Koneelleni tuli pari kuukautta sitten kellon viereen keltainen kolmio, joka ilmoitti jostakin "System erroreista". Se oli poissa 2-4 kk ja nyt se on taas alkanut ilmestymään tuonne. Alhaalla on siitä kuva. Sitten kun klikkaa sitä se pyytää lataamaan jotakin UltimateCleaneria. Lisäksi ohjauspaneeliin on ilmestynyt sellainen "System security center", vaikka siellä on jo tietoturvakeskus. Siitäkin on alhaalla kuva. Eli pitäisi jotenkin saada puhdistettua nämä. Tälläinen kuva tulee kun klikkaa puhekuplaa (alla) Logfile of HijackThis v1.99.1 Scan saved at 14:43:59, on 13.3.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16414) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe E:\Ohjelmat\Alwil Software\Avast4\aswUpdSv.exe E:\Ohjelmat\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\Drivers\bwcsrv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\VM_STI.EXE C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe E:\Ohjelmat\Nokia\Nokia PC Suite 6\LaunchApplication.exe C:\WINDOWS\system32\uzcderaf.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE C:\WINDOWS\system32\RunDLL32.exe E:\Ohjelmat\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\psctoolx.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\MSN Messenger\msnmsgr.exe E:\Ohjelmat\Nokia\Nokia PC Suite 6\PcSync2.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\Program Files\Philips\SPC 200NC PC Camera\TrayMin.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE E:\Ohjelmat\WinZip\WZQKPICK.EXE E:\Ohjelmat\Mozilla Firefox\firefox.exe E:\Ohjelmat\Alwil Software\Avast4\ashMaiSv.exe E:\Ohjelmat\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\PC Connectivity Solution\ServiceLayer.exe C:\Program Files\MSN Messenger\usnsvc.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\System32\msiexec.exe C:\hjt\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Ohjelmat\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {db0d07e4-1dd1-11b2-878c-90a261563af8} - C:\WINDOWS\system32\msasdwe2.dll O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Philips SPC 200NC PC Camera O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" O4 - HKLM\..\Run: [PCSuiteTrayApplication] E:\Ohjelmat\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup O4 - HKLM\..\Run: [uzcderaf.exe] C:\WINDOWS\system32\uzcderaf.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [EPSON Stylus C66 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE /P23 "EPSON Stylus C66 Series" /O6 "USB001" /M "Stylus C66" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [avast!] E:\Ohjelmat\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [PSC tool] C:\WINDOWS\system32\psctoolx.exe O4 - HKLM\..\Run: [tbrklfj.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\tbrklfj.dll,mvrjzlg O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [PcSync] E:\Ohjelmat\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = E:\Ohjelmat\Microsoft office\Office\OSA9.EXE O4 - Global Startup: TrayMin.lnk = ? O4 - Global Startup: WinZip Quick Pick.lnk = E:\Ohjelmat\WinZip\WZQKPICK.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} (Dldrv2 Control) - http://download.gigabyte.com.tw/object/Dldrv.ocx O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1142684588328 O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - E:\Ohjelmat\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - E:\Ohjelmat\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - E:\Ohjelmat\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - E:\Ohjelmat\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: BUFFALO Wireless Configuration Service (bwcsrv) - Unknown owner - C:\WINDOWS\system32\Drivers\bwcsrv.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
Lataa SmitfraudFix (by S!Ri) http://siri.urz.free.fr/Fix/SmitfraudFix.zip työpöydällesi. Printtaa ohjeet ulos tai tallenna nämä tekstitiedostoon. Käynnistä koneesi vikasietotilaan ja valitse tavallinen käyttäjätilisi. Vikasietotilaan pääset painamalla F8 käynnistyksen alussa piippauksen kuultuasi. Kun vikasietotilassa, tuplaklikkaa tiedostoa SmitfraudFix.exe Valitse optio #2 - Clean kirjoittamalla 2 ja painamalla "Enter" poistaaksesi tarttuneet tiedostot. Sinulta kysytään: "Registry cleaning - Do you want to clean the registry ?"; vastaa "Yes" kirjoittamalla Y ja paina "Enter" poistaaksesi työpöydän taustakuvan ja puhdistaaksesi tarttuneet rekisteriavaimet. Työkalu tarkistaa jos wininet.dll on tarttunut. Sinua saatetaan pyytää korvaamaan tarttunut .dll (jos löytyy); vastaa "Yes" kirjoittamalla Y ja painamalla "Enter". Työkalun saattaa tarvita käynnistää kone uudelleen; jos ei tee niin, käynnistä normaaliin Windowsiin. Tekstitiedosto ilmestyy, puhdistusprosessin jäljiltä; kopioi & liitä tämän raportin tulokset vastaukseesi. Raportti löytyy paikalliselta levyltäsi, useimmiten C:\rapport.txt. Laita uusi HJT logi myös nii puhistetaan se..
