Tehtäpalkki/ilmoitusalue/Spylocked -linkki

Discussion in 'Virukset ja haittaohjelmat' started by Dossi, May 9, 2007.

  1. Dossi

    Dossi Member

    Joined:
    Oct 30, 2004
    Messages:
    37
    Likes Received:
    0
    Trophy Points:
    16
    Tehtäväpalkin ilmoitusalueelle on ilmestynyt ikoni, joka vaihtuu vuorotellen kysymysmerkiksi(Windows) ja "pysäköinti kielletty" merkiksi.Tasaisin väliajoin tulee System Alert -ilmoitus. Klikkaamalla ikonia hiiren oik. tai vas. näppäimellä avautuu selain ja
    "http://www.spylocked.com/?aff=334" -sivu. Jos menen "ulkoasu ja teemat" ja sieltä "Tehtäväpalkki ja käynnistävalikko" ja "mukauta ilmoitukset" tämä kyseinen ikoni näkyy jompana kumpana ja sen perässä <ei otsikkoa>.
    Miten saan tuo linkin poistettua?
     
  2. Auttaja

    Auttaja Guest

    Lataa SmitfraudFix (by S!Ri) työpöydällesi.

    Tuplaklikkaa tiedostoa SmitfraudFix.exe

    Valitse optio #1 - Search kirjoittamalla 1 ja painamalla "Enter"; tekstitiedosto avautuu, joka listaa tarttuneet tiedostot (jos olemassa).
    Postita tämän tekstitiedoston sisältö viestiketjuusi.

    **Jos työkalu ei käynnisty työpöydältä niin siirrä SmitfraudFix.exe suoraan järjestelmäaseman juureen (yleensä C:). Kokeile sitten käynnistää ohjelma uudestaan sieltä.

    Huomaa : process.exe filun tunnistaa jotkut Anti-virus ohjelmat (AntiVir, Dr.Web, Kaspersky) "Haittakaluna"; se ei ole virus, vaan ohjelma joka pysäyttää prosesseja. A/V ohjelmat eivät pysty tunnistamaan hyvän ja pahan käytön tälläisten ohjelmian väliltä, silloin ne saattavat varoittaa käyttäjää.
    http://www.beyondlogic.org/consulting/processutil/processutil.htm

    ==========

    Printtaa ohjeet ulos tai tallenna nämä tekstitiedostoon.

    Käynnistä koneesi vikasietotilaan ja valitse tavallinen käyttäjätilisi.

    Vikasietotilaan pääset painamalla F8 käynnistyksen alussa piippauksen kuultuasi.


    Kun vikasietotilassa, tuplaklikkaa tiedostoa SmitfraudFix.exe
    Valitse optio #2 - Clean kirjoittamalla 2 ja painamalla "Enter" poistaaksesi tarttuneet tiedostot.

    Sinulta kysytään: "Registry cleaning - Do you want to clean the registry ?"; vastaa "Yes" kirjoittamalla Y ja paina "Enter" poistaaksesi työpöydän taustakuvan ja puhdistaaksesi tarttuneet rekisteriavaimet.

    Työkalu tarkistaa jos wininet.dll on tarttunut. Sinua saatetaan pyytää korvaamaan tarttunut .dll (jos löytyy); vastaa "Yes" kirjoittamalla Y ja painamalla "Enter".

    Työkalun saattaa tarvita käynnistää kone uudelleen; jos ei tee niin, käynnistä normaaliin Windowsiin.
    Tekstitiedosto ilmestyy, puhdistusprosessin jäljiltä; kopioi & liitä tämän raportin tulokset vastaukseesi.
    Raportti löytyy paikalliselta levyltäsi, useimmiten C:\rapport.txt.

    ==========

    Laita molempien kohtien lokit sekä

    -> Lataa Hijackthis: http://koti.mbnet.fi/pattaya1/HijackThis.exe
    -> Tallenna hakemistoon C:\hjt
    ->Uudelleennimeä HijackThis.exe -> scanner.exe:ksi näin:
    1. Klikkaa hiiren oikealla painikkeella HijackThis ikonia.
    [​IMG]

    2. Valitse Uudelleennineä/ Rename.
    [​IMG]

    3. Kirjoita scanner.exe
    [​IMG]
    -> Käynnistä HijackThis ja klikkaa: do a system scan and save a logfile.
    -> Lähetä ilmestynyt logisi tähän ketjuun
     
  3. Dossi

    Dossi Member

    Joined:
    Oct 30, 2004
    Messages:
    37
    Likes Received:
    0
    Trophy Points:
    16
    Kiitos! Vikasietotilan ja Registry cleaning -prosessin jälkeen, koneen käynnistyttyä ongelma oli poistunut.
     
  4. Auttaja

    Auttaja Guest

    Laitatko tuon hijackthis login niin poistetaan jämät smitistä.
     
