Smitfraud .C

Discussion in 'Virukset ja haittaohjelmat - HijackThis -logit' started by Juhia, Nov 27, 2006.

Thread Status:
Not open for further replies.
  1. Juhia

    Juhia Member

    Joined:
    Oct 16, 2005
    Messages:
    20
    Likes Received:
    0
    Trophy Points:
    11
    Tuo tuli taas vaihteeksi kiusaamaan viatonta sieluani. Kamppailin XoftspySE säilänäni ja oletettavasti poistin sen??
    Ainakaa mikään skanneri ei sitä löydä mutta onko tuolla jotain muuta?
    Tässä HJT-logi:

    Logfile of HijackThis v1.99.1
    Scan saved at 23:35:35, on 27.11.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\ZONELABS\vsmon.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\system32\CTHELPER.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\ITE\ITE IT8212 ATA RAID Controller\RaidMgr.exe
    C:\WINDOWS\ATKKBService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Juhia\Työpöytä\HijackThis_v1.99.1.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {12AFC344-0D35-436A-AB96-9DAB4C5355BB} - C:\WINDOWS\system32\awtsq.dll
    O2 - BHO: (no name) - {35F7813A-AF74-4474-B1DC-7EE6FB6C43C6} - C:\WINDOWS\system32\qjdihmhg.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: (no name) - {D4FAE274-4AB4-43E4-AD48-0CEA6D6C4F65} - C:\WINDOWS\system32\ssqppqr.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600"
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [web meta each hole] C:\Documents and Settings\All Users\Application Data\Citydumbwebmeta\Size body.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe /start
    O4 - HKCU\..\Run: [HeartOnline] C:\DOCUME~1\Juhia\APPLIC~1\DRVSET~1\Meoweggs.exe
    O4 - Global Startup: RAID Manager.lnk = ?
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Program Files\nordicbetMPP\MPPoker.exe
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: awtsq - C:\WINDOWS\system32\awtsq.dll
    O20 - Winlogon Notify: ssqppqr - C:\WINDOWS\SYSTEM32\ssqppqr.dll
    O20 - Winlogon Notify: winopn32 - C:\WINDOWS\SYSTEM32\winopn32.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe
     
  2. Juhia

    Juhia Member

    Joined:
    Oct 16, 2005
    Messages:
    20
    Likes Received:
    0
    Trophy Points:
    11
    On täälä jotain. Kovasti tahtoo asennella erilaisia virus- ym. skeidaskannereita.
     
  3. Hujo

    Hujo Guest

    Lataa VundoFix.exe
    http://www.atribune.org/ccount/click.php?id=4 työpöydällesi.

    • Tupla-klikkaa VundoFix.exe ajaaksesi sen.
    • Klikkaa Scan for Vundo valintaa.
    • Kun skannaus on valmis, klikkaa Remove Vundo valintaa.
    • Sinulta kysytään haluatko poistaa filut - klikkaa YES.
    • Kun olet klikannut yes, työpöytäsi tyhjenee kun se alkaa poistamaan Vundoa.
    • Kun se on valmis, fiksi ilmoittaa käynnistäväsi koneesi uudelleen, klikkaa OK.
    • Postita C:\vundofix.txt lokin sekä tuoreen HijackThis lokin sisältö.


    Huomaa: Se on mahdollista että VundoFix löysi tiedoston jota se ei pystynyt poistamaan.
    Tässä tilanteessa, VundoFix ajaa itsensä rebootissa, seuraa vain yläpuolelle olevia ohjeita alkaen kohdasta "Klikkaa Scan for Vundo valintaa." kun VundoFix ilmaantuu uudelleenkäynnistyksen yhteydessä.

    Lataa SmitfraudFix (c) S!Ri http://siri.urz.free.fr/Fix/SmitfraudFix.zip
    Pura sisältö (kansio nimeltä SmitfraudFix) työpöydällesi:

    Avaa SmitfraudFix kansio ja tupla-klikkaa smitfraudfix.cmd
    Valitse optio #1 - Search kirjoittamalla 1 ja painamalla "Enter"; tekstitiedosto avautuu, joka listaa tarttuneet tiedostot (jos olemassa).
    Postita tämän tekstitiedoston sisältö viestiketjuusi.