Logfile of HijackThis v1.99.1 Scan saved at 16:09:09, on 13.3.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16414) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe E:\Ohjelmat\Alwil Software\Avast4\aswUpdSv.exe E:\Ohjelmat\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\Drivers\bwcsrv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\VM_STI.EXE C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe E:\Ohjelmat\Nokia\Nokia PC Suite 6\LaunchApplication.exe C:\WINDOWS\system32\uzcderaf.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE C:\WINDOWS\system32\RunDLL32.exe E:\Ohjelmat\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\psctoolx.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\MSN Messenger\msnmsgr.exe E:\Ohjelmat\Nokia\Nokia PC Suite 6\PcSync2.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\Philips\SPC 200NC PC Camera\TrayMin.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE E:\Ohjelmat\WinZip\WZQKPICK.EXE E:\Ohjelmat\Alwil Software\Avast4\setup\avast.setup C:\WINDOWS\system32\wuauclt.exe C:\hjt\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Ohjelmat\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {db0d07e4-1dd1-11b2-878c-90a261563af8} - C:\WINDOWS\system32\msasdwe2.dll O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Philips SPC 200NC PC Camera O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" O4 - HKLM\..\Run: [PCSuiteTrayApplication] E:\Ohjelmat\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup O4 - HKLM\..\Run: [uzcderaf.exe] C:\WINDOWS\system32\uzcderaf.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [EPSON Stylus C66 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE /P23 "EPSON Stylus C66 Series" /O6 "USB001" /M "Stylus C66" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [avast!] E:\Ohjelmat\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [PSC tool] C:\WINDOWS\system32\psctoolx.exe O4 - HKLM\..\Run: [tbrklfj.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\tbrklfj.dll,mvrjzlg O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [PcSync] E:\Ohjelmat\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = E:\Ohjelmat\Microsoft office\Office\OSA9.EXE O4 - Global Startup: TrayMin.lnk = ? O4 - Global Startup: WinZip Quick Pick.lnk = E:\Ohjelmat\WinZip\WZQKPICK.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - E:\Ohjelmat\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - E:\Ohjelmat\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - E:\Ohjelmat\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - E:\Ohjelmat\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: BUFFALO Wireless Configuration Service (bwcsrv) - Unknown owner - C:\WINDOWS\system32\Drivers\bwcsrv.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe SmitFraudFix v2.148 Scan done at 16:04:27,35, ti 13.03.2007 Run from C:\Documents and Settings\Käyttäjä\Ty”p”yt„\SmitfraudFix\SmitfraudFix OS: Microsoft Windows XP [versio 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» hosts 127.0.0.1 localhost »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\DOCUME~1\Käyttäjä\Suosikit\Online Security Test.url Deleted »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End Tässä olisi lokit.