  5. Dossi

    Dossi Member

    Joined:
    Oct 30, 2004
    Messages:
    37
    Likes Received:
    0
    Trophy Points:
    16
    Logfile of HijackThis v1.99.1
    Scan saved at 14:19:44, on 10.5.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\PROGRA~1\ELISAT~1\backweb\4119343\Program\SERVIC~1.EXE
    C:\WINDOWS\system32\CTSvcCDA.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32st.exe
    C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\program\fsbwsys.exe
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\FSGK32.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMA32.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fssm32.exe
    C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMB32.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Elisa Tietoturvapalvelu\Common\FCH32.EXE
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Tablet.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsqh.exe
    C:\Program Files\Elisa Tietoturvapalvelu\Common\FAMEH32.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsrw.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsav32.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\WTablet\TabUserW.exe
    C:\Program Files\Ahead\InCD\InCD.exe
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\PROGRA~1\Lexmark\PHOTOC~1\LXBLKsk.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\Logitech\Video\LogiTray.exe
    C:\PROGRA~1\MAGICW~1\MW1HEL~1.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\ispnews.exe
    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
    C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\Program\fspex.exe
    C:\Program Files\Logitech\Video\FxSvr2.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Elisa Tietoturvapalvelu\FWES\Program\fsdfwd.exe
    C:\WINDOWS\system32\Tablet.exe
    C:\PROGRA~1\ELISAT~1\ANTI-S~1\fsaw.exe
    C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\fsguidll.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Ossi\Työpöytä\scanner.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Elisa Internet
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;;localhost;<local>
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet3_88.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: (no name) - {7A8F5B7A-A74F-495E-8A33-DF6226D2BAD8} - C:\Program Files\Video ActiveX Access\iesplg.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O2 - BHO: Elisa Avustaja Plugin - {DB87CDE1-EF9C-44EB-A42F-6D0B3C72C516} - C:\Program Files\Elisa\Avustaja\IEFixItNowPlugin.dll
    O3 - Toolbar: (no name) - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - (no file)
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Protection Bar - {31615D5C-5126-448A-818A-A7CDFEE85A9B} - C:\Program Files\Video ActiveX Access\iesbpl.dll (file missing)
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [LXBLKsk] C:\PROGRA~1\Lexmark\PHOTOC~1\LXBLKsk.exe
    O4 - HKLM\..\Run: [MemoryCardManager] C:\Program Files\Lexmark\Lexmark Photo Center\MemoryCardManager.exe -startup
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Elisa Tietoturvapalvelu\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\FSSW.EXE" /reboot
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
    O4 - HKLM\..\Run: [MW1HelperStartUp] C:\PROGRA~1\MAGICW~1\MW1HEL~1.EXE /partner MW1
    O4 - HKLM\..\Run: [News Service] "C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\ispnews.exe"
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup
    O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: Watch.lnk = C:\WINDOWS\twain_32\A4CIS\WATCH.exe
    O4 - Global Startup: Elisa Tietoturvapalvelu.lnk = C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\Program\fspex.exe
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Building basic 3D Web Sites.lnk = C:\Program Files\3DSTATE\3D Webmaker\Tutorials\Building basic 3D Web Sites.htm
    O4 - Global Startup: Building advanced 3D Web Sites.lnk = C:\Program Files\3DSTATE\3D Webmaker\Tutorials\Building advanced 3D Web Sites.htm
    O4 - Global Startup: Basic Samples.lnk = C:\Program Files\3DSTATE\3D Webmaker\Basic Samples\index.htm
    O4 - Global Startup: Advanced Samples.lnk = C:\Program Files\3DSTATE\3D Webmaker\3D Web Samples\Html\index.htm
    O4 - Global Startup: Converters.lnk = ?
    O4 - Global Startup: License.lnk = C:\Program Files\3DSTATE\3D Webmaker\License\License.txt
    O4 - Global Startup: Webmaker Book.lnk = C:\Program Files\3DSTATE\3D Webmaker\Webmaker book\Webmaker book.doc
    O4 - Global Startup: Programming Reference Manual.lnk = C:\Program Files\3DSTATE\3D Webmaker\Programming Reference Manual\default.htm
    O4 - Global Startup: Tutorials.lnk = C:\Program Files\3DSTATE\3D Webmaker\Tutorials\index.htm
    O4 - Global Startup: Resources.lnk = C:\Program Files\3DSTATE\3D Webmaker\wwwRes\resources.htm
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Free WebSite Tools.lnk = ?
    O8 - Extra context menu item: &Estä tämä kohoikkuna - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\blockpopups.htm
    O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
    O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: IE-suojaus - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\ieshield.dll
    O9 - Extra 'Tools' menuitem: IE-suojaus... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\ieshield.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
    O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: Tuki - {0883023E-F304-43A2-A843-64C9CFAC85DB} - http://tuki.elisa.net/ (file missing) (HKCU)
    O9 - Extra button: SMS-viesti - {0B5BFEC0-A026-4F5D-B338-E3DCD5B0B6F5} - http://sms.kolumbus.fi/ (file missing) (HKCU)
    O9 - Extra button: Palvelut - {8A77EEDF-87F7-443B-8559-FF6827677B05} - http://service.kolumbus.fi/ (file missing) (HKCU)
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O11 - Options group: [INTERNATIONAL] International*
    O14 - IERESET.INF: START_PAGE_URL=http://elisa.net/
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/installer.v4/vet_install_popup.pl?3&6&04.00.04.03&unknown&unknown&http://www.opel.fi/content_data/GME/019/FI/fi/GBPFI/microsite/0N/RTT/signum.html
    O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\edgqhtiq.exe
    O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
    O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
    O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll
    O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Elisa Tietoturvapalvelu (BackWeb Plug-in - 4119343) - BackWeb Technologies Inc. - C:\PROGRA~1\ELISAT~1\backweb\4119343\Program\SERVIC~1.EXE
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE
    O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32st.exe
    O23 - Service: FSBWSYS (fsbwsys) - F-Secure Corp. - C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\program\fsbwsys.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\FWES\Program\fsdfwd.exe
    O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMA32.EXE
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe

     
  6. Auttaja

    Auttaja Guest

    Ensin lataa LSPfix.exe http://www.cexx.org/lspfix.htm sopivaan sijaintiin (kuten C:\Program Files\LSPFix tai vaikkapa työpöydälle). ÄLÄ aja tätä ohjelmaa vielä. Tätä tulee käyttää VAIN jos internetyhteys häviää NewDotNetin poiston jäljiltä.

    NewDotNetin poisto; Mene;

    Käynnistä > Ohjauspaneeli > Lisää/Poista sovellus ja hävitä seuraava jos näkyy;

    New.Net Applications tai New.Net Domains (Mitä vain mikä sanoo New.Net)

    Jos Lisää/Poista sovelluksessa ei ole New.Net listattu, toimi näin.

    Varmista että anti-virus ja anti-spyware ohjelmat ovat suljettuna poiston ajan.

    Ne saattavat estää New.Netin poiston.

    Lataa NNuninstall.exe http://www.new.net/support/NNuninstall.exe



    * Tallenna se työpöydällesi.
    * Tupla-klikkaa NNuninstall.exe filua.
    * Ohjelma kysyy haluatko poistaa kaikki New.Netin nimet ja osat.
    * Klikkaa Yes.
    * Klikkaa poiston jälkeen OK.
    * Käynnistä kone uudelleen ("Yes - Restart now") ellei jäänyt mitään muuta kesken, jos jäi, jätä kone päälle ("No - I will restart later).



