HJT-logi...netti jumittaa...

Viestiketju Virukset ja haittaohjelmat -osiossa. Ketjun avasi kammo 25.10.2005.

  1. kammo

    kammo Member

    Liittynyt:
    24.10.2005
    Viestejä:
    6
    Kiitokset:
    0
    Pisteet:
    11
    Tämmönen ongelma,kun nettipiuha kiinni koneeseen jumittuu se välittömästi eli joku Pöpö siellä luuraa,oisko jollekin käynyt vastaavaa ja löytyisikö logeista jotain outoa?.

    Logfile of HijackThis v1.99.1
    Scan saved at 13:51:24, on 23.10.2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
    C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
    C:\Program Files\F-Secure\Common\FSMA32.EXE
    C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
    C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
    C:\Program Files\F-Secure\Common\FSMB32.EXE
    C:\Program Files\F-Secure\Common\FCH32.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\F-Secure\Common\FAMEH32.EXE
    C:\Program Files\F-Secure\Common\FNRB32.EXE
    C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    C:\Program Files\F-Secure\Common\FIH32.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
    C:\Program Files\F-Secure\Common\FSM32.EXE
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\DU Meter\DUMeter.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    E:\Asennettuja OHJELMIA\power dvd\PDVDServ.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
    C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    C:\Program Files\F-Secure\FSGUI\fsguiexe.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\F-Secure\BackWeb\7681197\Program\F-Secure Automatic Update.exe
    C:\HJT\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fi/0SEFIFI/SAOS01
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mtv3.fi/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
    O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [RemoteControl] "E:\Asennettuja OHJELMIA\power dvd\PDVDServ.exe"
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
    O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_06\bin\npjpi141_06.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_06\bin\npjpi141_06.dll
    O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
    O20 - AppInit_DLLs: MsgPlusLoader.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
    O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
    O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
     
  2.  
  3. -kemisti-

    -kemisti- Active member

    Liittynyt:
    06.06.2005
    Viestejä:
    6,305
    Kiitokset:
    0
    Pisteet:
    96
    Ei tossa mitään kummallista näy.

    Tuon voi fixata:

    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    Lisäks haepa tuolta -> http://www.ewido.net/en/download, asenna, päivitä ja skannaa sillä. Tallenna raportti ja lähetä se tänne.

    EDIT: Ja jollei ewidon sivut toimi (niin kun just nyt ei toimi), niin hae eScan täältä -> http://koti.mbnet.fi/pattaya1/escanmwav.htm Asennus- ja päivitysohjeet sivulla. Lähetä ne "örkkitulokset" tänne (ohje sivulla, alin kuva ja sen yläpuolella oleva teksti).
     
    Viimeksi muokattu: 25.10.2005
  4. Disa-

    Disa- Regular member

    Liittynyt:
    06.09.2005
    Viestejä:
    860
    Kiitokset:
    0
    Pisteet:
    26
    Sitten näitä "turhia", jotka hidastaa käynnistymistä:

    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
     
  5. kammo

    kammo Member

    Liittynyt:
    24.10.2005
    Viestejä:
    6
    Kiitokset:
    0
    Pisteet:
    11
    kiitti neuvoista,otin ton eScanin,siis toisella koneella,se oli aika tuore päivitys ja ajoin ton ongelmakoneen ja löytyhä noita sit.
    en tiedä poistiko se ne skannin jälkeen, painoin ok.

    File C:\Documents and Settings\kimmo\.jpi_cache\file\1.0\BlackBox.class-24df3800-3f358fa4.class infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
    File C:\Documents and Settings\kimmo\.jpi_cache\file\1.0\BlackBox.class-56f886f-6b2b0e71.class infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
    File C:\Documents and Settings\kimmo\.jpi_cache\file\1.0\BlackBox.class-5b7404c6-1f852d34.class infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
    File C:\Documents and Settings\kimmo\.jpi_cache\file\1.0\BlackBox.class-61bb7c42-7b9c57b6.class infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
    File C:\Documents and Settings\kimmo\.jpi_cache\file\1.0\BlackBox.class-6b558204-36c14454.class infected by "Trojan.Java.ClassLoader.f" Virus. Action Taken: File Deleted.
    File C:\Documents and Settings\kimmo\.jpi_cache\file\1.0\Dummy.class-196cc484-50762d36.class infected by "Trojan.Java.ClassLoader.Dummy.d" Virus. Action Taken: File Deleted.
    File C:\Documents and Settings\kimmo\.jpi_cache\file\1.0\Dummy.class-25a9d7e-12d5fb65.class infected by "Trojan.Java.ClassLoader.Dummy.d" Virus. Action Taken: File Deleted.
    File C:\Documents and Settings\kimmo\.jpi_cache\file\1.0\Dummy.class-3c66b782-423d40b7.class infected by "Trojan.Java.ClassLoader.Dummy.d" Virus. Action Taken: File Deleted.
    File C:\Documents and Settings\kimmo\.jpi_cache\file\1.0\Dummy.class-4af8e275-612319ce.class infected by "Trojan.Java.ClassLoader.Dummy.d" Virus. Action Taken: File Deleted.
    File C:\Documents and Settings\kimmo\.jpi_cache\file\1.0\Dummy.class-4ffef27c-218989eb.class infected by "Trojan.Java.ClassLoader.Dummy.d" Virus. Action Taken: File Deleted.
    File C:\Documents and Settings\kimmo\.jpi_cache\file\1.0\GetAccess.class-6dcbe320-21acd481.class infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
    File C:\Documents and Settings\kimmo\.jpi_cache\file\1.0\VerifierBug.class-1ed8d498-662c1ddc.class infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
    File C:\Documents and Settings\kimmo\.jpi_cache\file\1.0\VerifierBug.class-3a2d981a-3965efdf.class infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
    File C:\Documents and Settings\kimmo\.jpi_cache\file\1.0\VerifierBug.class-42ffba92-3bb8dcca.class infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
    File C:\Documents and Settings\kimmo\.jpi_cache\file\1.0\VerifierBug.class-682f4d94-49b3c558.class infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
    File C:\Documents and Settings\kimmo\.jpi_cache\file\1.0\VerifierBug.class-742dbd4b-484ab7b3.class infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
    File C:\Program Files\mIRC\mirc.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.616. No Action Taken.
    File C:\System Volume Information\_restore{19D1C78F-CA02-47E7-9A02-46531B60F279}\RP200\A0042616.exe infected by "Trojan.BAT.Favadd.a" Virus. Action Taken: File Deleted.
    File D:\asennus-ohjelmat\cleanerit\Ad-aware® Se Professional Edition Ver 1.06r1_retail + cz\Ceština.awl infected by "BkCln.Unknown" Virus. Action Taken: File Renamed.
    File D:\asennus-ohjelmat\mirc\mIRC.6.16+KEYGEN-ACME\mIRC 6.16.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.616. No Action Taken.
    File D:\asennus-ohjelmat\mirc\mIRC_6.16.rar tagged as not-a-virus:Client-IRC.Win32.mIRC.616. No Action Taken.
    File D:\asennus-ohjelmat\mirc616.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.616. No Action Taken.

