sitkeä troijalainen ja kaikkea muuta...

Discussion in 'Virukset ja haittaohjelmat - HijackThis -logit' started by Tuliti, Aug 29, 2008.

  1. Tuliti

    Tuliti Member

    Joined:
    Mar 29, 2008
    Messages:
    23
    Likes Received:
    0
    Trophy Points:
    11
    Eli siis, kaverin koneelle iski iloisesti troijalainen, joka ei monista poistoyrityksistä huolimatta suostu katoamaan. Malwarebytes on juoksutettu, kuten myös combofix.
    Apu olisi erittäin kaivattua.

    tässä hjt-logi:


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:01:22, on 29.8.2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
    C:\WINDOWS\System32\CTsvcCDA.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
    C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
    C:\Program Files\F-Secure\Common\FSMA32.EXE
    C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
    C:\Program Files\F-Secure\Common\FSMB32.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\F-Secure\Common\FCH32.EXE
    C:\Program Files\F-Secure\Common\FAMEH32.EXE
    C:\Program Files\F-Secure\Common\FNRB32.EXE
    C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    C:\Program Files\F-Secure\Common\FIH32.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    C:\Program Files\Java\jre1.5.0_03\bin\jucheck.exe
    C:\windows\system\hpsysdrv.exe
    C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe
    C:\Program Files\InterVideo\Common\Bin\WinRemote.exe
    C:\WINDOWS\System32\keyhook.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\WINDOWS\ALCWZRD.EXE
    C:\Program Files\F-Secure\Common\FSM32.EXE
    C:\WINDOWS\System32\LVCOMSX.EXE
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
    C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\PROGRA~1\HELPAN~1\Pavilion\XPHWWBF4\plugin\bin\pchbutton.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\F-Secure\BackWeb\7681197\Program\BackWeb-7681197.exe
    C:\Program Files\FinePixViewer\QuickDCF.exe
    C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Sony\OpenMG Jukebox\Omgtray.exe
    C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Documents and Settings\Katriina\Tyt臀winrar\WinRAR.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\WINDOWS\system32\33f8CH5O.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FI_FI&c=Q404&bd=pavilion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O3 - Toolbar: HP-n臾ym・- {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
    O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Documents and Settings\Katriina\Tyt臀veoh\Plugins\reg\VeohToolbar.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe"
    O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL
    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
    O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HELPAN~1\Pavilion\XPHWWBF4\plugin\bin\pchbutton.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9e.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9e.exe (User 'Default user')
    O4 - Startup: BitTorrent.lnk = C:\Program Files\BitTorrent\bittorrent.exe
    O4 - Global Startup: Exif Launcher.lnk = ?
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: OpenMG Jukebox Startup.lnk = C:\Program Files\Sony\OpenMG Jukebox\Omgtray.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: F-Secure Automatic Update (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
    O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
    O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod-palvelu (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

    --
    End of file - 10632 bytes





    ja sitten se combofix-logi (jonka siis pyöräytin jo ennen hijackthis:iä...):


    ComboFix 08-08-28.06 - Katriina 2008-08-29 17:03:39.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1035.18.698 [GMT 3:00]
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    ?:\WINDOWS\system32\ntdll.dll
    C:\Documents and Settings\Katriina\Application Data\install.dat
    C:\Documents and Settings\Katriina\Application Data\macromedia\Flash Player\#SharedObjects\6BTWNWQQ\iforex.com
    C:\Documents and Settings\Katriina\Application Data\macromedia\Flash Player\#SharedObjects\6BTWNWQQ\iforex.com\Emerp\Events\flash_object.swf\user_data.sol
    C:\Documents and Settings\Katriina\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
    C:\Documents and Settings\Katriina\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol
    C:\Documents and Settings\Katriina\Cookies\katriina@2o7[2].txt
    C:\Documents and Settings\Katriina\Cookies\katriina@clicktorrent[2].txt
    C:\Documents and Settings\Katriina\Cookies\katriina@date.ventivmedia[2].txt
    C:\Documents and Settings\Katriina\Cookies\katriina@ehg-dig.hitbox[2].txt
    C:\Documents and Settings\Katriina\Cookies\katriina@ehg-hollywoodmedia.hitbox[2].txt
    C:\Documents and Settings\Katriina\Cookies\katriina@ehg-nokiafin.hitbox[2].txt
    C:\Documents and Settings\Katriina\Cookies\katriina@insightexpressai[1].txt
    C:\Documents and Settings\Katriina\Cookies\katriina@ra01.relev-ant[1].txt
    C:\Documents and Settings\Katriina\Cookies\katriina@statcounter[1].txt
    C:\WINDOWS\Downloaded Program Files\setup.inf
    C:\WINDOWS\system32\actskn43.ocx
    C:\WINDOWS\system32\xvFn71s6.dll
    D:\Autorun.inf

    .
    ((((((((((((((((((((((((( Files Created from 2008-07-28 to 2008-08-29 )))))))))))))))))))))))))))))))
    .

