-08-18 19:19 572,802 ----a-w C:\Users\Tommi\setup.exe
    .

    (((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D187A56B-A33F-4CBE-9D77-459FC0BAE012}]
    2008-08-01 21:53 806912 --a------ C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}"= "C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll" [2008-08-01 21:53 806912]

    [HKEY_CLASSES_ROOT\clsid\{4f11acbb-393f-4c86-a214-ff3d0d155cc3}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}"= "C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll" [2008-08-01 21:53 806912]

    [HKEY_CLASSES_ROOT\clsid\{4f11acbb-393f-4c86-a214-ff3d0d155cc3}]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
    @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
    [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
    2008-03-04 23:38 121392 --a------ C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-21 05:23 1233920]
    "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
    "BitTorrent DNA"="C:\Users\Tommi\Program Files\DNA\btdna.exe" [2008-06-13 11:16 289088]
    "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-21 05:25 125952]
    "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 05:25 202240]
    "AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 10:37 2321600]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Acer Empowering Technology Monitor"="C:\Program Files\Acer\Empowering Technology\SysMonitor.exe" [2008-04-25 13:31 319488]
    "EmpoweringTechnology"="C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe" [2008-04-25 13:31 319488]
    "eDataSecurity Loader"="C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-04 23:38 526896]
    "PCMMediaSharing"="C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2008-01-25 18:49 204908]
    "BkupTray"="C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-02-25 18:57 34040]
    "StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 12:17 61440]
    "WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 21:48 57344]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
    "F-Secure Manager"="C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" [2007-05-25 16:12 183208]
    "F-Secure TNB"="C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" [2007-05-25 16:11 740208]
    "RtHDVCpl"="RtHDVCpl.exe" [2008-03-26 08:21 5369856 C:\Windows\RtHDVCpl.exe]

    C:\Users\Tommi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [2008-07-18 18:24:47 624416]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "msacm.mkdmp3enc"= C:\PROGRA~1\ACERAR~1\ACERVI~1\Kernel\Burner\MKDMP3Enc.ACM

