Voisko joku jeesata. Kone hidastelee ja ruudun alapalkki on hieman sumea. Spypot löytää Safe Erroria ja Smitfraud-C.Toolbar888. Tässä loki: Logfile of HijackThis v1.99.1 Scan saved at 15:12:48, on 22.12.2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0011) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe C:\Program Files\Ahead\InCD\InCD.exe C:\Program Files\D-Tools\daemon.exe C:\WINDOWS\system32\ezSP_Px.exe C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\Logitech\Video\LogiTray.exe C:\Program Files\F-Secure Anti-Virus\Common\FSM32.EXE C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe C:\Program Files\Winamp\winampa.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe D:\VolumeWatcher\SPUVolumeWatcher.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure Anti-Virus\backweb\4476822\program\fsbwsys.exe C:\Program Files\F-Secure Anti-Virus\Anti-Virus\FSGK32.EXE C:\Program Files\F-Secure Anti-Virus\Common\FSMA32.EXE C:\Program Files\F-Secure Anti-Virus\Common\FSMB32.EXE C:\WINDOWS\System32\svchost.exe C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fssm32.exe C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Program\fspex.exe C:\Program Files\F-Secure Anti-Virus\Common\FCH32.EXE C:\Program Files\F-Secure Anti-Virus\Common\FAMEH32.EXE C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsqh.exe C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsrw.exe C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsav32.exe C:\Program Files\F-Secure Anti-Virus\FWES\Program\fsdfwd.exe C:\PROGRA~1\F-SECU~1\ANTI-S~1\fsaw.exe C:\Program Files\F-Secure Anti-Virus\FSGUI\fsguidll.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Documents and Settings\Seija\Työpöytä\HijackThis_v1.99.1.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe" O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Anti-Virus\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Anti-Virus\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Anti-Virus\FSGUI\FSSW.EXE" /reboot O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [News Service] "C:\Program Files\F-Secure Anti-Virus\FSGUI\ispnews.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [TypingSatellite] "C:\Program Files\TypingMaster\KBOOST.EXE" O4 - HKCU\..\Run: [LDM] \Program\ O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe O4 - Startup: Cyber-shot Viewer Media Check Tool.lnk = D:\VolumeWatcher\SPUVolumeWatcher.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O4 - Global Startup: F-Secure 2006.lnk = C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Program\fspex.exe O8 - Extra context menu item: &Estä tämä kohoikkuna - C:\Program Files\F-Secure Anti-Virus\Anti-Spyware\blockpopups.htm O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll O9 - Extra button: IE-suojaus - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Anti-Virus\Anti-Spyware\ieshield.dll O9 - Extra 'Tools' menuitem: IE-suojaus... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Anti-Virus\Anti-Spyware\ieshield.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Broken Internet access because of LSP provider 'xfire_lsp_11078.dll' missing O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1092985043656 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab O18 - Protocol: bw+0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw+0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O18 - Protocol: bwg0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwg0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0s - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: offline-8876480 - {8C35B13B-AC5A-4A6C-950E-C2F61EC1DDA1} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: F-Secure 2006 (BackWeb Plug-in - 4476822) - F-Secure Internet Security 2005 - C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corporation - C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsgk32st.exe O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure Anti-Virus\backweb\4476822\program\fsbwsys.exe O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Anti-Virus\FWES\Program\fsdfwd.exe O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\F-Secure Anti-Virus\Common\FSMA32.EXE O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Moi! Siirrä HijackThis.exe omaan kansioo malli C:\HJT\HijackThis.exe ja sitten Lataa SmitfraudFix (by S!Ri) työpöydällesi. Tuplaklikkaa tiedostoa SmitfraudFix.exe Valitse optio #1 - Search kirjoittamalla 1 ja painamalla "Enter"; tekstitiedosto avautuu, joka listaa tarttuneet tiedostot (jos olemassa). Postita tämän tekstitiedoston sisältö viestiketjuusi. **Jos työkalu ei käynnisty työpöydältä niin siirrä SmitfraudFix.exe suoraan järjestelmäaseman juureen (yleensä C:). Kokeile sitten käynnistää ohjelma uudestaan sieltä. Huomaa : process.exe filun tunnistaa jotkut Anti-virus ohjelmat (AntiVir, Dr.Web, Kaspersky) "Haittakaluna"; se ei ole virus, vaan ohjelma joka pysäyttää prosesseja. A/V ohjelmat eivät pysty tunnistamaan hyvän ja pahan käytön tälläisten ohjelmian väliltä, silloin ne saattavat varoittaa käyttäjää. http://www.beyondlogic.org/consulting/processutil/processutil.htm Lähetä uusi hjt-logi ja smittfraud-logi