    2008-08-29 15:38 . 2008-08-29 15:38 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-08-29 15:38 . 2008-08-29 15:38 <KANSIO> d-------- C:\Documents and Settings\Katriina\Application Data\Malwarebytes
    2008-08-29 15:38 . 2008-08-29 15:38 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-08-29 15:38 . 2008-08-17 15:01 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
    2008-08-29 15:38 . 2008-08-17 15:01 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
    2008-08-13 21:52 . 2008-05-01 17:32 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-08-29 13:10 81,410 ----a-w C:\WINDOWS\system32\33f8CH5O.exe
    2008-08-05 22:48 --------- d-----w C:\Documents and Settings\Katriina\Application Data\AdobeUM
    2008-07-13 22:58 29,760 ----a-w C:\WINDOWS\system32\T2Koigr7.exe
    2008-07-13 16:42 --------- d-----w C:\Documents and Settings\Eila\Application Data\AdobeUM
    2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\es.dll
    2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
    2008-06-23 16:29 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
    2008-06-20 17:41 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll
    2007-12-08 21:07 91,240 ----a-w C:\Documents and Settings\Eila\Application Data\GDIPFONTCACHEV1.DAT
    2007-10-07 14:55 91,240 ----a-w C:\Documents and Settings\Katriina\Application Data\GDIPFONTCACHEV1.DAT
    2007-09-02 13:05 75,952 ----a-w C:\Documents and Settings\Vieras\Application Data\GDIPFONTCACHEV1.DAT
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Acme.PCHButton"="C:\PROGRA~1\HELPAN~1\Pavilion\XPHWWBF4\plugin\bin\pchbutton.exe" [2004-01-01 12:57 159744]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-15 02:12 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48 36975]
    "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 17:04 52736]
    "Home Theater SchSvr"="C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe" [2004-08-20 13:42 155648]
    "WINREMOTE"="C:\Program Files\InterVideo\Common\Bin\WinRemote.exe" [2004-06-25 12:47 192512]
    "Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 21:43 233472]
    "SiS Windows KeyHook"="C:\WINDOWS\System32\keyhook.exe" [2004-05-20 10:47 249856]
    "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-06-24 22:10 339968]
    "F-Secure Manager"="C:\Program Files\F-Secure\Common\FSM32.EXE" [2003-11-17 19:34 118832]
    "F-Secure TNB"="C:\Program Files\F-Secure\TNB\TNBUtil.exe" [2003-10-28 14:10 647168]
    "REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 22:32 53248]
    "LVCOMSX"="C:\WINDOWS\System32\LVCOMSX.EXE" [2005-07-19 17:32 221184]
    "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]
    "KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 17:44 61440]
    "PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-11-08 14:27 222208]
    "NSLauncher"="C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2006-11-28 02:12 2658304]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 16:27 385024]
    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 04:22 267048]
    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-04-05 11:42 185896]
    "AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 18:06 88363 C:\WINDOWS\AGRSMMSG.exe]
    "SoundMan"="SOUNDMAN.EXE" [2004-07-01 19:58 73728 C:\WINDOWS\SOUNDMAN.EXE]
    "AlcWzrd"="ALCWZRD.EXE" [2004-07-06 02:05 2550272 C:\WINDOWS\ALCWZRD.EXE]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-11-09 18:15 1634304]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-14 17:10 68856]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "FlashPlayerUpdate"="C:\WINDOWS\system32\Macromed\Flash\FlashUtil9e.exe" [2007-11-21 03:04 218496]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "NoResolveSearch"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "msacm.divxa32"= msaud32_divx.acm

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\F-Secure\\BackWeb\\7681197\\program\\backWeb-7681197.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\MSN Messenger\\livecall.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
    "C:\\Program Files\\iTunes\\iTunes.exe"=

    R0 FSFW;F-Secure Firewall Driver;C:\WINDOWS\system32\drivers\fsdfw.sys [2003-12-01 12:18]
    R2 BackWeb Client - 7681197;F-Secure Automatic Update;C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE [2005-02-10 09:48]
    R2 F-Secure Filter;F-Secure File System Filter;C:\Program Files\F-Secure\Anti-Virus\Win2K\FSfilter.sys [2003-11-14 19:52]
    R2 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\F-Secure\Anti-Virus\Win2K\FSgk.sys [2003-11-14 13:40]
    R2 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\F-Secure\Anti-Virus\Win2K\FSrec.sys [2003-02-06 15:32]
    R3 Cap7134;ASUS TV7134 WDM Video Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys [2004-06-23 21:34]
    R3 PhTVTune;ASUS WDM TV Tuner;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys [2004-05-27 19:49]
    R3 PRISM_A00;Intersil PRISM 802.11a/g Driver;C:\WINDOWS\system32\DRIVERS\PCTELSAP.SYS [2004-01-30 06:29]
    S3 MBAMSwissArmy;MBAMSwissArmy;C:\WINDOWS\system32\drivers\mbamswissarmy.sys [2008-08-17 15:01]
    S3 MemStPCI;Sony Memory Stick controller (PCI);C:\WINDOWS\system32\DRIVERS\MemStPCI.SYS [2004-08-04 09:00]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{10a39147-3645-11dd-b939-00112f8cacd0}]
    \Shell\AutoRun\command - K:\LaunchU3.exe -a
    .
    Contents of the 'Scheduled Tasks' folder

    2008-08-21 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 15:57]
    .
    - - - - ORPHANS REMOVED - - - -

    HKCU-Run-Veoh - C:\Documents and Settings\Katriina\Ty&#58520;&#58529;t&#33216;veoh\VeohClient.exe
    HKLM-Run-BearShare - C:\Program Files\BearShare\BearShare.exe
    HKLM-Run-WinampAgent - C:\Documents and Settings\Katriina\Ty&#58520;&#58529;t&#33216;winamp\winampa.exe
    HKLM-Run-VTTimer - VTTimer.exe


