Tehtäväpalkin ilmoitusalueelle on ilmestynyt ikoni, joka vaihtuu vuorotellen kysymysmerkiksi(Windows) ja "pysäköinti kielletty" merkiksi.Tasaisin väliajoin tulee System Alert -ilmoitus. Klikkaamalla ikonia hiiren oik. tai vas. näppäimellä avautuu selain ja "http://www.spylocked.com/?aff=334" -sivu. Jos menen "ulkoasu ja teemat" ja sieltä "Tehtäväpalkki ja käynnistävalikko" ja "mukauta ilmoitukset" tämä kyseinen ikoni näkyy jompana kumpana ja sen perässä <ei otsikkoa>. Miten saan tuo linkin poistettua?
Lataa SmitfraudFix (by S!Ri) työpöydällesi. Tuplaklikkaa tiedostoa SmitfraudFix.exe Valitse optio #1 - Search kirjoittamalla 1 ja painamalla "Enter"; tekstitiedosto avautuu, joka listaa tarttuneet tiedostot (jos olemassa). Postita tämän tekstitiedoston sisältö viestiketjuusi. **Jos työkalu ei käynnisty työpöydältä niin siirrä SmitfraudFix.exe suoraan järjestelmäaseman juureen (yleensä C:). Kokeile sitten käynnistää ohjelma uudestaan sieltä. Huomaa : process.exe filun tunnistaa jotkut Anti-virus ohjelmat (AntiVir, Dr.Web, Kaspersky) "Haittakaluna"; se ei ole virus, vaan ohjelma joka pysäyttää prosesseja. A/V ohjelmat eivät pysty tunnistamaan hyvän ja pahan käytön tälläisten ohjelmian väliltä, silloin ne saattavat varoittaa käyttäjää. http://www.beyondlogic.org/consulting/processutil/processutil.htm ========== Printtaa ohjeet ulos tai tallenna nämä tekstitiedostoon. Käynnistä koneesi vikasietotilaan ja valitse tavallinen käyttäjätilisi. Vikasietotilaan pääset painamalla F8 käynnistyksen alussa piippauksen kuultuasi. Kun vikasietotilassa, tuplaklikkaa tiedostoa SmitfraudFix.exe Valitse optio #2 - Clean kirjoittamalla 2 ja painamalla "Enter" poistaaksesi tarttuneet tiedostot. Sinulta kysytään: "Registry cleaning - Do you want to clean the registry ?"; vastaa "Yes" kirjoittamalla Y ja paina "Enter" poistaaksesi työpöydän taustakuvan ja puhdistaaksesi tarttuneet rekisteriavaimet. Työkalu tarkistaa jos wininet.dll on tarttunut. Sinua saatetaan pyytää korvaamaan tarttunut .dll (jos löytyy); vastaa "Yes" kirjoittamalla Y ja painamalla "Enter". Työkalun saattaa tarvita käynnistää kone uudelleen; jos ei tee niin, käynnistä normaaliin Windowsiin. Tekstitiedosto ilmestyy, puhdistusprosessin jäljiltä; kopioi & liitä tämän raportin tulokset vastaukseesi. Raportti löytyy paikalliselta levyltäsi, useimmiten C:\rapport.txt. ========== Laita molempien kohtien lokit sekä -> Lataa Hijackthis: http://koti.mbnet.fi/pattaya1/HijackThis.exe -> Tallenna hakemistoon C:\hjt ->Uudelleennimeä HijackThis.exe -> scanner.exe:ksi näin: 1. Klikkaa hiiren oikealla painikkeella HijackThis ikonia. 2. Valitse Uudelleennineä/ Rename. 3. Kirjoita scanner.exe -> Käynnistä HijackThis ja klikkaa: do a system scan and save a logfile. -> Lähetä ilmestynyt logisi tähän ketjuun
Kiitos! Vikasietotilan ja Registry cleaning -prosessin jälkeen, koneen käynnistyttyä ongelma oli poistunut.
Logfile of HijackThis v1.99.1 Scan saved at 14:19:44, on 10.5.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16414) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\PROGRA~1\ELISAT~1\backweb\4119343\Program\SERVIC~1.EXE C:\WINDOWS\system32\CTSvcCDA.EXE C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32st.exe C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\program\fsbwsys.exe C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\FSGK32.EXE C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMA32.EXE C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fssm32.exe C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMB32.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Elisa Tietoturvapalvelu\Common\FCH32.EXE c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Tablet.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsqh.exe C:\Program Files\Elisa Tietoturvapalvelu\Common\FAMEH32.EXE C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsrw.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsav32.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\WTablet\TabUserW.exe C:\Program Files\Ahead\InCD\InCD.exe C:\Program Files\Microsoft IntelliType Pro\type32.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\PROGRA~1\Lexmark\PHOTOC~1\LXBLKsk.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\Logitech\Video\LogiTray.exe C:\PROGRA~1\MAGICW~1\MW1HEL~1.EXE C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\ispnews.exe C:\Program Files\MessengerPlus! 3\MsgPlus.exe C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE C:\Program Files\QuickTime\qttask.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\Program\fspex.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Elisa Tietoturvapalvelu\FWES\Program\fsdfwd.exe C:\WINDOWS\system32\Tablet.exe C:\PROGRA~1\ELISAT~1\ANTI-S~1\fsaw.exe C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\fsguidll.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Ossi\Työpöytä\scanner.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Elisa Internet R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;;localhost;<local> R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet3_88.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: (no name) - {7A8F5B7A-A74F-495E-8A33-DF6226D2BAD8} - C:\Program Files\Video ActiveX Access\iesplg.dll (file missing) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file) O2 - BHO: Elisa Avustaja Plugin - {DB87CDE1-EF9C-44EB-A42F-6D0B3C72C516} - C:\Program Files\Elisa\Avustaja\IEFixItNowPlugin.dll O3 - Toolbar: (no name) - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - (no file) O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file) O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: Protection Bar - {31615D5C-5126-448A-818A-A7CDFEE85A9B} - C:\Program Files\Video ActiveX Access\iesbpl.dll (file missing) O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [LXBLKsk] C:\PROGRA~1\Lexmark\PHOTOC~1\LXBLKsk.exe O4 - HKLM\..\Run: [MemoryCardManager] C:\Program Files\Lexmark\Lexmark Photo Center\MemoryCardManager.exe -startup O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Elisa Tietoturvapalvelu\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\FSSW.EXE" /reboot O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg O4 - HKLM\..