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
    "{F437FC51-8447-4F50-A200-AB48ADA85752}"= C:\Program Files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live
    "{72B98891-2783-4F50-A5CF-18A6FC8E6F7D}"= C:\Program Files\Acer Arcade Live\Acer DV Magician\Acer DV Magician.exe:Acer DV Magician
    "{481EC971-D056-46AB-A7C2-B27E04C7DCDF}"= C:\Program Files\Acer Arcade Live\Acer SlideShow DVD\Acer SlideShow DVD.exe:Acer SlideShow DVD
    "{9F8B81CB-436E-4454-BAF2-282F31A9FE30}"= C:\Program Files\Acer Arcade Live\Acer VideoMagician\Acer VideoMagician.exe:Acer VideoMagician
    "{70AF495A-DD48-4DD5-B65C-2FD8152267F5}"= C:\Program Files\Acer Arcade Live\Acer DVDivine\Acer DVDivine.exe:Acer DVDivine
    "{89A83514-7802-44E6-B1CE-505EB11398A1}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia\Acer HomeMedia.exe:Acer HomeMedia
    "{17E28DA0-6226-404D-90FF-9478B108674D}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Acer HomeMedia Connect.exe:Acer HomeMedia Connect
    "{A9AA388F-5DFE-4CEE-BB6C-D0CF7C7C03C6}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:Acer HomeMedia Connect Service
    "{9C462EB5-87D6-4836-9DB3-F7DED0602CF9}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Trial Creator\Acer HomeMedia Trial Creator.exe:Acer HomeMedia Trial Creator
    "{447AD60F-F14B-4AA1-B364-55E446901A57}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{BA054699-71A1-45C8-979C-AF723553ADF2}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{15455CCB-28FF-48C8-A3DA-2CDEC00A110A}"= UDP:C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
    "{B1965491-35E8-4A69-9875-7C55F1B3F124}"= UDP:C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
    "{E112860F-0203-4E8E-86F5-CA337A84BE1E}"= UDP:C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
    "{7BE1C121-92E6-43A1-AA34-32074866D361}"= TCP:C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
    "{404163B8-B600-4FDE-8D53-A994AA8121AF}"= TCP:C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
    "{F76A28F9-8EDB-492E-9A15-C890DBFDB6BB}"= TCP:C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
    "{C4527736-9434-4877-B775-E2211C1E4092}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
    "{C5F3AAF3-6A72-408D-BB18-E0756D6FF85F}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
    "{406E801D-86B4-46E9-94B0-82F859C9DB24}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
    "{77C2F6B1-55BC-4EE2-9237-0D65DF76AD7F}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
    "{873FC9EC-31C0-4108-BD1A-AF3968444306}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
    "{733FC620-B8CD-4262-B330-66ECF9DDC6AA}"= Disabled:UDP:C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
    "{0BCCAA60-9365-42EE-955A-AB2EEBF5ACA4}"= Disabled:TCP:C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
    "{A7378ABF-E9FC-4CAE-9A9B-9F7A00B551BD}"= UDP:C:\Users\Tommi\Documents\fm.exe:Football Manager 2008
    "{DE88E7F6-51D9-462F-8C0B-CF73C1D1028C}"= TCP:C:\Users\Tommi\Documents\fm.exe:Football Manager 2008
    "TCP Query User{034CCA25-1BE1-496C-BAE6-4A2955D14ECF}C:\\program files\\dc++\\dcplusplus.exe"= UDP:C:\program files\dc++\dcplusplus.exe:DC++
    "UDP Query User{BAF93112-B5D7-4F90-AA80-2D7E71CFE64F}C:\\program files\\dc++\\dcplusplus.exe"= TCP:C:\program files\dc++\dcplusplus.exe:DC++
    "TCP Query User{F185B79F-5496-45B1-A683-C267B180EF79}C:\\program files\\revconnect\\dcplusplus.exe"= UDP:C:\program files\revconnect\dcplusplus.exe:DC++
    "UDP Query User{0BFAA5C1-B512-433A-B806-126702EDDB53}C:\\program files\\revconnect\\dcplusplus.exe"= TCP:C:\program files\revconnect\dcplusplus.exe:DC++
    "TCP Query User{C69BA5DA-3836-4A4D-B087-788433E88FE4}C:\\users\\tommi\\program files\\dna\\btdna.exe"= UDP:C:\users\tommi\program files\dna\btdna.exe:btdna.exe
    "UDP Query User{74688A95-0DE0-41CF-89B4-CB6AB82E86A6}C:\\users\\tommi\\program files\\dna\\btdna.exe"= TCP:C:\users\tommi\program files\dna\btdna.exe:btdna.exe
    "TCP Query User{889AA4ED-A492-4D36-8551-D2CD764BC7D5}C:\\users\\tommi\\documents\\sports interactive\\football manager 2008\\fm.exe"= UDP:C:\users\tommi\documents\sports interactive\football manager 2008\fm.exe:fm.exe
    "UDP Query User{3C278A0B-8B59-42EA-9294-3B47572F70BE}C:\\users\\tommi\\documents\\sports interactive\\football manager 2008\\fm.exe"= TCP:C:\users\tommi\documents\sports interactive\football manager 2008\fm.exe:fm.exe
    "TCP Query User{F1EF1083-1885-4DC2-9705-DB66B646C818}C:\\program files\\videolan\\vlc\\vlc.exe"= UDP:C:\program files\videolan\vlc\vlc.exe:VLC media player
    "UDP Query User{02B22D37-A1A8-4DFE-8799-0B0427F91E12}C:\\program files\\videolan\\vlc\\vlc.exe"= TCP:C:\program files\videolan\vlc\vlc.exe:VLC media player