    Jos poisto ei onnistu ja virustorjuntaohjelma(t) estävät poisto-ohjelman ajon kokonaan tai
    osittain, tee näin: Irrota koneen verkko- tai modeemijohto koneesta siten, ettei sillä
    ole yhteyttä internettiin. Sulje tämän jälkeen virustorjuntaohjelma(t) ja aja
    NNuninstall.exe. Laita tämän jälkeen virustorjuntaohjelma(t) takaisin päälle ja
    vasta sitten kytke verkko- tai modeemijohto takaisin koneeseen.

    Tyhjennä roskakori.

    JOS menetät nettiyhteytesi kun olet New.Netin poistanut, tupla-klikkaa LSPFix.exe jonka latasit aiemmin. Rastita "I know what I'm doing" valinta. Näet kaksi paneelia; Jos on jotain listattu "Remove" paneeliin oikealla puolella, anna sen olla ja klikkaa "Finish>>". Seuraavaksi käynnistä uudelleen ja netin pitäisi toimia hyvin. Jos mitään ei ole listattu "Remove" paneeliin, ÄLÄ tee MITÄÄN - sulje LSPFix. Tule joltain toiselta koneelta hakemaan lisää neuvoa. (Tämä on vain varotoimenpide, useimmiten netti pysyy ihan kunnossa]

    ==========

    Laita uusi hjt logi :)
     
  7. Dossi

    Dossi Member

    Joined:
    Oct 30, 2004
    Messages:
    37
    Likes Received:
    0
    Trophy Points:
    16
    Logfile of HijackThis v1.99.1
    Scan saved at 21:23:33, on 11.5.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16441)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\PROGRA~1\ELISAT~1\backweb\4119343\Program\SERVIC~1.EXE
    C:\WINDOWS\system32\CTSvcCDA.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32st.exe
    C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\program\fsbwsys.exe
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\FSGK32.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMA32.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fssm32.exe
    C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMB32.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\Program Files\Elisa Tietoturvapalvelu\Common\FCH32.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Tablet.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\Program Files\Elisa Tietoturvapalvelu\Common\FAMEH32.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsqh.exe
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsrw.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsav32.exe
    C:\Program Files\Ahead\InCD\InCD.exe
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\PROGRA~1\Lexmark\PHOTOC~1\LXBLKsk.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\Logitech\Video\LogiTray.exe
    C:\PROGRA~1\MAGICW~1\MW1HEL~1.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\ispnews.exe
    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
    C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\Program\fspex.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\Logitech\Video\FxSvr2.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Elisa Tietoturvapalvelu\FWES\Program\fsdfwd.exe
    C:\WINDOWS\system32\Tablet.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\PROGRA~1\ELISAT~1\ANTI-S~1\fsaw.exe
    C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\fsguidll.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Ossi\Työpöytä\Työkaluja\scanner.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Elisa Internet
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;;localhost;<local>
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: (no name) - {7A8F5B7A-A74F-495E-8A33-DF6226D2BAD8} - C:\Program Files\Video ActiveX Access\iesplg.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O2 - BHO: Elisa Avustaja Plugin - {DB87CDE1-EF9C-44EB-A42F-6D0B3C72C516} - C:\Program Files\Elisa\Avustaja\IEFixItNowPlugin.dll
    O3 - Toolbar: (no name) - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - (no file)
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Protection Bar - {31615D5C-5126-448A-818A-A7CDFEE85A9B} - C:\Program Files\Video ActiveX Access\iesbpl.dll (file missing)
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [LXBLKsk] C:\PROGRA~1\Lexmark\PHOTOC~1\LXBLKsk.exe
    O4 - HKLM\..\Run: [MemoryCardManager] C:\Program Files\Lexmark\Lexmark Photo Center\MemoryCardManager.exe -startup
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Elisa Tietoturvapalvelu\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\FSSW.EXE" /reboot
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
    O4 - HKLM\..\Run: [MW1HelperStartUp] C:\PROGRA~1\MAGICW~1\MW1HEL~1.EXE /partner MW1
    O4 - HKLM\..\Run: [News Service] "C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\ispnews.exe"
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: Watch.lnk = C:\WINDOWS\twain_32\A4CIS\WATCH.exe
    O4 - Global Startup: Elisa Tietoturvapalvelu.lnk = C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\Program\fspex.exe
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Building basic 3D Web Sites.lnk = C:\Program Files\3DSTATE\3D Webmaker\Tutorials\Building basic 3D Web Sites.htm
    O4 - Global Startup: Building advanced 3D Web Sites.lnk = C:\Program Files\3DSTATE\3D Webmaker\Tutorials\Building advanced 3D Web Sites.htm
    O4 - Global Startup: Basic Samples.lnk = C:\Program Files\3DSTATE\3D Webmaker\Basic Samples\index.htm
    O4 - Global Startup: Advanced Samples.lnk = C:\Program Files\3DSTATE\3D Webmaker\3D Web Samples\Html\index.htm
    O4 - Global Startup: Converters.lnk = ?
    O4 - Global Startup: License.lnk = C:\Program Files\3DSTATE\3D Webmaker\License\License.txt
    O4 - Global Startup: Webmaker Book.lnk = C:\Program Files\3DSTATE\3D Webmaker\Webmaker book\Webmaker book.doc
    O4 - Global Startup: Programming Reference Manual.lnk = C:\Program Files\3DSTATE\3D Webmaker\Programming Reference Manual\default.htm
    O4 - Global Startup: Tutorials.lnk = C:\Program Files\3DSTATE\3D Webmaker\Tutorials\index.htm
    O4 - Global Startup: Resources.lnk = C:\Program Files\3DSTATE\3D Webmaker\wwwRes\resources.htm
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Free WebSite Tools.lnk = ?
    O8 - Extra context menu item: &Estä tämä kohoikkuna - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\blockpopups.htm
    O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
    O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: IE-suojaus - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\ieshield.dll
    O9 - Extra 'Tools' menuitem: IE-suojaus... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\ieshield.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
    O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: Tuki - {0883023E-F304-43A2-A843-64C9CFAC85DB} - http://tuki.elisa.net/ (file missing) (HKCU)
    O9 - Extra button: SMS-viesti - {0B5BFEC0-A026-4F5D-B338-E3DCD5B0B6F5} - http://sms.kolumbus.fi/ (file missing) (HKCU)
    O9 - Extra button: Palvelut - {8A77EEDF-87F7-443B-8559-FF6827677B05} - http://service.kolumbus.fi/ (file missing) (HKCU)
    O11 - Options group: [INTERNATIONAL] International*
    O14 - IERESET.INF: START_PAGE_URL=http://elisa.net/
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/installer.v4/vet_install_popup.pl?3&6&04.00.04.03&unknown&unknown&http://www.opel.fi/content_data/GME/019/FI/fi/GBPFI/microsite/0N/RTT/signum.html
    O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\edgqhtiq.exe
    O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
    O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
    O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll
    O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Elisa Tietoturvapalvelu (BackWeb Plug-in - 4119343) - BackWeb Technologies Inc. - C:\PROGRA~1\ELISAT~1\backweb\4119343\Program\SERVIC~1.EXE
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE
    O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32st.exe
    O23 - Service: FSBWSYS (fsbwsys) - F-Secure Corp. - C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\program\fsbwsys.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\FWES\Program\fsdfwd.exe
    O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMA32.EXE
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe

     
  8. Auttaja

    Auttaja Guest

    Avaa hijackthis merkkaa seuraavat rivi(t) ja paina fix checked, sulje muut ohjelmat siksi aikaa

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: (no name) - {7A8F5B7A-A74F-495E-8A33-DF6226D2BAD8} - C:\Program Files\Video ActiveX Access\iesplg.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O3 - Toolbar: (no name) - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - (no file)
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O3 - Toolbar: Protection Bar - {31615D5C-5126-448A-818A-A7CDFEE85A9B} - C:\Program Files\Video ActiveX Access\iesbpl.dll (file missing)
    O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\edgqhtiq.exe


    Tässä ohje miten merkataan:
    [​IMG]


    ==========

    1,Lataa AVG Anti-Spyware 7.5 ja tallenna ohjelma työpöydällesi. Jos sinulla on jo kyseinen ohjelma siirry suoraan kohtaan 2!

    [*]Kun olet ladannut ohjelman, kaksoisklikkaa asennuohjelman pikakuvaketta työpöydälläsi, asennus alkaa.
    [*]Asennuksen jälkeen täytyy ohjelma käynnistää ja sen tunnisteet päivittää.

    2. [*]Käynnistä AVG eAnti-Spyware.
    [*]Klikkaa "Update" kuvaketta päävalikossa. Sen jälkeen klikkaa "Update now" painiketta.
    [*]Sitten klikkaa "Start Update" kuvaketta jolloin päivitys alkaa.
    [*]Paina hetken kuluttua uudestaan "Start Update" , jos päivitykset eivät heti onnistu
    [*]Jos automaattipäivitys ei jostain syystä toimi, niin tunnisteet voi ladata manuaalisesti http://www.ewido.net/en/download/updates/ -linkin takaa.
    [*]Kun päivitykset on ladattu, klikkaa "Scanner" kuvaketta ikkunan ylälaidassa. Valitse sitten "Settings" välilehti.
    [*]Kun "Settings" valikko on auennut, klikkaa "Recommended actions" ja sitten valitse "Quarantine".
    [*]Sitten "Reports" valikon alta:a
    [*]Laita täppi kohtaan "Automatically generate report after every scan"
    [*]Ota täppi pois kohdasta"Only if threats were found"
    [*]Sitten klikkaa "Shield" kuvaketta ikkunan ylälaidassa
    [*]"Resident shield is", muuta tila active:sta inactive:ksi
    [*]Sulje ohjelma, ÄLÄ skannaa vielä.

    Käynnistä tietokone vikasietotilaan:
    1. Käynnistä tietokone uudelleen.
    2. Kun tietokone käynnistyy, paina F8-näppäintä.
    3. Näyttöön tulee erilaisia käynnistysvaihtoehtoja.
    4. Valitse näppäimistön nuolinäppäinten avulla Vikasietotila.
    5. Paina ENTER-näppäintä.

    HUOM! Älä käytä muita ohjelmia AVG skannauksen aikana, tämä saattaa häiritä skannausta.
    [*]Kun vikasietotilassa, käynnistä AVG Anti-Spyware.
    [*]Klikkaa "Scanner" kuvaketta ikkunan ylälaidassa ja valitse "Scan" välilehti. Sitten klikkaa "Complete System Scan".
    [*]AVG aloittaa nyt tietokoneen skannaamisen, ole kärsivällinen sillä skannaus vie aikaa.
    Kun skannaus on valmis:
    TÄRKEÄÄ : Älä klikkaa "Save Scan Report" ennen kuin klikkaat "Apply all Actions"
    [*]Varmistu, että Set all elements to: näyttää Quarantine (1), jos ei, klikkaa linkkiä ja valitse Quarantine popup-valikosta.
    [*]Sinulta kysytään mitä tehdä jos infektioita löytyi, valitse silloin "Apply all actions"
    [​IMG]
    [*]Sitten klikkaa "Reports" kuvaketta ohjelma yläosasta.
    [*]Klikkaa "Save report as" painiketta ikkunan vasemmassa alalaidassa ja tallenna raportti työpöydälle.
    [*]Sulje ohjelma, käynnistä kone normaalisti ja lähetä AVG:n raportti viestiketjuusi.

    ==========

    Avaa Oma tietokone
    -> Tee seuraava toimenpide kaikille Paikallisille levyille
    [​IMG]

    ==========

    Lataa CCleaner ja asenna se:
    Avaa "Options", sieltä "Language" ja valitse "Suomi (Finnish)"

    Avaa "Virheet" kohta, paina "Etsi rekisterin virheitä", paina "Korjaa valitut rekisterin virheet..". Paina "Kyllä", kun ohjelma kysyy "Haluatko varmuuskopioida muutokset rekisteriin", tallenna tiedosto esim. työpöydälle.