\Run: [MW1HelperStartUp] C:\PROGRA~1\MAGICW~1\MW1HEL~1.EXE /partner MW1 O4 - HKLM\..\Run: [News Service] "C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\ispnews.exe" O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Startup: Watch.lnk = C:\WINDOWS\twain_32\A4CIS\WATCH.exe O4 - Global Startup: Elisa Tietoturvapalvelu.lnk = C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\Program\fspex.exe O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Building basic 3D Web Sites.lnk = C:\Program Files\3DSTATE\3D Webmaker\Tutorials\Building basic 3D Web Sites.htm O4 - Global Startup: Building advanced 3D Web Sites.lnk = C:\Program Files\3DSTATE\3D Webmaker\Tutorials\Building advanced 3D Web Sites.htm O4 - Global Startup: Basic Samples.lnk = C:\Program Files\3DSTATE\3D Webmaker\Basic Samples\index.htm O4 - Global Startup: Advanced Samples.lnk = C:\Program Files\3DSTATE\3D Webmaker\3D Web Samples\Html\index.htm O4 - Global Startup: Converters.lnk = ? O4 - Global Startup: License.lnk = C:\Program Files\3DSTATE\3D Webmaker\License\License.txt O4 - Global Startup: Webmaker Book.lnk = C:\Program Files\3DSTATE\3D Webmaker\Webmaker book\Webmaker book.doc O4 - Global Startup: Programming Reference Manual.lnk = C:\Program Files\3DSTATE\3D Webmaker\Programming Reference Manual\default.htm O4 - Global Startup: Tutorials.lnk = C:\Program Files\3DSTATE\3D Webmaker\Tutorials\index.htm O4 - Global Startup: Resources.lnk = C:\Program Files\3DSTATE\3D Webmaker\wwwRes\resources.htm O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Free WebSite Tools.lnk = ? O8 - Extra context menu item: &Estä tämä kohoikkuna - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\blockpopups.htm O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: IE-suojaus - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\ieshield.dll O9 - Extra 'Tools' menuitem: IE-suojaus... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\ieshield.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra button: Tuki - {0883023E-F304-43A2-A843-64C9CFAC85DB} - http://tuki.elisa.net/ (file missing) (HKCU) O9 - Extra button: SMS-viesti - {0B5BFEC0-A026-4F5D-B338-E3DCD5B0B6F5} - http://sms.kolumbus.fi/ (file missing) (HKCU) O9 - Extra button: Palvelut - {8A77EEDF-87F7-443B-8559-FF6827677B05} - http://service.kolumbus.fi/ (file missing) (HKCU) O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O11 - Options group: [INTERNATIONAL] International* O14 - IERESET.INF: START_PAGE_URL=http://elisa.net/ O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/installer.v4/vet_install_popup.pl?3&6&04.00.04.03&unknown&unknown&http://www.opel.fi/content_data/GME/019/FI/fi/GBPFI/microsite/0N/RTT/signum.html O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\edgqhtiq.exe O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Elisa Tietoturvapalvelu (BackWeb Plug-in - 4119343) - BackWeb Technologies Inc. - C:\PROGRA~1\ELISAT~1\backweb\4119343\Program\SERVIC~1.EXE O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32st.exe O23 - Service: FSBWSYS (fsbwsys) - F-Secure Corp. - C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\program\fsbwsys.exe O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\FWES\Program\fsdfwd.exe O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMA32.EXE O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
Ensin lataa LSPfix.exe http://www.cexx.org/lspfix.htm sopivaan sijaintiin (kuten C:\Program Files\LSPFix tai vaikkapa työpöydälle). ÄLÄ aja tätä ohjelmaa vielä. Tätä tulee käyttää VAIN jos internetyhteys häviää NewDotNetin poiston jäljiltä. NewDotNetin poisto; Mene; Käynnistä > Ohjauspaneeli > Lisää/Poista sovellus ja hävitä seuraava jos näkyy; New.Net Applications tai New.Net Domains (Mitä vain mikä sanoo New.Net) Jos Lisää/Poista sovelluksessa ei ole New.Net listattu, toimi näin. Varmista että anti-virus ja anti-spyware ohjelmat ovat suljettuna poiston ajan. Ne saattavat estää New.Netin poiston. Lataa NNuninstall.exe http://www.new.net/support/NNuninstall.exe * Tallenna se työpöydällesi. * Tupla-klikkaa NNuninstall.exe filua. * Ohjelma kysyy haluatko poistaa kaikki New.Netin nimet ja osat. * Klikkaa Yes. * Klikkaa poiston jälkeen OK. * Käynnistä kone uudelleen ("Yes - Restart now") ellei jäänyt mitään muuta kesken, jos jäi, jätä kone päälle ("No - I will restart later). Jos poisto ei onnistu ja virustorjuntaohjelma(t) estävät poisto-ohjelman ajon kokonaan tai osittain, tee näin: Irrota koneen verkko- tai modeemijohto koneesta siten, ettei sillä ole yhteyttä internettiin. Sulje tämän jälkeen virustorjuntaohjelma(t) ja aja NNuninstall.exe. Laita tämän jälkeen virustorjuntaohjelma(t) takaisin päälle ja vasta sitten kytke verkko- tai modeemijohto takaisin koneeseen. Tyhjennä roskakori. JOS menetät nettiyhteytesi kun olet New.Netin poistanut, tupla-klikkaa LSPFix.exe jonka latasit aiemmin. Rastita "I know what I'm doing" valinta. Näet kaksi paneelia; Jos on jotain listattu "Remove" paneeliin oikealla puolella, anna sen olla ja klikkaa "Finish>>". Seuraavaksi käynnistä uudelleen ja netin pitäisi toimia hyvin. Jos mitään ei ole listattu "Remove" paneeliin, ÄLÄ tee MITÄÄN - sulje LSPFix. Tule joltain toiselta koneelta hakemaan lisää neuvoa. (Tämä on vain varotoimenpide, useimmiten netti pysyy ihan kunnossa] ========== Laita uusi hjt logi