    .
    ------- Supplementary Scan -------
    .
    FireFox -: Profile - C:\Documents and Settings\Katriina\Application Data\Mozilla\Firefox\Profiles\nt25d5z6.default\
    FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
    FF -: plugin - C:\Documents and Settings\Katriina\Ty&#65411;&#65398;p&#65411;&#65398;yt&#65411;&#65380;\DivX\DivX Content Uploader\npUpload.dll
    FF -: plugin - C:\Documents and Settings\Katriina\Ty&#65411;&#65398;p&#65411;&#65398;yt&#65411;&#65380;\DivX\DivX Player\npDivxPlayerPlugin.dll
    FF -: plugin - C:\Documents and Settings\Katriina\Ty&#65411;&#65398;p&#65411;&#65398;yt&#65411;&#65380;\DivX\DivX Web Player\npdivx32.dll
    FF -: plugin - C:\Documents and Settings\Katriina\Ty&#65411;&#65398;p&#65411;&#65398;yt&#65411;&#65380;\veoh\Plugins\noreg\NPVeohVersion.dll
    FF -: plugin - C:\Program Files\Adobe\Acrobat 6.0\Reader\browser\nppdf32.dll
    FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
    FF -: plugin - C:\Program Files\Java\jre1.5.0_03\bin\NPJava11.dll
    FF -: plugin - C:\Program Files\Java\jre1.5.0_03\bin\NPJava12.dll
    FF -: plugin - C:\Program Files\Java\jre1.5.0_03\bin\NPJava13.dll
    FF -: plugin - C:\Program Files\Java\jre1.5.0_03\bin\NPJava14.dll
    FF -: plugin - C:\Program Files\Java\jre1.5.0_03\bin\NPJava32.dll
    FF -: plugin - C:\Program Files\Java\jre1.5.0_03\bin\NPJPI150_03.dll
    FF -: plugin - C:\Program Files\Java\jre1.5.0_03\bin\NPOJI610.dll
    .

    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-08-29 17:13:58
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
    "VTTimer"="VTTimer.exe"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    PROCESS: C:\WINDOWS\system32\winlogon.exe
    -> C:\WINDOWS\system32\Ati2evxx.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\WINDOWS\system32\ati2evxx.exe
    C:\WINDOWS\system32\ati2evxx.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\system32\CTSVCCDA.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
    C:\Program Files\F-Secure\Anti-Virus\fsgk32.exe
    C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
    C:\Program Files\F-Secure\Common\FSMA32.exe
    C:\Program Files\F-Secure\Common\FSMB32.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\Program Files\F-Secure\Common\fch32.exe
    C:\Program Files\F-Secure\BackWeb\7681197\program\backWeb-7681197.exe
    C:\Program Files\F-Secure\Common\FAMEH32.exe
    C:\Program Files\F-Secure\Common\FNRB32.exe
    C:\Program Files\F-Secure\FWES\program\fsdfwd.exe
    C:\Program Files\F-Secure\Common\FIH32.exe
    C:\Program Files\F-Secure\Anti-Virus\FSAV32.exe
    C:\Program Files\Java\jre1.5.0_03\bin\jucheck.exe
    C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    C:\Program Files\Help and Support Additions\Pavilion\XPHWWBF4\plugin\bin\PCHButton.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\FinePixViewer\QuickDCF.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Sony\OpenMG Jukebox\Omgtray.exe
    C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
    C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
    .
    **************************************************************************
    .
    Completion time: 2008-08-29 17:22:47 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-08-29 14:22:41

    Pre-Run: 27,202,510,848 tavua vapaana
    Post-Run: 29,007,757,312 tavua vapaana

    206 --- E O F --- 2008-08-13 19:49:24




    Kiitos jo etukäteen :)
     
  2. Hujo

    Hujo Guest

    Javan päivitys ja välimuistin tyhjennys:

    Lataa JavaRa ja pura se työpöydällesi.

    ***Sulje kaikki päällä olevat Internet Explorerin ikkunat ennen jatkamista!***

    * Tuplaklikkaa JavaRa.exeä käynnistääksesi ohjelma.
    * Valitse English pudotusvalikosta valitaksesi kieleksi englannin ja klikkaa Select.
    * Klikkaa Remove Older Versions poistaaksesi vanhat Java-versiot koneeltasi.
    * Klikkaa Yes kun pyydetään. Kun JavaRa on valmis, se ilmoittaa, että lokitiedosto on luotu. Klikkaa OK.
    * Lokitiedosto avautuu. Lähetä sen sisältö seuraavassa viestissäsi.
    4. Asenna uusin Java päivitys seuraavasta linkistä..

    http://java.sun.com/javase/downloads/index.jsp

    Rullaa alas kohteeseen Java Runtime Environment (JRE) 6 Update 7
    Paina Download
    Laita Platform -kohtaan Windows
    Ruksaa I agree to the Java SE Runtime Environment 6 License Agreement ja paina Continue
    Paina Windows Offline Installationin alapuolella jre-6u4-windows-i586-p.exe

    Tallenna tiedosto vaikka työpöydälle ja asenna se.

    5. Käynnistä kone uudelleen asennuksen jälkeen.
    6. Käynnistyksen jälkeen, mene takaisin Ohjauspaneeliin ja avaa Java asetuksesi (Muita Ohjauspaneelin asetuksia -> Java kahvikuppi).
    7. General-välilehdellä klikkaa Settings. Vedä liukusäädintä (Disk Space) pienemmälle.

    (Jotkut javapohjaiset ohjelmat saattavat tarvita enemmän levytilaa.
    Jos huomaat säädön pienentämisen jälkeen koneessa hitautta, siirrä liukusäädintä isommalle).

    8. Klikkaa Delete Files -nappia. Varmista että kaikki kaksi valintaa ovat rastitettuja:
    * Applications and Applets
    * Trace and Log Files

    Ja paina OK -nappia
    Huomaa: Tämä poistaa kaikki ladatut sovellukset ja appletit VÄLIMUISTISTA.

    9. Klikkaa OK "Temporary Files Settings" -ikkunassasi.
    10. Välilehti Update: ota ruksi pois kohdasta Check for Updates automatically
    Valitse Never check
    11. Klikkaa Apply ja OK jättääksesi Java asetusikkunasi.

    ==============

    Escan
    Ohjeet tuolla sivulla.
    http://koti.mbnet.fi/pattaya1/escanmwav.htm
    lataa tuosta
    http://www.spywareinfo.dk/download/mwav.exe
    päivitä tuosta
    http://koti.mbnet.fi/pattaya1/lataus/Mwav.bat
    laita täpit merkkauksien mukaan
    http://koti.mbnet.fi/pattaya1/eScan6.jpg

    scannaa

    jos ala luukkuun tulee jotain niin kopioi se näin:
    Käytä komentoa Ctrl+A.
    Kopioi rivit komennolla Ctrl+C.
    Liitä rivit komennolla Ctrl+V.