     
  6. -kemisti-

    -kemisti- Active member

    Liittynyt:
    06.06.2005
    Viestejä:
    6,305
    Kiitokset:
    0
    Pisteet:
    96
    Kaikki, missä lukee "file deleted" on poistettu.

    Näistä ei kannata välittää:

    File C:\Program Files\mIRC\mirc.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.616. No Action Taken.
    File D:\asennus-ohjelmat\mirc\mIRC.6.16+KEYGEN-ACME\mIRC 6.16.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.616. No Action Taken.
    File D:\asennus-ohjelmat\mirc\mIRC_6.16.rar tagged as not-a-virus:Client-IRC.Win32.mIRC.616. No Action Taken.
    File D:\asennus-ohjelmat\mirc616.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.616. No Action Taken.

    Nuo missä lukee "file renamed" (eli javaörkit) saat pois kun menet Ohjauspaneeli -> Java -> Temporary Internet Files -> Delete Files...
     
  7. kammo

    kammo Member

    Liittynyt:
    24.10.2005
    Viestejä:
    6
    Kiitokset:
    0
    Pisteet:
    11
    Ei ole tuo eScanin käyttö auttanut. Kone jökkää vieläkin kun laittaa nettipiuhan kiinni.
     
  8. -kemisti-

    -kemisti- Active member

    Liittynyt:
    06.06.2005
    Viestejä:
    6,305
    Kiitokset:
    0
    Pisteet:
    96
  9. kammo

    kammo Member

    Liittynyt:
    24.10.2005
    Viestejä:
    6
    Kiitokset:
    0
    Pisteet:
    11
    jaa-a kyllä toi kone vielä jumittuu, mut tässä ewidon raportti.


    ÿþ- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    e w i d o s e c u r i t y s u i t e - S c a n r e p o r t

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -



    + C r e a t e d o n : 2 2 : 5 1 : 2 2 , 2 6 . 1 0 . 2 0 0 5

    + R e p o r t - C h e c k s u m : F 2 D 3 7 9 8 A



    + S c a n r e s u l t :



    C : \ D o c u m e n t s a n d S e t t i n g s \ k i m m o \ . j p i _ c a c h e \ f i l e \ 1 . 0 \ V e r i f i e r B u g . c l a s s - 1 e d 8 d 4 9 8 - 6 6 2 c 1 d d c . c l a s s . m w t - > T r o j a n . B y t e v e r i f y : C l e a n e d w i t h b a c k u p

    C : \ D o c u m e n t s a n d S e t t i n g s \ k i m m o \ . j p i _ c a c h e \ f i l e \ 1 . 0 \ V e r i f i e r B u g . c l a s s - 3 a 2 d 9 8 1 a - 3 9 6 5 e f d f . c l a s s . m w t - > T r o j a n . B y t e v e r i f y : C l e a n e d w i t h b a c k u p

    C : \ D o c u m e n t s a n d S e t t i n g s \ k i m m o \ . j p i _ c a c h e \ f i l e \ 1 . 0 \ V e r i f i e r B u g . c l a s s - 4 2 f f b a 9 2 - 3 b b 8 d c c a . c l a s s . m w t - > T r o j a n . B y t e v e r i f y : C l e a n e d w i t h b a c k u p

    C : \ D o c u m e n t s a n d S e t t i n g s \ k i m m o \ . j p i _ c a c h e \ f i l e \ 1 . 0 \ V e r i f i e r B u g . c l a s s - 6 8 2 f 4 d 9 4 - 4 9 b 3 c 5 5 8 . c l a s s . m w t - > T r o j a n . B y t e v e r i f y : C l e a n e d w i t h b a c k u p

    C : \ D o c u m e n t s a n d S e t t i n g s \ k i m m o \ . j p i _ c a c h e \ f i l e \ 1 . 0 \ V e r i f i e r B u g . c l a s s - 7 4 2 d b d 4 b - 4 8 4 a b 7 b 3 . c l a s s . m w t - > T r o j a n . B y t e v e r i f y : C l e a n e d w i t h b a c k u p

    : m o z i l l a . 3 1 : C : \ D o c u m e n t s a n d S e t t i n g s \ k i m m o \ A p p l i c a t i o n D a t a \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ b 4 m 5 3 m c 0 . d e f a u l t \ c o o k i e s . t x t - > S p y w a r e . C o o k i e . D o u b l e c l i c k : C l e a n e d w i t h b a c k u p

    : m o z i l l a . 3 2 : C : \ D o c u m e n t s a n d S e t t i n g s \ k i m m o \ A p p l i c a t i o n D a t a \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ b 4 m 5 3 m c 0 . d e f a u l t \ c o o k i e s . t x t - > S p y w a r e . C o o k i e . R e v e n u e : C l e a n e d w i t h b a c k u p

    : m o z i l l a . 3 4 : C : \ D o c u m e n t s a n d S e t t i n g s \ k i m m o \ A p p l i c a t i o n D a t a \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ b 4 m 5 3 m c 0 . d e f a u l t \ c o o k i e s . t x t - > S p y w a r e . C o o k i e . B u r s t n e t : C l e a n e d w i t h b a c k u p