Logfile of HijackThis v1.99.1 Scan saved at 21:23:33, on 11.5.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16441) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\PROGRA~1\ELISAT~1\backweb\4119343\Program\SERVIC~1.EXE C:\WINDOWS\system32\CTSvcCDA.EXE C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32st.exe C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\program\fsbwsys.exe C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\FSGK32.EXE C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMA32.EXE C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fssm32.exe C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMB32.EXE C:\WINDOWS\system32\nvsvc32.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Program Files\Elisa Tietoturvapalvelu\Common\FCH32.EXE C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Tablet.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\Program Files\Elisa Tietoturvapalvelu\Common\FAMEH32.EXE C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsqh.exe C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsrw.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsav32.exe C:\Program Files\Ahead\InCD\InCD.exe C:\Program Files\Microsoft IntelliType Pro\type32.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\PROGRA~1\Lexmark\PHOTOC~1\LXBLKsk.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\Logitech\Video\LogiTray.exe C:\PROGRA~1\MAGICW~1\MW1HEL~1.EXE C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\ispnews.exe C:\Program Files\MessengerPlus! 3\MsgPlus.exe C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE C:\Program Files\QuickTime\qttask.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\Program\fspex.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Elisa Tietoturvapalvelu\FWES\Program\fsdfwd.exe C:\WINDOWS\system32\Tablet.exe C:\Program Files\iPod\bin\iPodService.exe C:\PROGRA~1\ELISAT~1\ANTI-S~1\fsaw.exe C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\fsguidll.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Ossi\Työpöytä\Työkaluja\scanner.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Elisa Internet R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;;localhost;<local> R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: (no name) - {7A8F5B7A-A74F-495E-8A33-DF6226D2BAD8} - C:\Program Files\Video ActiveX Access\iesplg.dll (file missing) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file) O2 - BHO: Elisa Avustaja Plugin - {DB87CDE1-EF9C-44EB-A42F-6D0B3C72C516} - C:\Program Files\Elisa\Avustaja\IEFixItNowPlugin.dll O3 - Toolbar: (no name) - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - (no file) O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file) O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: Protection Bar - {31615D5C-5126-448A-818A-A7CDFEE85A9B} - C:\Program Files\Video ActiveX Access\iesbpl.dll (file missing) O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [LXBLKsk] C:\PROGRA~1\Lexmark\PHOTOC~1\LXBLKsk.exe O4 - HKLM\..\Run: [MemoryCardManager] C:\Program Files\Lexmark\Lexmark Photo Center\MemoryCardManager.exe -startup O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Elisa Tietoturvapalvelu\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\FSSW.EXE" /reboot O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg O4 - HKLM\..\Run: [MW1HelperStartUp] C:\PROGRA~1\MAGICW~1\MW1HEL~1.EXE /partner MW1 O4 - HKLM\..\Run: [News Service] "C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\ispnews.exe" O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Startup: Watch.lnk = C:\WINDOWS\twain_32\A4CIS\WATCH.exe O4 - Global Startup: Elisa Tietoturvapalvelu.lnk = C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\Program\fspex.exe O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Building basic 3D Web Sites.lnk = C:\Program Files\3DSTATE\3D Webmaker\Tutorials\Building basic 3D Web Sites.htm O4 - Global Startup: Building advanced 3D Web Sites.lnk = C:\Program Files\3DSTATE\3D Webmaker\Tutorials\Building advanced 3D Web Sites.htm O4 - Global Startup: Basic Samples.lnk = C:\Program Files\3DSTATE\3D Webmaker\Basic Samples\index.htm O4 - Global Startup: Advanced Samples.lnk = C:\Program Files\3DSTATE\3D Webmaker\3D Web Samples\Html\index.htm O4 - Global Startup: Converters.lnk = ? O4 - Global Startup: License.lnk = C:\Program Files\3DSTATE\3D Webmaker\License\License.txt O4 - Global Startup: Webmaker Book.lnk = C:\Program Files\3DSTATE\3D Webmaker\Webmaker book\Webmaker book.doc O4 - Global Startup: Programming Reference Manual.lnk = C:\Program Files\3DSTATE\3D Webmaker\Programming Reference Manual\default.htm O4 - Global Startup: Tutorials.lnk = C:\Program Files\3DSTATE\3D Webmaker\Tutorials\index.htm O4 - Global Startup: Resources.lnk = C:\Program Files\3DSTATE\3D Webmaker\wwwRes\resources.htm O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Free WebSite Tools.lnk = ? O8 - Extra context menu item: &Estä tämä kohoikkuna - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\blockpopups.htm O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: IE-suojaus - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\ieshield.dll O9 - Extra 'Tools' menuitem: IE-suojaus... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\ieshield.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra button: Tuki - {0883023E-F304-43A2-A843-64C9CFAC85DB} - http://tuki.elisa.net/ (file missing) (HKCU) O9 - Extra button: SMS-viesti - {0B5BFEC0-A026-4F5D-B338-E3DCD5B0B6F5} - http://sms.kolumbus.fi/ (file missing) (HKCU) O9 - Extra button: Palvelut - {8A77EEDF-87F7-443B-8559-FF6827677B05} - http://service.kolumbus.fi/ (file missing) (HKCU) O11 - Options group: [INTERNATIONAL] International* O14 - IERESET.INF: START_PAGE_URL=http://elisa.net/ O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/installer.v4/vet_install_popup.pl?3&6&04.00.04.03&unknown&unknown&http://www.opel.fi/content_data/GME/019/FI/fi/GBPFI/microsite/0N/RTT/signum.html O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\edgqhtiq.exe O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Elisa Tietoturvapalvelu (BackWeb Plug-in - 4119343) - BackWeb Technologies Inc. - C:\PROGRA~1\ELISAT~1\backweb\4119343\Program\SERVIC~1.EXE O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32st.exe O23 - Service: FSBWSYS (fsbwsys) - F-Secure Corp. - C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\program\fsbwsys.exe O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\FWES\Program\fsdfwd.exe O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMA32.EXE O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