    Laita virus log tänne.
     
  3. Tuliti

    Tuliti Member

    Joined:
    Mar 29, 2008
    Messages:
    23
    Likes Received:
    0
    Trophy Points:
    11
    oukei, eli tässä tuo javara-logi:

    JavaRa 1.11 Removal Log.

    Report follows after line.

    ------------------------------------

    The JavaRa removal process was started on Sat Aug 30 17:25:27 2008

    Found and removed: C:\Program Files\Java\j2re1.4.2_03

    Found and removed: C:\Program Files\Common Files\Java\Update\Base Images\j2re1.4.2_03-b02

    Found and removed: C:\Windows\System32\jpicpl32.cpl

    Found and removed: C:\Windows\Installer\{7148F0A8-6813-11D6-A77B-00B0D0142030}

    Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4

    Found and removed: Software\JavaSoft\Java2D\1.5.0_03

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D510003

    Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D510003

    Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D510003

    Found and removed: SOFTWARE\Classes\JavaPlugin.150_03

    Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0

    Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_03

    Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5

    Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_03

    Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D510003

    Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510003

    Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150030}

    Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7148F0A8-6813-11D6-A77B-00B0D0142030}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\Installer\Products\8A0F841731866D117AB7000B0D410203

    Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F841731866D117AB7000B0D410203

    Found and removed: SOFTWARE\Classes\JavaPlugin.142_03

    Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.4.2_03

    Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4.2_03

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.4.2_03

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_03

    Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\

    Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_03\

    Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core1.zip

    Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core2.zip

    Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core3.zip

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

    ------------------------------------

    Finished reporting.




    ja tässä tuo virus-scan:


    File C:\WINDOWS\OEM.exe.bak infected by "Trojan-Proxy.Win32.Agent.jw" Virus. Action Taken: File Deleted.
    File C:\Documents and Settings\All Users\Tiedostot\install.exe infected by "Trojan.Win32.Starter.a" Virus. Action Taken: File Deleted.
    File C:\Documents and Settings\All Users\Tiedostot\setup32.exe infected by "Net-Worm.Win32.Dedler.u" Virus. Action Taken: File Deleted.
    File C:\Documents and Settings\All Users\Tiedostot\update32.exe infected by "Trojan-DDoS.Win32.Boxed.w" Virus. Action Taken: File Deleted.
    File C:\Documents and Settings\Katriina\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmsecman.jar-69ee0e0e-60c6383e.zip infected by "Trojan-Downloader.Java.Agent.f" Virus. Action Taken: File Deleted.
    File C:\Documents and Settings\Katriina\Työpöytä\musa\jrock invasion\49 ??(???).mp3 infected by "BkCln.Unknown" Virus. Action Taken: File Renamed.
    File C:\Documents and Settings\Katriina\Työpöytä\musa\jrock invasion\50 ????(??????).mp3 infected by "BkCln.Unknown" Virus. Action Taken: File Renamed.
    File C:\System Volume Information\_restore{86283E28-56CD-405F-A5E5-91300FF64AF1}\RP938\A0367479.dll infected by "Trojan.Win32.BHO.fha" Virus. Action Taken: File Deleted.
    File C:\System Volume Information\_restore{86283E28-56CD-405F-A5E5-91300FF64AF1}\RP941\A0371599.exe infected by "Trojan-Downloader.Win32.Agent.yxn" Virus. Action Taken: File Deleted.
    File C:\System Volume Information\_restore{86283E28-56CD-405F-A5E5-91300FF64AF1}\RP942\A0371654.dll infected by "Trojan.Win32.BHO.fun" Virus. Action Taken: File Deleted.
    File C:\System Volume Information\_restore{86283E28-56CD-405F-A5E5-91300FF64AF1}\RP945\A0373931.exe infected by "Backdoor.Win32.Rbot.tas" Virus. Action Taken: File Renamed.
    File C:\System Volume Information\_restore{86283E28-56CD-405F-A5E5-91300FF64AF1}\RP956\A0381500.exe infected by "Trojan-Downloader.Win32.Agent.acfq" Virus. Action Taken: File Deleted.
    File C:\System Volume Information\_restore{86283E28-56CD-405F-A5E5-91300FF64AF1}\RP956\A0383481.exe infected by "Trojan-Downloader.Win32.Agent.acve" Virus. Action Taken: File Deleted.
    File C:\System Volume Information\_restore{86283E28-56CD-405F-A5E5-91300FF64AF1}\RP957\A0383537.exe infected by "Trojan-Downloader.Win32.Agent.admz" Virus. Action Taken: File Deleted.
    File C:\System Volume Information\_restore{86283E28-56CD-405F-A5E5-91300FF64AF1}\RP959\A0385810.exe infected by "Trojan.Win32.Starter.a" Virus. Action Taken: File Deleted.
    File C:\System Volume Information\_restore{86283E28-56CD-405F-A5E5-91300FF64AF1}\RP959\A0385811.exe infected by "Net-Worm.Win32.Dedler.u" Virus. Action Taken: File Deleted.
    File C:\System Volume Information\_restore{86283E28-56CD-405F-A5E5-91300FF64AF1}\RP959\A0385812.exe infected by "Trojan-DDoS.Win32.Boxed.w" Virus. Action Taken: File Deleted.
    File C:\t.inx infected by "Trojan-Downloader.Win32.Tibs.cu" Virus. Action Taken: File Deleted.
     
  4. Hujo

    Hujo Guest

    Lataa SDFix by AndyManchesta ja tallenna se työpöydällesi.

