HJT login tarkistaminen. kone tökkii ja hidastunut.

Viestiketju Virukset ja haittaohjelmat - HijackThis -logit -osiossa. Ketjun avasi juha123 03.03.2007.

  1. juha123

    juha123 Regular member

    Liittynyt:
    27.11.2006
    Viestejä:
    182
    Kiitokset:
    0
    Pisteet:
    26
    Logfile of HijackThis v1.99.1
    Scan saved at 15:47:37, on 3.3.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    D:\Java\jre1.5.0_11\bin\jusched.exe
    C:\WINDOWS\system32\RunDll32.exe
    D:\F-Secure intert\Common\FSM32.EXE
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\system32\ctfmon.exe
    D:\F-Secure intert\Anti-Virus\fsgk32st.exe
    D:\F-Secure intert\Common\FSMA32.EXE
    D:\F-Secure intert\Anti-Virus\FSGK32.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\slserv.exe
    D:\F-Secure intert\Common\FSMB32.EXE
    C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    D:\F-Secure intert\Common\FCH32.EXE
    D:\F-Secure intert\Anti-Virus\fssm32.exe
    D:\F-Secure intert\Anti-Virus\fsqh.exe
    D:\F-Secure intert\Common\FAMEH32.EXE
    D:\F-Secure intert\FSAUA\program\fsaua.exe
    D:\F-Secure intert\FWES\Program\fsdfwd.exe
    D:\F-Secure intert\FSAUA\program\fsus.exe
    C:\WINDOWS\System32\svchost.exe
    D:\F-Secure intert\Anti-Virus\fsav32.exe
    D:\F-Secure intert\FSGUI\fsguidll.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    D:\Mozilla Firefox\firefox.exe
    C:\hjt\hjt\HijackThis_v1.99.1.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [High Definition Audio -ominaisuussivun pikakuvake] HDAudPropShortcut.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Java\jre1.5.0_11\bin\jusched.exe"
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [F-Secure Manager] "D:\F-Secure intert\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "D:\F-Secure intert\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [DAEMON Tools] "D:\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] D:\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [PcSync] D:\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {83AFB5CA-ED35-11D4-A452-0080C8D85045} (GameDesire Poker Games) - http://67.15.101.3/g_bin/eng/poker_2_0_0_43.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - D:\F-Secure intert\Anti-Virus\fsgk32st.exe
    O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - D:\F-Secure intert\FSAUA\program\fsaua.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - D:\F-Secure intert\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - D:\F-Secure intert\Common\FSMA32.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
     
  2.  
  3. Hujo

    Hujo Guest

    scannaa hjt:llä merkkaa paina Fix checked

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    aja escan
    Ohjeet tuolla sivulla.
    http://koti.mbnet.fi/pattaya1/escanmwav.htm
    lataa tuosta
    http://www.spywareinfo.dk/download/mwav.exe
    päivitä tuosta
    http://koti.mbnet.fi/pattaya1/lataus/Mwav.bat
    laita täpit merkkauksien mukaan
    http://koti.mbnet.fi/pattaya1/eScan6.jpg

    scannaa

    jos ala luukkuun tulee jotain niin kopioi se näin:
    Käytä komentoa Ctrl+A.
    Kopioi rivit komennolla Ctrl+C.
    Liitä rivit komennolla Ctrl+V.

    Laita virus log tänne.
     
  4. juha123

    juha123 Regular member

    Liittynyt:
    27.11.2006
    Viestejä:
    182
    Kiitokset:
    0
    Pisteet:
    26
    ala luukkuun ei tullut mitään. Teinköhän kaikki oikein ? Toivottavasti :)
     
  5. Hujo

    Hujo Guest

    jos päivitit ja laitoit täpit kuvan mukaan
    Epäilen vahvasti että teit oikeen :D

    ajas tuosta vielä ATF cleaner

    Lataa Atribunen ATF Cleaner

    Ohjeet;

    Tupla-klikkaa ATF-Cleaner.exe käynnistääksesi ohjelman.
    • Main:n alla valitse: Select All
      Klikkaa Empty Selected valintaa.
    Jos käytät FireFoxia selaimenasi
    • Klikkaa Firefox yläpuolelta ja valitse: Select All
      Klikkaa Empty Selected valintaa.
      HUOMIO: Jos haluaisit pitää tallennetut salasanasi, klikkaa No kun se sitä kysyy.
    Jos käytät Operaa selaimenasi
    • Klikkaa Opera yläpuolelta ja valitse: Select All
      Klikkaa Empty Selected valintaa taas.
      HUOMIO: Jos haluaisit pitää tallennetut salasanasi, klikkaa No kun se sitä kysyy.
    Klikkaa Exit päävalikosta sulkeaksesi ohjelman.
     
  6. juha123

    juha123 Regular member

    Liittynyt:
    27.11.2006
    Viestejä:
    182
    Kiitokset:
    0
    Pisteet:
    26
    Näyttääkö tuo nyt hyvältä ? :) Kun tuntuu et kone ois vielä laiskempi kuin ennen. Mutta kai se on aika ostaa uusia osia jo tuohon koneeseen.

    Logfile of HijackThis v1.99.1
    Scan saved at 21:26:16, on 8.3.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    D:\Java\jre1.5.0_11\bin\jusched.exe
    C:\WINDOWS\system32\RunDll32.exe
    D:\F-Secure intert\Common\FSM32.EXE
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\system32\ctfmon.exe
    D:\F-Secure intert\Anti-Virus\fsgk32st.exe
    D:\F-Secure intert\Common\FSMA32.EXE
    D:\F-Secure intert\Anti-Virus\FSGK32.EXE
    D:\F-Secure intert\Common\FSMB32.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\slserv.exe
    C:\Program Files\Messenger\msmsgs.exe
    D:\F-Secure intert\Common\FCH32.EXE
    D:\F-Secure intert\Anti-Virus\fsqh.exe
    D:\F-Secure intert\Common\FAMEH32.EXE
    D:\F-Secure intert\FSAUA\program\fsaua.exe
    D:\F-Secure intert\Anti-Virus\fssm32.exe
    D:\F-Secure intert\FWES\Program\fsdfwd.exe
    C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    C:\WINDOWS\System32\svchost.exe
    D:\F-Secure intert\Anti-Virus\fsav32.exe
    D:\F-Secure intert\FSGUI\fsguidll.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    D:\Mozilla Firefox\firefox.exe
    C:\hjt\hjt\HijackThis_v1.99.1.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [High Definition Audio -ominaisuussivun pikakuvake] HDAudPropShortcut.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Java\jre1.5.0_11\bin\jusched.exe"
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [F-Secure Manager] "D:\F-Secure intert\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "D:\F-Secure intert\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [DAEMON Tools] "D:\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] D:\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [AntiviralGolden] C:\Program Files\AntiviralGolden\AntiviralGolden.exe /h
    O4 - HKLM\..\Run: [sXe Injected] C:\Program Files\sXe Injected\sXe Injected.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [PcSync] D:\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: d:\f-secure intert\fsps\program\fslsp.dll
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {83AFB5CA-ED35-11D4-A452-0080C8D85045} (GameDesire Poker Games) - http://67.15.101.3/g_bin/eng/poker_2_0_0_43.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - D:\F-Secure intert\Anti-Virus\fsgk32st.exe
    O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - D:\F-Secure intert\FSAUA\program\fsaua.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - D:\F-Secure intert\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - D:\F-Secure intert\Common\FSMA32.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
     

Jaa tämä sivu