    : m o z i l l a . 3 5 : C : \ D o c u m e n t s a n d S e t t i n g s \ k i m m o \ A p p l i c a t i o n D a t a \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ b 4 m 5 3 m c 0 . d e f a u l t \ c o o k i e s . t x t - > S p y w a r e . C o o k i e . B u r s t n e t : C l e a n e d w i t h b a c k u p

    : m o z i l l a . 3 6 : C : \ D o c u m e n t s a n d S e t t i n g s \ k i m m o \ A p p l i c a t i o n D a t a \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ b 4 m 5 3 m c 0 . d e f a u l t \ c o o k i e s . t x t - > S p y w a r e . C o o k i e . T r i b a l f u s i o n : C l e a n e d w i t h b a c k u p

    : m o z i l l a . 3 7 : C : \ D o c u m e n t s a n d S e t t i n g s \ k i m m o \ A p p l i c a t i o n D a t a \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ b 4 m 5 3 m c 0 . d e f a u l t \ c o o k i e s . t x t - > S p y w a r e . C o o k i e . F a l k a g : C l e a n e d w i t h b a c k u p

    : m o z i l l a . 3 9 : C : \ D o c u m e n t s a n d S e t t i n g s \ k i m m o \ A p p l i c a t i o n D a t a \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ b 4 m 5 3 m c 0 . d e f a u l t \ c o o k i e s . t x t - > S p y w a r e . C o o k i e . T r a f i c : C l e a n e d w i t h b a c k u p

    : m o z i l l a . 4 0 : C : \ D o c u m e n t s a n d S e t t i n g s \ k i m m o \ A p p l i c a t i o n D a t a \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ b 4 m 5 3 m c 0 . d e f a u l t \ c o o k i e s . t x t - > S p y w a r e . C o o k i e . C a s a l e m e d i a : C l e a n e d w i t h b a c k u p

    : m o z i l l a . 4 9 : C : \ D o c u m e n t s a n d S e t t i n g s \ k i m m o \ A p p l i c a t i o n D a t a \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ b 4 m 5 3 m c 0 . d e f a u l t \ c o o k i e s . t x t - > S p y w a r e . C o o k i e . A t d m t : C l e a n e d w i t h b a c k u p

    : m o z i l l a . 6 : C : \ D o c u m e n t s a n d S e t t i n g s \ p e t r i \ A p p l i c a t i o n D a t a \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ r 3 s 4 k y 9 r . d e f a u l t \ c o o k i e s . t x t - > S p y w a r e . C o o k i e . D o u b l e c l i c k : C l e a n e d w i t h b a c k u p

    : m o z i l l a . 7 : C : \ D o c u m e n t s a n d S e t t i n g s \ p e t r i \ A p p l i c a t i o n D a t a \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ r 3 s 4 k y 9 r . d e f a u l t \ c o o k i e s . t x t - > S p y w a r e . C o o k i e . A d t e c h : C l e a n e d w i t h b a c k u p

    : m o z i l l a . 8 : C : \ D o c u m e n t s a n d S e t t i n g s \ p e t r i \ A p p l i c a t i o n D a t a \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ r 3 s 4 k y 9 r . d e f a u l t \ c o o k i e s . t x t - > S p y w a r e . C o o k i e . A d t e c h : C l e a n e d w i t h b a c k u p

    : m o z i l l a . 1 5 : C : \ D o c u m e n t s a n d S e t t i n g s \ p e t r i \ A p p l i c a t i o n D a t a \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ r 3 s 4 k y 9 r . d e f a u l t \ c o o k i e s . t x t - > S p y w a r e . C o o k i e . T r a d e d o u b l e r : C l e a n e d w i t h b a c k u p

    : m o z i l l a . 1 6 : C : \ D o c u m e n t s a n d S e t t i n g s \ p e t r i \ A p p l i c a t i o n D a t a \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ r 3 s 4 k y 9 r . d e f a u l t \ c o o k i e s . t x t - > S p y w a r e . C o o k i e . T r a d e d o u b l e r : C l e a n e d w i t h b a c k u p

    : m o z i l l a . 1 9 : C : \ D o c u m e n t s a n d S e t t i n g s \ p e t r i \ A p p l i c a t i o n D a t a \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ r 3 s 4 k y 9 r . d e f a u l t \ c o o k i e s . t x t - > S p y w a r e . C o o k i e . A d v e r t i s i n g : C l e a n e d w i t h b a c k u p

    : m o z i l l a . 2 2 : C : \ D o c u m e n t s a n d S e t t i n g s \ p e t r i \ A p p l i c a t i o n D a t a \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ r 3 s 4 k y 9 r . d e f a u l t \ c o o k i e s . t x t - > S p y w a r e . C o o k i e . A d v e r t i s i n g : C l e a n e d w i t h b a c k u p

    : m o z i l l a . 2 3 : C : \ D o c u m e n t s a n d S e t t i n g s \ p e t r i \ A p p l i c a t i o n D a t a \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ r 3 s 4 k y 9 r . d e f a u l t \ c o o k i e s . t x t - > S p y w a r e . C o o k i e . A d v e r t i s i n g : C l e a n e d w i t h b a c k u p

    : m o z i l l a . 2 4 : C : \ D o c u m e n t s a n d S e t t i n g s \ p e t r i \ A p p l i c a t i o n D a t a \ M o z i l l a \ F i r e f o x \ P r o f i l e s \ r 3 s 4 k y 9 r . d e f a u l t \ c o o k i e s . t x t - > S p y w a r e . C o o k i e . A d v e r t i s i n g : C l e a n e d w i t h b a c k u p

    D : \ a s e n n u s - o h j e l m a t \ p o l t t o - o h j e l m a t \ v i s i o n p l u g i t \ A h e a d N e r o 6 . 3 E x t r a P a c k - P l u g I n C o d e c A d d O n . z i p / T o o l s / A h e a d . N e r o . B u r n i n g . R O M . v 6 . 3 . 0 . 0 . U l t r a . E d i t i o n . N e w . F I X E D . K e y g e n . O n l y - O R I O N . z i p / K e y g e n . e x e - > S p y w a r e . H i j a c k e r . G e n e r i c : E r r o r d u r i n g c l e a n i n g