    Käynnistä koneesi vikasietotilaan:

    sammuta ja käynnistä
    käynnistyksen yhteydessä hakkaa F8 nappia
    valitse nuolinäppäimellä vikasietotila
    paina enter ja enter
    valitse käyttäjätilisi
    paina kyllä

    Jossakin koneissa hakataan F8:sin sijasta F5:tä

    " Kun vikasietotilassa, pura tiedoston SDFix.zip sisältö (SDFix kansio) työpöydällesi. Työpöydälle pitäisi ilmestyä kansio nimeltä SDFix.
    " Avaa SDFix-kansio ja tuplaklikkaa tiedostoa RunThis.bat käynnistääksesi ohjelman.
    " Paina Y käynnistääksesi skriptin.
    " Työkalu puhdistaa troijalaisen palvelut ja tekee myös joitakin korjauksia rekisteriin. Lopuksi se pyytää käynnistämään koneen uudelleen, "Press any key to Reboot".
    " Paina mitä tahansa näppäintä ja kone käynnistyy uudelleen.
    " Käynnistyminen kestää normaalia kauemmin sillä SDFix puhdistaa konetta.
    " Kun kone on käynnistynyt ja työpöytä latautunut, SDFix kertoo että puhdistus on suoritettu, "Finished".
    " Paina sitten mitä tahansa näppäintä sulkeaksesi skriptin ja ladataksesi pikakuvakkeet työpöydälle.
    " Lopuksi avaa SDFix kansio (työpöydällä) ja kopioi & liitä tiedoston Report.txt sisältö viestiketjuusi uuden HijackThis:n lokin kera.
     
  5. Tuliti

    Tuliti Member

    Joined:
    Mar 29, 2008
    Messages:
    23
    Likes Received:
    0
    Trophy Points:
    11
    eli tässä on SDFix:in Report:

    SDFix: Version 1.220
    Run by Katriina on su 31.08.2008 at 15:17

    Microsoft Windows XP [versio 5.1.2600]
    Running From: C:\Documents and Settings\Katriina\Ty”p”yt„\SDFix

    Checking Services :


    Restoring Default Security Values
    Restoring Default Hosts File

    Rebooting


    Checking Files :

    No Trojan Files Found






    Removing Temp Files

    ADS Check :



    Final Check :

    catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-08-31 15:32:15
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden services & system hive ...

    scanning hidden registry entries ...

    scanning hidden files ...

    C:\Documents and Settings\Katriina\Työpöytä\uudempia ei sv kesken olevia\koi suru boukun- tyrant who fall in love(shattered tai bibibloeros kai)\The_Tyrant_who_Fall_in_Love_Vol_2\The_tyrant_who_fall_in_love_v02_c01\The tyrant who fall in love v02 c01\Thumbs.db:encryptable 0 bytes hidden from API

    scan completed successfully
    hidden processes: 0
    hidden services: 0
    hidden files: 1


    Remaining Services :




    Authorized Application Key Export:

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019"
    "C:\\Program Files\\F-Secure\\BackWeb\\7681197\\program\\backWeb-7681197.exe"="C:\\Program Files\\F-Secure\\BackWeb\\7681197\\program\\backWeb-7681197.exe:*:Disabled:backWeb-7681197"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000"
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
    "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
    "C:\\Kaspersky\\kavupd.exe"="C:\\Kaspersky\\kavupd.exe:*:Enabled:kavupd"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000"
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

    Remaining Files :



    Files with Hidden Attributes :