    Avaa "Puhdistaja", paina "Tutki" ja tämän jälkeen "Aja Ccleaner". Puhdista väliaikaistiedostot ja -kansiot ohjelmalla säännöllisesti.

    ==========

    Jos sinulla ei ole tätä java versiota (6.1):

    Javan päivitys ja välimuistin tyhjennys:

    1. Klikkaa Käynnistä -> Ohjauspaneeli ja tupla-klikkaa Lisää tai poista sovellus Ohjauspaneelissa.
    2. Etsi listasta kaikki entiset Java versiosi. (J2SE Runtime Environment.... )
    Niissä pitäisi olla seuraava kuva vieressä: [​IMG]
    3. Valitse kaikki entiset Java versiosi ja valitse Poista.
    4. Asenna uusin Java päivitys seuraavasta linkistä..
    5. Käynnistä kone uudelleen asennuksen jälkeen:

    http://java.sun.com/javase/downloads/index.jsp

    Rullaa alas kohteeseen Java Runtime Environment (JRE) 6u1

    Paina Download

    Ruksaa Accept, ota offline installation, tallenna vaikka työpöydälle ja asenna se.

    6. Käynnistyksen jälkeen, mene takaisin Ohjauspaneeliin ja avaa Java asetuksesi (Muita Ohjauspaneelin asetuksia -> Java kahvikuppi).

    7. General Settings -osion alla, vedä liukusäädintä (Disk Space) pienemmälle, ja klikkaa Delete Files -nappia.

    (Jotkut javapohjaiset ohjelmat saattavat tarvita enemmän levytilaa.
    Jos huomaat säädön pienentämisen jälkeen koneessa hitautta, siirrä liukusäädintä isommalle
    ).

    8. Varmista että kaikki kaksi valintaa ovat rastitettuja:

    *Applications and Applets

    *Trace and Log Files



    Ja paina OK -nappia

    9. Klikkaa OK "Temporary Files Settings" -ikkunassasi.

    10. Klikkaa OK jättääksesi Java asetusikkunasi.

    ==========

    Uusi Hijackthis logi ja onko ongelmia?
     
  9. Dossi

    Dossi Member

    Joined:
    Oct 30, 2004
    Messages:
    37
    Likes Received:
    0
    Trophy Points:
    16
    ---------------------------------------------------------
    AVG Anti-Spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 22:12:47 12.5.2007

    + Scan result:



    C:\Program Files\Magic Waterfall Screensaver\MagicWaterfall.exe -> Adware.GAINNetwork : Cleaned with backup (quarantined).
    C:\Program Files\Magic Waterfall Screensaver\MW1Helper.exe -> Adware.Gator : Cleaned with backup (quarantined).
    C:\Program Files\Magic Waterfall Screensaver\MW1Uninstaller.exe -> Adware.Gator : Cleaned with backup (quarantined).
    C:\Documents and Settings\Teemu\Local Settings\Temp\SHNTK.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
    C:\Program Files\Sky Fire\NNSUNA3_88.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP574\A0242651.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP633\A0271144.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP633\A0271145.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
    HKU\S-1-5-21-1220945662-308236825-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Adware.NewDotNet : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP574\A0242694.exe -> Adware.Relevant : Cleaned with backup (quarantined).
    C:\Program Files\Sky Fire\VVSNInst.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
    C:\Documents and Settings\Teemu\Työpöytä\HobbitSetup-dm.exe -> Adware.Trymedia : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP632\A0268943.dll -> Downloader.Agent.bkd : Cleaned with backup (quarantined).
    C:\WINDOWS\Downloaded Program Files\miniclipGameLoader.dll -> Downloader.Small : Cleaned with backup (quarantined).
    C:\Program Files\Video ActiveX Access\imsmn.exe -> Downloader.Small.cx : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP630\A0268641.exe -> Downloader.Small.cx : Cleaned with backup (quarantined).
    C:\Program Files\Video ActiveX Access\imsunst.exe -> Downloader.Zlob.azc : Cleaned with backup (quarantined).
    C:\Program Files\Video ActiveX Access\iesbunst.exe -> Downloader.Zlob.bor : Cleaned with backup (quarantined).
    C:\Program Files\Video ActiveX Access\IESMIN.0XE -> Downloader.Zlob.bti : Cleaned with backup (quarantined).
    C:\Program Files\Video ActiveX Access\IESPLG.0LL -> Downloader.Zlob.bti : Cleaned with backup (quarantined).
    C:\Documents and Settings\Teemu\Incomplete\T-268800-HAMSTERBALL V3.10 GOLD.0XE -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\Documents and Settings\Sami\Local Settings\Temp\heroes_trial.exe -> Heuristic.Win32.Dialer : Cleaned with backup (quarantined).
    C:\Documents and Settings\All Users\Tiedostot\ErrorSafeFreeInstall_fi.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Cleaned with backup (quarantined).
    :mozilla.282:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
    :mozilla.232:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.299:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.77:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.78:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.79:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.80:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.81:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.82:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.83:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.84:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.85:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.86:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.87:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@ad.admarketplace[1].txt -> TrackingCookie.Admarketplace : Cleaned.
    :mozilla.403:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Adobe : Cleaned.
    :mozilla.121:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
    :mozilla.122:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
    :mozilla.55:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.56:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.57:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.58:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.44:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@www.burstbeacon[3].txt -> TrackingCookie.Burstbeacon : Cleaned.
    :mozilla.297:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@burstnet[3].txt -> TrackingCookie.Burstnet : Cleaned.
    C:\Documents and Settings\Sami\Local Settings\Temp\Cookies\sami@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
    C:\Documents and Settings\Sari\Cookies\sari@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
    :mozilla.153:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
    :mozilla.97:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
    :mozilla.98:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@cz3.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@cz5.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned.
    :mozilla.6:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Com : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@commissionpartner[2].txt -> TrackingCookie.Commissionpartner : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@commissionpartner[3].txt -> TrackingCookie.Commissionpartner : Cleaned.
    C:\Documents and Settings\Teemu\Cookies\teemu@commissionpartner[1].txt -> TrackingCookie.Commissionpartner : Cleaned.
    C:\Documents and Settings\Teemu\Cookies\teemu@commissionpartner[2].txt -> TrackingCookie.Commissionpartner : Cleaned.
    :mozilla.402:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Cqcounter : Cleaned.
    :mozilla.32:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@c.enhance[2].txt -> TrackingCookie.Enhance : Cleaned.
    :mozilla.183:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
    :mozilla.156:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
    :mozilla.285:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
    :mozilla.72:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
    :mozilla.308:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Gamershell : Cleaned.
    :mozilla.49:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Gemius : Cleaned.
    :mozilla.50:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Gemius : Cleaned.
    :mozilla.52:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Gemius : Cleaned.
    :mozilla.107:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.101:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.102:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.103:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.104:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.147:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.246:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.247:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@idot[1].txt -> TrackingCookie.Idot : Cleaned.
    :mozilla.269:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
    :mozilla.270:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@ilead.itrack[1].txt -> TrackingCookie.Itrack : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@ilead.itrack[3].txt -> TrackingCookie.Itrack : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@ilead.itrack[4].txt -> TrackingCookie.Itrack : Cleaned.
    C:\Documents and Settings\Sami\Local Settings\Temp\Cookies\sami@ilead.itrack[2].txt -> TrackingCookie.Itrack : Cleaned.
    C:\Documents and Settings\Tommi\Cookies\tommi@ilead.itrack[1].txt -> TrackingCookie.Itrack : Cleaned.
    C:\Documents and Settings\Sari\Cookies\sari@search.live[2].txt -> TrackingCookie.Live : Cleaned.
    C:\Documents and Settings\Teemu\Cookies\teemu@search.live[1].txt -> TrackingCookie.Live : Cleaned.
    C:\Documents and Settings\Tommi\Cookies\tommi@search.live[1].txt -> TrackingCookie.Live : Cleaned.
    C:\Documents and Settings\Tommi\Cookies\tommi@search.live[2].txt -> TrackingCookie.Live : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@image.masterstats[1].txt -> TrackingCookie.Masterstats : Cleaned.
    :mozilla.205:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
    :mozilla.206:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
    C:\Documents and Settings\Sami\Local Settings\Temp\Cookies\sami@www.myaffiliateprogram[2].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
    :mozilla.154:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
    :mozilla.54:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@www.paypal[1].txt -> TrackingCookie.Paypal : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@paypopup[3].txt -> TrackingCookie.Paypopup : Cleaned.
    :mozilla.135:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.136:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.137:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.138:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@ppms.popularix[1].txt -> TrackingCookie.Popularix : Cleaned.
    :mozilla.43:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
    :mozilla.45:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
    :mozilla.5:C:\Documents and Settings\Teemu\Application Data\Mozilla\Profiles\default\6evzdyqm.slt\cookies.txt -> TrackingCookie.Real : Cleaned.
    :mozilla.6:C:\Documents and Settings\Teemu\Application Data\Mozilla\Profiles\default\6evzdyqm.slt\cookies.txt -> TrackingCookie.Real : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@ads.realcastmedia[1].txt -> TrackingCookie.Realcastmedia : Cleaned.
    :mozilla.345:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
    :mozilla.346:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
    :mozilla.347:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
    :mozilla.213:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.214:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.215:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.216:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.217:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.218:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.334:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@starware[2].txt -> TrackingCookie.Starware : Cleaned.
    :mozilla.66:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.67:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.68:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.35:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Statistik-gallup : Cleaned.
    :mozilla.197:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.203:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@toplist[1].txt -> TrackingCookie.Toplist : Cleaned.
    :mozilla.36:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
    :mozilla.37:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
    :mozilla.356:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Trafic : Cleaned.
    :mozilla.13:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
    :mozilla.335:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
    :mozilla.336:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
    :mozilla.337:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
    :mozilla.338:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
    :mozilla.233:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
    :mozilla.73:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
    :mozilla.130:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
    C:\Documents and Settings\Sari\Cookies\sari@m.webtrends[1].txt -> TrackingCookie.Webtrends : Cleaned.
    C:\Documents and Settings\Tommi\Cookies\tommi@m.webtrends[1].txt -> TrackingCookie.Webtrends : Cleaned.
    C:\Documents and Settings\Tommi\Cookies\tommi@m.webtrends[3].txt -> TrackingCookie.Webtrends : Cleaned.
    C:\Documents and Settings\Ossi\Cookies\ossi@yadro[2].txt -> TrackingCookie.Yadro : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@yadro[1].txt -> TrackingCookie.Yadro : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@yadro[2].txt -> TrackingCookie.Yadro : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@yadro[3].txt -> TrackingCookie.Yadro : Cleaned.
    :mozilla.11:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    :mozilla.12:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    :mozilla.14:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    C:\Documents and Settings\Sami\Cookies\sami@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
    :mozilla.88:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
    :mozilla.89:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
    :mozilla.90:C:\Documents and Settings\Tommi\Application Data\Mozilla\Firefox\Profiles\4qnrl5n7.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
    C:\Program Files\Video ActiveX Access\imsmain.exe -> Trojan.FakeAV : Cleaned with backup (quarantined).
    C:\Documents and Settings\Teemu\Local Settings\Temp\laf4C4.tmp -> Trojan.Renos.naz : Cleaned with backup (quarantined).