    Huomaa : process.exe filun tunnistaa jotkut Anti-virus ohjelmat (AntiVir, Dr.Web, Kaspersky) "Haittakaluna"; se ei ole virus, vaan ohjelma joka pysäyttää prosesseja. A/V ohjelmat eivät pysty tunnistamaan hyvän ja pahan käytön tälläisten ohjelmian väliltä, silloin ne saattavat varoittaa käyttäjää.

    Lataa NoLoptyöpöydällesi yhdestä seuraavista linkeistä...
    http://www.spywareedge.net/nolop/NoLop.exe

    1.Sulje kaikki ohjelmat, koska tämä vaihe vaatii uudelleenkäynnistyksen
    2.Tuplaklikkaa NoLop.exe ajaaksesi sen
    3.Klikkaa nappulaa "Search and Destroy"
    <<Tietokoneesi skannataan saastuneiden tiedostojen osalta>>
    4, Kun skannaus on valmis, sinua pyydetään käynnistämään kone uudestaan, jos infektio löytyy. Klikkaa OK
    5. Klikkaa "REBOOT"-painiketta.
    6. NoLopin pitäisi antaa viesti. Jos ei, tuplaklikkaa ohjelmaa ja se valmistuu. Lähetä C:\NoLop.log-tiedoston sisältö uuden HijackThis-lokin kera.


    lähetä
    vundofix.txt loki
    SmitfraudFix loki
    C:\NoLop.log-tiedoston sisältö
    Hjt -loki
     
    Last edited by a moderator: Nov 28, 2006
  4. Juhia

    Juhia Member

    Joined:
    Oct 16, 2005
    Messages:
    20
    Likes Received:
    0
    Trophy Points:
    11
    Logfile of HijackThis v1.99.1
    Scan saved at 23:03:50, on 28.11.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZONELABS\vsmon.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\ATKKBService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\ishost.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\system32\CTHELPER.EXE
    C:\WINDOWS\system32\ismini.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\Program Files\Common Files\{A0BFE2ED-0C8B-1035-0617-051123040166}\Update.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    c:\progra~1\intern~1\iexplore.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\ITE\ITE IT8212 ATA RAID Controller\RaidMgr.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    C:\WINDOWS\system32\taskmgr.exe
    C:\Documents and Settings\Juhia\Työpöytä\HijackThis_v1.99.1.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {35F7813A-AF74-4474-B1DC-7EE6FB6C43C6} - C:\WINDOWS\system32\qjdihmhg.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {A98909A8-9565-4D5F-91F4-4FD2204E2B53} - C:\WINDOWS\system32\awtsq.dll (file missing)
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: 888Bar - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{30BFE~1\888Bar.dll
    O2 - BHO: (no name) - {D4FAE274-4AB4-43E4-AD48-0CEA6D6C4F65} - C:\WINDOWS\system32\ssqppqr.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: 888Bar - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{30BFE~1\888Bar.dll
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600"
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [web meta each hole] C:\Documents and Settings\All Users\Application Data\Citydumbwebmeta\Size body.exe
    O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvzul.dll,startup
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe /start
    O4 - HKCU\..\Run: [HeartOnline] C:\DOCUME~1\Juhia\APPLIC~1\DRVSET~1\Meoweggs.exe
    O4 - Global Startup: RAID Manager.lnk = ?
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Program Files\nordicbetMPP\MPPoker.exe
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: ssqppqr - C:\WINDOWS\SYSTEM32\ssqppqr.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe


    NoLop! Log by Skate_Punk_21

    Fix running from: C:\Documents and Settings\Juhia\Työpöytä
    [28.11.2006]
    [22:56:27]

    ---Infection Files Found/Removed---
    C:\WINDOWS\tasks\AA33677D919CE56D.job

    Beginning Removal...
    Rebooting...
    Removing Lop's Leftover Files/Folders...
    Editing Registry...
    **Fix Complete!**