    Tue 14 Dec 2004 196 A.SHR --- "C:\BOOT.BAK"
    Sat 15 Oct 2005 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
    Sun 6 Aug 2006 401 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv16.bak"
    Thu 15 Dec 2005 401 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv17.bak"
    Sun 9 Dec 2007 44,032 ...H. --- "C:\Documents and Settings\All Users\Tiedostot\~WRL0001.tmp"
    Tue 11 Dec 2007 44,544 ...H. --- "C:\Documents and Settings\All Users\Tiedostot\~WRL0002.tmp"
    Tue 11 Dec 2007 45,056 ...H. --- "C:\Documents and Settings\All Users\Tiedostot\~WRL0003.tmp"
    Tue 11 Dec 2007 44,032 ...H. --- "C:\Documents and Settings\All Users\Tiedostot\~WRL0004.tmp"
    Sat 8 Dec 2007 31,232 ...H. --- "C:\Documents and Settings\All Users\Tiedostot\~WRL0020.tmp"
    Tue 11 Dec 2007 44,544 ...H. --- "C:\Documents and Settings\All Users\Tiedostot\~WRL0064.tmp"
    Sat 8 Dec 2007 29,184 ...H. --- "C:\Documents and Settings\All Users\Tiedostot\~WRL0079.tmp"
    Tue 11 Dec 2007 44,032 ...H. --- "C:\Documents and Settings\All Users\Tiedostot\~WRL1045.tmp"
    Sat 8 Dec 2007 24,064 ...H. --- "C:\Documents and Settings\All Users\Tiedostot\~WRL1979.tmp"
    Sat 8 Dec 2007 34,304 ...H. --- "C:\Documents and Settings\All Users\Tiedostot\~WRL2712.tmp"
    Wed 12 Dec 2007 45,056 ...H. --- "C:\Documents and Settings\All Users\Tiedostot\~WRL2789.tmp"
    Wed 12 Dec 2007 45,056 ...H. --- "C:\Documents and Settings\All Users\Tiedostot\~WRL3084.tmp"
    Tue 11 Dec 2007 45,056 ...H. --- "C:\Documents and Settings\All Users\Tiedostot\~WRL3268.tmp"
    Tue 11 Dec 2007 44,544 ...H. --- "C:\Documents and Settings\All Users\Tiedostot\~WRL3338.tmp"
    Wed 12 Dec 2007 44,544 ...H. --- "C:\Documents and Settings\All Users\Tiedostot\~WRL3433.tmp"
    Tue 24 Oct 2006 25,088 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0003.tmp"
    Sat 23 Apr 2005 88,576 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0004.tmp"
    Sat 4 Mar 2006 26,624 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0086.tmp"
    Sun 24 Apr 2005 95,232 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0089.tmp"
    Sun 24 Apr 2005 101,888 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0096.tmp"
    Sun 24 Apr 2005 102,400 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0161.tmp"
    Sun 24 Apr 2005 99,840 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0164.tmp"
    Mon 19 Dec 2005 396,288 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0212.tmp"
    Tue 24 Oct 2006 31,232 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0229.tmp"
    Mon 19 Dec 2005 338,432 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0333.tmp"
    Tue 24 Oct 2006 51,200 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0340.tmp"
    Mon 19 Dec 2005 338,944 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0387.tmp"
    Sun 24 Apr 2005 94,208 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0419.tmp"
    Sun 24 Apr 2005 1,113,600 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0428.tmp"
    Mon 19 Dec 2005 397,824 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0433.tmp"
    Sun 24 Apr 2005 90,624 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0467.tmp"
    Mon 19 Dec 2005 338,944 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0492.tmp"
    Tue 24 Oct 2006 54,272 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0510.tmp"
    Mon 19 Dec 2005 338,432 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0540.tmp"
    Mon 19 Dec 2005 397,824 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0542.tmp"
    Sun 24 Apr 2005 99,840 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0546.tmp"
    Sun 24 Apr 2005 2,286,592 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0614.tmp"
    Tue 24 Oct 2006 53,248 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0652.tmp"
    Mon 19 Dec 2005 394,752 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0654.tmp"
    Mon 19 Dec 2005 340,480 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0693.tmp"
    Mon 19 Dec 2005 337,920 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0702.tmp"
    Sun 24 Apr 2005 956,928 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0745.tmp"
    Mon 19 Dec 2005 337,920 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0774.tmp"
    Sat 4 Mar 2006 25,600 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0789.tmp"
    Mon 19 Dec 2005 394,752 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0824.tmp"
    Sun 24 Apr 2005 742,912 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0825.tmp"
    Tue 24 Oct 2006 27,136 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0845.tmp"
    Mon 19 Dec 2005 338,944 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0879.tmp"
    Sun 24 Apr 2005 101,376 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0935.tmp"
    Mon 19 Dec 2005 338,944 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0945.tmp"
    Sun 24 Apr 2005 101,888 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0952.tmp"
    Mon 19 Dec 2005 337,920 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0953.tmp"
    Mon 19 Dec 2005 342,016 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL0960.tmp"
    Sun 24 Apr 2005 3,685,376 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1052.tmp"
    Sun 24 Apr 2005 2,177,536 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1086.tmp"
    Sun 24 Apr 2005 3,685,376 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1088.tmp"
    Mon 19 Dec 2005 339,456 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1092.tmp"
    Sun 24 Apr 2005 101,376 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1103.tmp"
    Sat 4 Mar 2006 26,624 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1104.tmp"
    Mon 19 Dec 2005 339,456 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1113.tmp"
    Tue 24 Oct 2006 52,736 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1135.tmp"
    Mon 19 Dec 2005 400,384 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1150.tmp"
    Sun 24 Apr 2005 90,624 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1158.tmp"
    Sun 24 Apr 2005 90,112 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1184.tmp"
    Mon 19 Dec 2005 339,456 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1224.tmp"
    Sat 4 Mar 2006 25,600 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1230.tmp"
    Mon 19 Dec 2005 338,944 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1320.tmp"
    Sun 24 Apr 2005 742,400 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1323.tmp"
    Mon 19 Dec 2005 350,720 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1325.tmp"
    Sun 24 Apr 2005 97,280 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1365.tmp"
    Sun 24 Apr 2005 3,875,328 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1407.tmp"
    Mon 19 Dec 2005 400,384 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1439.tmp"
    Mon 19 Dec 2005 339,968 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1445.tmp"
    Mon 19 Dec 2005 396,288 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1456.tmp"
    Tue 24 Oct 2006 29,696 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1460.tmp"
    Mon 19 Dec 2005 344,064 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1468.tmp"
    Mon 19 Dec 2005 338,944 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1469.tmp"
    Mon 19 Dec 2005 351,232 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1480.tmp"
    Sun 24 Apr 2005 100,352 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1489.tmp"
    Sun 24 Apr 2005 92,672 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1568.tmp"
    Tue 24 Oct 2006 31,232 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1571.tmp"
    Sun 24 Apr 2005 103,424 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1623.tmp"
    Tue 24 Oct 2006 27,648 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1633.tmp"
    Sun 24 Apr 2005 101,376 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1648.tmp"
    Sun 24 Apr 2005 1,960,448 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1656.tmp"
    Tue 24 Oct 2006 28,160 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1668.tmp"
    Sun 24 Apr 2005 3,947,520 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1670.tmp"
    Sun 24 Apr 2005 100,864 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1732.tmp"
    Mon 19 Dec 2005 339,456 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1751.tmp"
    Sun 24 Apr 2005 96,768 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1754.tmp"
    Tue 24 Oct 2006 31,232 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1793.tmp"
    Sun 24 Apr 2005 99,328 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1806.tmp"
