ELi kone sanoo suoritinkäytön olevan lähes koko ajan 100% ja on ihan hemmetin hidas, vaíkkei koneella olis mitään messengeriä ihmeellisempää päällä. Tossa olis toi HJT logi, jos siitä jotain löytys Logfile of HijackThis v1.99.1 Scan saved at 17:13:35, on 25.9.2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\cisvc.exe C:\Program Files\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe C:\WINDOWS\system32\tcpsvcs.exe C:\WINDOWS\System32\snmp.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe C:\WINDOWS\system32\Fast.exe c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe C:\Program Files\MessengerPlus! 3\MsgPlus.exe C:\WINDOWS\ALCFDRTM.EXE C:\WINDOWS\system32\taskswitch.exe C:\WINDOWS\system32\fast.exe C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\WINDOWS\system32\taskmgr.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\HijackThis1991.exe R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [AlcFDMonitor] C:\WINDOWS\ALCFDRTM.EXE O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe O4 - HKLM\..\Run: [FastUser] C:\WINDOWS\system32\fast.exe O4 - HKLM\..\Run: [PMCS] C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe -host -clearDebug O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg O4 - HKLM\..\Run: [PMCRemote] C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe O4 - HKLM\..\Run: [mwavscan] "C:\Kaspersky\mwavscan.com" /s O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Startup: Client kissa.lnk = C:\Program Files\Samurize\Client.exe O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm O8 - Extra context menu item: Zoom In - C:\WINDOWS\web\zoomin.htm O8 - Extra context menu item: Zoom Out - C:\WINDOWS\web\zoomout.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O20 - Winlogon Notify: MCPClient - C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\Nvc\BIN\Zanda.exe (file missing) O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Lokissa ei näy örkkejä(jos mese plus asennettu ilman sponsoriohjelmaa , muutama ehkä turhaan käynnistyvä ohjelma. Paljonko sulla on keskusmuistia? Varoiksi voit ajaa ewidon -> http://www.ewido.net/en/download Asenna, päivitä,skannaa, tallenna raportti ja lähetä se raportti tänne.
Juu sponsori ohjelmia ei tueta. Suurin ihme tässä ny on, ku eilen vielä toimi ihan normalisti, mutta yöksi kun laitoin kovon eheytyksen (nettipiuha irti ja kaikki virusturvaa myöten pois päältä), ni aamulla oli ihan jumissa. Edit: Niin ja sitä muistia on 512mbit.
En tehnyt. En tiedä olisiko pitänyt, mutta noin se on pelittänyt ennenkin. Logi tulee heti kun tämä romu saa sen valmiiksi.
Ctrl+alt+del -> prosessit. Klikkaa alalehteä suoritin. Mikä prosessi aiheuttaa sen suorittimen 100% täytön? Jos on explorer.exe, suosittelisin asentamaan winukan uudelleen.
Mikä prosessi sen suoritintehon kuluttaa (paina CTRL+ALT+DEL ja Tehtävienhallinta/Task Manager)? (Höh, aina myöhässä.)
Nyt kun seuraa, niin tuo explorer ei ole enää ongelma, mutta tuo taskmgr syö tehoja niin paljon ku vaan saa. Milläköhän moisen sais kuriin?