Avaa hijackthis merkkaa seuraavat rivi(t) ja paina fix checked, sulje muut ohjelmat siksi aikaa O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: (no name) - {7A8F5B7A-A74F-495E-8A33-DF6226D2BAD8} - C:\Program Files\Video ActiveX Access\iesplg.dll (file missing) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file) O3 - Toolbar: (no name) - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - (no file) O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file) O3 - Toolbar: Protection Bar - {31615D5C-5126-448A-818A-A7CDFEE85A9B} - C:\Program Files\Video ActiveX Access\iesbpl.dll (file missing) O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\edgqhtiq.exe Tässä ohje miten merkataan: ========== 1,Lataa AVG Anti-Spyware 7.5 ja tallenna ohjelma työpöydällesi. Jos sinulla on jo kyseinen ohjelma siirry suoraan kohtaan 2! [*]Kun olet ladannut ohjelman, kaksoisklikkaa asennuohjelman pikakuvaketta työpöydälläsi, asennus alkaa. [*]Asennuksen jälkeen täytyy ohjelma käynnistää ja sen tunnisteet päivittää. 2. [*]Käynnistä AVG eAnti-Spyware. [*]Klikkaa "Update" kuvaketta päävalikossa. Sen jälkeen klikkaa "Update now" painiketta. [*]Sitten klikkaa "Start Update" kuvaketta jolloin päivitys alkaa. [*]Paina hetken kuluttua uudestaan "Start Update" , jos päivitykset eivät heti onnistu [*]Jos automaattipäivitys ei jostain syystä toimi, niin tunnisteet voi ladata manuaalisesti http://www.ewido.net/en/download/updates/ -linkin takaa. [*]Kun päivitykset on ladattu, klikkaa "Scanner" kuvaketta ikkunan ylälaidassa. Valitse sitten "Settings" välilehti. [*]Kun "Settings" valikko on auennut, klikkaa "Recommended actions" ja sitten valitse "Quarantine". [*]Sitten "Reports" valikon alta:a [*]Laita täppi kohtaan "Automatically generate report after every scan" [*]Ota täppi pois kohdasta"Only if threats were found" [*]Sitten klikkaa "Shield" kuvaketta ikkunan ylälaidassa [*]"Resident shield is", muuta tila active:sta inactive:ksi [*]Sulje ohjelma, ÄLÄ skannaa vielä. Käynnistä tietokone vikasietotilaan: 1. Käynnistä tietokone uudelleen. 2. Kun tietokone käynnistyy, paina F8-näppäintä. 3. Näyttöön tulee erilaisia käynnistysvaihtoehtoja. 4. Valitse näppäimistön nuolinäppäinten avulla Vikasietotila. 5. Paina ENTER-näppäintä. HUOM! Älä käytä muita ohjelmia AVG skannauksen aikana, tämä saattaa häiritä skannausta. [*]Kun vikasietotilassa, käynnistä AVG Anti-Spyware. [*]Klikkaa "Scanner" kuvaketta ikkunan ylälaidassa ja valitse "Scan" välilehti. Sitten klikkaa "Complete System Scan". [*]AVG aloittaa nyt tietokoneen skannaamisen, ole kärsivällinen sillä skannaus vie aikaa. Kun skannaus on valmis: TÄRKEÄÄ : Älä klikkaa "Save Scan Report" ennen kuin klikkaat "Apply all Actions" [*]Varmistu, että Set all elements to: näyttää Quarantine (1), jos ei, klikkaa linkkiä ja valitse Quarantine popup-valikosta. [*]Sinulta kysytään mitä tehdä jos infektioita löytyi, valitse silloin "Apply all actions" [*]Sitten klikkaa "Reports" kuvaketta ohjelma yläosasta. [*]Klikkaa "Save report as" painiketta ikkunan vasemmassa alalaidassa ja tallenna raportti työpöydälle. [*]Sulje ohjelma, käynnistä kone normaalisti ja lähetä AVG:n raportti viestiketjuusi. ========== Avaa Oma tietokone -> Tee seuraava toimenpide kaikille Paikallisille levyille ========== Lataa CCleaner ja asenna se: Avaa "Options", sieltä "Language" ja valitse "Suomi (Finnish)" Avaa "Virheet" kohta, paina "Etsi rekisterin virheitä", paina "Korjaa valitut rekisterin virheet..". Paina "Kyllä", kun ohjelma kysyy "Haluatko varmuuskopioida muutokset rekisteriin", tallenna tiedosto esim. työpöydälle. Avaa "Puhdistaja", paina "Tutki" ja tämän jälkeen "Aja Ccleaner". Puhdista väliaikaistiedostot ja -kansiot ohjelmalla säännöllisesti. ========== Jos sinulla ei ole tätä java versiota (6.1): Javan päivitys ja välimuistin tyhjennys: 1. Klikkaa Käynnistä -> Ohjauspaneeli ja tupla-klikkaa Lisää tai poista sovellus Ohjauspaneelissa. 2. Etsi listasta kaikki entiset Java versiosi. (J2SE Runtime Environment.... ) Niissä pitäisi olla seuraava kuva vieressä: 3. Valitse kaikki entiset Java versiosi ja valitse Poista. 4. Asenna uusin Java päivitys seuraavasta linkistä.. 5. Käynnistä kone uudelleen asennuksen jälkeen: http://java.sun.com/javase/downloads/index.jsp Rullaa alas kohteeseen Java Runtime Environment (JRE) 6u1 Paina Download Ruksaa Accept, ota offline installation, tallenna vaikka työpöydälle ja asenna se. 6. Käynnistyksen jälkeen, mene takaisin Ohjauspaneeliin ja avaa Java asetuksesi (Muita Ohjauspaneelin asetuksia -> Java kahvikuppi). 7. General Settings -osion alla, vedä liukusäädintä (Disk Space) pienemmälle, ja klikkaa Delete Files -nappia. (Jotkut javapohjaiset ohjelmat saattavat tarvita enemmän levytilaa. Jos huomaat säädön pienentämisen jälkeen koneessa hitautta, siirrä liukusäädintä isommalle). 8. Varmista että kaikki kaksi valintaa ovat rastitettuja: *Applications and Applets *Trace and Log Files Ja paina OK -nappia 9. Klikkaa OK "Temporary Files Settings" -ikkunassasi. 10. Klikkaa OK jättääksesi Java asetusikkunasi. ========== Uusi Hijackthis logi ja onko ongelmia?
--------------------------------------------------------- AVG Anti-Spyware - Scan Report --------------------------------------------------------- + Created at: 22:12:47 12.5.2007 + Scan result: C:\Program Files\Magic Waterfall Screensaver\MagicWaterfall.exe -> Adware.GAINNetwork : Cleaned with backup (quarantined). C:\Program Files\Magic Waterfall Screensaver\MW1Helper.exe -> Adware.Gator : Cleaned with backup (quarantined). C:\Program Files\Magic Waterfall Screensaver\MW1Uninstaller.exe -> Adware.Gator : Cleaned with backup (quarantined). C:\Documents and Settings\Teemu\Local Settings\Temp\SHNTK.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\Program Files\Sky Fire\NNSUNA3_88.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP574\A0242651.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP633\A0271144.dll -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP633\A0271145.