    Sun 24 Apr 2005 101,376 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1838.tmp"
    Sun 24 Apr 2005 97,280 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1852.tmp"
    Mon 19 Dec 2005 397,824 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1860.tmp"
    Mon 19 Dec 2005 338,944 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1867.tmp"
    Sun 9 Apr 2006 310,784 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1877.tmp"
    Tue 24 Oct 2006 52,224 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1903.tmp"
    Tue 24 Oct 2006 27,136 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1959.tmp"
    Tue 24 Oct 2006 31,232 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1964.tmp"
    Mon 19 Dec 2005 339,968 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1983.tmp"
    Sat 4 Mar 2006 26,624 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1987.tmp"
    Tue 24 Oct 2006 26,112 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL1988.tmp"
    Tue 24 Oct 2006 26,624 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2000.tmp"
    Mon 19 Dec 2005 339,456 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2003.tmp"
    Mon 19 Dec 2005 338,944 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2043.tmp"
    Sat 4 Mar 2006 27,648 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2061.tmp"
    Mon 19 Dec 2005 398,336 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2075.tmp"
    Mon 19 Dec 2005 338,944 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2104.tmp"
    Sun 24 Apr 2005 102,400 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2121.tmp"
    Tue 24 Oct 2006 29,184 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2173.tmp"
    Mon 19 Dec 2005 398,336 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2191.tmp"
    Mon 19 Dec 2005 338,944 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2259.tmp"
    Sat 4 Mar 2006 29,184 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2351.tmp"
    Sat 4 Mar 2006 29,184 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2362.tmp"
    Sun 24 Apr 2005 615,424 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2366.tmp"
    Mon 19 Dec 2005 341,504 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2367.tmp"
    Sat 4 Mar 2006 28,672 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2368.tmp"
    Tue 24 Oct 2006 31,232 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2407.tmp"
    Sun 24 Apr 2005 101,888 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2435.tmp"
    Mon 19 Dec 2005 338,432 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2518.tmp"
    Sun 24 Apr 2005 90,624 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2539.tmp"
    Mon 19 Dec 2005 343,552 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2540.tmp"
    Mon 19 Dec 2005 343,552 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2548.tmp"
    Sun 24 Apr 2005 92,160 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2567.tmp"
    Sun 24 Apr 2005 915,456 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2584.tmp"
    Tue 24 Oct 2006 26,112 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2619.tmp"
    Tue 24 Oct 2006 29,184 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2669.tmp"
    Sun 24 Apr 2005 90,112 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2676.tmp"
    Mon 19 Dec 2005 337,920 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2682.tmp"
    Sun 24 Apr 2005 90,624 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2742.tmp"
    Sun 24 Apr 2005 614,912 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2756.tmp"
    Mon 19 Dec 2005 338,944 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2764.tmp"
    Tue 24 Oct 2006 28,160 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2770.tmp"
    Tue 24 Oct 2006 31,232 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2782.tmp"
    Mon 19 Dec 2005 338,432 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2802.tmp"
    Tue 24 Oct 2006 54,272 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2825.tmp"
    Tue 24 Oct 2006 25,088 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2849.tmp"
    Tue 24 Oct 2006 30,208 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2898.tmp"
    Sun 24 Apr 2005 3,742,720 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2912.tmp"
    Mon 19 Dec 2005 338,944 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2915.tmp"
    Mon 19 Dec 2005 396,288 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2973.tmp"
    Sun 24 Apr 2005 3,695,616 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL2981.tmp"
    Sun 24 Apr 2005 90,112 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3033.tmp"
    Tue 24 Oct 2006 31,232 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3076.tmp"
    Sun 24 Apr 2005 101,888 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3149.tmp"
    Mon 19 Dec 2005 338,944 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3156.tmp"
    Sun 24 Apr 2005 90,624 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3158.tmp"
    Sun 24 Apr 2005 97,280 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3180.tmp"
    Sun 24 Apr 2005 398,848 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3183.tmp"
    Tue 24 Oct 2006 30,720 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3187.tmp"
    Mon 19 Dec 2005 396,288 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3205.tmp"
    Sun 24 Apr 2005 2,139,648 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3263.tmp"
    Tue 24 Oct 2006 26,624 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3272.tmp"
    Mon 19 Dec 2005 398,336 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3322.tmp"
    Mon 19 Dec 2005 339,456 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3346.tmp"
    Sun 7 Jan 2007 2,297,856 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3369.tmp"
    Mon 19 Dec 2005 339,456 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3381.tmp"
    Mon 19 Dec 2005 337,408 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3388.tmp"
    Tue 24 Oct 2006 28,672 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3417.tmp"
    Sun 24 Apr 2005 3,876,864 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3441.tmp"
    Sat 4 Mar 2006 29,184 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3462.tmp"
    Sun 24 Apr 2005 3,504,640 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3489.tmp"
    Sun 24 Apr 2005 102,400 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3536.tmp"
    Sat 4 Mar 2006 25,088 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3568.tmp"
    Sun 24 Apr 2005 92,160 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3592.tmp"
    Mon 19 Dec 2005 338,944 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3638.tmp"
    Sun 24 Apr 2005 158,720 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3652.tmp"
    Mon 19 Dec 2005 338,432 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3703.tmp"
    Mon 19 Dec 2005 399,872 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3753.tmp"
    Sun 24 Apr 2005 90,624 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3758.tmp"
    Mon 19 Dec 2005 339,968 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3804.tmp"
    Mon 19 Dec 2005 396,288 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3864.tmp"
    Sun 24 Apr 2005 301,056 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3882.tmp"
    Sat 4 Mar 2006 28,672 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3939.tmp"
    Sun 24 Apr 2005 1,870,848 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3942.tmp"
    Mon 19 Dec 2005 339,968 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3969.tmp"
    Sun 24 Apr 2005 97,280 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3971.tmp"
    Sun 24 Apr 2005 1,113,600 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL3982.tmp"
    Sun 24 Apr 2005 101,376 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL4013.tmp"
    Tue 24 Oct 2006 51,712 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL4058.tmp"
    Sun 4 Dec 2005 342,528 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL4070.tmp"
    Mon 19 Dec 2005 337,920 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL4087.tmp"
    Sun 24 Apr 2005 915,968 ...H. --- "C:\Documents and Settings\Katriina\Ty”p”yt„\~WRL4095.tmp"
    Thu 1 May 2008 24,064 ...H. --- "C:\Documents and Settings\Eila\Omat tiedostot\dvd\~WRL0004.tmp"
    Wed 7 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\e2cdfda265544b05233b12ad6d933aba\BIT52A.tmp"
    Mon 12 Feb 2007 3,096,576 A..H. --- "C:\Documents and Settings\Katriina\Application Data\U3\temp\Launchpad Removal.exe"