Tuossa tuo logi. --------------------------------------------------------- ewido security suite - Scan report --------------------------------------------------------- + Created on: 18:57:33, 25.9.2005 + Report-Checksum: 136B966F + Scan result: HKLM\SOFTWARE\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Spyware.MyWebSearch : Cleaned with backup HKU\S-1-5-21-329068152-527237240-725345543-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} -> Spyware.MyWebSearch : Cleaned with backup HKU\S-1-5-21-329068152-527237240-725345543-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0519A9C9-064A-4CBC-BC47-D0EACD581477} -> Spyware.Icoo : Cleaned with backup HKU\S-1-5-21-329068152-527237240-725345543-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} -> Spyware.MyWebSearch : Cleaned with backup HKU\S-1-5-21-329068152-527237240-725345543-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{465A59EC-20E5-4FCA-A38A-E5EC3C480218} -> Spyware.Icoo : Cleaned with backup [1332] C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll -> Spyware.MyWebSearch : Error during cleaning C:\backups\backup-20050907-183448-660.dll -> Spyware.MyWebSearch : Cleaned with backup C:\backups\backup-20050907-183448-795.dll -> Spyware.MyWebSearch : Cleaned with backup :mozilla.14:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.15:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.16:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.17:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.18:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.19:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.29:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.48:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup :mozilla.50:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup :mozilla.51:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.52:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup :mozilla.55:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.64:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.65:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.66:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.67:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.79:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.80:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.81:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.82:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.83:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.84:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.85:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.97:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.99:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.100:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.101:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.102:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.105:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.112:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup :mozilla.120:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup :mozilla.121:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup :mozilla.123:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.124:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.125:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.136:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.137:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.138:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.139:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.154:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup :mozilla.155:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup :mozilla.159:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Adjuggler : Cleaned with backup :mozilla.160:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Adjuggler : Cleaned with backup :mozilla.161:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Xxxtoolbar : Cleaned with backup :mozilla.169:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.170:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.171:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Clickhype : Cleaned with backup :mozilla.183:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Spylog : Cleaned with backup :mozilla.192:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.211:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup :mozilla.227:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup :mozilla.228:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup :mozilla.249:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.250:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.251:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.252:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.253:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.270:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.271:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.272:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.273:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.279:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.280:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.281:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.282:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.283:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.284:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.285:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.286:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.287:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.288:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.289:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.298:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup :mozilla.299:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup :mozilla.320:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup :mozilla.348:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup :mozilla.349:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup :mozilla.358:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.359:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.360:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.361:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.364:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.365:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.366:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.377:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.397:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.417:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Xhit : Cleaned with backup :mozilla.418:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Xhit : Cleaned with backup :mozilla.423:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.426:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.437:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.438:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.439:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.452:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.453:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.468:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Trafic : Cleaned with backup :mozilla.478:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\a4n6p4sy.default\cookies.txt -> Spyware.Cookie.Counted : Cleaned with backup C:\Documents and Settings\Juha\Application Data\Opera\Opera\profile\cache4\opr0002B.js -> TrojanDownloader.IstBar.ad : Cleaned with backup C:\Documents and Settings\Juha\Cookies\juha@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup C:\Documents and Settings\Juha\Cookies\juha@atdmt[1].txt -> Spyware.Cookie.Atdmt : Cleaned with backup C:\Documents and Settings\Juha\Cookies\juha@fastclick[1].txt -> Spyware.Cookie.Fastclick : Cleaned with backup C:\Program Files\Mozilla Firefox\plugins\__delete_on_reboot__NPMyWebS.dll -> Spyware.MyWebSearch : Cleaned with backup C:\Program Files\MSN Messenger\riched20.dll -> Spyware.MyWebSearch : Cleaned with backup C:\WINDOWS\system32\f3PSSavr.scr -> Spyware.MyWebSearch : Cleaned with backup D:\build\filerepository\Microsoft-Windows-CoreUserModePnp-DriverCab_4e9013d9\driver.cab/pctspk.exe -> Worm.Bobic.k : Error during cleaning D:\Downloads\Softat\Hyöty\SmileyCentralFFSetup2.0.4.0.exe -> Spyware.MyWebSearch : Cleaned with backup D:\Windows\Driver Cache\i386\driver.cab/pctspk.exe -> Worm.Bobic.k : Error during cleaning D:\Windows\WinSxS\x86_microsoft-windows-c..ermodepnp-drivercab_31bf3856ad364e35_6.0.5112.0_neutral_81468488fc3eb132\driver.cab/pctspk.exe -> Worm.Bobic.k : Error during cleaning ::Report End
Ei tuossa muuta ole, kun että poista lisää/poista sovellus-kohdasta (ohjauspaneeli) MyWebSearch (jos on, voi olla jotain sanojen tuon perässä) Jos oli MyWebSearch, niin poista kansio C:\Program Files\==>MyWebSearch<== vikasietotilassa Käynnistä uudestaan ja lähetä uusi hjt-loki.
