Firewall.exe (mato?)

Viestiketju Virukset ja haittaohjelmat -osiossa. Ketjun avasi helsinki 21.08.2006.

  1. helsinki

    helsinki Member

    Liittynyt:
    16.10.2003
    Viestejä:
    25
    Kiitokset:
    0
    Pisteet:
    11
    Moikka,
    Vähänaikaa sitten alkoi tulemaan koneen käynnistettäessä herjaa firewall.exe nimisestä tiedostosta. Tämän jälkeen alkoi nettiyhteys katkeilla satunnaisesti ja sen käynnistys vaati aina modeemin buuttauksen. Nyt eilen en saanut enään luotua ollenkaan yhteyttä nettiin. Koneeseen on asennettu Norton (system works 2005) virusohjlma eikä sillä löydy skannakusessa mitään viruksia tai vastaavia. Olisiko jollakin tietoa kyseisestä tiedostota voiko se aiheuttaa tämän netin kaatumisen ja kuinka sen saisi postettua?
     
  2.  
  3. NUIJJA

    NUIJJA Active member

    Liittynyt:
    12.01.2005
    Viestejä:
    4,410
    Kiitokset:
    0
    Pisteet:
    66
    firewall.exe ei pitäs olla pöpö. Mutta ajappa vaikka
    - BitDefender Online scan
    http://www.bitdefender.com/scan/licence.php

    Elisan verkko pätki eilen ja tänään, varmaan palveluntarjoajasta riippumatta jotka vain toimii elisan verkossa.
     
  4. helsinki

    helsinki Member

    Liittynyt:
    16.10.2003
    Viestejä:
    25
    Kiitokset:
    0
    Pisteet:
    11
    Mä en pääse ollenkaan nettiin (tai vielä ainakaan aamulla en päässyt) joten en voi ajaa "online scan" ohjelmaa. Yhteys on saunalahden joten voihan se tietysti olla että toi Elisan verkkoongelma myös koskee saunalahtea.
     
  5. OneMember

    OneMember Active member

    Liittynyt:
    12.01.2006
    Viestejä:
    3,197
    Kiitokset:
    60
    Pisteet:
    78
    Eli jos et käytä tuota palomuuria niin poista koko roska...
    Eikös siinä Norton ole palomuuria?

    Ethän useata palomuuria käytä? Yksi riittää...
     
  6. alypaa

    alypaa Member

    Liittynyt:
    20.10.2006
    Viestejä:
    14
    Kiitokset:
    0
    Pisteet:
    11
    auttakees ny mua.. eilisen jälkeen alko tulla texti bsplayer jotain exe yrittää muodostaa yhteyden nettiin ja firewall setting please chek plaa plaa..norton on helisemäs koko ajan torjuu jotain.. minkä teen ja mikä on oikeastaan vialla????????
     
  7. Marku2

    Marku2 Regular member

    Liittynyt:
    07.12.2005
    Viestejä:
    1,259
    Kiitokset:
    0
    Pisteet:
    46
  8. alypaa

    alypaa Member

    Liittynyt:
    20.10.2006
    Viestejä:
    14
    Kiitokset:
    0
    Pisteet:
    11
    voi luoja mites se taas onnistuu hermo menee just ja kone lentää pihalle olen aivan avuton
     
  9. Marku2

    Marku2 Regular member

    Liittynyt:
    07.12.2005
    Viestejä:
    1,259
    Kiitokset:
    0
    Pisteet:
    46
    Viimeksi muokattu: 20.10.2006
  10. alypaa

    alypaa Member

    Liittynyt:
    20.10.2006
    Viestejä:
    14
    Kiitokset:
    0
    Pisteet:
    11
    joo elikkä se on nyt koneella ja mitäs sitte? en saanu selvää kuitenkaan kuinka lähetän sen tänne?? etsäviittis tulla kädestä pitäen neuvoo vanha akka tälläsiä osaa!!!!!!!!!
     
  11. Marku2

    Marku2 Regular member

    Liittynyt:
    07.12.2005
    Viestejä:
    1,259
    Kiitokset:
    0
    Pisteet:
    46
    Ymmärsitkö?
     
  12. alypaa

    alypaa Member

    Liittynyt:
    20.10.2006
    Viestejä:
    14
    Kiitokset:
    0
    Pisteet:
    11
    nyt yritän ok!!!!
     
  13. alypaa

    alypaa Member

    Liittynyt:
    20.10.2006
    Viestejä:
    14
    Kiitokset:
    0
    Pisteet:
    11
    Logfile of HijackThis v1.99.1
    Scan saved at 14:50:29, on 20.10.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Norton Internet Security\ISSVC.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\D-Tools\daemon.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
    C:\Program Files\Sonera\InternetAvustaja\bin\tgcmd.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Save\Save.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Documents and Settings\Nina The Angel\Työpöytä\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
    O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\ereg.ini"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [SoneraAgent] "C:\Program Files\Sonera\InternetAvustaja\bin\tgcmd.exe" /server /startmonitor /deaf
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O23 - Service: Automattinen LiveUpdate-ajastustoiminto - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Norton AntiVirus Auto-Protect -palvelu (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

     
  14. alypaa

    alypaa Member

    Liittynyt:
    20.10.2006
    Viestejä:
    14
    Kiitokset:
    0
    Pisteet:
    11
    mitas ny sitte
     
  15. Marku2

    Marku2 Regular member

    Liittynyt:
    07.12.2005
    Viestejä:
    1,259
    Kiitokset:
    0
    Pisteet:
    46
    [bold]Puhdistusohjeet alypaalle![/bold]

    Avaa [bold]OhjausPaneeli[/bold]->[bold]Lisää/Poista Sovellus[/bold]->[bold]Poista:[/bold]
    WhenUSave

    Avaa HijackThis
    -> Paina [bold]Do a system scan only[/bold]
    -> Merkkaa seuraava rivi
    -> Paina [bold]Fix Checked[/bold]

    [bold]Fixaa tämä rivi:[/bold] (ohjeet yläpuolella)
    O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"

    Laita piilotiedostot näkyviin -> Ohje!
    Käynnistä kone Vikasietotilaan.