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). HKU\S-1-5-21-1220945662-308236825-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP574\A0242694.exe -> Adware.Relevant : Cleaned with backup (quarantined). C:\Program Files\Sky Fire\VVSNInst.exe -> Adware.SaveNow : Cleaned with backup (quarantined). C:\Documents and Settings\Teemu\Työpöytä\HobbitSetup-dm.exe -> Adware.Trymedia : Cleaned with backup (quarantined). C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP632\A0268943.dll -> Downloader.Agent.bkd : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\miniclipGameLoader.dll -> Downloader.Small : Cleaned with backup (quarantined). C:\Program Files\Video ActiveX Access\imsmn.exe -> Downloader.Small.cx : Cleaned with backup (quarantined). C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP630\A0268641.exe -> Downloader.Small.cx : Cleaned with backup (quarantined). C:\Program Files\Video ActiveX Access\imsunst.exe -> Downloader.Zlob.azc : Cleaned with backup (quarantined). C:\Program Files\Video ActiveX Access\iesbunst.exe -> Downloader.Zlob.bor : Cleaned with backup (quarantined). C:\Program Files\Video ActiveX Access\IESMIN.0XE -> Downloader.Zlob.bti : Cleaned with backup (quarantined). C:\Program Files\Video ActiveX Access\IESPLG.0LL -> Downloader.Zlob.bti : Cleaned with backup (quarantined). C:\Documents and Settings\Teemu\Incomplete\T-268800-HAMSTERBALL V3.10 GOLD.0XE -> Dropper.VB.lu : Cleaned with backup (quarantined). C:\Documents and Settings\Sami\Local Settings\Temp\heroes_trial.exe -> Heuristic.Win32.Dialer : Cleaned with backup (quarantined). C:\Documents and Settings\All Users\Tiedostot\ErrorSafeFreeInstall_fi.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Cleaned with backup (quarantined). :mozilla.282:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned. :mozilla.232:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.299:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.77:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.78:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.79:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.80:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.81:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.82:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.83:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.84:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.85:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.86:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.87:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@ad.admarketplace[1].txt -> TrackingCookie.Admarketplace : Cleaned. :mozilla.403:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Adobe : Cleaned. :mozilla.121:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.122:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.55:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.56:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.57:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.58:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.44:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@www.burstbeacon[3].txt -> TrackingCookie.Burstbeacon : Cleaned. :mozilla.297:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@burstnet[3].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Sami\Local Settings\Temp\Cookies\sami@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Sari\Cookies\sari@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.153:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.97:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned. :mozilla.98:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@cz3.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@cz5.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned. :mozilla.6:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Com : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@commissionpartner[2].txt -> TrackingCookie.Commissionpartner : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@commissionpartner[3].txt -> TrackingCookie.Commissionpartner : Cleaned. C:\Documents and Settings\Teemu\Cookies\teemu@commissionpartner[1].txt -> TrackingCookie.Commissionpartner : Cleaned. C:\Documents and Settings\Teemu\Cookies\teemu@commissionpartner[2].txt -> TrackingCookie.Commissionpartner : Cleaned. :mozilla.402:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Cqcounter : Cleaned. :mozilla.32:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@c.enhance[2].txt -> TrackingCookie.Enhance : Cleaned. :mozilla.183:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.156:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.285:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.72:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.308:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Gamershell : Cleaned. :mozilla.49:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Gemius : Cleaned. :mozilla.50:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Gemius : Cleaned. :mozilla.52:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Gemius : Cleaned. :mozilla.107:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.101:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.102:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.103:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.104:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.147:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.246:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.247:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@idot[1].txt -> TrackingCookie.Idot : Cleaned. :mozilla.269:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.270:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@ilead.itrack[1].txt -> TrackingCookie.Itrack : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@ilead.itrack[3].txt -> TrackingCookie.Itrack : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@ilead.itrack[4].txt -> TrackingCookie.Itrack : Cleaned. C:\Documents and Settings\Sami\Local Settings\Temp\Cookies\sami@ilead.itrack[2].txt -> TrackingCookie.Itrack : Cleaned. C:\Documents and Settings\Tommi\Cookies\tommi@ilead.itrack[1].txt -> TrackingCookie.Itrack : Cleaned. C:\Documents and Settings\Sari\Cookies\sari@search.live[2].txt -> TrackingCookie.Live : Cleaned. C:\Documents and Settings\Teemu\Cookies\teemu@search.live[1].txt -> TrackingCookie.Live : Cleaned. C:\Documents and Settings\Tommi\Cookies\tommi@search.live[1].txt -> TrackingCookie.Live : Cleaned. C:\Documents and Settings\Tommi\Cookies\tommi@search.live[2].txt -> TrackingCookie.Live : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@image.masterstats[1].txt -> TrackingCookie.Masterstats : Cleaned. :mozilla.205:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.206:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. C:\Documents and Settings\Sami\Local Settings\Temp\Cookies\sami@www.myaffiliateprogram[2].txt -> TrackingCookie.Myaffiliateprogram : Cleaned. :mozilla.154:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.54:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@www.paypal[1].txt -> TrackingCookie.Paypal : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@paypopup[3].txt -> TrackingCookie.Paypopup : Cleaned. :mozilla.135:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.136:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.137:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.138:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@ppms.popularix[1].txt -> TrackingCookie.Popularix : Cleaned. :mozilla.43:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.45:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.5:C:\Documents and Settings\Teemu\Application Data\Mozilla\Profiles\default\6evzdyqm.slt\cookies.txt -> TrackingCookie.Real : Cleaned. :mozilla.6:C:\Documents and Settings\Teemu\Application Data\Mozilla\Profiles\default\6evzdyqm.slt\cookies.txt -> TrackingCookie.Real : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@ads.realcastmedia[1].txt -> TrackingCookie.Realcastmedia : Cleaned. :mozilla.345:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.346:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.347:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.213:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.214:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.215:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.216:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.217:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.218:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.334:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@starware[2].txt -> TrackingCookie.Starware : Cleaned. :mozilla.66:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.67:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.68:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.35:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Statistik-gallup : Cleaned. :mozilla.197:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.203:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@toplist[1].txt -> TrackingCookie.Toplist : Cleaned. :mozilla.36:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.37:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.356:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Trafic : Cleaned. :mozilla.13:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.335:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.336:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.337:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.338:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.233:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned. :mozilla.73:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned. :mozilla.130:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned. C:\Documents and Settings\Sari\Cookies\sari@m.webtrends[1].txt -> TrackingCookie.Webtrends : Cleaned. C:\Documents and Settings\Tommi\Cookies\tommi@m.webtrends[1].txt -> TrackingCookie.Webtrends : Cleaned. C:\Documents and Settings\Tommi\Cookies\tommi@m.webtrends[3].txt -> TrackingCookie.Webtrends : Cleaned. C:\Documents and Settings\Ossi\Cookies\ossi@yadro[2].txt -> TrackingCookie.Yadro : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@yadro[1].txt -> TrackingCookie.Yadro : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@yadro[2].txt -> TrackingCookie.Yadro : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@yadro[3].txt -> TrackingCookie.Yadro : Cleaned. :mozilla.11:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.12:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.14:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\Sami\Cookies\sami@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.88:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.89:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.90:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. C:\Program Files\Video ActiveX Access\imsmain.exe -> Trojan.FakeAV : Cleaned with backup (quarantined). C:\Documents and Settings\Teemu\Local Settings\Temp\laf4C4.tmp -> Trojan.Renos.naz : Cleaned with backup (quarantined). ::Report end ----------------------------------------------------- Logfile of HijackThis v1.99.1 Scan saved at 23:03:16, on 12.5.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16441) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\ELISAT~1\backweb\4119343\Program\SERVIC~1.EXE C:\WINDOWS\system32\CTSvcCDA.EXE C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32st.exe C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\program\fsbwsys.exe C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\FSGK32.EXE C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMA32.EXE C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fssm32.exe C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMB32.EXE C:\WINDOWS\system32\nvsvc32.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Tablet.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\Program Files\Elisa Tietoturvapalvelu\Common\FCH32.EXE C:\Program Files\Elisa Tietoturvapalvelu\Common\FAMEH32.EXE C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsqh.exe C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsrw.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsav32.