Tuo MyWebSearch löytyy kyllä lisää ja poista työkalusta, mutta program filessistä se on hävinnyt kokonaan. Tuossa nyt joka tapauksessa se logi. Logfile of HijackThis v1.99.1 Scan saved at 19:56:50, on 25.9.2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\cisvc.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\Program Files\ewido\security suite\ewidoguard.exe C:\Program Files\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe C:\WINDOWS\system32\tcpsvcs.exe C:\WINDOWS\System32\snmp.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\system32\svchost.exe C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\Fast.exe C:\Program Files\MessengerPlus! 3\MsgPlus.exe C:\WINDOWS\ALCFDRTM.EXE C:\WINDOWS\system32\taskswitch.exe C:\WINDOWS\system32\fast.exe C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\QuickTime\qttask.exe C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\WINDOWS\system32\ctfmon.exe c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\HijackThis1991.exe R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [AlcFDMonitor] C:\WINDOWS\ALCFDRTM.EXE O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe O4 - HKLM\..\Run: [FastUser] C:\WINDOWS\system32\fast.exe O4 - HKLM\..\Run: [PMCS] C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe -host -clearDebug O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg O4 - HKLM\..\Run: [PMCRemote] C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe O4 - HKLM\..\Run: [mwavscan] "C:\Kaspersky\mwavscan.com" /s O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Startup: Client kissa.lnk = C:\Program Files\Samurize\Client.exe O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm O8 - Extra context menu item: Zoom In - C:\WINDOWS\web\zoomin.htm O8 - Extra context menu item: Zoom Out - C:\WINDOWS\web\zoomout.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O20 - Winlogon Notify: MCPClient - C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\Nvc\BIN\Zanda.exe (file missing) O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Ei, en pysty. Ilmoittaa jonkun tiedoston puuttumisesta. Ja suoritinkäyttökin on suurimmaksi osaksi 100%
Joo toi MyWebSearchin poistamisen "mahdottomuus" ohjauspaneelista johtuu siitä, että ewido meni poistamaan sen Tuskin haittaa, tuon merkinnän voit poistaa vaikka EasyCleanerilla tai ccleanerilla (siis sen sieltä lisää/poista sovelluskohdasta). Tohon suoritinkäyttöön on paha sanoa juuri mitään
Tarkistapa muuten nämä tiedostot: D:\Windows\Driver Cache\i386\driver.cab D:\Windows\WinSxS\x86_microsoft-windows-c..ermodepnp-drivercab_31bf3856ad364e35_6.0.5112.0_neutral_81468488fc3eb132\driver.cab täällä -> http://virusscan.jotti.org (sieltä ylhäältä Selaa.. ja sitten submit). Jäi eilen huomaamatta :/
Semmonen juttu vielä, että siis pelaaminen ja leffojen kattominen koneella onnistuu suhteellisen hyvin, ja bs playerkin käynnistyy varsin nopeasti. Cs:s ää kun kokeilin, niin toimi muuten täsillä krafiikoilla, mut reunanpehmennyksestä otin vähän pois. Ja tuolla d:llähän mulla on vaan vista ja latauksia ja vista toimii ihan hyvin. Eli ongelma on pelkästään xp:n puolella ja c:llä.
Jooh, tuo virusscan.jotti.org ei toiminut. 15min. odottulu ajan jälkeen se sano toisen tiedostoista olevan tyhjä ja toisen ladattuaan tuli ilmoitus "sivua ei voida näyttää". eScannia ajelin useempaan otteeseen läpi tuloksetta, mutta tuo ewido tuntuu taas löytävän jotain. 43% mennyt ja 81 kohdetta löytynyt.