    D : \ a s e n n u s - o h j e l m a t \ p o l t t o - o h j e l m a t \ v i s i o n p l u g i t \ N e r o P l u g - I n s A u d i o I V i d e o - E n c o d e r s D e c o d e r s ( D v d ( V i s i o n E x p r e s s ) - M p e g 2 - A c 3 - E t c ) . r a r / A h e a d N e r o 6 . 3 E x t r a P a c k - P l u g I n C o d e c A d d O n . z i p / T o o l s / A h e a d . N e r o . B u r n i n g . R O M . v 6 . 3 . 0 . 0 . U l t r a . E d i t i o n . N e w . F I X E D . K e y g e n . O n l y - O R I O N . z i p / K e y g e n . e x e - > S p y w a r e . H i j a c k e r . G e n e r i c : E r r o r d u r i n g c l e a n i n g





    : : R e p o r t E n d
     
  10. -kemisti-

    -kemisti- Active member

    Liittynyt:
    06.06.2005
    Viestejä:
    6,305
    Kiitokset:
    0
    Pisteet:
    96
    Laitapa vielä startuplista HjT:stä: Open misc tools -> generate startuplist ja rastit niihin kahteen ruutuun.
     
  11. kammo

    kammo Member

    Liittynyt:
    24.10.2005
    Viestejä:
    6
    Kiitokset:
    0
    Pisteet:
    11
    Otin palomuurin käytöstä ja netti rupes pelittää, eli f-secure jumitti ja asensin sen uusiks, sillä noin 3-viikkoa sitten oli sellainen nopea sähkökatkos ja sen jälkeen alkoi pikkuhiljaa ilmetä tämä ongelma, että olisikohan se voinut sotkea ton muurin jotenkin?,mut tässä toi lista jos siit jotain selvii ja KIITOKSET KEMISTILLE noista fiksauksista.


    StartupList report, 31.10.2005, 13:35:19
    StartupList version: 1.52.2
    Started from : C:\HJT\HijackThis.EXE
    Detected: Windows XP SP2 (WinNT 5.01.2600)
    Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    * Using default options
    * Including empty and uninteresting sections
    * Showing rarely important sections
    ==================================================

    Running processes:

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
    C:\Program Files\ewido\security suite\ewidoctrl.exe
    C:\Program Files\ewido\security suite\ewidoguard.exe
    C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
    C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
    C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
    C:\Program Files\F-Secure\Common\FSMA32.EXE
    C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
    C:\Program Files\F-Secure\Common\FSMB32.EXE
    C:\Program Files\F-Secure\Common\FCH32.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\F-Secure\Common\FAMEH32.EXE
    C:\Program Files\F-Secure\Common\FNRB32.EXE
    C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    C:\Program Files\F-Secure\Common\FIH32.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
    C:\Program Files\DU Meter\DUMeter.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    E:\Asennettuja OHJELMIA\power dvd\PDVDServ.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    C:\Program Files\F-Secure\Common\FSM32.EXE
    C:\Program Files\F-Secure\FSGUI\fsguiexe.exe
    C:\Program Files\F-Secure\BackWeb\7681197\Program\F-Secure Automatic Update.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\HJT\HijackThis.exe

    --------------------------------------------------

    Listing of startup folders:

    Shell folders Startup:
    [C:\Documents and Settings\kimmo\Käynnistä-valikko\Ohjelmat\Käynnistys]
    *No files*

    Shell folders AltStartup:
    *Folder not found*

    User shell folders Startup:
    *Folder not found*

    User shell folders AltStartup:
    *Folder not found*

    Shell folders Common Startup:
    [C:\Documents and Settings\All Users\Käynnistä-valikko\Ohjelmat\Käynnistys]
    ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe

    Shell folders Common AltStartup:
    *Folder not found*

    User shell folders Common Startup:
    *Folder not found*

    User shell folders Alternate Common Startup:
    *Folder not found*

    --------------------------------------------------

    Checking Windows NT UserInit:

    [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    UserInit = C:\WINDOWS\system32\userinit.exe,

    [HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
    *Registry key not found*

    [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    *Registry value not found*

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
    *Registry key not found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    NVMixerTray = "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
    NeroFilterCheck = C:\WINDOWS\system32\NeroCheck.exe
    HP Component Manager = "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    HPDJ Taskbar Utility = C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
    ATIPTA = C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    DU Meter = C:\Program Files\DU Meter\DUMeter.exe
    ISUSPM Startup = C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    ISUSScheduler = "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    RemoteControl = "E:\Asennettuja OHJELMIA\power dvd\PDVDServ.exe"
    ATICCC = "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
    dla = C:\WINDOWS\system32\dla\tfswctrl.exe
    MessengerPlus3 = "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    HP Software Update = C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    F-Secure Manager = "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
    F-Secure TNB = "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
    CTRegRun = C:\WINDOWS\CTRegRun.EXE
    TkBellExe = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

    *No values found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

    *No values found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

    *No values found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

    *No values found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    CTFMON.EXE = C:\WINDOWS\system32\ctfmon.exe
    MSMSGS = "C:\Program Files\Messenger\msmsgs.exe" /background
    Window Washer = C:\Program Files\Webroot\Washer\wwDisp.exe

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

    *No values found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

    *No values found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

    *No values found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

    *No values found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

    *Registry key not found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

    *Registry key not found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    [OptionalComponents]
    *No values found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
    *No subkeys found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
    *No subkeys found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
    *No subkeys found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
    *No subkeys found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    *No subkeys found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
    *No subkeys found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
    *No subkeys found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
    *No subkeys found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
    *No subkeys found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
    *Registry key not found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
    *Registry key not found*

    --------------------------------------------------

    File association entry for .EXE:
    HKEY_CLASSES_ROOT\exefile\shell\open\command

    (Default) = "%1" %*

    --------------------------------------------------

    File association entry for .COM:
    HKEY_CLASSES_ROOT\comfile\shell\open\command

    (Default) = "%1" %*

    --------------------------------------------------

    File association entry for .BAT:
    HKEY_CLASSES_ROOT\batfile\shell\open\command

    (Default) = "%1" %*

    --------------------------------------------------

    File association entry for .PIF:
    HKEY_CLASSES_ROOT\piffile\shell\open\command