    "TCP Query User{CD8C1D34-F3E1-4A11-8789-7AD688E21158}C:\\program files\\emco malware destroyer\\malwaredestroyer.exe"= UDP:C:\program files\emco malware destroyer\malwaredestroyer.exe:Malware Scanner for Home User's
    "UDP Query User{603FCFB9-8D88-48A2-B44F-3C6ACEE5F13B}C:\\program files\\emco malware destroyer\\malwaredestroyer.exe"= TCP:C:\program files\emco malware destroyer\malwaredestroyer.exe:Malware Scanner for Home User's
    "TCP Query User{54A82EF6-AA27-4B0E-94B4-21744246C21F}C:\\users\\tommi\\program files\\dna\\btdna.exe"= UDP:C:\users\tommi\program files\dna\btdna.exe:btdna.exe
    "UDP Query User{1D6C9851-A8FA-4D0E-AB42-6E7ACCE09276}C:\\users\\tommi\\program files\\dna\\btdna.exe"= TCP:C:\users\tommi\program files\dna\btdna.exe:btdna.exe
    "TCP Query User{8381218E-DD56-47B7-8843-F3DA0332F6B2}C:\\program files\\mirc\\mirc.exe"= UDP:C:\program files\mirc\mirc.exe:mIRC
    "UDP Query User{0982D26C-EA81-42E3-853D-DE73490E4213}C:\\program files\\mirc\\mirc.exe"= TCP:C:\program files\mirc\mirc.exe:mIRC
    "TCP Query User{FA8F92A7-65C0-462D-88BF-74DEFA2A6EDC}C:\\program files\\bittorrent\\bittorrent.exe"= UDP:C:\program files\bittorrent\bittorrent.exe:bittorrent
    "UDP Query User{3A69BDBE-D1DF-427A-843C-80BDEE5A567E}C:\\program files\\bittorrent\\bittorrent.exe"= TCP:C:\program files\bittorrent\bittorrent.exe:bittorrent
    "TCP Query User{B84F12EF-1B4D-416E-B682-FBA3FC2FCA94}C:\\program files\\revconnect\\dcplusplus.exe"= UDP:C:\program files\revconnect\dcplusplus.exe:DC++
    "UDP Query User{C64B66AC-E66F-4E25-90A5-574D191E2B8C}C:\\program files\\revconnect\\dcplusplus.exe"= TCP:C:\program files\revconnect\dcplusplus.exe:DC++
    "TCP Query User{6E65BC34-CA6E-497A-B8EE-BF409DAF7FEE}C:\\program files\\soulseekns\\slsk.exe"= UDP:C:\program files\soulseekns\slsk.exe:SoulSeek
    "UDP Query User{2A205C96-F974-4178-8E9D-3A01E6B0C31C}C:\\program files\\soulseekns\\slsk.exe"= TCP:C:\program files\soulseekns\slsk.exe:SoulSeek
    "TCP Query User{1D2D4CFA-C0DA-49A0-A712-1E819274E4F3}C:\\program files\\b2bpoker\\pokerihuone\\jre\\bin\\javaw.exe"= UDP:C:\program files\b2bpoker\pokerihuone\jre\bin\javaw.exe:Java(TM) 2 Platform Standard Edition binary
    "UDP Query User{C7584C6B-83D7-4253-8D0A-C8022EC574B3}C:\\program files\\b2bpoker\\pokerihuone\\jre\\bin\\javaw.exe"= TCP:C:\program files\b2bpoker\pokerihuone\jre\bin\javaw.exe:Java(TM) 2 Platform Standard Edition binary
    "TCP Query User{0D955E2A-C20D-4767-9A1D-90C50A5EFC91}C:\\program files\\b2bpoker\\pokerihuone\\jre\\bin\\javaw.exe"= UDP:C:\program files\b2bpoker\pokerihuone\jre\bin\javaw.exe:Java(TM) 2 Platform Standard Edition binary
    "UDP Query User{9168F2A4-EAE8-4AF1-87CE-71DDE715D086}C:\\program files\\b2bpoker\\pokerihuone\\jre\\bin\\javaw.exe"= TCP:C:\program files\b2bpoker\pokerihuone\jre\bin\javaw.exe:Java(TM) 2 Platform Standard Edition binary
    "TCP Query User{FE896EBE-1591-48DE-A2C7-EF80D5AA7426}C:\\program files\\mirc\\mirc.exe"= UDP:C:\program files\mirc\mirc.exe:mIRC
    "UDP Query User{3A065421-77DC-40B6-9895-ABE6DCFDA4FD}C:\\program files\\mirc\\mirc.exe"= TCP:C:\program files\mirc\mirc.exe:mIRC
    "TCP Query User{FE3E3235-7BDC-447E-AA9D-FD94FA01D7FB}C:\\program files\\mozilla firefox\\firefox.exe"= UDP:C:\program files\mozilla firefox\firefox.exe:Firefox
    "UDP Query User{35BBF606-EE64-46D3-892C-FF864F6624EF}C:\\program files\\mozilla firefox\\firefox.exe"= TCP:C:\program files\mozilla firefox\firefox.exe:Firefox
    "TCP Query User{05C77AF1-F171-44F8-B1D7-9D8BA33A1807}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent
    "UDP Query User{AA6F9D10-5C0F-41FD-B54A-C8751BAC9B56}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent
    "TCP Query User{C1CDDB73-71ED-4B8F-A4E2-D0B0FF502357}C:\\users\\tommi\\program files\\bittorrent\\bittorrent.exe"= UDP:C:\users\tommi\program files\bittorrent\bittorrent.exe:bittorrent.exe
    "UDP Query User{9B300AEC-7F6B-48B1-BE09-1BCDF5957FD4}C:\\users\\tommi\\program files\\bittorrent\\bittorrent.exe"= TCP:C:\users\tommi\program files\bittorrent\bittorrent.exe:bittorrent.exe
    "TCP Query User{B1BC1ECC-3D31-4D08-A22F-5A48D3F1C4F9}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
    "UDP Query User{54BE115C-F62B-4383-B5E1-3ADA541243CB}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
    "TCP Query User{CF53ACD9-B359-44AE-AE3B-D7B6420DAD50}C:\\program files\\soulseekns\\slsk.exe"= UDP:C:\program files\soulseekns\slsk.exe:SoulSeek
    "UDP Query User{EF68107C-396D-4900-B589-9C58EF29CBC0}C:\\program files\\soulseekns\\slsk.exe"= TCP:C:\program files\soulseekns\slsk.exe:SoulSeek