    ---Listing AppData sub directories---

    C:\Documents and Settings\Default User\Application Data\Microsoft
    C:\Documents and Settings\All Users\Application Data\Microsoft
    C:\Documents and Settings\All Users\Application Data\Symantec
    C:\Documents and Settings\All Users\Application Data\Cyberlink
    C:\Documents and Settings\All Users\Application Data\Downloaded Installations -- EMPTY Directory
    C:\Documents and Settings\All Users\Application Data\Pc Suite
    C:\Documents and Settings\All Users\Application Data\Adobe
    C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    C:\Documents and Settings\All Users\Application Data\Dvd Shrink
    C:\Documents and Settings\All Users\Application Data\Apple Computer
    C:\Documents and Settings\All Users\Application Data\Citydumbwebmeta
    C:\Documents and Settings\Networkservice\Application Data\Microsoft
    C:\Documents and Settings\Localservice\Application Data\Microsoft
    C:\Documents and Settings\Localservice\Application Data\Symantec
    C:\Documents and Settings\Juhia\Application Data\Microsoft
    C:\Documents and Settings\Juhia\Application Data\Identities
    C:\Documents and Settings\Juhia\Application Data\Symantec
    C:\Documents and Settings\Juhia\Application Data\Mozilla
    C:\Documents and Settings\Juhia\Application Data\Lavasoft
    C:\Documents and Settings\Juhia\Application Data\Macromedia
    C:\Documents and Settings\Juhia\Application Data\Cyberlink
    C:\Documents and Settings\Juhia\Application Data\Pc Suite
    C:\Documents and Settings\Juhia\Application Data\Adobe
    C:\Documents and Settings\Juhia\Application Data\Microsoft Web Folders -- EMPTY Directory
    C:\Documents and Settings\Juhia\Application Data\Ati -- EMPTY Directory
    C:\Documents and Settings\Juhia\Application Data\Azureus
    C:\Documents and Settings\Juhia\Application Data\Syntrillium
    C:\Documents and Settings\Juhia\Application Data\Microgaming
    C:\Documents and Settings\Juhia\Application Data\Help -- EMPTY Directory
    C:\Documents and Settings\Juhia\Application Data\Netscape
    C:\Documents and Settings\Juhia\Application Data\Sun
    C:\Documents and Settings\Juhia\Application Data\Real
    C:\Documents and Settings\Juhia\Application Data\Bsplayer Pro
    C:\Documents and Settings\Juhia\Application Data\Uqm
    C:\Documents and Settings\Juhia\Application Data\Skype
    C:\Documents and Settings\Juhia\Application Data\Datalayer
    C:\Documents and Settings\Juhia\Application Data\Adobeum -- EMPTY Directory
    C:\Documents and Settings\Juhia\Application Data\Talkback
    C:\Documents and Settings\Juhia\Application Data\Drv Settings For



    SmitFraudFix v2.124

    Scan done at 22:54:06,78, ti 28.11.2006
    Run from C:\Documents and Settings\Juhia\Ty”p”yt„\SmitfraudFix\SmitfraudFix
    OS: Microsoft Windows XP [versio 5.1.2600] - Windows_NT
    Fix run in normal mode

    »»»»»»»»»»»»»»»»»»»»»»»» C:\


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

    C:\WINDOWS\system32\ishost.exe FOUND !
    C:\WINDOWS\system32\ismini.exe FOUND !
    C:\WINDOWS\system32\drvzul.dll FOUND !
    C:\WINDOWS\system32\components\flx?.dll FOUND !
    C:\WINDOWS\system32\components\flx??.dll FOUND !
    C:\WINDOWS\system32\components\flx???.dll FOUND !

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Juhia


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Juhia\Application Data


    »»»»»»»»»»»»»»»»»»»»»»»» Start Menu


    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\JUHIA\SUOSIKIT


    »»»»»»»»»»»»»»»»»»»»»»»» Desktop


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


    »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


    »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
    "Source"="About:Home"
    "SubscribedURL"="About:Home"
    "FriendlyName"="Nykyinen kotisivu"


    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=""


    »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32


    »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


    »»»»»»»»»»»»»»»»»»»»»»»» End




    VundoFix V6.2.13

    Checking Java version...

    Java version is 1.5.0.8

    Scan started at 22:44:06 28.11.2006

    Listing files found while scanning....

    C:\WINDOWS\system32\winopn32.dll
    C:\WINDOWS\system32\awtsq.dll
    C:\WINDOWS\system32\qstwa.ini
    C:\WINDOWS\system32\qstwa.bak1
    C:\WINDOWS\system32\qstwa.bak2
    C:\WINDOWS\system32\qstwa.ini2
    C:\WINDOWS\system32\awtsq.dll
    C:\WINDOWS\system32\qstwa.ini
    C:\WINDOWS\system32\qstwa.bak1
    C:\WINDOWS\system32\qstwa.bak2
    C:\WINDOWS\system32\qstwa.ini2
    C:\WINDOWS\system32\qstwa.ini
    C:\WINDOWS\system32\qstwa.bak1
    C:\WINDOWS\system32\qstwa.bak2
    C:\WINDOWS\system32\qstwa.ini2

    Beginning removal...