    (Default) = "%1" %*

    --------------------------------------------------

    File association entry for .SCR:
    HKEY_CLASSES_ROOT\scrfile\shell\open\command

    (Default) = "%1" /S

    --------------------------------------------------

    File association entry for .HTA:
    HKEY_CLASSES_ROOT\htafile\shell\open\command

    (Default) = C:\WINDOWS\system32\mshta.exe "%1" %*

    --------------------------------------------------

    File association entry for .TXT:
    HKEY_CLASSES_ROOT\txtfile\shell\open\command

    (Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

    --------------------------------------------------

    Enumerating Active Setup stub paths:
    HKLM\Software\Microsoft\Active Setup\Installed Components
    (* = disabled by HKCU twin)

    [>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
    StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

    [>{26923b43-4d38-484f-9b9e-de460746276c}] *
    StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE

    [>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
    StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

    [>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
    StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

    [{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
    StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

    [{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
    StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

    [{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
    StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

    [{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
    StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser

    [{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
    StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub

    [{7790769C-0471-11d2-AF11-00C04FA35D02}] *
    StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

    [{89820200-ECBD-11cf-8B85-00AA005B4340}] *
    StubPath = regsvr32.exe /s /n /i:U shell32.dll

    [{89820200-ECBD-11cf-8B85-00AA005B4383}] *
    StubPath = %SystemRoot%\system32\ie4uinit.exe

    [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
    StubPath = C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install

    --------------------------------------------------

    Enumerating ICQ Agent Autostart apps:
    HKCU\Software\Mirabilis\ICQ\Agent\Apps

    *Registry key not found*

    --------------------------------------------------

    Load/Run keys from C:\WINDOWS\WIN.INI:

    load=*INI section not found*
    run=*INI section not found*

    Load/Run keys from Registry:

    HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
    HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
    HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
    HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
    HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
    HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
    HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
    HKCU\..\Windows NT\CurrentVersion\Windows: load=
    HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=MsgPlusLoader.dll

    --------------------------------------------------

    Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

    Shell=*INI section not found*
    SCRNSAVE.EXE=*INI section not found*
    drivers=*INI section not found*

    Shell & screensaver key from Registry:

    Shell=Explorer.exe
    SCRNSAVE.EXE=*Registry value not found*
    drivers=*Registry value not found*

    Policies Shell key:

    HKCU\..\Policies: Shell=*Registry key not found*
    HKLM\..\Policies: Shell=*Registry value not found*

    --------------------------------------------------

    Checking for EXPLORER.EXE instances:

    C:\WINDOWS\Explorer.exe: PRESENT!

    C:\Explorer.exe: not present
    C:\WINDOWS\Explorer\Explorer.exe: not present
    C:\WINDOWS\System\Explorer.exe: not present
    C:\WINDOWS\System32\Explorer.exe: not present
    C:\WINDOWS\Command\Explorer.exe: not present
    C:\WINDOWS\Fonts\Explorer.exe: not present

    --------------------------------------------------

    Checking for superhidden extensions:

    .lnk: HIDDEN! (arrow overlay: yes)
    .pif: HIDDEN! (arrow overlay: yes)
    .exe: not hidden
    .com: not hidden
    .bat: not hidden
    .hta: not hidden
    .scr: not hidden
    .shs: HIDDEN!
    .shb: HIDDEN!
    .vbs: not hidden
    .vbe: not hidden
    .wsh: not hidden
    .scf: HIDDEN! (arrow overlay: NO!)
    .url: HIDDEN! (arrow overlay: yes)
    .js: not hidden
    .jse: not hidden

    --------------------------------------------------

    Verifying REGEDIT.EXE integrity:

    - Regedit.exe found in C:\WINDOWS
    - .reg open command is normal (regedit.exe %1)
    - Regedit.exe has no CompanyName property! It is either missing or named something else.
    - Regedit.exe has no OriginalFilename property! It is either missing or named something else.
    - Regedit.exe has no FileDescription property! It is either missing or named something else.

    Registry check failed!

    --------------------------------------------------

    Enumerating Browser Helper Objects:

    (no name) - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
    (no name) - C:\WINDOWS\system32\dla\tfswshx.dll - {5CA3D70E-1895-11CF-8E15-001234567890}
    (no name) - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll - {9394EDE7-C8B5-483E-8773-474BF36AF6E4}
    (no name) - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}

    --------------------------------------------------

    Enumerating Task Scheduler jobs:

    *No jobs found*

    --------------------------------------------------

    Enumerating Download Program Files:

    [Windows Genuine Advantage Validation Tool]
    InProcServer32 = C:\WINDOWS\system32\LegitCheckControl.DLL
    CODEBASE = http://go.microsoft.com/fwlink/?linkid=39204

    [Java Plug-in 1.4.1_06]
    InProcServer32 = C:\Program Files\Java\j2re1.4.1_06\bin\npjpi141_06.dll
    CODEBASE = http://java.sun.com/products/plugin/1.4/jinstall-14_06-windows-i586.cab

    [MsnMessengerSetupDownloadControl Class]
    InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.ocx
    CODEBASE = http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab

    [Java Plug-in 1.4.1_06]
    InProcServer32 = C:\Program Files\Java\j2re1.4.1_06\bin\npjpi141_06.dll
    CODEBASE = http://java.sun.com/products/plugin/1.4/jinstall-14_06-windows-i586.cab

    [Shockwave Flash Object]
    InProcServer32 = C:\WINDOWS\system32\macromed\flash\Flash.ocx
    CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    --------------------------------------------------

    Enumerating Winsock LSP files:

    NameSpace #1: C:\WINDOWS\System32\mswsock.dll
    NameSpace #2: C:\WINDOWS\System32\winrnr.dll
    NameSpace #3: C:\WINDOWS\System32\mswsock.dll
    Protocol #1: C:\WINDOWS\system32\mswsock.dll
    Protocol #2: C:\WINDOWS\system32\mswsock.dll
    Protocol #3: C:\WINDOWS\system32\mswsock.dll
    Protocol #4: C:\WINDOWS\system32\rsvpsp.dll
    Protocol #5: C:\WINDOWS\system32\rsvpsp.dll
    Protocol #6: C:\WINDOWS\system32\mswsock.dll
    Protocol #7: C:\WINDOWS\system32\mswsock.dll
    Protocol #8: C:\WINDOWS\system32\mswsock.dll
    Protocol #9: C:\WINDOWS\system32\mswsock.dll
    Protocol #10: C:\WINDOWS\system32\mswsock.dll
    Protocol #11: C:\WINDOWS\system32\mswsock.dll
    Protocol #12: C:\WINDOWS\system32\mswsock.dll
    Protocol #13: C:\WINDOWS\system32\mswsock.dll
    Protocol #14: C:\WINDOWS\system32\mswsock.dll
    Protocol #15: C:\WINDOWS\system32\mswsock.dll