    ::Report end
    -----------------------------------------------------


    Logfile of HijackThis v1.99.1
    Scan saved at 23:03:16, on 12.5.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16441)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\ELISAT~1\backweb\4119343\Program\SERVIC~1.EXE
    C:\WINDOWS\system32\CTSvcCDA.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32st.exe
    C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\program\fsbwsys.exe
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\FSGK32.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMA32.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fssm32.exe
    C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMB32.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Tablet.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\Program Files\Elisa Tietoturvapalvelu\Common\FCH32.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Common\FAMEH32.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsqh.exe
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsrw.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsav32.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\WTablet\TabUserW.exe
    C:\Program Files\Ahead\InCD\InCD.exe
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\PROGRA~1\Lexmark\PHOTOC~1\LXBLKsk.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\Logitech\Video\LogiTray.exe
    C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\ispnews.exe
    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
    C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\Program\fspex.exe
    C:\Program Files\Logitech\Video\FxSvr2.exe
    C:\Program Files\Elisa Tietoturvapalvelu\FWES\Program\fsdfwd.exe
    C:\WINDOWS\system32\Tablet.exe
    C:\PROGRA~1\ELISAT~1\ANTI-S~1\fsaw.exe
    C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\fsguidll.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\Documents and Settings\Ossi\Työpöytä\Työkaluja\scanner.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Elisa Internet
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;;localhost;<local>
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Elisa Avustaja Plugin - {DB87CDE1-EF9C-44EB-A42F-6D0B3C72C516} - C:\Program Files\Elisa\Avustaja\IEFixItNowPlugin.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [LXBLKsk] C:\PROGRA~1\Lexmark\PHOTOC~1\LXBLKsk.exe
    O4 - HKLM\..\Run: [MemoryCardManager] C:\Program Files\Lexmark\Lexmark Photo Center\MemoryCardManager.exe -startup
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Elisa Tietoturvapalvelu\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\FSSW.EXE" /reboot
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
    O4 - HKLM\..\Run: [News Service] "C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\ispnews.exe"
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: Watch.lnk = C:\WINDOWS\twain_32\A4CIS\WATCH.exe
    O4 - Global Startup: Elisa Tietoturvapalvelu.lnk = C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\Program\fspex.exe
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Building basic 3D Web Sites.lnk = C:\Program Files\3DSTATE\3D Webmaker\Tutorials\Building basic 3D Web Sites.htm
    O4 - Global Startup: Building advanced 3D Web Sites.lnk = C:\Program Files\3DSTATE\3D Webmaker\Tutorials\Building advanced 3D Web Sites.htm
    O4 - Global Startup: Basic Samples.lnk = C:\Program Files\3DSTATE\3D Webmaker\Basic Samples\index.htm
    O4 - Global Startup: Advanced Samples.lnk = C:\Program Files\3DSTATE\3D Webmaker\3D Web Samples\Html\index.htm
    O4 - Global Startup: Converters.lnk = ?
    O4 - Global Startup: License.lnk = C:\Program Files\3DSTATE\3D Webmaker\License\License.txt
    O4 - Global Startup: Webmaker Book.lnk = C:\Program Files\3DSTATE\3D Webmaker\Webmaker book\Webmaker book.doc
    O4 - Global Startup: Programming Reference Manual.lnk = C:\Program Files\3DSTATE\3D Webmaker\Programming Reference Manual\default.htm
    O4 - Global Startup: Tutorials.lnk = C:\Program Files\3DSTATE\3D Webmaker\Tutorials\index.htm
    O4 - Global Startup: Resources.lnk = C:\Program Files\3DSTATE\3D Webmaker\wwwRes\resources.htm
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Free WebSite Tools.lnk = ?
    O8 - Extra context menu item: &Estä tämä kohoikkuna - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\blockpopups.htm
    O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
    O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
    O9 - Extra button: IE-suojaus - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\ieshield.dll
    O9 - Extra 'Tools' menuitem: IE-suojaus... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\ieshield.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
    O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: Tuki - {0883023E-F304-43A2-A843-64C9CFAC85DB} - http://tuki.elisa.net/ (file missing) (HKCU)
    O9 - Extra button: SMS-viesti - {0B5BFEC0-A026-4F5D-B338-E3DCD5B0B6F5} - http://sms.kolumbus.fi/ (file missing) (HKCU)
    O9 - Extra button: Palvelut - {8A77EEDF-87F7-443B-8559-FF6827677B05} - http://service.kolumbus.fi/ (file missing) (HKCU)
    O11 - Options group: [INTERNATIONAL] International*
    O14 - IERESET.INF: START_PAGE_URL=http://elisa.net/
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/installer.v4/vet_install_popup.pl?3&6&04.00.04.03&unknown&unknown&http://www.opel.fi/content_data/GME/019/FI/fi/GBPFI/microsite/0N/RTT/signum.html
    O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
    O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
    O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll
    O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Elisa Tietoturvapalvelu (BackWeb Plug-in - 4119343) - BackWeb Technologies Inc. - C:\PROGRA~1\ELISAT~1\backweb\4119343\Program\SERVIC~1.EXE
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE
    O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32st.exe
    O23 - Service: FSBWSYS (fsbwsys) - F-Secure Corp. - C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\program\fsbwsys.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\FWES\Program\fsdfwd.exe
    O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMA32.EXE
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe



     
  10. Auttaja

    Auttaja Guest

    C:\Program Files\Magic Waterfall Screensaver
    C:\Program Files\Video ActiveX Access\i

    Poista noi kansit

    ======

    Lataa Dr.Web CureIt työpöydälle:
    ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

    [*]Tuplaklikkaa drweb-cureit.exe ja anna sen tehdä express scan
    [*]Se skannaa käynnissä olevat ohjelmat ja jos jotain löytyy, klikkaa yes kun se kysyy haluatko poistaa sen. Tämä on vain lyhyt scan.
    [*]Kun scan on valmis, merkkaa asemat, jotka haluat scannata.
    [*]Valitse kaikki asemat. Punainen piste osoittaa, mitkä asemat on valittu.
    [*]Klikaa vihreää nuolta oikealla ja scan alkaa.
    [*]Klikkaa 'Yes to all', jos kysytään haluatko poistaa/siirtää tiedoston.
    [*]Kun scan on valmis, katso voitko klikata next-kuvaketta löytyneiden tiedostojen vieressä: [​IMG]
    [*]Jos asia on niin, klikkaa sitä ja sitten klikkaa next-kuvaketta oikealla alhaalla ja valitse Move incurable kuten alla olevalla kuvassa:
    [​IMG]
    Tämä siirtää sen %userprofile%\DoctorWeb\quarantine-hakemistoon.
    [*]Tämän jälkeen klikkaa Dr.Web CureIt-valikossa file ja valitse save report list
    [*]Tallenna raportti työpöydälle. Raportin nimi on DrWeb.csv
    [*]Sulje Dr.Web Cureit.
    [*]Käynnistä kone uudelleen !! Tämä siksi, että käytössä olevat tiedostot poistetaan/siirretään käynnistyksen yhteydessä.
    [*]Käynnistyksen jälkeen liitä Dr.Web-lokin, jonka tallensit aiemmin, sisältö seuraavaan vastaukseesi.
     