Tuossa ois smitfraud loki: SmitFraudFix v2.131 Scan done at 15:25:31,06, ti 26.12.2006 Run from C:\Documents and Settings\Seija\Ty”p”yt„\SmitfraudFix OS: Microsoft Windows XP [versio 5.1.2600] - Windows_NT The filesystem type is FAT32 Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Seija »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Seija\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\SEIJA\SUOSIKIT »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End Ja tuossa uus HJT: Logfile of HijackThis v1.99.1 Scan saved at 15:28:42, on 26.12.2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0011) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe C:\Program Files\Ahead\InCD\InCD.exe C:\Program Files\D-Tools\daemon.exe C:\WINDOWS\system32\ezSP_Px.exe C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\Logitech\Video\LogiTray.exe C:\Program Files\F-Secure Anti-Virus\Common\FSM32.EXE C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe C:\Program Files\Logitech\Video\FxSvr2.exe D:\VolumeWatcher\SPUVolumeWatcher.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure Anti-Virus\backweb\4476822\program\fsbwsys.exe C:\Program Files\F-Secure Anti-Virus\Anti-Virus\FSGK32.EXE C:\Program Files\F-Secure Anti-Virus\Common\FSMA32.EXE C:\Program Files\F-Secure Anti-Virus\Common\FSMB32.EXE C:\WINDOWS\System32\svchost.exe C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fssm32.exe C:\Program Files\F-Secure Anti-Virus\Common\FCH32.EXE C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Program\fspex.exe C:\Program Files\F-Secure Anti-Virus\Common\FAMEH32.EXE C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsqh.exe C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsrw.exe C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsav32.exe C:\Program Files\F-Secure Anti-Virus\FWES\Program\fsdfwd.exe C:\PROGRA~1\F-SECU~1\ANTI-S~1\fsaw.exe C:\Program Files\F-Secure Anti-Virus\FSGUI\fsguidll.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Internet Explorer\iexplore.exe C:\HJT\HijackThis_v1.99.1.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe" O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Anti-Virus\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Anti-Virus\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Anti-Virus\FSGUI\FSSW.EXE" /reboot O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [News Service] "C:\Program Files\F-Secure Anti-Virus\FSGUI\ispnews.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [TypingSatellite] "C:\Program Files\TypingMaster\KBOOST.EXE" O4 - HKCU\..\Run: [LDM] \Program\ O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe O4 - Startup: Cyber-shot Viewer Media Check Tool.lnk = D:\VolumeWatcher\SPUVolumeWatcher.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O4 - Global Startup: F-Secure 2006.lnk = C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Program\fspex.exe O8 - Extra context menu item: &Estä tämä kohoikkuna - C:\Program Files\F-Secure Anti-Virus\Anti-Spyware\blockpopups.htm O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll O9 - Extra button: IE-suojaus - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Anti-Virus\Anti-Spyware\ieshield.dll O9 - Extra 'Tools' menuitem: IE-suojaus... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Anti-Virus\Anti-Spyware\ieshield.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Broken Internet access because of LSP provider 'xfire_lsp_11078.dll' missing O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1092985043656 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: F-Secure 2006 (BackWeb Plug-in - 4476822) - F-Secure Internet Security 2005 - C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corporation - C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsgk32st.exe O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure Anti-Virus\backweb\4476822\program\fsbwsys.exe O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Anti-Virus\FWES\Program\fsdfwd.exe O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\F-Secure Anti-Virus\Common\FSMA32.EXE O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Moi! Smitfraudia ei löytynyt ja loki on ok.kokeillaan vielä toinen ohjelma * Lataa Dr.Web CureIt työpöydälle: ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe [*]Tuplaklikkaa drweb-cureit.exe ja anna sen tehdä express scan [*]Se skannaa käynnissä olevat ohjelmat ja jos jotain löytyy, klikkaa yes kun se kysyy haluatko poistaa sen. Tämä on vain lyhyt scan. [*]Kun scan on valmis, merkkaa asemat, jotka haluat scannata. [*]Valitse kaikki asemat. Punainen piste osoittaa, mitkä asemat on valittu. [*]Klikaa vihreää nuolta oikealla ja scan alkaa. [*]Klikkaa 'Yes to all', jos kysytään haluatko poistaa/siirtää tiedoston. [*]Kun scan on valmis, katso voitko klikata next-kuvaketta löytyneiden tiedostojen vieressä: [*]Jos asia on niin, klikkaa sitä ja sitten klikkaa next-kuvaketta oikealla alhaalla ja valitse Move incurable kuten alla olevalla kuvassa: Tämä siirtää sen %userprofile%\DoctorWeb\quarantine-hakemistoon. [*]Tämän jälkeen klikkaa Dr.Web CureIt-valikossa file ja valitse save report list [*]Tallenna raportti työpöydälle. Raportin nimi on DrWeb.csv [*]Sulje Dr.Web Cureit. [*]Käynnistä kone uudelleen !! Tämä siksi, että käytössä olevat tiedostot poistetaan/siirretään käynnistyksen yhteydessä. [*]Käynnistyksen jälkeen liitä Dr.Web-lokin, jonka tallensit aiemmin, sisältö seuraavaan vastaukseesi.