    --------------------------------------------------

    Enumerating Windows NT/2000/XP services

    61883 Unit Device: system32\DRIVERS\61883.sys (manual start)
    a347bus: system32\DRIVERS\a347bus.sys (system)
    a347scsi: System32\Drivers\a347scsi.sys (system)
    Microsoft ACPI Driver: system32\DRIVERS\ACPI.sys (system)
    Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
    AFD: \SystemRoot\System32\drivers\afd.sys (system)
    Hälytys: %SystemRoot%\system32\svchost.exe -k LocalService (disabled)
    Sovelluskerroksen yhdyskäytäväpalvelu: %SystemRoot%\System32\alg.exe (manual start)
    AMD K7 Processor Driver: system32\DRIVERS\amdk7.sys (system)
    AnyDVD: System32\Drivers\AnyDVD.sys (manual start)
    Sovellusten hallinta: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
    1394 ARP -asiakasprotokolla: system32\DRIVERS\arp1394.sys (manual start)
    ASP.NET-tilapalvelu: %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (manual start)
    RAS Asynchronous Media Driver: system32\DRIVERS\asyncmac.sys (manual start)
    Standardi IDE/ESDI-kiintolevyohjain: system32\DRIVERS\atapi.sys (system)
    Ati HotKey Poller: %SystemRoot%\system32\Ati2evxx.exe (autostart)
    ATI Smart: C:\WINDOWS\system32\ati2sgag.exe (autostart)
    ati2mtag: system32\DRIVERS\ati2mtag.sys (manual start)
    ATM ARP Client -protokolla: system32\DRIVERS\atmarpc.sys (manual start)
    Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Audio Stub Driver: system32\DRIVERS\audstub.sys (manual start)
    AVC-laite: system32\DRIVERS\avc.sys (manual start)
    F-Secure Automatic Update: C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE (autostart)
    BITS-tausta-ajo (Background Intelligent Transfer Service): %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    Tietokoneiden selaus: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    Closed Caption Decoder: system32\DRIVERS\CCDECODE.sys (manual start)
    CD-ROM-ohjain: system32\DRIVERS\cdrom.sys (system)
    Indeksointipalvelu: %SystemRoot%\system32\cisvc.exe (manual start)
    Leikekirja: %SystemRoot%\system32\clipsrv.exe (disabled)
    COM+-järjestelmäsovellus: C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
    Salauspalvelut: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    d346bus: system32\DRIVERS\d346bus.sys (system)
    d346prt: System32\Drivers\d346prt.sys (system)
    DCOM-palvelinprosessin käynnistys: %SystemRoot%\system32\svchost -k DcomLaunch (autostart)
    DHCP-asiakas: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    Levyohjain: system32\DRIVERS\disk.sys (system)
    Loogisen levyn hallinnan valvontapalvelu: %SystemRoot%\System32\dmadmin.exe /com (manual start)
    dmboot: System32\drivers\dmboot.sys (disabled)
    Loogisen levyn hallinta -ohjain: System32\drivers\dmio.sys (system)
    dmload: System32\drivers\dmload.sys (system)
    Loogisen levyn hallinta: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
    DNS-asiakas: %SystemRoot%\system32\svchost.exe -k NetworkService (autostart)
    Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
    drvmcdb: system32\DRIVERS\drvmcdb.sys (system)
    drvnddm: system32\drivers\drvnddm.sys (autostart)
    ElbyCDIO Driver: System32\Drivers\ElbyCDIO.sys (autostart)
    Virheraportointipalvelut: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Tapahtumaloki: %SystemRoot%\system32\services.exe (autostart)
    COM+-tapahtumajärjestelmä: C:\WINDOWS\system32\svchost.exe -k netsvcs (manual start)
    ewido security suite control: C:\Program Files\ewido\security suite\ewidoctrl.exe (autostart)
    ewido security suite driver: \??\C:\Program Files\ewido\security suite\guard.sys (system)
    ewido security suite guard: C:\Program Files\ewido\security suite\ewidoguard.exe (autostart)
    F-Secure File System Filter: \??\C:\Program Files\F-Secure\Anti-Virus\Win2K\FSfilter.sys (autostart)
    F-Secure Gatekeeper: \??\C:\Program Files\F-Secure\Anti-Virus\Win2K\FSgk.sys (autostart)
    F-Secure Gatekeeper Handler Starter: "C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe" (autostart)
    F-Secure Network Request Broker: "C:\Program Files\F-Secure\Common\FNRB32.EXE" (manual start)
    F-Secure File System Recognizer: \??\C:\Program Files\F-Secure\Anti-Virus\Win2K\FSrec.sys (autostart)
    Nopean käyttäjän vaihdon yhteensopivuus: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    Levykeaseman ohjain: system32\DRIVERS\fdc.sys (manual start)
    FltMgr: system32\DRIVERS\fltMgr.sys (system)
    fsbwsys: "C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe" (autostart)
    F-Secure Anti-Virus Firewall Daemon: "C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe" (manual start)
    F-Secure Firewall Driver: System32\drivers\fsdfw.sys (system)
    F-Secure Management Agent: "C:\Program Files\F-Secure\Common\FSMA32.EXE" (autostart)
    Volume Manager -ohjain: system32\DRIVERS\ftdisk.sys (system)
    Game Port Enumerator: system32\DRIVERS\gameenum.sys (manual start)
    Yleinen paketinmääritys: system32\DRIVERS\msgpc.sys (manual start)
    Ohjeet ja tuotetuki: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    HID (Human Interface Device) -liittymä: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
    Microsoft HID -luokkaohjain: system32\DRIVERS\hidusb.sys (manual start)
    HTTP: System32\Drivers\HTTP.sys (manual start)
    HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start)
    i8042-näppäimistö ja PS/2-hiiriohjain: system32\DRIVERS\i8042prt.sys (system)
    InstallDriver Table Manager: "C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe" (manual start)
    CD-Burning Filter Driver: system32\DRIVERS\imapi.sys (system)
    CD-levyjen kirjoittamisen IMAPI COM -palvelu: C:\WINDOWS\system32\imapi.exe (manual start)
    Windowsin IPv6-palomuurin ohjain: system32\DRIVERS\Ip6Fw.sys (manual start)
    IP Traffic Filter Driver: system32\DRIVERS\ipfltdrv.sys (manual start)
    IP in IP Tunnel Driver: system32\DRIVERS\ipinip.sys (manual start)
    IP Network Address Translator: system32\DRIVERS\ipnat.sys (manual start)
    IPSEC-ohjain: system32\DRIVERS\ipsec.sys (system)
    IR Enumerator Service: system32\DRIVERS\irenum.sys (manual start)
    PnP ISA/EISA -väyläohjain: system32\DRIVERS\isapnp.sys (system)
    Näppäimistön luokkaohjain: system32\DRIVERS\kbdclass.sys (system)
    Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
    Palvelin: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    Työasema: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    TCP/IP NetBIOS Helper: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
    Pinnacle Marvin Bus: system32\DRIVERS\MarvinBus.sys (manual start)
    Viestinvälitys: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
    NetMeeting etätyöpöydän jakaminen: C:\WINDOWS\system32\mnmsrvc.exe (manual start)
    Hiiren luokkaohjain: system32\DRIVERS\mouclass.sys (system)
    WebDav Client Redirector: system32\DRIVERS\mrxdav.sys (manual start)
    MRXSMB: system32\DRIVERS\mrxsmb.sys (system)
    Distributed Transaction Coordinator: C:\WINDOWS\system32\msdtc.exe (manual start)
    Microsoft DV Camera and VCR: system32\DRIVERS\msdv.sys (manual start)
    Windows Installer -ohjelma: C:\WINDOWS\system32\msiexec.exe /V (manual start)
    Microsoft Streaming Service -välityspalvelin: system32\drivers\MSKSSRV.sys (manual start)
    Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
    Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
    Microsoft-järjestelmänhallinnan BIOS-ohjain: system32\DRIVERS\mssmbios.sys (manual start)
    MSSQL$SONY_MEDIAMGR: C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe -sSONY_MEDIAMGR (autostart)
    MSSQLServerADHelper: C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe (manual start)
    Microsoft Streaming Tee/Sink-to-Sink -muunnin: system32\drivers\MSTEE.sys (manual start)
    Microsoft MPU-401 MIDI UART Driver: system32\drivers\msmpu401.sys (manual start)
    NABTS/FEC VBI Codec: system32\DRIVERS\NABTSFEC.sys (manual start)
    Microsoft TV/Video Connection: system32\DRIVERS\NdisIP.sys (manual start)
    Remote Access NDIS TAPI Driver: system32\DRIVERS\ndistapi.sys (manual start)
    NDIS Usermode I/O -protokolla: system32\DRIVERS\ndisuio.sys (manual start)
    Remote Access NDIS WAN Driver: system32\DRIVERS\ndiswan.sys (manual start)