Lataa VundoFix.exe työpöydällesi. *Tupla-klikkaa VundoFix.exe ajaaksesi sen. *Klikkaa Scan for Vundo valintaa. *Kun skannaus on valmis, klikkaa Remove Vundo valintaa. *Sinulta kysytään haluatko poistaa filut - klikkaa YES. *Kun olet klikannut yes, työpöytäsi tyhjenee kun se alkaa poistamaan Vundoa. *Kun se on valmis, fiksi ilmoittaa käynnistäväsi koneesi uudelleen, klikkaa OK. *Postita C:\vundofix.txt lokin sekä tuoreen HijackThis lokin sisältö. Huomaa: Se on mahdollista että VundoFix löysi tiedoston jota se ei pystynyt poistamaan. Tässä tilanteessa, VundoFix ajaa itsensä rebootissa, seuraa vain yläpuolelle olevia ohjeita alkaen kohdasta "Klikkaa Scan for Vundo valintaa." kun VundoFix ilmaantuu uudelleenkäynnistyksen yhteydessä. Laita uusi HJT-logi
On sul sontaa. tehään nää: avaa hijackthis merkkaa ja fixaa nää rivit: O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: (no name) - {db0d07e4-1dd1-11b2-878c-90a261563af8} - C:\WINDOWS\system32\msasdwe2.dll O4 - HKLM\..\Run: [uzcderaf.exe] C:\WINDOWS\system32\uzcderaf.exe O4 - HKLM\..\Run: [tbrklfj.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\tbrklfj.dll,mvrjzlg ******************************* lataa ATF Cleaner http://www.atribune.org/ccount/click.php?id=1 Tupla-klikkaa ATF-Cleaner.exe käynnistääksesi ohjelman. Main:n alla valitse: Select All Klikkaa Empty Selected valintaa. Jos käytät FireFoxia selaimenasi Klikkaa Firefox yläpuolelta ja valitse: Select All Klikkaa Empty Selected valintaa. HUOMIO: Jos haluaisit pitää tallennetut salasanasi, klikkaa No kun se sitä kysyy. Jos käytät Operaa selaimenasi Klikkaa Opera yläpuolelta ja valitse: Select All Klikkaa Empty Selected valintaa taas. HUOMIO: Jos haluaisit pitää tallennetut salasanasi, klikkaa No kun se sitä kysyy. Klikkaa Exit päävalikosta sulkeaksesi ohjelman. Teknistä tukea tulee jos tupla-klikkaat sähköpostiosoitetta joka sijaitsee jokaisen menun alapuolella kyseisessä työkalussa. (Huomatkaa että se tuki on sitten englanniksi) ************************** Lataa AVG Anti-Spyware 7.5 ja tallenna ohjelma työpöydällesi. [*]Kun olet ladannut ohjelman, kaksoisklikkaa asennuohjelman pikakuvaketta työpöydälläsi, asennus alkaa. [*]Asennuksen jälkeen täytyy ohjelma käynnistää ja sen tunnisteet päivittää. [*]Käynnistä AVG Anti-Spyware. [*]Klikkaa "Update" kuvaketta päävalikossa. Sen jälkeen klikkaa "Update now" painiketta. [*]Sitten klikkaa "Start Update" kuvaketta jolloin päivitys alkaa. [*]Kun päivitykset on ladattu, klikkaa "Scanner" kuvaketta ikkunan ylälaidassa. Valitse sitten "Settings" välilehti. [*]Kun "Settings" valikko on auennut, klikkaa "Recommended actions" ja sitten valitse "Quarantine". [*]Sitten "Reports" valikon alta: [*]Laita täppi kohtaan "Automatically generate report after every scan" [*]Ota täppi pois kohdasta"Only if threats were found" [*]Sitten klikkaa "Shield" kuvaketta ikkunan ylälaidassa [*]"Resident shield is", muuta tila active:sta inactive:ksi [*]Sulje ohjelma, ÄLÄ skannaa vielä. Käynnistä tietokone vikasietotilaan: 1. Käynnistä tietokone uudelleen. 2. Kun tietokone käynnistyy, paina F8-näppäintä. 3. Näyttöön tulee erilaisia käynnistysvaihtoehtoja. 4. Valitse näppäimistön nuolinäppäinten avulla Vikasietotila. 5. Paina ENTER-näppäintä. Poista nää C:\WINDOWS\system32\msasdwe2.dll C:\WINDOWS\system32\uzcderaf.exe C:\WINDOWS\system32\tbrklfj.dll ******************* Jos ei löydy laita piilotiedostot näkyviin * Avaa Oma Tietokone. * Valitse Työkalut ylämenusta ja klikkaa Kansion asetukset. * Valitse Näytä välilehti. * Piilotiedostot/kansiot kohdalla valitse Näytä piilotetut tiedostot ja kansiot. * Poista rasti ruudusta -> Piilota suojatut käyttöjärjestelmätiedostot * Klikkaa Kyllä varmistaaksesi muutokset. * Klikkaa OK. * Muista kanssa laittaa ne piilon takasin! ************* HUOM! Älä käytä muita ohjelmia AVG skannauksen aikana, tämä saattaa häiritä skannausta. [*]Kun vikasietotilassa, käynnistä AVG Anti-Spyware. [*]Klikkaa "Scanner" kuvaketta ikkunan ylälaidassa ja valitse "Scan" välilehti. Sitten klikkaa "Complete System Scan". [*]AVG aloittaa nyt tietokoneen skannaamisen, ole kärsivällinen sillä skannaus vie aikaa. Kun skannaus on valmis: TÄRKEÄÄ : Älä klikkaa "Save Scan Report" ennen kuin klikkaat "Apply all Actions" [*]Varmistu, että Set all elements to: näyttää Quarantine (1), jos ei, klikkaa linkkiä ja valitse Quarantine popup-valikosta. [*]Sinulta kysytään mitä tehdä jos infektioita löytyi, valitse silloin "Apply all actions" [*]Sitten klikkaa "Reports" kuvaketta ohjelma yläosasta. [*]Klikkaa "Save report as" painiketta ikkunan vasemmassa alalaidassa ja tallenna raportti työpöydälle. [*]Sulje ohjelma, käynnistä kone normaalisti ja lähetä AVG:n raportti viestiketjuusi. ********* Uusi logi..
En löytänyt poistettavista tiedostoista ekaa, vaikka oli piilotiedostot näkyvillä. ATF -Cleanerissa ei ylhäällä pystynyt firefox tai opera valikkoa edes avaamaan, kun olivat sellaiset harmaat joita ei voi valita. Logfile of HijackThis v1.99.1 Scan saved at 17:48:20, on 14.3.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16414) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe E:\Ohjelmat\Alwil Software\Avast4\aswUpdSv.exe E:\Ohjelmat\Alwil Software\Avast4\ashServ.exe E:\Ohjelmat\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\Drivers\bwcsrv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\VM_STI.EXE C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe E:\Ohjelmat\Nokia\Nokia PC Suite 6\LaunchApplication.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE C:\WINDOWS\system32\RunDLL32.exe E:\Ohjelmat\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\psctoolx.exe E:\Ohjelmat\AVG Anti-Spyware 7.5\avgas.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\MSN Messenger\msnmsgr.exe E:\Ohjelmat\Alwil Software\Avast4\ashMaiSv.exe E:\Ohjelmat\Nokia\Nokia PC Suite 6\PcSync2.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe E:\Ohjelmat\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\PC Connectivity Solution\ServiceLayer.exe C:\Program Files\Philips\SPC 200NC PC Camera\TrayMin.exe E:\Ohjelmat\WinZip\WZQKPICK.EXE E:\Ohjelmat\Alwil Software\Avast4\setup\avast.setup C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe C:\WINDOWS\system32\wuauclt.exe E:\Ohjelmat\Mozilla Firefox\firefox.exe C:\hjt\HijackThis.exe C:\Program Files\MSN Messenger\usnsvc.