Morjesta! Löytyskö tuosta mitään erikoista? ============================================================================= Dr.Web(R) Scanner for Windows v4.33.2 (4.33.2.10060) Copyright (c) Igor Daniloff, 1992-2006 Log generated on: 2006-12-29, 12:06:36 [KAUPPI][Seija] Command-line: "C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\cureit.exe" /lng /ini:cureit_XP.ini Operating system:Windows XP Home Edition x86 (Build 2600), Service Pack 2 ============================================================================= Engine version: 4.33 (4.33.5.10110) Engine API version: 2.01 [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crwtoday.cdb - 745 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43367.cdb - 1834 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43366.cdb - 4015 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43365.cdb - 1342 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43364.cdb - 1335 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43363.cdb - 1152 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43362.cdb - 1006 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43361.cdb - 879 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43360.cdb - 988 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43359.cdb - 1205 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43358.cdb - 1139 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43357.cdb - 1302 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43356.cdb - 1332 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43355.cdb - 2456 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43354.cdb - 1283 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43353.cdb - 795 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43352.cdb - 2016 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43351.cdb - 941 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43350.cdb - 1020 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43349.cdb - 1008 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43348.cdb - 1096 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43347.cdb - 707 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43346.cdb - 1428 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43345.cdb - 1358 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43344.cdb - 694 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43343.cdb - 1186 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43342.cdb - 744 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43341.cdb - 841 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43340.cdb - 822 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43339.cdb - 1071 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43338.cdb - 989 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43337.cdb - 855 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43336.cdb - 1297 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43335.cdb - 1195 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43334.cdb - 900 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43333.cdb - 1381 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43332.cdb - 1340 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43331.cdb - 2735 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43330.cdb - 2078 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43329.cdb - 2490 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43328.cdb - 743 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43327.cdb - 958 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43326.cdb - 793 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43325.cdb - 713 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43324.cdb - 655 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43323.cdb - 655 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43322.cdb - 778 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43321.cdb - 846 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43320.cdb - 808 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43319.cdb - 764 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43318.cdb - 838 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43317.cdb - 363 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43316.cdb - 730 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43315.cdb - 627 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43314.cdb - 824 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43313.cdb - 842 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43312.cdb - 830 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43311.cdb - 862 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43310.cdb - 853 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43309.cdb - 733 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43308.cdb - 708 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43307.cdb - 839 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43306.cdb - 930 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43305.cdb - 759 