    Attempting to delete C:\WINDOWS\system32\winopn32.dll
    C:\WINDOWS\system32\winopn32.dll Could not be deleted.

    Attempting to delete C:\WINDOWS\system32\awtsq.dll
    C:\WINDOWS\system32\awtsq.dll Could not be deleted.

    Attempting to delete C:\WINDOWS\system32\qstwa.ini
    C:\WINDOWS\system32\qstwa.ini Has been deleted!

    Attempting to delete C:\WINDOWS\system32\qstwa.bak1
    C:\WINDOWS\system32\qstwa.bak1 Has been deleted!

    Attempting to delete C:\WINDOWS\system32\qstwa.bak2
    C:\WINDOWS\system32\qstwa.bak2 Has been deleted!

    Attempting to delete C:\WINDOWS\system32\qstwa.ini2
    C:\WINDOWS\system32\qstwa.ini2 Has been deleted!

    Attempting to delete C:\WINDOWS\system32\awtsq.dll
    C:\WINDOWS\system32\awtsq.dll Could not be deleted.

    Performing Repairs to the registry.
    Done!

    Beginning removal...

    Attempting to delete C:\WINDOWS\system32\winopn32.dll
    C:\WINDOWS\system32\winopn32.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\awtsq.dll
    C:\WINDOWS\system32\awtsq.dll Has been deleted!

    Performing Repairs to the registry.
    Done!





    Olihan sielä tavaraa. Nuo pirun ismini.exe ja update.exe riivasivat äskeisten skannausten aikana monta kertaa. Ja explooderi starttasi vähän väliä ja mainosteli jotaki winvirussoftwareturboremoveinjection2005-ohjelmaa mikä poistaa kaikki ylimääräiset ja tekee konesta niin kauniin että! Eikä maksanukkaa edes paljoa :). Ärsyttäviä nuo troijjalaaset! Ja tuo mollukka tuolla oikealla alhaalla varoittelee vähän väliä että nyt kuuleppas taitaa olla viirus herran koneella että clickkaappas tähän niin saat vähä infoa jne. Nortonikin deletoitti vähän väliä troijjan heppoja.
    Onneksi tästä kaikesta saa syyttää sitä rumaa joka joka aamu tsiigaa vessan peilistä tukka pystys...
    Koko cee-asema on kyllä muutenkin menossa jyrän alle muttakun pitäisi siirtää tavaraa ensin pois ulkoiselle kovolle enkä halua että tämän moskan palaakaan siirtyy mukana. Siksi tärkeää pitäis päästä tuosta eroon.
     
    Last edited: Nov 28, 2006
  5. Hujo

    Hujo Guest

    Sulla on vanha versio Smitfraudfix poista se ja ota uusi versio.
    sitten scannaa uudella versiolla.

    optio 1
     
  6. Juhia

    Juhia Member

    Joined:
    Oct 16, 2005
    Messages:
    20
    Likes Received:
    0
    Trophy Points:
    11
    Kas näin



    SmitFraudFix v2.125

    Scan done at 23:33:59,26, ti 28.11.2006
    Run from C:\Documents and Settings\Juhia\Ty”p”yt„\SmitfraudFix
    OS: Microsoft Windows XP [versio 5.1.2600] - Windows_NT
    Fix run in normal mode

    »»»»»»»»»»»»»»»»»»»»»»»» C:\


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

    C:\WINDOWS\system32\ishost.exe FOUND !
    C:\WINDOWS\system32\ismini.exe FOUND !
    C:\WINDOWS\system32\drvzul.dll FOUND !
    C:\WINDOWS\system32\components\flx?.dll FOUND !
    C:\WINDOWS\system32\components\flx??.dll FOUND !
    C:\WINDOWS\system32\components\flx???.dll FOUND !

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Juhia


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Juhia\Application Data


    »»»»»»»»»»»»»»»»»»»»»»»» Start Menu


    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\JUHIA\SUOSIKIT


    »»»»»»»»»»»»»»»»»»»»»»»» Desktop


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


    »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


    »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
    "Source"="About:Home"
    "SubscribedURL"="About:Home"
    "FriendlyName"="Nykyinen kotisivu"


    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=""


    »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32


    »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


    »»»»»»»»»»»»»»»»»»»»»»»» End

     
  7. Hujo

    Hujo Guest

    Ja kas näin sitten jatketaan ;)

    Printtaa ohjeet ulos.