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Ohjelmat\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Philips SPC 200NC PC Camera O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" O4 - HKLM\..\Run: [PCSuiteTrayApplication] E:\Ohjelmat\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [EPSON Stylus C66 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE /P23 "EPSON Stylus C66 Series" /O6 "USB001" /M "Stylus C66" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [avast!] E:\Ohjelmat\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [PSC tool] C:\WINDOWS\system32\psctoolx.exe O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Ohjelmat\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [PcSync] E:\Ohjelmat\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = E:\Ohjelmat\Microsoft office\Office\OSA9.EXE O4 - Global Startup: TrayMin.lnk = ? O4 - Global Startup: WinZip Quick Pick.lnk = E:\Ohjelmat\WinZip\WZQKPICK.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - E:\Ohjelmat\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - E:\Ohjelmat\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - E:\Ohjelmat\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - E:\Ohjelmat\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Ohjelmat\AVG Anti-Spyware 7.5\guard.exe O23 - Service: BUFFALO Wireless Configuration Service (bwcsrv) - Unknown owner - C:\WINDOWS\system32\Drivers\bwcsrv.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe --------------------------------------------------------- AVG Anti-Spyware - Scan Report --------------------------------------------------------- + Created at: 17:44:50 14.3.2007 + Scan result: C:\WINDOWS\system32\isc_cpl.cpl -> Adware.SecurityCenter : Cleaned with backup (quarantined). C:\WINDOWS\system32\isc_ui.exe -> Adware.UltimateDefender : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\CLSID\{40dcff6e-af8d-4183-8ebe-a82270ac449e} -> Adware.VirusBursters : Cleaned with backup (quarantined). E:\Ohjelmat\GTA\GTA San Andreas\hlm-intro.exe -> Backdoor.Hupigon.kg : Cleaned with backup (quarantined). C:\WINDOWS\system32\qewiyrui1.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined). C:\WINDOWS\system32\qewiyrui2.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined). C:\WINDOWS\system32\qewiyrui3.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined). :mozilla.258:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.259:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.260:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.261:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.263:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.264:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.265:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.266:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.267:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.268:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.269:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.270:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.415:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.590:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.598:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.701:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.702:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.703:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.87:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.88:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.89:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.451:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned. :mozilla.452:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned. :mozilla.453:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned. :mozilla.621:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Adocean : Cleaned. :mozilla.622:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Adocean : Cleaned. :mozilla.627:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Adocean : Cleaned. :mozilla.300:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.301:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.12:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.13:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.62:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.63:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.6:C:\Documents and Settings\Pirjo\Application Data\Mozilla\Firefox\Profiles\nnxd66gs.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.7:C:\Documents and Settings\Pirjo\Application Data\Mozilla\Firefox\Profiles\nnxd66gs.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.124:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.125:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.126:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.127:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.128:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.28:C:\Documents and Settings\Pirjo\Application Data\Mozilla\Firefox\Profiles\nnxd66gs.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.70:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.71:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.163:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Adviva : Cleaned. :mozilla.10:C:\Documents and Settings\Ari\Application Data\Mozilla\Firefox\Profiles\fbgdwl4f.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.111:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.386:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Belstat : Cleaned. :mozilla.896:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Bfast : Cleaned. :mozilla.751:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned. :mozilla.848:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.601:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned. :mozilla.733:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned. :mozilla.734:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned. :mozilla.26:C:\Documents and Settings\Pirjo\Application Data\Mozilla\Firefox\Profiles\nnxd66gs.