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43304.cdb - 721 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43303.cdb - 638 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43302.cdb - 806 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43301.cdb - 504 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crw43300.cdb - 24 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crwebase.cdb - 78674 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\cwrtoday.cdb - 366 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\cwr43301.cdb - 697 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crwrisky.cdb - 1271 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\cwntoday.cdb - 338 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\cwn43306.cdb - 781 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\cwn43305.cdb - 752 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\cwn43304.cdb - 793 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\cwn43303.cdb - 766 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\cwn43302.cdb - 850 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\cwn43301.cdb - 772 virus records [Virus base] C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\crwnasty.cdb - 4867 virus records Total virus records: 165071 Key file: C:\DOCUME~1\Seija\LOCALS~1\Temp\RarSFX0\cureit.key License key number: 0000000010 Registered to: Dr.Web CureIt Project License key activates: 2005-03-05 License key expires: 2007-03-05 ----------------------------------------------------------------------------- Scan statistics ----------------------------------------------------------------------------- Objects scanned: 0 Infected objects found: 0 Objects with modifications found: 0 Suspicious objects found: 0 Adware programs found: 0 Dialer programs found: 0 Joke programs found: 0 Riskware programs found: 0 Hacktool programs found: 0 Objects cured: 0 Objects deleted: 0 Objects renamed: 0 Objects moved: 0 Objects ignored: 0 Scan speed: 0 Kb/s Scan time: 00:00:00 ----------------------------------------------------------------------------- [Scan path] c:\documents and settings\all users\käynnistä-valikko\ohjelmat\käynnistys\desktop.ini [Scan path] c:\documents and settings\seija\käynnistä-valikko\ohjelmat\käynnistys\desktop.ini [Scan path] c:\documents and settings\seija\local settings\temp\rarsfx0\_start.exe [Scan path] c:\documents and settings\seija\local settings\temp\rarsfx0\cureit.exe [Scan path] c:\documents and settings\seija\työpöytä\drweb-cureit.exe [Scan path] c:\program files\adobe\acrobat 6.0\reader\activex\acroiehelper.dll [Scan path] c:\program files\ahead\incd\incd.exe [Scan path] c:\program files\ahead\incd\incdshx.dll [Scan path] c:\program files\ahead\incd\incdsrv.exe [Scan path] c:\program files\canon\easy-webprint\toolband.dll [Scan path] c:\program files\common files\microsoft shared\web folders\msonsext.dll [Scan path] c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll [Scan path] c:\program files\common files\sony shared\avlib\pacsptisvr.exe [Scan path] c:\program files\common files\sony shared\avlib\sptisrv.exe [Scan path] c:\program files\common files\symantec shared\security center\symwsc.exe [Scan path] c:\program files\common files\system\ole db\oledb32.dll [Scan path] c:\program files\cyberlink dvd solution\powerdvd\pdvdserv.exe [Scan path] c:\program files\d-tools\daemon.exe [Scan path] c:\program files\f-secure anti-virus\anti-spyware\fsaw.exe [Scan path] c:\program files\f-secure anti-virus\anti-virus\fsav32.exe [Scan path] c:\program files\f-secure anti-virus\anti-virus\fsgk32.exe [Scan path] c:\program files\f-secure anti-virus\anti-virus\fsgk32st.exe [Scan path] c:\program files\f-secure anti-virus\anti-virus\fsqh.exe [Scan path] c:\program files\f-secure anti-virus\anti-virus\fsrw.exe [Scan path] c:\program files\f-secure anti-virus\anti-virus\fssm32.exe [Scan path] c:\program files\f-secure anti-virus\anti-virus\win2k\fsfilter.sys [Scan path] c:\program files\f-secure anti-virus\anti-virus\win2k\fsgk.sys [Scan path] c:\program files\f-secure anti-virus\anti-virus\win2k\fsrec.sys [Scan path] c:\program files\f-secure anti-virus\backweb\4476822\program\fsbwsys.exe [Scan path] c:\program files\f-secure anti-virus\backweb\4476822\program\fspex.exe [Scan path] c:\program files\f-secure anti-virus\backweb\4476822\program\servicewrapper-4476822.exe [Scan path] c:\program files\f-secure anti-virus\common\fameh32.exe [Scan path] c:\program files\f-secure anti-virus\common\fch32.exe [Scan path] c:\program files\f-secure anti-virus\common\fsm32.exe [Scan path] c:\program files\f-secure anti-virus\common\fsma32.exe [Scan path] c:\program files\f-secure anti-virus\common\fsmb32.exe [Scan path] c:\program files\f-secure anti-virus\fsgui\fsguidll.exe [Scan path] c:\program files\f-secure anti-virus\fsgui\fssw.exe [Scan path] c:\program files\f-secure anti-virus\fsgui\ispnews.exe [Scan path] c:\program files\f-secure anti-virus\fwes\program\fsdfwd.exe [Scan path] c:\program files\f-secure anti-virus\tnb\tnbutil.exe [Scan path] c:\program files\google\googletoolbar2.dll [Scan path] c:\program files\google\googletoolbarnotifier\1.2.908.5008\googletoolbarnotifier.exe [Scan