    Käynnistä koneesi vikasietotilaan ja valitse tavallinen käyttäjätilisi.

    Kun vikasietotilassa, avaa SmitfraudFix kansio ja tupla-klikkaa smitfraudfix.cmd
    Valitse optio #2 - Clean kirjoittamalla 2 ja painamalla "Enter" poistaaksesi tarttuneet tiedostot.

    Sinulta kysytään: "Registry cleaning - Do you want to clean the registry ?"; vastaa "Yes" kirjoittamalla Y ja paina "Enter" poistaaksesi työpöydän taustakuvan ja puhdistaaksesi tarttuneet rekisteriavaimet.

    Työkalu tarkistaa jos wininet.dll on tarttunut. Sinua saatetaan pyytää korvaamaan tarttunut .dll (jos löytyy); vastaa "Yes" kirjoittamalla Y ja painamalla "Enter".

    Työkalun saattaa tarvita käynnistää kone uudelleen; jos ei tee niin, käynnistä normaaliin Windowsiin.
    Tekstitiedosto ilmestyy, puhdistusprosessin jäljiltä; kopioi & liitä tämän raportin tulokset vastaukseesi.
    Raportti löytyy paikalliselta levyltäsi, useimmiten C:\rapport.txt.

    Varoitus : Ajamalla optio 2:n EI-tarttuneessa tietokoneessa, poistaa sinun työpöytäsi taustakuvan.


    Ohje AVG Anti-Spyware 7.5:n käyttöön
    Huom! Tässä ohjeessa sammutetaan tuo reaaliaikasuojaus (Shield). Näin vältetään tilanteet joissa suojaus estäisi esim HijackThis työkalun toimintaa.

    Tallenna nämä ohjeet tekstitiedostoon tai tulosta nämä, muuten et pääse niihin käsiksi vikasietotilasta

    Lataa AVG Anti-Spyware 7.5 http://www.ewido.net/en/download/
    ja tallenna ohjelma työpöydällesi.
    • Kun olet ladannut ohjelman, kaksoisklikkaa asennuohjelman pikakuvaketta työpöydälläsi, asennus alkaa.
    • Asennuksen jälkeen täytyy ohjelma käynnistää ja sen tunnisteet päivittää.
    • Käynnistä AVG Anti-Spyware.
    • Klikkaa "Update" kuvaketta päävalikossa. Sen jälkeen klikkaa "Update now" painiketta.

    o Sitten klikkaa "Start Update" kuvaketta jolloin päivitys alkaa.

    • Kun päivitykset on ladattu, klikkaa "Scanner" kuvaketta ikkunan ylälaidassa. Valitse sitten "Settings" välilehti.
    • Kun "Settings" valikko on auennut, klikkaa "Recommended actions" ja sitten valitse "Quarantine".
    • Sitten "Reports" valikon alta:

    o Laita täppi kohtaan "Automatically generate report after every scan"
    o Ota täppi pois kohdasta"Only if threats were found"

    • Sitten klikkaa "Shield" kuvaketta ikkunan ylälaidassa
    • "Resident shield is", muuta tila active:sta inactive:ksi
    • Sulje ohjelma, ÄLÄ skannaa vielä.
    Käynnistä koneesi vikasietotilaan,

    sammuta ja käynnistä
    käynnistyksen yhteydessä naputtele F8
    valitse nuoli näppäimellä vikasietotila
    paina enter ja enter

    HUOM! Älä käytä muita ohjelmia AVG skannauksen aikana, tämä saattaa häiritä skannausta.
    • Kun vikasietotilassa, käynnistä AVG Anti-Spyware.
    • Klikkaa "Scanner" kuvaketta ikkunan ylälaidassa ja valitse "Scan" välilehti. Sitten klikkaa "Complete System Scan".
    • Ewido aloittaa nyt tietokoneen skannaamisen, ole kärsivällinen sillä skannaus vie aikaa.