    Poista tämä kansio:
    C:\Program Files\[bold]Save[/bold]

    Käynnistä kone normaalitilaan!

    Hae AVG Anti-Spyware -> http://aaxxeell.googlepages.com/ewido4
    Päivitä, Scannaa, [bold]Poista Löydöt[/bold] ja tallenna raportti.

    Lähetä uusi HjT-loki ja AVG:n raportti.
     
  16. alypaa

    alypaa Member

    Liittynyt:
    20.10.2006
    Viestejä:
    14
    Kiitokset:
    0
    Pisteet:
    11
    huh huh ja tuosta kaikestako suoriudun ihan itse... apuuuuuvaaaaaaaa!
     
  17. pkaksp

    pkaksp Moderator Ylläpitäjä

    Liittynyt:
    11.01.2005
    Viestejä:
    12,233
    Kiitokset:
    53
    Pisteet:
    128
    Jos ei noiden ohjeiden mukaan onnistu, niin viisainta on viedä se kone huoltoon ammattilaisen käsiin.
     
  18. alypaa

    alypaa Member

    Liittynyt:
    20.10.2006
    Viestejä:
    14
    Kiitokset:
    0
    Pisteet:
    11
    kun kone sanoo että muuta tai poista ja siitä ei anna poistaa vaan käskee soittaa help lineen
     
  19. Marku2

    Marku2 Regular member

    Liittynyt:
    07.12.2005
    Viestejä:
    1,259
    Kiitokset:
    0
    Pisteet:
    46
    Tuossa on noi ohjeet mitkä tein sulle. Kun olet tehnyt nuo, niin lähetä pyydetyt lokit.
     
  20. alypaa

    alypaa Member

    Liittynyt:
    20.10.2006
    Viestejä:
    14
    Kiitokset:
    0
    Pisteet:
    11
    ---------------------------------------------------------
    AVG Anti-Spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 18:34:40 20.10.2006

    + Scan result:



    C:\Program Files\Save -> Adware.SaveNow : Cleaned with backup (quarantined).
    C:\Program Files\Save\ACM.dll -> Adware.SaveNow : Cleaned with backup (quarantined).
    C:\Program Files\Save\Save.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
    C:\Program Files\Save\SaveUninst.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
    C:\Program Files\Save\ffext.mod -> Adware.SaveNow : Cleaned with backup (quarantined).
    C:\Program Files\Save\save.htm -> Adware.SaveNow : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\WUSN.1 -> Adware.SaveNow : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WhenUSaveMsg -> Adware.SaveNow : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\WhenUSave -> Adware.SaveNow : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\WhenUSave\Partners -> Adware.SaveNow : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\WhenUSave\Partners\BSPL -> Adware.SaveNow : Cleaned with backup (quarantined).
    :mozilla.136:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.137:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.140:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.146:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.147:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.148:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.149:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.239:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.365:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.391:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Nina The Angel\Cookies\nina the angel@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Nina The Angel\Cookies\nina the angel@msnaccountservices.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Nina The Angel\Cookies\nina the angel@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.121:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.122:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.382:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
    :mozilla.383:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
    :mozilla.370:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.371:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.321:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
    C:\Documents and Settings\Nina The Angel\Cookies\nina the angel@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
    :mozilla.353:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
    :mozilla.198:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Etracker : Cleaned.
    :mozilla.218:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
    :mozilla.219:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
    :mozilla.220:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
    :mozilla.221:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
    :mozilla.354:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
    :mozilla.385:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.386:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.10:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.12:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.13:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.209:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.212:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.330:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
    :mozilla.276:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Realtracker : Cleaned.
    :mozilla.259:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
    :mozilla.260:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
    :mozilla.261:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
    :mozilla.262:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
    :mozilla.313:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
    :mozilla.82:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.83:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.84:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.17:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
    :mozilla.18:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
    :mozilla.292:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
    :mozilla.283:C:\Documents and Settings\Nina The Angel\Application Data\Mozilla\Firefox\Profiles\kxnem2t3.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.


    ::Report end

     
  21. alypaa

    alypaa Member

    Liittynyt:
    20.10.2006
    Viestejä:
    14
    Kiitokset:
    0
    Pisteet:
    11
    Logfile of HijackThis v1.99.1
    Scan saved at 18:38:48, on 20.10.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Norton Internet Security\ISSVC.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\D-Tools\daemon.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
    C:\Program Files\Sonera\InternetAvustaja\bin\tgcmd.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Documents and Settings\Nina The Angel\Työpöytä\HijackThis.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\wuauclt.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
    O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\ereg.ini"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [SoneraAgent] "C:\Program Files\Sonera\InternetAvustaja\bin\tgcmd.exe" /server /startmonitor /deaf
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O23 - Service: Automattinen LiveUpdate-ajastustoiminto - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Norton AntiVirus Auto-Protect -palvelu (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

     

Jaa tämä sivu