path] c:\program files\internet explorer\iexplore.exe [Scan path] c:\program files\java\jre1.5.0_09\bin\jusched.exe [Scan path] c:\program files\java\jre1.5.0_09\bin\ssv.dll [Scan path] c:\program files\logitech\desktop messenger\8876480\program\ldmconf.exe [Scan path] c:\program files\logitech\video\fxsvr2.exe [Scan path] c:\program files\logitech\video\isstart.exe [Scan path] c:\program files\logitech\video\logitray.exe [Scan path] c:\program files\logitech\video\manifestengine.exe [Scan path] c:\program files\logitech\video\namespc2.dll [Scan path] c:\program files\messenger\msmsgs.exe [Scan path] c:\program files\microsoft office\office\1035\unbind.dll [Scan path] c:\program files\msn messenger\fsshext.8.0.0812.00.dll [Scan path] c:\program files\outlook express\setup50.exe [Scan path] c:\program files\outlook express\wabfind.dll [Scan path] c:\program files\scansoft\omnipagese2.0\opwarese2.exe [Scan path] c:\program files\spybot - search & destroy\sdhelper.dll [Scan path] c:\program files\spybot - search & destroy\spybotsd.exe [Scan path] c:\program files\symantec\liveupdate\alunotify.exe [Scan path] c:\program files\symnetdrv\sndwarn.exe [Scan path] c:\program files\winamp\winampa.exe [Scan path] c:\program files\windows live toolbar\msntb.dll [Scan path] c:\windows\explorer.exe [Scan path] c:\windows\inf\unregmp2.exe [Scan path] c:\windows\msagent\agentpsh.dll [Scan path] c:\windows\network diagnostic\xpnetdiag.exe [Scan path] c:\windows\soundman.exe [Scan path] c:\windows\system32\advapi32.dll [Scan path] c:\windows\system32\advpack.dll [Scan path] c:\windows\system32\alg.exe [Scan path] c:\windows\system32\appwiz.cpl [Scan path] c:\windows\system32\audiodev.dll [Scan path] c:\windows\system32\autochk.exe [Scan path] c:\windows\system32\browseui.dll [Scan path] c:\windows\system32\cabview.dll [Scan path] c:\windows\system32\cisvc.exe [Scan path] c:\windows\system32\clipsrv.exe [Scan path] c:\windows\system32\cnbjmon.dll [Scan path] c:\windows\system32\cnmlm7k.dll [Scan path] c:\windows\system32\comdlg32.dll [Scan path] c:\windows\system32\crypt32.dll [Scan path] c:\windows\system32\cryptext.dll [Scan path] c:\windows\system32\cryptnet.dll [Scan path] c:\windows\system32\cscdll.dll [Scan path] c:\windows\system32\cscui.dll [Scan path] c:\windows\system32\csrss.exe [Scan path] c:\windows\system32\ctfmon.exe [Scan path] c:\windows\system32\deskadp.dll [Scan path] c:\windows\system32\deskmon.dll [Scan path] c:\windows\system32\deskperf.dll [Scan path] c:\windows\system32\dfsshlex.dll [Scan path] c:\windows\system32\diskcopy.dll [Scan path] c:\windows\system32\dllhost.exe [Scan path] c:\windows\system32\dmadmin.exe [Scan path] c:\windows\system32\docprop.dll [Scan path] c:\windows\system32\docprop2.dll [Scan path] c:\windows\system32\drivers\acpi.sys [Scan path] c:\windows\system32\drivers\aec.sys [Scan path] c:\windows\system32\drivers\afd.sys [Scan path] c:\windows\system32\drivers\alcxsens.sys [Scan path] c:\windows\system32\drivers\alcxwdm.sys [Scan path] c:\windows\system32\drivers\amdk7.sys [Scan path] c:\windows\system32\drivers\asyncmac.sys [Scan path] c:\windows\system32\drivers\atapi.sys [Scan path] c:\windows\system32\drivers\atmarpc.sys [Scan path] c:\windows\system32\drivers\audstub.sys [Scan path] c:\windows\system32\drivers\ccdecode.sys [Scan path] c:\windows\system32\drivers\cdrom.sys [Scan path] c:\windows\system32\drivers\d344bus.sys [Scan path] c:\windows\system32\drivers\d344prt.sys [Scan path] c:\windows\system32\drivers\disk.sys [Scan path] c:\windows\system32\drivers\dmboot.sys [Scan path] c:\windows\system32\drivers\dmio.sys [Scan path] c:\windows\system32\drivers\dmload.sys [Scan path] c:\windows\system32\drivers\dmusic.sys [Scan path] c:\windows\system32\drivers\drmkaud.sys [Scan path] c:\windows\system32\drivers\fdc.sys [Scan path] c:\windows\system32\drivers\fetnd5.sys [Scan path] c:\windows\system32\drivers\flpydisk.sys [Scan path] c:\windows\system32\drivers\fltmgr.sys [Scan path] c:\windows\system32\drivers\fsdfw.sys [Scan path] c:\windows\system32\drivers\ftdisk.sys [Scan path] c:\windows\system32\drivers\hcf_msft.sys [Scan path] c:\windows\system32\drivers\hidusb.sys [Scan path] c:\windows\system32\drivers\http.sys [Scan path] c:\windows\system32\drivers\i8042prt.sys [Scan path] c:\windows\system32\drivers\imapi.sys [Scan path] c:\windows\system32\drivers\incdpass.sys [Scan path] c:\windows\system32\drivers\ip6fw.sys [Scan path] c:\windows\system32\drivers\ipfltdrv.sys [Scan path] c:\windows\system32\drivers\ipinip.sys [Scan path] c:\windows\system32\drivers\ipnat.sys [Scan path] c:\windows\system32\drivers\ipsec.sys [Scan path] c:\windows\system32\drivers\irenum.sys [Scan path] c:\windows\system32\drivers\isapnp.sys [Scan path] c:\windows\system32\drivers\kbdclass.sys [Scan path] c:\windows\system32\drivers\kmixer.sys [Scan path] c:\windows\system32\drivers\lvcm.sys [Scan path] c:\windows\system32\drivers\lvusbsta.sys [Scan path] c:\windows\system32\drivers\mouclass.sys [Scan path] c:\windows\system32\drivers\mouhid.sys [Scan path] c:\windows\system32\drivers\mrxdav.sys [Scan path] c:\windows\system32\drivers\mrxsmb.sys [Scan path] c:\windows\system32\drivers\msgpc.sys [Scan