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\WTablet\TabUserW.exe C:\Program Files\Ahead\InCD\InCD.exe C:\Program Files\Microsoft IntelliType Pro\type32.exe C:\PROGRA~1\Lexmark\PHOTOC~1\LXBLKsk.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\Logitech\Video\LogiTray.exe C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\ispnews.exe C:\Program Files\MessengerPlus! 3\MsgPlus.exe C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE C:\Program Files\QuickTime\qttask.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\Program\fspex.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\Program Files\Elisa Tietoturvapalvelu\FWES\Program\fsdfwd.exe C:\WINDOWS\system32\Tablet.exe C:\PROGRA~1\ELISAT~1\ANTI-S~1\fsaw.exe C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\fsguidll.exe C:\WINDOWS\system32\msiexec.exe C:\Documents and Settings\Ossi\Työpöytä\Työkaluja\scanner.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Elisa Internet R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;;localhost;<local> R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Elisa Avustaja Plugin - {DB87CDE1-EF9C-44EB-A42F-6D0B3C72C516} - C:\Program Files\Elisa\Avustaja\IEFixItNowPlugin.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [LXBLKsk] C:\PROGRA~1\Lexmark\PHOTOC~1\LXBLKsk.exe O4 - HKLM\..\Run: [MemoryCardManager] C:\Program Files\Lexmark\Lexmark Photo Center\MemoryCardManager.exe -startup O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Elisa Tietoturvapalvelu\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\FSSW.EXE" /reboot O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg O4 - HKLM\..\Run: [News Service] "C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\ispnews.exe" O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Startup: Watch.lnk = C:\WINDOWS\twain_32\A4CIS\WATCH.exe O4 - Global Startup: Elisa Tietoturvapalvelu.lnk = C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\Program\fspex.exe O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Building basic 3D Web Sites.lnk = C:\Program Files\3DSTATE\3D Webmaker\Tutorials\Building basic 3D Web Sites.htm O4 - Global Startup: Building advanced 3D Web Sites.lnk = C:\Program Files\3DSTATE\3D Webmaker\Tutorials\Building advanced 3D Web Sites.htm O4 - Global Startup: Basic Samples.lnk = C:\Program Files\3DSTATE\3D Webmaker\Basic Samples\index.htm O4 - Global Startup: Advanced Samples.lnk = C:\Program Files\3DSTATE\3D Webmaker\3D Web Samples\Html\index.htm O4 - Global Startup: Converters.lnk = ? O4 - Global Startup: License.lnk = C:\Program Files\3DSTATE\3D Webmaker\License\License.txt O4 - Global Startup: Webmaker Book.lnk = C:\Program Files\3DSTATE\3D Webmaker\Webmaker book\Webmaker book.doc O4 - Global Startup: Programming Reference Manual.lnk = C:\Program Files\3DSTATE\3D Webmaker\Programming Reference Manual\default.htm O4 - Global Startup: Tutorials.lnk = C:\Program Files\3DSTATE\3D Webmaker\Tutorials\index.htm O4 - Global Startup: Resources.lnk = C:\Program Files\3DSTATE\3D Webmaker\wwwRes\resources.htm O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Free WebSite Tools.lnk = ? O8 - Extra context menu item: &Estä tämä kohoikkuna - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\blockpopups.htm O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll O9 - Extra button: IE-suojaus - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\ieshield.dll O9 - Extra 'Tools' menuitem: IE-suojaus... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\ieshield.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra button: Tuki - {0883023E-F304-43A2-A843-64C9CFAC85DB} - http://tuki.elisa.net/ (file missing) (HKCU) O9 - Extra button: SMS-viesti - {0B5BFEC0-A026-4F5D-B338-E3DCD5B0B6F5} - http://sms.kolumbus.fi/ (file missing) (HKCU) O9 - Extra button: Palvelut - {8A77EEDF-87F7-443B-8559-FF6827677B05} - http://service.kolumbus.fi/ (file missing) (HKCU) O11 - Options group: [INTERNATIONAL] International* O14 - IERESET.INF: START_PAGE_URL=http://elisa.net/ O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/installer.v4/vet_install_popup.pl?3&6&04.00.04.03&unknown&unknown&http://www.opel.fi/content_data/GME/019/FI/fi/GBPFI/microsite/0N/RTT/signum.html O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Elisa Tietoturvapalvelu (BackWeb Plug-in - 4119343) - BackWeb Technologies Inc. - C:\PROGRA~1\ELISAT~1\backweb\4119343\Program\SERVIC~1.EXE O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32st.exe O23 - Service: FSBWSYS (fsbwsys) - F-Secure Corp. - C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\program\fsbwsys.exe O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\FWES\Program\fsdfwd.exe O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMA32.EXE O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
C:\Program Files\Magic Waterfall Screensaver C:\Program Files\Video ActiveX Access\i Poista noi kansit ====== Lataa Dr.Web CureIt työpöydälle: ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe [*]Tuplaklikkaa drweb-cureit.exe ja anna sen tehdä express scan [*]Se skannaa käynnissä olevat ohjelmat ja jos jotain löytyy, klikkaa yes kun se kysyy haluatko poistaa sen. Tämä on vain lyhyt scan. [*]Kun scan on valmis, merkkaa asemat, jotka haluat scannata. [*]Valitse kaikki asemat. Punainen piste osoittaa, mitkä asemat on valittu. [*]Klikaa vihreää nuolta oikealla ja scan alkaa. [*]Klikkaa 'Yes to all', jos kysytään haluatko poistaa/siirtää tiedoston. [*]Kun scan on valmis, katso voitko klikata next-kuvaketta löytyneiden tiedostojen vieressä: [*]Jos asia on niin, klikkaa sitä ja sitten klikkaa next-kuvaketta oikealla alhaalla ja valitse Move incurable kuten alla olevalla kuvassa: Tämä siirtää sen %userprofile%\DoctorWeb\quarantine-hakemistoon. [*]Tämän jälkeen klikkaa Dr.Web CureIt-valikossa file ja valitse save report list [*]Tallenna raportti työpöydälle. Raportin nimi on DrWeb.csv [*]Sulje Dr.Web Cureit. [*]Käynnistä kone uudelleen !! Tämä siksi, että käytössä olevat tiedostot poistetaan/siirretään käynnistyksen yhteydessä. [*]Käynnistyksen jälkeen liitä Dr.Web-lokin, jonka tallensit aiemmin, sisältö seuraavaan vastaukseesi.