    Kun skannaus on valmis:
    TÄRKEÄÄ : Älä klikkaa "Save Scan Report" ennen kuin klikkaat "Apply all Actions"
    • Varmistu, että Set all elements to: näyttää Quarantine (1), jos ei, klikkaa linkkiä ja valitse Quarantine popup-valikosta.
    • Sinulta kysytään mitä tehdä jos infektioita löytyi, valitse silloin "Apply all actions"

    • Sitten klikkaa "Reports" kuvaketta ohjelma yläosasta.
    • Klikkaa "Save report as" painiketta ikkunan vasemmassa alalaidassa ja tallenna raportti työpöydälle.
    • Sulje ohjelma, käynnistä kone normaalisti ja lähetä AVG:n raportti viestikejuusi.


    lähetä
    smitfraudfix loki
    avg raportti
    Hjt loki

     
  8. Juhia

    Juhia Member

    Joined:
    Oct 16, 2005
    Messages:
    20
    Likes Received:
    0
    Trophy Points:
    11
    ok teen nuo varmaankin huomenna tänään tuskin kerkiän tekemään mitään
     
  9. Juhia

    Juhia Member

    Joined:
    Oct 16, 2005
    Messages:
    20
    Likes Received:
    0
    Trophy Points:
    11
    SmitFraudFix v2.125

    Scan done at 14:44:26,98, to 30.11.2006
    Run from C:\Documents and Settings\Juhia\Ty”p”yt„\SmitfraudFix
    OS: Microsoft Windows XP [versio 5.1.2600] - Windows_NT
    Fix run in safe mode

    »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Killing process


    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

    C:\WINDOWS\system32\ishost.exe Deleted
    C:\WINDOWS\system32\ismini.exe Deleted
    C:\WINDOWS\system32\drvzul.dll Deleted
    C:\WINDOWS\system32\components\flx?.dll Deleted

    »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


    »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

    Registry Cleaning done.

    »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» End


    ---------------------------------------------------------
    AVG Anti-Spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 16:56:36 30.11.2006

    + Scan result:



    C:\WINDOWS\Centrebet Poker setup.exe -> Adware.Casino : Cleaned with backup (quarantined).
    C:\Program Files\Common Files\{A0BFE2ED-0C8B-1035-0617-051123040166}\Update.exe -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\Program Files\Common Files\{A0BFE2ED-0C8B-1035-0617-051123040166}\system.dll -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\jkkighg.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\tuvssrr.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
    C:\WINDOWS\Temp\winED.tmp.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
    E:\Studio Plugarit\All Music Programs 2\Music Software\Refx Vsti Pack Junox2.rar/ReFX VSTI PACK_Junox2 v1.4_Slayer v2.0_Beast v1.0_PlastiCZ v1.02_QuadraSID6581 v1.41_TBL Bassline v1.3_Vanguard v1.03\ReFX Junox2 VSTI v1.4 -PARADOX.zip/ReFX_Junox2_VSTi_v1.4-PARADOX/pdx-rfj2.zip/CrcCheck.exe -> Downloader.Dadobr.bk : Cleaned with backup (quarantined).
    E:\Studio Plugarit\All Music Programs 2\Music Software\Refx Vsti Pack Junox2\ReFX VSTI PACK_Junox2 v1.4_Slayer v2.0_Beast v1.0_PlastiCZ v1.02_QuadraSID6581 v1.41_TBL Bassline v1.3_Vanguard v1.03\ReFX Junox2 VSTI v1.4 -PARADOX.zip/ReFX_Junox2_VSTi_v1.4-PARADOX/pdx-rfj2.zip/CrcCheck.exe -> Downloader.Dadobr.bk : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\drvjox.dll -> Not-A-Virus.Hoax.Win32.Renos.fw : Cleaned with backup (quarantined).
    :mozilla.26:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.27:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.28:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.29:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.30:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.33:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.34:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.36:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Admarketplace : Cleaned.
    :mozilla.39:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
    :mozilla.40:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
    :mozilla.148:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
    :mozilla.42:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
    :mozilla.43:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
    :mozilla.44:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
    :mozilla.45:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
    :mozilla.46:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
    :mozilla.200:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.201:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.202:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.203:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.204:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.205:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.86:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
    :mozilla.98:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
    :mozilla.99:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
    :mozilla.17:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
    :mozilla.19:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
    :mozilla.23:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
    :mozilla.24:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
    :mozilla.25:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
    :mozilla.110:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
    :mozilla.111:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.112:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.113:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.114:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.115:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.124:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.125:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.126:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.135:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Trafic : Cleaned.
    :mozilla.136:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
    :mozilla.142:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
    :mozilla.143:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
    :mozilla.145:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    :mozilla.146:C:\Documents and Settings\Juhia\Application Data\Mozilla\Firefox\Profiles\xjem0b54.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    C:\VundoFix Backups\winopn32.dll.bad -> Trojan.Mezzia : Cleaned with backup (quarantined).
    C:\Documents and Settings\Juhia\Työpöytä\keygen.exe -> Trojan.Obfuscated.an : Cleaned with backup (quarantined).