path] c:\windows\system32\drivers\mskssrv.sys [Scan path] c:\windows\system32\drivers\mspclock.sys [Scan path] c:\windows\system32\drivers\mspqm.sys [Scan path] c:\windows\system32\drivers\mssmbios.sys [Scan path] c:\windows\system32\drivers\mstee.sys [Scan path] c:\windows\system32\drivers\nabtsfec.sys [Scan path] c:\windows\system32\drivers\ndisip.sys [Scan path] c:\windows\system32\drivers\ndistapi.sys [Scan path] c:\windows\system32\drivers\ndisuio.sys [Scan path] c:\windows\system32\drivers\ndiswan.sys [Scan path] c:\windows\system32\drivers\netbios.sys [Scan path] c:\windows\system32\drivers\netbt.sys [Scan path] c:\windows\system32\drivers\nv4_mini.sys [Scan path] c:\windows\system32\drivers\nwlnkflt.sys [Scan path] c:\windows\system32\drivers\nwlnkfwd.sys [Scan path] c:\windows\system32\drivers\parport.sys [Scan path] c:\windows\system32\drivers\pci.sys [Scan path] c:\windows\system32\drivers\pfc.sys [Scan path] c:\windows\system32\drivers\processr.sys [Scan path] c:\windows\system32\drivers\psched.sys [Scan path] c:\windows\system32\drivers\ptilink.sys [Scan path] c:\windows\system32\drivers\pxhelp20.sys [Scan path] c:\windows\system32\drivers\rasacd.sys [Scan path] c:\windows\system32\drivers\rasl2tp.sys [Scan path] c:\windows\system32\drivers\raspppoe.sys [Scan path] c:\windows\system32\drivers\raspptp.sys [Scan path] c:\windows\system32\drivers\raspti.sys [Scan path] c:\windows\system32\drivers\rdbss.sys [Scan path] c:\windows\system32\drivers\rdpcdd.sys [Scan path] c:\windows\system32\drivers\redbook.sys [Scan path] c:\windows\system32\drivers\scsiport.sys [Scan path] c:\windows\system32\drivers\secdrv.sys [Scan path] c:\windows\system32\drivers\serenum.sys [Scan path] c:\windows\system32\drivers\serial.sys [Scan path] c:\windows\system32\drivers\slip.sys [Scan path] c:\windows\system32\drivers\sonypvu1.sys [Scan path] c:\windows\system32\drivers\splitter.sys [Scan path] c:\windows\system32\drivers\sr.sys [Scan path] c:\windows\system32\drivers\srv.sys [Scan path] c:\windows\system32\drivers\streamip.sys [Scan path] c:\windows\system32\drivers\swenum.sys [Scan path] c:\windows\system32\drivers\swmidi.sys [Scan path] c:\windows\system32\drivers\sysaudio.sys [Scan path] c:\windows\system32\drivers\tcpip.sys [Scan path] c:\windows\system32\drivers\termdd.sys [Scan path] c:\windows\system32\drivers\update.sys [Scan path] c:\windows\system32\drivers\usbaudio.sys [Scan path] c:\windows\system32\drivers\usbccgp.sys [Scan path] c:\windows\system32\drivers\usbehci.sys [Scan path] c:\windows\system32\drivers\usbhub.sys [Scan path] c:\windows\system32\drivers\usbprint.sys [Scan path] c:\windows\system32\drivers\usbscan.sys [Scan path] c:\windows\system32\drivers\usbstor.sys [Scan path] c:\windows\system32\drivers\usbuhci.sys [Scan path] c:\windows\system32\drivers\vga.sys [Scan path] c:\windows\system32\drivers\viaagp1.sys [Scan path] c:\windows\system32\drivers\viaide.sys [Scan path] c:\windows\system32\drivers\wanarp.sys [Scan path] c:\windows\system32\drivers\wdmaud.sys [Scan path] c:\windows\system32\drivers\ws2ifsl.sys [Scan path] c:\windows\system32\drivers\wstcodec.sys [Scan path] c:\windows\system32\dskquoui.dll [Scan path] c:\windows\system32\dsquery.dll [Scan path] c:\windows\system32\dssec.dll [Scan path] c:\windows\system32\dsuiext.dll [Scan path] c:\windows\system32\dumprep.exe [Scan path] c:\windows\system32\extmgr.dll [Scan path] c:\windows\system32\ezsp_px.exe [Scan path] c:\windows\system32\fontext.dll [Scan path] c:\windows\system32\gdi32.dll [Scan path] c:\windows\system32\hticons.dll [Scan path] c:\windows\system32\icmui.dll [Scan path] c:\windows\system32\ie4uinit.exe [Scan path] c:\windows\system32\iedkcs32.dll [Scan path] c:\windows\system32\ieframe.dll [Scan path] c:\windows\system32\ieudinit.exe [Scan path] c:\windows\system32\imagehlp.dll [Scan path] c:\windows\system32\imapi.exe [Scan path] c:\windows\system32\inetcomm.dll [Scan path] c:\windows\system32\itss.dll [Scan path] c:\windows\system32\kerberos.dll [Scan path] c:\windows\system32\kernel32.dll [Scan path] c:\windows\system32\localspl.dll [Scan path] c:\windows\system32\locator.exe [Scan path] c:\windows\system32\logonui.exe [Scan path] c:\windows\system32\lsass.exe [Scan path] c:\windows\system32\lvcomsx.exe [Scan path] c:\windows\system32\lz32.dll [Scan path] c:\windows\system32\mmcshext.dll [Scan path] c:\windows\system32\mmsys.cpl [Scan path] c:\windows\system32\mnmsrvc.exe [Scan path] c:\windows\system32\msdtc.exe [Scan path] c:\windows\system32\mshtml.dll [Scan path] c:\windows\system32\msieftp.dll [Scan path] c:\windows\system32\msiexec.exe [Scan path] c:\windows\system32\mstask.dll [Scan path] c:\windows\system32\msv1_0.dll [Scan path] c:\windows\system32\msvidctl.dll [Scan path] c:\windows\system32\mswsock.dll [Scan path] c:\windows\system32\mydocs.dll [Scan path] c:\windows\system32\nerocheck.exe [Scan path] c:\windows\system32\netdde.exe [Scan path] c:\windows\system32\netplwiz.dll [Scan path] c:\windows\system32\netshell.dll [Scan path] c:\windows\system32\ntlanui2.dll [Scan path] c:\windows\system32\ntsd.exe [Scan path] c:\windows\system32\ntshrui.dll [Scan path] c:\windows\system32\nvshell.dll [Scan path] c:\windows\system32\occache.dll [Scan