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.27:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.76:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.817:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Estat : Cleaned. :mozilla.583:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Etracker : Cleaned. :mozilla.164:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.165:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.91:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.92:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.623:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Gemius : Cleaned. :mozilla.624:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Gemius : Cleaned. :mozilla.199:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.241:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.318:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.243:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.254:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.592:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.593:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.668:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.679:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.709:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.785:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.892:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned. :mozilla.373:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Information : Cleaned. :mozilla.203:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Ivwbox : Cleaned. :mozilla.670:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Komtrack : Cleaned. :mozilla.671:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Komtrack : Cleaned. :mozilla.586:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.587:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.447:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.120:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Paypal : Cleaned. :mozilla.209:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Paypal : Cleaned. :mozilla.735:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.736:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.188:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.189:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.190:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.191:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.458:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Realtracker : Cleaned. :mozilla.459:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Realtracker : Cleaned. :mozilla.760:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Revenue : Cleaned. :mozilla.302:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.303:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.304:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.737:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.738:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.683:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.684:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.685:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.686:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.687:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.688:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.911:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.912:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.913:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.914:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.915:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.916:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.917:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.918:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.919:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.920:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.921:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.922:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.923:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.924:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.925:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.926:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.927:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.928:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.929:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.930:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.931:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.932:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.933:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.934:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.935:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.936:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.937:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.938:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.939:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.940:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.941:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.942:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.943:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.944:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.945:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.946:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.947:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.948:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.949:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.950:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.951:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.952:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.953:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.954:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.955:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.956:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.957:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.958:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.959:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.960:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.967:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned. :mozilla.968:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned. :mozilla.969:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned. :mozilla.690:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned. :mozilla.298:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Skype : Cleaned. :mozilla.299:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Skype : Cleaned. :mozilla.377:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Skype : Cleaned. :mozilla.7:C:\Documents and Settings\Ari\Application Data\Mozilla\Firefox\Profiles\fbgdwl4f.default\cookies.txt -> TrackingCookie.Skype : Cleaned. :mozilla.8:C:\Documents and Settings\Ari\Application Data\Mozilla\Firefox\Profiles\fbgdwl4f.default\cookies.txt -> TrackingCookie.Skype : Cleaned. :mozilla.114:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.217:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.218:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.219:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.220:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.221:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.222:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.223:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.224:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.225:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.226:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.227:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.228:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.229:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.230:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.231:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.232:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.233:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.609:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.610:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.320:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Toplist : Cleaned. :mozilla.24:C:\Documents and Settings\Pirjo\Application Data\Mozilla\Firefox\Profiles\nnxd66gs.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.85:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.86:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.88:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.89:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.91:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.92:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.93:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.262:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.329:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned. :mozilla.361:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned. :mozilla.809:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned. :mozilla.175:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned. :mozilla.498:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Yadro : Cleaned. :mozilla.180:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.181:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.182:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.90:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.93:C:\Documents and Settings\Raine\Application Data\Mozilla\Firefox\Profiles\qg82vmqt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.599:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.600:C:\Documents and Settings\Erno\Application Data\Mozilla\Firefox\Profiles\3uf5vugg.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. E:\Raine\Ladatut tiedostot\01 Track 1.wma -> Trojan.Wimad.a : Cleaned with backup (quarantined). ::Report end
C:\WINDOWS\system32\psctoolx.exe http://www.virustotal.com lähetä sinne ja laita tulokset tähän ketjuu niin mietitään mitä tehään! ******************* laita piilotiedostot näkyviin, jos et löydä * Avaa Oma Tietokone. * Valitse Työkalut ylämenusta ja klikkaa Kansion asetukset. * Valitse Näytä välilehti. * Piilotiedostot/kansiot kohdalla valitse Näytä piilotetut tiedostot ja kansiot. * Poista rasti ruudusta -> Piilota suojatut käyttöjärjestelmätiedostot * Klikkaa Kyllä varmistaaksesi muutokset. * Klikkaa OK. * Muista kanssa laittaa ne piilon takasin! **************
Tälläisen tuloksen antoi VirusTotal: Piilotiedostot oli näkyvissä, mutta en löytänyt siltikään, eikä haku myöskään. Voisin nyt vielä katsoa sitö kerran...
Sulta puuttuu ilmanen palomuuri Lataa sellanen **************** Fixaa nää rivit O4 - HKLM\..\Run: [PSC tool] C:\WINDOWS\system32\psctoolx.exe ************** Lataa Killbox Option^Explicitiltä. Huomaa: Jos sinulla on jo Killbox, tämä on uusi versio joka sinun tulee asentaa. Poista aikaisempi. [*]Tallenna työpöydällesi. [*] Tupla-klikkaa Killbox.exe ajaaksesi ohjelman. [*] Valitse: [*]Delete on Reboot[*] sitten klikkaa All Files valintaa. [*]Kopioi ja liitä alapuolella olevat tiedostopolut leikepöydälle mustaamalla KAIKKI ne ja painamalla CTRL + C (tai, mustaamisen jälkeen, oikea klikki hiirellä ja valitse kopioi): C:\WINDOWS\system32\psctoolx.exe [*] Palaa Killboxiin, mene File valikkoon, ja valitse Paste from Clipboard. [*]Klikkaa puna-valkoista Delete File valintaa. Klikkaa Yes "Delete on Reboot" pyyntöön. Klikkaa OK mihin vain PendingFileRenameOperations pyyntöön (ja anna fixaajan tietää jos jokin tälläinen tulee!). Käynnistä koneesi itse jos se ei sitä automaattisesti tee Jos saat tälläisen viestin: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." Kun yrität ajaa KillBoxia, klikkaa tätä ladataksesi ja ajaaksesi Missingfilessetup.exe;n. Sitten koita KillBoxia uudestaan.