    Finished!

    ja sitten hijackthis:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 15:44:18, on 31.8.2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
    C:\WINDOWS\System32\CTsvcCDA.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
    C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
    C:\Program Files\F-Secure\Common\FSMA32.EXE
    C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
    C:\Program Files\F-Secure\Common\FSMB32.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\F-Secure\Common\FCH32.EXE
    C:\Program Files\F-Secure\BackWeb\7681197\Program\BackWeb-7681197.exe
    C:\Program Files\F-Secure\Common\FAMEH32.EXE
    C:\Program Files\F-Secure\Common\FNRB32.EXE
    C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    C:\Program Files\F-Secure\Common\FIH32.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\notepad.exe
    C:\windows\system\hpsysdrv.exe
    C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe
    C:\Program Files\InterVideo\Common\Bin\WinRemote.exe
    C:\WINDOWS\System32\keyhook.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\WINDOWS\ALCWZRD.EXE
    C:\Program Files\F-Secure\Common\FSM32.EXE
    C:\WINDOWS\System32\LVCOMSX.EXE
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
    C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\PROGRA~1\HELPAN~1\Pavilion\XPHWWBF4\plugin\bin\pchbutton.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    C:\Program Files\FinePixViewer\QuickDCF.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Sony\OpenMG Jukebox\Omgtray.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FI_FI&c=Q404&bd=pavilion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O3 - Toolbar: HP-näkymä - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
    O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Documents and Settings\Katriina\Työpöytä\veoh\Plugins\reg\VeohToolbar.dll
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe"
    O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL
    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
    O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HELPAN~1\Pavilion\XPHWWBF4\plugin\bin\pchbutton.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9e.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9e.exe (User 'Default user')
    O4 - Startup: BitTorrent.lnk = C:\Program Files\BitTorrent\bittorrent.exe
    O4 - Global Startup: Exif Launcher.lnk = ?
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: OpenMG Jukebox Startup.lnk = C:\Program Files\Sony\OpenMG Jukebox\Omgtray.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: F-Secure Automatic Update (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
    O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
    O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod-palvelu (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

    --
    End of file - 10265 bytes
     
  6. Hujo

    Hujo Guest

    1. Klikkaa käynnistä > Oma tietokone oikean puoleisella hiiren napilla
    2. Valitse ominaisuudet
    3. Valitse järjestelmän palauttaminen välilehti
    4. Ruksi eteen ¤ poista järjestelmän palauttaminen kaikissa asemissa
    5. Paina Käytä
    6. Paina ok
    7. Sammuta ja käynnistä
    8. Ota ruksi pois ¤ poista järjestelmän palauttaminen kaikissa asemissa
    9. Käytä ja OK
     
  7. Tuliti

    Tuliti Member

    Joined:
    Mar 29, 2008
    Messages:
    23
    Likes Received:
    0
    Trophy Points:
    11
    Ok, tehty. Onko vielä jotain tehtävää?
     
  8. Hujo

    Hujo Guest

    Lataa OTMoveIt
    OTMoveIt ja tallenna se työpöydällesi.

    Tuplaklikkaa OTMoveIt.exe.
    Klikkaa CleanUp!.
    Valitse Yes kun kysytään "Begin cleanup Process?".
    Jos pyydetään, että saako koneen käynnistää uudeelleen, valitse Yes.OTMoveIt poistaa itsensä kun se on valmis, jos näin ei käy poista se itse.

    HUOM: Jos palomuurisi tai joku muu tietoturvaohjelma varoittaa, että OTMoveIt yrittää päästä nettin, niin anna sen päästä sinne.


    ===============

    Lataa Tästä Ccleaner
    CCleaner v2.05.555- Standard Build, ÄLÄ aseenna Yahoo toolbaria!
    Asennuksessa poista merkki/rasti kohdasta "asenna Yahoo! toolbar/työkalupalkki".
    Asennuksen jälkeen aukaise CCleaner.
    Valitse vasemmalta pystyrivistä Options.
    Valitse viereisestä pystyrivistä Settings.
    Language kohtaan valitse Suomi.

    Puhdistaja
    Valitse vasemmalta pystyrivistä Puhdistaja.
    Paina alhaalta Tutki.
    Nyt CCleaner tutkii, mitä voidaan poistaa (tempit, cookiessit jne.).
    Kun tutkiminen on valmis, paina Aja CCleaner.
    Nyt CCleaner poistaa löydetyt tempit, cookiessit jne.

    Rekisterin virheiden korjaus
    Valitse vasemmalta pystyrivistä Rekisteri.
    Paina alhaalta Etsi rekisterin virheitä.
    Kun etsintä on valmis ja olet varma, että haluat korjata ne rivit jotka ovat merkattuja, niin paina Korjaa valitut rekisterin virheet.
    Sinulta kysytään "haluatko varmuuskopioida muutokset rekisteriin", paina Kyllä. Tallenna varmuuskopio vaikka "Omat tiedostot" -kansioon.
    Klikkaa uudesta aukeavasta ikkunasta Korjaa kaikki valitut virheet.
    Saat vielä varmistus kysymyksen, paina Ok.
    Kun virheet on korjattu, paina Sulje.
    Nyt voit sulkea CCleanerin painamalla oikealta ylhäältä punaista rastia.
     
  9. Tuliti

    Tuliti Member

    Joined:
    Mar 29, 2008
    Messages:
    23
    Likes Received:
    0
    Trophy Points:
    11
    Nämäkin on nyt tehty. Onko vielä muita ohjeita?
     
  10. Hujo

    Hujo Guest

    eipä muuta
     
  11. Tuliti

    Tuliti Member

    Joined:
    Mar 29, 2008
    Messages:
    23
    Likes Received:
    0
    Trophy Points:
    11
    Selvä. Kiitoksia paljon avusta! :)
     

Share This Page