  11. Dossi

    Dossi Member

    Joined:
    Oct 30, 2004
    Messages:
    37
    Likes Received:
    0
    Trophy Points:
    16
    Bowsroam.exe C:\Documents and Settings\All Users\Application Data\namesoftpartmeet Trojan.Swizzor Deleted.
    army sixth.exe C:\Documents and Settings\All Users\Application Data\namesoftpartmeet Trojan.Swizzor Deleted.
    Process.exe C:\Documents and Settings\Ossi\Työpöytä\SmitfraudFix Tool.Prockill Incurable.Moved.
    restart.exe C:\Documents and Settings\Ossi\Työpöytä\SmitfraudFix Tool.ShutDown.11 Incurable.Moved.
    pic.tiff C:\Documents and Settings\Sami\Local Settings\Temp Exploit.MS05-053 Deleted.
    bis324.0xe C:\Documents and Settings\Teemu\Local Settings\Temp Trojan.Isbar.459 Deleted.
    bis3CC.0xe C:\Documents and Settings\Teemu\Local Settings\Temp Trojan.Isbar.459 Deleted.
    SETUPWMA.0XE C:\Documents and Settings\Teemu\Application Data\Test Window Bags Trojan.Isbar.459 Deleted.
    amlkhsnp.exe C:\Documents and Settings\Teemu\Application Data\Test Window Bags Trojan.Swizzor Deleted.
    fyyitbof.exe C:\Documents and Settings\Teemu\Application Data\Test Window Bags Trojan.Swizzor Deleted.
    Clock.mbt C:\Program Files\Free_Java_Web_Button\Samples Win32.HLLM.Graz Deleted.
    Process.exe C:\Program Files\Mozilla Firefox\SmitfraudFix Tool.Prockill Incurable.Moved.
    restart.exe C:\Program Files\Mozilla Firefox\SmitfraudFix Tool.ShutDown.11 Incurable.Moved.
    A0273218.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP633 Trojan.Popuper Deleted.
    A0273221.0xe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP633 Trojan.Popuper Deleted.
    A0273222.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP633 Adware.NewDotNet Incurable.Moved.
    A0273223.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP633 Adware.TryMedia Incurable.Moved.
    A0273224.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP633 Adware.Gator Incurable.Moved.
    A0273225.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP633 Adware.Gator Incurable.Moved.
    A0273227.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP633 Adware.SaveNow Incurable.Moved.
    A0273228.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP633 Trojan.DownLoader.6550 Deleted.
    A0274835.exe\data002 C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP640\A0274835.exe Trojan.Popuper
    A0274835.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP640 Archive contains infected objects Moved.
    A0274842.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP640 Trojan.Swizzor Deleted.
    A0274843.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP640 Trojan.Swizzor Deleted.
    A0274844.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP640 Trojan.Swizzor Deleted.
    A0274845.exe C:\System Volume Information\_restore{0366D7FF-063B-4A86-8395-04CDB13565A6}\RP640 Trojan.Swizzor Deleted.
     
  12. Auttaja

    Auttaja Guest

    Lataa ATF Cleaner
    http://www.atribune.org/ccount/click.php?id=1

    Tupla-klikkaa ATF-Cleaner.exe käynnistääksesi ohjelman. Main:n alla valitse: Select All
    Klikkaa Empty Selected valintaa.
    Jos käytät FireFoxia selaimenasi Klikkaa Firefox yläpuolelta ja valitse: Select All
    Klikkaa Empty Selected valintaa.
    HUOMIO: Jos haluaisit pitää tallennetut salasanasi, klikkaa No kun se sitä kysyy.
    Jos käytät Operaa selaimenasi Klikkaa Opera yläpuolelta ja valitse: Select All
    Klikkaa Empty Selected valintaa taas.
    HUOMIO: Jos haluaisit pitää tallennetut salasanasi, klikkaa No kun se sitä kysyy.
    Klikkaa Exit päävalikosta sulkeaksesi ohjelman.
    Teknistä tukea tulee jos tupla-klikkaat sähköpostiosoitetta joka sijaitsee jokaisen menun alapuolella kyseisessä työkalussa. (Huomatkaa että se tuki on sitten englanniksi)

    ==========

    Täll vois viel varmistaa

    Tarkista koneesi F-Securen online skannerilla

    Huom, skanneri toimii vain Internet Explorer selaimella

    * Lue sivun ohjeet huolella läpi
    * Klikkaa Start scanning
    * Mikäli saat Internet Explorer -suojausvaroituksen, klikkaa Asenna
    * Klikkaa Accept
    * Klikkaa Custom Scan
    * Säädä asetukset seuraavasti

    o "Virus Scan Option" kohdasta valitse Scan whole system
    o "Other Scan Option" kohdasta valitse Scan All Files
    o Valitse Scan whole system for rootkits
    o Valitse Scan whole system for spyware
    o Laita ruksi kohtaan Scan inside archives
    o Varmista että Use advanced heuristics on valittuna

    * Klikkaa Start
    * Skannaus käynnistyy kun tarvittavat tiedostot/päivitykset on ladattu
    * Odota kärsivällisesti
    * Kun sakannaus on suoritettu, klikkaa Automatic cleaning
    * Klikkaa Show Report
    * Raportti aukeaa selaimessa, kopioi teksti kokonaan
    * Liitä kopioitu teksti esim. muistioon tai Wordiin ja tallenna työpöydälle
    * Voit sulkea skannerin
    * Lähetä raportti viestiketjuusi
     

Share This Page