path] c:\windows\system32\ole32.dll [Scan path] c:\windows\system32\oleaut32.dll [Scan path] c:\windows\system32\olecli32.dll [Scan path] c:\windows\system32\olecnv32.dll [Scan path] c:\windows\system32\olesvr32.dll [Scan path] c:\windows\system32\olethk32.dll [Scan path] c:\windows\system32\photowiz.dll [Scan path] c:\windows\system32\pjlmon.dll [Scan path] c:\windows\system32\printui.dll [Scan path] c:\windows\system32\regsvr32.exe [Scan path] c:\windows\system32\remotepg.dll [Scan path] c:\windows\system32\rpcrt4.dll [Scan path] c:\windows\system32\rpcss.dll [Scan path] c:\windows\system32\rshx32.dll [Scan path] c:\windows\system32\rsvp.exe [Scan path] c:\windows\system32\rsvpsp.dll [Scan path] c:\windows\system32\rundll32.exe [Scan path] c:\windows\system32\scardsvr.exe [Scan path] c:\windows\system32\scecli.dll [Scan path] c:\windows\system32\schannel.dll [Scan path] c:\windows\system32\sclgntfy.dll [Scan path] c:\windows\system32\sendmail.dll [Scan path] c:\windows\system32\services.exe [Scan path] c:\windows\system32\sessmgr.exe [Scan path] c:\windows\system32\shdocvw.dll [Scan path] c:\windows\system32\shell32.dll [Scan path] c:\windows\system32\shimgvw.dll [Scan path] c:\windows\system32\shmedia.dll [Scan path] c:\windows\system32\shmgrate.exe [Scan path] c:\windows\system32\shscrap.dll [Scan path] c:\windows\system32\slayerxp.dll [Scan path] c:\windows\system32\smlogsvc.exe [Scan path] c:\windows\system32\smss.exe [Scan path] c:\windows\system32\spoolsv.exe [Scan path] c:\windows\system32\ssmypics.scr [Scan path] c:\windows\system32\stobject.dll [Scan path] c:\windows\system32\svchost.exe [Scan path] c:\windows\system32\syncui.dll [Scan path] c:\windows\system32\tcpmon.dll [Scan path] c:\windows\system32\themeui.dll [Scan path] c:\windows\system32\twext.dll [Scan path] c:\windows\system32\ups.exe [Scan path] c:\windows\system32\url.dll [Scan path] c:\windows\system32\urlmon.dll [Scan path] c:\windows\system32\usbmon.dll [Scan path] c:\windows\system32\user32.dll [Scan path] c:\windows\system32\version.dll [Scan path] c:\windows\system32\vssvc.exe [Scan path] c:\windows\system32\wbem\wmiapsrv.exe [Scan path] c:\windows\system32\wdfmgr.exe [Scan path] c:\windows\system32\wdigest.dll [Scan path] c:\windows\system32\webcheck.dll [Scan path] c:\windows\system32\wiascr.dll [Scan path] c:\windows\system32\wiashext.dll [Scan path] c:\windows\system32\wininet.dll [Scan path] c:\windows\system32\winlogon.exe [Scan path] c:\windows\system32\wldap32.dll [Scan path] c:\windows\system32\wlnotify.dll [Scan path] c:\windows\system32\wmpshell.dll [Scan path] c:\windows\system32\wshext.dll [Scan path] c:\windows\system32\wuaucpl.cpl [Scan path] c:\windows\system32\xfire_lsp_11078.dll [Scan path] c:\windows\system32\zipfldr.dll [Scan path] d:\volumewatcher\spuvolumewatcher.exe ----------------------------------------------------------------------------- Scan statistics ----------------------------------------------------------------------------- Objects scanned: 323 Infected objects found: 0 Objects with modifications found: 0 Suspicious objects found: 0 Adware programs found: 0 Dialer programs found: 0 Joke programs found: 0 Riskware programs found: 0 Hacktool programs found: 0 Objects cured: 0 Objects deleted: 0 Objects renamed: 0 Objects moved: 0 Objects ignored: 0 Scan speed: 2627 Kb/s Scan time: 00:00:34 ----------------------------------------------------------------------------- [Scan path] C:\ C:\WINDOWS\system32\config\system.LOG - read error C:\WINDOWS\system32\config\software.LOG - read error C:\WINDOWS\system32\config\default.LOG - read error C:\WINDOWS\system32\config\SECURITY - read error C:\WINDOWS\system32\config\SAM - read error C:\WINDOWS\system32\config\SAM.LOG - read error C:\WINDOWS\system32\config\SECURITY.LOG - read error C:\WINDOWS\system32\config\SYSTEM - read error C:\WINDOWS\system32\config\SOFTWARE - read error C:\WINDOWS\system32\config\DEFAULT - read error C:\WINDOWS\system32\CatRoot2\edb.log - read error C:\WINDOWS\system32\CatRoot2\tmp.edb - read error C:\Documents and Settings\NetworkService\NTUSER.DAT - read error C:\Documents and Settings\NetworkService\NTUSER~1.LOG - read error C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\USRCLASS.DAT - read error C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\USRCLA~1.LOG - read error C:\Documents and Settings\LocalService\NTUSER.DAT - read error C:\Documents and Settings\LocalService\NTUSER~1.LOG - read error C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\USRCLASS.DAT - read error C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\USRCLA~1.LOG - read error C:\Documents and Settings\Seija\NTUSER.DAT - read error C:\Documents and Settings\Seija\NTUSER~1.LOG - read error C:\Documents and Settings\Seija\Local Settings\Application Data\Microsoft\Windows\USRCLASS.DAT - read error C:\Documents and Settings\Seija\Local Settings\Application Data\Microsoft\Windows\USRCLA~1.LOG - read error C:\Documents and Settings\Seija\Työpöytä\SmitfraudFix\Process.exe is hacktool program Tool.Prockill C:\Documents and Settings\Seija\Työpöytä\SmitfraudFix\restart.exe is hacktool program Tool.ShutDown.11 C:\Documents and Settings\Seija\Application Data\ispnews\ISPNR~1.ITE - read error C:\Documents and Settings\Seija\Application Data\ispnews\ISPNC~1.ITE - read error C:\Documents and Settings\Seija\Application Data\ispnews\ispn.ini - read error C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Users\Default\Data\chandir.idx - read error C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Users\Default\Data\D0000000.FCS - read error C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Users\Default\Data\L0000031.FCS - read error C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Users\Default\Data\storydb.dat - read error C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Users\Default\Data\storydb.idx - read error C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Users\Default\Data\chn.dat - read error C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Users\Default\Data\chn.idx - read error C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Users\Default\Data\prs_die.dat - read error C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Users\Default\Data\prs_die.idx - read error C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Users\Default\Data\prs_dnd.dat - read error C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Users\Default\Data\prs_dnd.idx - read error C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Users\Default\Data\prs_ext.dat - read error C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Users\Default\Data\prs_ext.idx - read error C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Users\Default\Data\prs_rcv.dat - read error C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Users\Default\Data\prs_rcv.idx - read error C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Users\Default\Data\prs.dat - read error C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Users\Default\Data\prs.idx - read error C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Users\Default\Data\chandir.dat - read error C:\Program Files\F-Secure Anti-Virus\Common\admin.pub - read error C:\Program Files\F-Secure Anti-Virus\Common\policy.ipf - read error C:\System Volume Information\_restore{0E817AE6-2B79-4061-8843-1B227871B599}\RP817\A0116633.exe is hacktool program Tool.Prockill C:\System Volume Information\_restore{0E817AE6-2B79-4061-8843-1B227871B599}\RP817\A0116635.exe is hacktool program Tool.ShutDown.11 C:\System Volume Information\_restore{0E817AE6-2B79-4061-8843-1B227871B599}\RP757\A0110970.exe is riskware program Program.mIRC.616 C:\System Volume Information\_restore{0E817AE6-2B79-4061-8843-1B227871B599}\RP793\A0114276.exe is hacktool program Tool.Prockill C:\System Volume Information\_restore{0E817AE6-2B79-4061-8843-1B227871B599}\RP793\A0114294.exe is hacktool program Tool.Prockill C:\System Volume Information\_restore{0E817AE6-2B79-4061-8843-1B227871B599}\RP793\A0114296.exe is hacktool program Tool.ShutDown.11 C:\System Volume Information\_restore{0E817AE6-2B79-4061-8843-1B227871B599}\RP811\A0115592.exe is hacktool program Tool.Prockill [Scan path] D:\ ----------------------------------------------------------------------------- Scan statistics ----------------------------------------------------------------------------- Objects scanned: 172428 Infected objects found: 0 Objects with modifications found: 0 Suspicious objects found: 0 Adware programs found: 0 Dialer programs found: 0 Joke programs found: 0 Riskware programs found: 1 Hacktool programs found: 8 Objects cured: 0 Objects deleted: 0 Objects renamed: 0 Objects moved: 0 Objects ignored: 0 Scan speed: 840 Kb/s Scan time: 01:22:20 ----------------------------------------------------------------------------- C:\Documents and Settings\Seija\Työpöytä\SmitfraudFix\Process.exe - incurable - will be moved after reboot C:\Documents and Settings\Seija\Työpöytä\SmitfraudFix\restart.exe C:\System Volume Information\_restore{0E817AE6-2B79-4061-8843-1B227871B599}\RP817\A0116633.exe - incurable - moved C:\System Volume Information\_restore{0E817AE6-2B79-4061-8843-1B227871B599}\RP817\A0116635.exe - incurable - moved C:\System Volume Information\_restore{0E817AE6-2B79-4061-8843-1B227871B599}\RP757\A0110970.exe - incurable - moved C:\System Volume Information\_restore{0E817AE6-2B79-4061-8843-1B227871B599}\RP793\A0114276.exe - incurable - moved C:\System Volume Information\_restore{0E817AE6-2B79-4061-8843-1B227871B599}\RP793\A0114294.exe - incurable - moved C:\System Volume Information\_restore{0E817AE6-2B79-4061-8843-1B227871B599}\RP793\A0114296.exe - incurable - moved C:\System Volume Information\_restore{0E817AE6-2B79-4061-8843-1B227871B599}\RP811\A0115592.exe - incurable - moved ============================================================================= Total session statistics ============================================================================= Objects scanned: 172751 Infected objects found: 0 Objects with modifications found: 0 Suspicious objects found: 0 Adware programs found: 0 Dialer programs found: 0 Joke programs found: 0 Riskware programs found: 1 Hacktool programs found: 8 Objects cured: 0 Objects deleted: 0 Objects renamed: 0 Objects moved: 8 Objects ignored: 0 Scan speed: 9 Kb/s Scan time: 01:22:54 =============================================================================