    ::Report end



    Logfile of HijackThis v1.99.1
    Scan saved at 17:01:56, on 30.11.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZONELABS\vsmon.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\system32\CTHELPER.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\ITE\ITE IT8212 ATA RAID Controller\RaidMgr.exe
    C:\WINDOWS\ATKKBService.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    c:\progra~1\intern~1\iexplore.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Documents and Settings\Juhia\Työpöytä\HijackThis_v1.99.1.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {35F7813A-AF74-4474-B1DC-7EE6FB6C43C6} - C:\WINDOWS\system32\qjdihmhg.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O2 - BHO: (no name) - {7E00C9E9-D155-4C36-BA3D-57F82C41251E} - C:\WINDOWS\system32\pmkhe.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {A98909A8-9565-4D5F-91F4-4FD2204E2B53} - C:\WINDOWS\system32\awtsq.dll (file missing)
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: 888Bar - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{30BFE~1\888Bar.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: 888Bar - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{30BFE~1\888Bar.dll
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600"
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [web meta each hole] C:\Documents and Settings\All Users\Application Data\Citydumbwebmeta\Size body.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe /start
    O4 - HKCU\..\Run: [HeartOnline] C:\DOCUME~1\Juhia\APPLIC~1\DRVSET~1\Meoweggs.exe
    O4 - Global Startup: RAID Manager.lnk = ?
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Program Files\nordicbetMPP\MPPoker.exe
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: pmkhe - C:\WINDOWS\system32\pmkhe.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe


    No niin olihan sielä kakkaa. Toolbar888 ei vaan lähteny mihkään. ainakaan tuolla alakulmassa ei ole sitä pirun pallukkaa herjaamassa viruksista.

    Viimmeeksi konees oli spysheriff ja sen poistos meni monta päivää. Mulla oli joku ohjelma siinä millä revin sen juurineen irti mutta en kuolemaksenikaa muista mikä se oli ja mistä sen löysin. Yhtä sitkeältä tuo toolbariki tuntuu. ja nortoni poistelee vähän väliä troijjalaasia.
    Perk!
     
    Last edited: Nov 30, 2006
  10. Hujo

    Hujo Guest

    Aja vuondofix uudestaan.
     
  11. Juhia

    Juhia Member

    Joined:
    Oct 16, 2005
    Messages:
    20
    Likes Received:
    0
    Trophy Points:
    11
    No niin, 11 eri ohjelmaa käytettyäni ja lukuisia uudelleenkäynnistyksiä tehtyäni mikään skanneri ei löydä mitään, kone on kaunis ja toimii ja hjt-logissa ei näy ylimääräisiä pirhanoita.
    Ei muutakuin tavaraa siirtämään, ja maltan tuskin odottaa sitä hetkeä jolloinka saa vahvistaa komennon FORMATOI C: ASEMA.
    Kiitos kaunis Hujolle, Superammattilaiselle.
    Hyvää joulua!
     
  12. Hujo

    Hujo Guest

    Hyppääs nyt jarrun päälle laita hjt loki.

    siellä on fixsattavaa
     
    Last edited by a moderator: Nov 30, 2006
  13. Juhia

    Juhia Member

    Joined:
    Oct 16, 2005
    Messages:
    20
    Likes Received:
    0
    Trophy Points:
    11
    Elikkä pitkä itku lyhyestä ilosta.

    Logfile of HijackThis v1.99.1
    Scan saved at 23:40:15, on 30.11.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZONELABS\vsmon.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\system32\CTHELPER.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\ITE\ITE IT8212 ATA RAID Controller\RaidMgr.exe
    C:\WINDOWS\ATKKBService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Documents and Settings\Juhia\Työpöytä\HijackThis_v1.99.1.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600"
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe /start
    O4 - Global Startup: RAID Manager.lnk = ?
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Program Files\nordicbetMPP\MPPoker.exe
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe
     
  14. Hujo

    Hujo Guest

    Ok, ei muuta kuin tietojen siirtoon.
    Katoin tuota vanhaa lokia siinä oli vielä. Mutta tästä lokista ovat poistuneet.

    Hyvät joulut vain.
     
Thread Status:
Not open for further replies.

Share This Page