Logfile of HijackThis v1.97.7 Scan saved at 22:42:55, on 25.2.2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\WINDOWS\system32\RunDll32.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\VVSN\VVSN.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\TGTSoft\StyleXP\StyleXP.exe C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Norton Internet Security\ISSVC.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Messenger\msmsgs.exe C:\Documents and Settings\tumppi\Työpöytä\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.accoona.com/search_assis...leftnav&utm_source=&utm_medium=&utm_campaign= R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.accoona.com R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit R3 - URLSearchHook: (no name) - <default> - (no file) O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Accoona Search Assistant - {944864A5-3916-46E2-96A9-A2E84F3F1208} - C:\Program Files\Accoona\ASearchAssist.dll (file missing) O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 -noicon O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM) O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1138395726281
Lataappa uusin versio Hijack This:istä. Sinulla on vanha. Eli täältä http://koti.mbnet.fi/pattaya1/HijackThis.exe LAita se sitten omaan kansioonsa C:n juureen, eikä Työpöydälle. Eli: C:\hjt\HijackThis.exe
Logfile of HijackThis v1.99.1 Scan saved at 11:24:56, on 26.2.2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\WINDOWS\system32\RunDll32.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\VVSN\VVSN.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\TGTSoft\StyleXP\StyleXP.exe C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Norton Internet Security\ISSVC.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\System32\msiexec.exe C:\PROGRA~1\MOZILL~1\FIREFOX.EXE C:\hjt\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit R3 - URLSearchHook: (no name) - <default> - (no file) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 -noicon O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1138395726281 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Autodata Limited License Service - Autodata Limited - C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
Poista lisää/poista -sovelluksesta seuraavat: WhenU (voi olla sanoja perässä/edessä) Fixaa seuraavat, eli do a system scan only, laita rastit seuraaviin ja fix checked: R3 - URLSearchHook: (no name) - - (no file) O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k Käynnistä vikasietotilaan (F8 käynnistyksen yhteydessä) poista seuraava: C:\Program Files\VVSN\ <- kansio Käynnist tavallisesti. Hae täältä -> http://www.ewido.net/en/download ewido, asenna, päivitä ja skannaa. Anna poistaa mitä löytää, tallenna raportti. Lähetä ewidon raportti ja uusi HjT-loki.
Kiitos paljon avusta, toivottavasti se rupee nyt näyttää paremmalta! --------------------------------------------------------- ewido anti-malware - Scan report --------------------------------------------------------- + Created on: 14:06:20, 28.2.2006 + Report-Checksum: DBCB801F + Scan result: HKLM\SOFTWARE\Classes\CLSID\{364B6276-C6C1-40B6-A6D7-6C48871FD707} -> Adware.Accoona : Cleaned without backup HKU\S-1-5-21-2025429265-1708537768-682003330-1003\Software\Microsoft\Internet Explorer\URLSearchHooks\{944864A5-3916-46E2-96A9-A2E84F3F1208} -> Adware.Accoona : Cleaned without backup HKU\S-1-5-21-2025429265-1708537768-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{364B6276-C6C1-40B6-A6D7-6C48871FD707} -> Adware.Accoona : Cleaned with backup HKU\S-1-5-21-2025429265-1708537768-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{944864A5-3916-46E2-96A9-A2E84F3F1208} -> Adware.Accoona : Cleaned with backup :mozilla.19:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup :mozilla.20:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup :mozilla.21:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup :mozilla.22:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup :mozilla.48:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.49:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.50:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.51:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.52:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.53:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.54:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.55:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.56:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.57:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.58:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.59:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.60:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.61:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.62:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.63:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.65:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup :mozilla.66:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup :mozilla.67:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned with backup :mozilla.74:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup :mozilla.75:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup :mozilla.76:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup :mozilla.80:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.81:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.82:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.83:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.84:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.85:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.92:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup :mozilla.140:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.141:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.142:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.143:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.144:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.145:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.146:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.153:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.154:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.155:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.156:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.157:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.158:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.167:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Trafic : Cleaned with backup :mozilla.171:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.172:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.182:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup :mozilla.185:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup :mozilla.194:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup :mozilla.195:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup :mozilla.197:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup :mozilla.198:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup :mozilla.204:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup :mozilla.209:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Spylog : Cleaned with backup :mozilla.213:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.214:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.215:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.216:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.217:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.218:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.219:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.220:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned with backup :mozilla.223:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup :mozilla.277:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.278:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.279:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.280:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.281:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.282:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.283:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.284:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.285:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.286:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.287:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.288:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.292:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.305:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.306:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.311:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.312:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.313:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.314:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.321:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup :mozilla.329:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup :mozilla.330:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup :mozilla.335:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Ivwbox : Cleaned with backup :mozilla.336:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.338:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Komtrack : Cleaned with backup :mozilla.340:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Komtrack : Cleaned with backup :mozilla.364:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup :mozilla.365:C:\Documents and Settings\tumppi\Application Data\Mozilla\Firefox\Profiles\tr5nu8zg.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup C:\Documents and Settings\tumppi\Cookies\tumppi@2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup C:\Documents and Settings\tumppi\Cookies\tumppi@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup C:\Documents and Settings\tumppi\Cookies\tumppi@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned with backup C:\Documents and Settings\tumppi\Cookies\tumppi@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup C:\Documents and Settings\tumppi\Cookies\tumppi@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup C:\Documents and Settings\tumppi\Cookies\tumppi@media.fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned with backup C:\Documents and Settings\tumppi\Cookies\tumppi@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Cleaned with backup C:\Documents and Settings\tumppi\Cookies\tumppi@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup C:\Documents and Settings\tumppi\Cookies\tumppi@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup C:\Program Files\DAEMON Tools\SetupDTSB.exe -> Adware.SaveNow : Cleaned with backup C:\Program Files\themexp\Themexp.org File\NNWDAB638.EXE -> Adware.NewDotNet : Cleaned with backup C:\Program Files\themexp\Themexp.org File\VVSNInst.exe -> Adware.SaveNow : Cleaned with backup C:\WINDOWS\NDNuninstall6_38-1.exe -> Adware.NewDotNet : Cleaned with backup C:\WINDOWS\NDNuninstall6_38.exe -> Adware.NewDotNet : Cleaned with backup C:\WINDOWS\NDNuninstall7_22-1.exe -> Adware.NewDotNet : Cleaned with backup C:\WINDOWS\NDNuninstall7_22.exe -> Adware.NewDotNet : Cleaned with backup ::Report End Logfile of HijackThis v1.99.1 Scan saved at 14:09:39, on 28.2.2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\WINDOWS\system32\RunDll32.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\TGTSoft\StyleXP\StyleXP.exe C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\ewido anti-malware\ewidoguard.exe C:\Program Files\Norton Internet Security\ISSVC.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\ewido anti-malware\securitysuite.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\hjt\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 -noicon O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1138395726281 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Autodata Limited License Service - Autodata Limited - C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe Kiitos!