Bowsroam.exe C:\Documents and Settings\All Users\Application Data\namesoftpartmeet Trojan.Swizzor Deleted. army sixth.exe C:\Documents and Settings\All Users\Application Data\namesoftpartmeet Trojan.Swizzor Deleted. Process.exe C:\Documents and Settings\Ossi\Työpöytä\SmitfraudFix Tool.Prockill Incurable.Moved. restart.exe C:\Documents and Settings\Ossi\Työpöytä\SmitfraudFix Tool.ShutDown.11 Incurable.Moved. pic.tiff C:\Documents and Settings\Sami\Local Settings\Temp Exploit.MS05-053 Deleted. bis324.0xe C:\Documents and Settings\Teemu\Local Settings\Temp Trojan.Isbar.459 Deleted. bis3CC.0xe C:\Documents and Settings\Teemu\Local Settings\Temp Trojan.Isbar.459 Deleted. SETUPWMA.0XE C:\Documents and Settings\Teemu\Application Data\Test Window Bags Trojan.Isbar.459 Deleted. amlkhsnp.exe C:\Documents and Settings\Teemu\Application Data\Test Window Bags Trojan.Swizzor Deleted. fyyitbof.exe C:\Documents and Settings\Teemu\Application Data\Test Window Bags Trojan.Swizzor Deleted. Clock.mbt C:\Program Files\Free_Java_Web_Button\Samples Win32.HLLM.Graz Deleted. Process.exe C:\Program Files\Mozilla Firefox\SmitfraudFix Tool.Prockill Incurable.Moved. restart.exe C:\Program Files\Mozilla Firefox\SmitfraudFix Tool.ShutDown.11 Incurable.Moved. A0273218.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP633 Trojan.Popuper Deleted. A0273221.0xe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP633 Trojan.Popuper Deleted. A0273222.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP633 Adware.NewDotNet Incurable.Moved. A0273223.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP633 Adware.TryMedia Incurable.Moved. A0273224.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP633 Adware.Gator Incurable.Moved. A0273225.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP633 Adware.Gator Incurable.Moved. A0273227.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP633 Adware.SaveNow Incurable.Moved. A0273228.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP633 Trojan.DownLoader.6550 Deleted. A0274835.exe\data002 C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP640\A0274835.exe Trojan.Popuper A0274835.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP640 Archive contains infected objects Moved. A0274842.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP640 Trojan.Swizzor Deleted. A0274843.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP640 Trojan.Swizzor Deleted. A0274844.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP640 Trojan.Swizzor Deleted. A0274845.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP640 Trojan.Swizzor Deleted.
Lataa ATF Cleaner http://www.atribune.org/ccount/click.php?id=1 Tupla-klikkaa ATF-Cleaner.exe käynnistääksesi ohjelman. Main:n alla valitse: Select All Klikkaa Empty Selected valintaa. Jos käytät FireFoxia selaimenasi Klikkaa Firefox yläpuolelta ja valitse: Select All Klikkaa Empty Selected valintaa. HUOMIO: Jos haluaisit pitää tallennetut salasanasi, klikkaa No kun se sitä kysyy. Jos käytät Operaa selaimenasi Klikkaa Opera yläpuolelta ja valitse: Select All Klikkaa Empty Selected valintaa taas. HUOMIO: Jos haluaisit pitää tallennetut salasanasi, klikkaa No kun se sitä kysyy. Klikkaa Exit päävalikosta sulkeaksesi ohjelman. Teknistä tukea tulee jos tupla-klikkaat sähköpostiosoitetta joka sijaitsee jokaisen menun alapuolella kyseisessä työkalussa. (Huomatkaa että se tuki on sitten englanniksi) ========== Täll vois viel varmistaa Tarkista koneesi F-Securen online skannerilla Huom, skanneri toimii vain Internet Explorer selaimella * Lue sivun ohjeet huolella läpi * Klikkaa Start scanning * Mikäli saat Internet Explorer -suojausvaroituksen, klikkaa Asenna * Klikkaa Accept * Klikkaa Custom Scan * Säädä asetukset seuraavasti o "Virus Scan Option" kohdasta valitse Scan whole system o "Other Scan Option" kohdasta valitse Scan All Files o Valitse Scan whole system for rootkits o Valitse Scan whole system for spyware o Laita ruksi kohtaan Scan inside archives o Varmista että Use advanced heuristics on valittuna * Klikkaa Start * Skannaus käynnistyy kun tarvittavat tiedostot/päivitykset on ladattu * Odota kärsivällisesti * Kun sakannaus on suoritettu, klikkaa Automatic cleaning * Klikkaa Show Report * Raportti aukeaa selaimessa, kopioi teksti kokonaan * Liitä kopioitu teksti esim. muistioon tai Wordiin ja tallenna työpöydälle * Voit sulkea skannerin * Lähetä raportti viestiketjuusi