Onko pakko olla softapalomuuri on on jo rautapalomuuri? Kaikki antamasi fixaukset sain tehtyä. Tässä vielä loki. Logfile of HijackThis v1.99.1 Scan saved at 21:10:54, on 14.3.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16414) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe E:\Ohjelmat\Alwil Software\Avast4\aswUpdSv.exe E:\Ohjelmat\Alwil Software\Avast4\ashServ.exe E:\Ohjelmat\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\Drivers\bwcsrv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\VM_STI.EXE C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe E:\Ohjelmat\Nokia\Nokia PC Suite 6\LaunchApplication.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE C:\WINDOWS\system32\RunDLL32.exe E:\Ohjelmat\ALWILS~1\Avast4\ashDisp.exe E:\Ohjelmat\AVG Anti-Spyware 7.5\avgas.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\MSN Messenger\msnmsgr.exe E:\Ohjelmat\Nokia\Nokia PC Suite 6\PcSync2.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\Philips\SPC 200NC PC Camera\TrayMin.exe E:\Ohjelmat\WinZip\WZQKPICK.EXE E:\Ohjelmat\Mozilla Firefox\firefox.exe E:\Ohjelmat\Alwil Software\Avast4\setup\avast.setup C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe E:\Ohjelmat\Alwil Software\Avast4\ashMaiSv.exe E:\Ohjelmat\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\PC Connectivity Solution\ServiceLayer.exe C:\hjt\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Ohjelmat\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Philips SPC 200NC PC Camera O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" O4 - HKLM\..\Run: [PCSuiteTrayApplication] E:\Ohjelmat\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [EPSON Stylus C66 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE /P23 "EPSON Stylus C66 Series" /O6 "USB001" /M "Stylus C66" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [avast!] E:\Ohjelmat\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Ohjelmat\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [PcSync] E:\Ohjelmat\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = E:\Ohjelmat\Microsoft office\Office\OSA9.EXE O4 - Global Startup: TrayMin.lnk = ? O4 - Global Startup: WinZip Quick Pick.lnk = E:\Ohjelmat\WinZip\WZQKPICK.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - E:\Ohjelmat\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - E:\Ohjelmat\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - E:\Ohjelmat\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - E:\Ohjelmat\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Ohjelmat\AVG Anti-Spyware 7.5\guard.exe O23 - Service: BUFFALO Wireless Configuration Service (bwcsrv) - Unknown owner - C:\WINDOWS\system32\Drivers\bwcsrv.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
On: 1) Voinko poistaa nyt noi ohjelmat, joita käytettiin haittaohjelmien poistamiseen? 2) Kannattaisiko asentaa vielä varmuudeksi softamuuri, vai pystyykö rautamuuri blokkaamaan kaikki? 3) Kiitos avusta! =)
1)Kaiken muun voit poistaa paitsi AVG-antispywarea, sitä ei sen takia että se on hyvä skanneri spywarea varten. Päivität sen ja skannailet sillon tällön niin pärjäät hyvin 2)Ei tarvitse softapalomuuria, windowsin oma riittää hyvin 3)Ole hyvä 4)Nää on ihan ok juttui: ********************** Avaa omatietokone Paina oikealla napilla C: asemaa ->valitse ominaisuudet Avaa työkalut välilehti ->aja virheen etsintä ->eheytä kiintolevy ********* Lataa tuosta CCleaner ja asenna se: http://ccleaner.com/download/downloadpage.aspx?1 Kun asennat tätä ohjelmaa niin älä asenna sen mukana tulevaa yahoo-toolbaria. Tämä ohjelma etsii ja poistaa ns. turhia tiedostoja koneeltasi eli esim: temp tiedostot ja tällä saat myös puhdistettua rekisterisi.
Ccleanerin olen ajanutkin säännöllisesti ja eheyttänyt kiintolevyn. Nyt kone on sitten kunnossa, kiitos sinulle