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
    "C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent

    R0 ahcix86s;ahcix86s;C:\Windows\system32\drivers\ahcix86s.sys [2007-12-19 09:45]
    R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-30 06:23]
    R1 F-Secure HIPS;F-Secure HIPS;C:\Program Files\F-Secure Internet Security\HIPS\fshs.sys [2008-08-14 20:43]
    R1 FSES;F-Secure Email Scanning Driver;C:\Windows\system32\drivers\fses.sys [2007-05-25 16:09]
    R1 FSFW;F-Secure Firewall Driver;C:\Windows\system32\drivers\fsdfw.sys [2008-08-14 20:44]
    R1 fsvista;F-Secure Vista Support Driver;C:\Program Files\F-Secure Internet Security\Anti-Virus\minifilter\fsvista.sys [2007-05-25 16:08]
    R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-01-25 18:49]
    R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-02-25 18:57]
    R2 ETService;Empowering Technology Service;C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [2008-04-25 13:30]
    R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-02-25 02:02]
    R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-02-25 18:53]
    R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2008-03-09 17:58]
    R3 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\F-Secure Internet Security\Anti-Virus\minifilter\fsgk.sys [2007-05-25 16:08]
    R3 MusCDriverV32;MusCDriverV32;C:\Windows\system32\drivers\MusCDriverV32.sys [2008-06-04 10:19]
    R3 RTL85n86;Realtek 8180/8185 Extensible 802.11 Wireless Device Driver;C:\Windows\system32\DRIVERS\RTL85n86.sys [2007-01-24 15:23]
    R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-12-28 05:51]
    S3 SoundMovieServer;SoundMovieServer;C:\Windows\system32\snmvtsvc.exe [2008-06-04 12:05]
    S4 ErrDev;Microsoft Hardware Error Device Driver;C:\Windows\system32\drivers\errdev.sys [2008-01-21 05:23]
    S4 F-Secure Filter;F-Secure File System Filter;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSfilter.sys [2007-05-25 16:09]
    S4 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSrec.sys [2007-05-25 16:09]
    S4 MegaSR;MegaSR;C:\Windows\system32\drivers\megasr.sys [2008-01-21 05:23]
    .
    - - - - ORPHANS REMOVED - - - -

    HKLM-Run-Malwarebytes Anti-Malware Reboot - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe


    .
    ------- Supplementary Scan -------
    .
    FireFox -: Profile - C:\Users\Tommi\AppData\Roaming\Mozilla\Firefox\Profiles\gs2iba4m.default\
    FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://phnet.fi/
    FF -: plugin - C:\Program Files\DNA\plugins\npbtdna.dll
    FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
    FF -: plugin - C:\Users\Tommi\Program Files\DNA\plugins\npbtdna.dll
    .
    .
    ------- File Associations (Beta) -------
    .
    VBEFile="%SystemRoot%\System32\WScript.exe" "%1" %*
    VBSFile="%SystemRoot%\System32\WScript.exe" "%1" %*
    vbefile\shell\open\command="%SystemRoot%\System32\WScript.exe" "%1" %*
    vbsfile\shell\open\command="%SystemRoot%\System32\WScript.exe" "%1" %*
    jsefile\shell\open\command=%SystemRoot%\System32\WScript.exe "%1" %*
    .

    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-08-18 22:33:14
    Windows 6.0.6001 Service Pack 1 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2008-08-18 22:34:59
    ComboFix-quarantined-files.txt 2008-08-18 19:34:56

    Pre-Run: 53,802,336,256 tavua vapaana
    Post-Run: 55,344,869,376 tavua vapaana

    289 --- E O F --- 2008-08-16 08:51:56
     
    Last edited: Aug 18, 2008
  6. Hujo

    Hujo Guest

    kyllä tuo aapeli ihan normaalilta näyttää.

    firefoxsin asetuksissa saattaa olla jotain pois ... katos että hyväksyy javan
    olekos koittanut poistaa Firefoxsin ja asentaa uudelleen
     
    Last edited by a moderator: Aug 18, 2008

Share This Page