    NetBIOS-käyttöliittymä: system32\DRIVERS\netbios.sys (system)
    NetBIOS TCP/IP:n päällä: system32\DRIVERS\netbt.sys (system)
    Verkon DDE: %SystemRoot%\system32\netdde.exe (disabled)
    Verkon DDE DSDM: %SystemRoot%\system32\netdde.exe (disabled)
    Verkkokirjautuminen: %SystemRoot%\system32\lsass.exe (manual start)
    Verkkoyhteydet: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    1394-verkko-ohjain: system32\DRIVERS\nic1394.sys (manual start)
    NLA-nimiavaruus (Network Location Awareness): %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
    NT LM -suojaustuen toimittaja: %SystemRoot%\system32\lsass.exe (manual start)
    Siirrettävät tallennusvälineet: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
    nvatabus: system32\DRIVERS\nvatabus.sys (system)
    Service for NVIDIA(R) nForce(TM) Audio Enumerator: system32\drivers\nvax.sys (manual start)
    NVIDIA nForce Networking Controller Driver: system32\DRIVERS\NVENET.sys (manual start)
    Service for NVIDIA(R) nForce(TM) Audio: system32\drivers\nvapu.sys (manual start)
    NVIDIA nForce AGP Bus Filter: system32\DRIVERS\nv_agp.sys (system)
    IPX Traffic Filter Driver: system32\DRIVERS\nwlnkflt.sys (manual start)
    IPX Traffic Forwarder Driver: system32\DRIVERS\nwlnkfwd.sys (manual start)
    OHCI Compliant IEEE 1394 Host Controller: system32\DRIVERS\ohci1394.sys (system)
    Office Source Engine: "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" (manual start)
    Creative WebCam NX: system32\DRIVERS\P1110VID.sys (manual start)
    Rinnakkaisporttiohjain: system32\DRIVERS\parport.sys (manual start)
    PCI Bus Driver: system32\DRIVERS\pci.sys (system)
    PCIIde: system32\DRIVERS\pciide.sys (system)
    PCLEPCI: \??\C:\WINDOWS\system32\drivers\pclepci.sys (system)
    Plug and Play: %SystemRoot%\system32\services.exe (autostart)
    IPSEC-palvelut: %SystemRoot%\system32\lsass.exe (autostart)
    WAN Miniport (PPTP): system32\DRIVERS\raspptp.sys (manual start)
    Suojattu tallennuspaikka: %SystemRoot%\system32\lsass.exe (autostart)
    QoS-paketinajoitus: system32\DRIVERS\psched.sys (manual start)
    Direct Parallel Link Driver: system32\DRIVERS\ptilink.sys (manual start)
    PxHelp20: System32\Drivers\PxHelp20.sys (system)
    Casio Digital Camera: system32\DRIVERS\qv2kux.sys (manual start)
    Remote Access Auto Connection -ohjain: system32\DRIVERS\rasacd.sys (system)
    Remote Access Auto Connection -hallinta: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
    WAN Miniport (L2TP): system32\DRIVERS\rasl2tp.sys (manual start)
    Etäkäytön (RAS) yhteyksienhallinta: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
    Remote Access PPPOE Driver: system32\DRIVERS\raspppoe.sys (manual start)
    Suora rinnakkainen: system32\DRIVERS\raspti.sys (manual start)
    Rdbss: system32\DRIVERS\rdbss.sys (system)
    RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
    Terminal Server Device Redirector -ohjain: system32\DRIVERS\rdpdr.sys (manual start)
    Etätyöpöydän ohjeen istunnonhallinta: C:\WINDOWS\system32\sessmgr.exe (manual start)
    Digital CD Audio Playback Filter Driver: system32\DRIVERS\redbook.sys (system)
    Reititys ja etäkäyttö: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
    Etärekisteri: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
    Etäproseduurikutsujen (RPC) paikannin: %SystemRoot%\system32\locator.exe (manual start)
    Etäproseduurikutsu (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
    QoS RSVP: %SystemRoot%\system32\rsvp.exe (manual start)
    Käyttöoikeustilien hallinta: %SystemRoot%\system32\lsass.exe (autostart)
    Älykortti: %SystemRoot%\System32\SCardSvr.exe (manual start)
    Tehtävien ajoitus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Secdrv: system32\DRIVERS\secdrv.sys (autostart)
    Toissijainen kirjautuminen: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Järjestelmätapahtuman ilmoitus: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    Serenum Filter -ohjain: system32\DRIVERS\serenum.sys (manual start)
    Sarjaporttiohjain: system32\DRIVERS\serial.sys (system)
    Windowsin palomuuri / Internet-yhteyden jakaminen (ICS): %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    Käyttöliittymän laitteistotunnistus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    BDA Slip De-Framer: system32\DRIVERS\SLIP.sys (manual start)
    Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
    Taustatulostusohjain: %SystemRoot%\system32\spoolsv.exe (autostart)
    SQLAgent$SONY_MEDIAMGR: C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE -i SONY_MEDIAMGR (manual start)
    Järjestelmän palautussuodatin -ohjain: system32\DRIVERS\sr.sys (system)
    Järjestelmän palauttaminen -palvelu: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    Srv: system32\DRIVERS\srv.sys (manual start)
    sscdbhk5: system32\drivers\sscdbhk5.sys (system)
    SSDP-palvelu (Simple Service Discovery Protocol): %SystemRoot%\system32\svchost.exe -k LocalService (manual start)
    ssrtln: system32\drivers\ssrtln.sys (system)
    WIA (Windows Image Acquisition): %SystemRoot%\system32\svchost.exe -k imgsvc (autostart)
    BDA IPSink: system32\DRIVERS\StreamIP.sys (manual start)
    Ohjelmistoväyläohjain: system32\DRIVERS\swenum.sys (manual start)
    Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
    MS Software Shadow Copy Provider: C:\WINDOWS\system32\dllhost.exe /Processid:{A27A559A-1E09-4346-8DE5-9A63D3279389} (manual start)
    Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
    Resurssilokit ja -hälytykset: %SystemRoot%\system32\smlogsvc.exe (manual start)
    Puhelin: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    TCP/IP-protokollaohjain: system32\DRIVERS\tcpip.sys (system)
    Päätelaiteohjain: system32\DRIVERS\termdd.sys (system)
    Päätepalvelut: %SystemRoot%\System32\svchost -k DComLaunch (manual start)
    tfsnboio: system32\dla\tfsnboio.sys (autostart)
    tfsncofs: system32\dla\tfsncofs.sys (autostart)
    tfsndrct: system32\dla\tfsndrct.sys (autostart)
    tfsndres: system32\dla\tfsndres.sys (autostart)
    tfsnifs: system32\dla\tfsnifs.sys (autostart)
    tfsnopio: system32\dla\tfsnopio.sys (autostart)
    tfsnpool: system32\dla\tfsnpool.sys (autostart)
    tfsnudf: system32\dla\tfsnudf.sys (autostart)
    tfsnudfa: system32\dla\tfsnudfa.sys (autostart)
    Teemat: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Telnet: C:\WINDOWS\system32\tlntsvr.exe (disabled)
    Tiedostolinkkijäljityksen asiakas: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    Windows User Mode Driver Framework: C:\WINDOWS\system32\wdfmgr.exe (autostart)
    Microcode Update -ohjain: system32\DRIVERS\update.sys (manual start)
    Universal Plug & Play -laiteisäntä: %SystemRoot%\system32\svchost.exe -k LocalService (manual start)
    UPS: %SystemRoot%\System32\ups.exe (manual start)
    USB-ääniohjain (WDM): system32\drivers\usbaudio.sys (manual start)
    Microsoft USB Generic Parent Driver: system32\DRIVERS\usbccgp.sys (manual start)
    Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: system32\DRIVERS\usbehci.sys (manual start)
    USB2 Enabled Hub: system32\DRIVERS\usbhub.sys (manual start)
    Microsoft USB Open Host Controller Miniport Driver: system32\DRIVERS\usbohci.sys (manual start)
    Microsoft USB PRINTER -luokka: system32\DRIVERS\usbprint.sys (manual start)
    USB-massamuistiohjain: system32\DRIVERS\USBSTOR.SYS (manual start)
    VgaSave: \SystemRoot\System32\drivers\vga.sys (system)
    Aseman tilannevedos: %SystemRoot%\System32\vssvc.exe (manual start)
    Windows Time: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Remote Access IP ARP Driver: system32\DRIVERS\wanarp.sys (manual start)
    Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
    WebClient: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
    WMI-palvelu (Windows Management Instrumentation): %systemroot%\system32\svchost.exe -k netsvcs (autostart)
    Kannettavan mediasoittimen sarjanumeropalvelu: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    WMI-palvelun ohjainlaajennukset: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    WMI resurssisovitin: C:\WINDOWS\system32\wbem\wmiapsrv.exe (manual start)
    Tietoturvakeskus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    World Standard Teletext Codec: system32\DRIVERS\WSTCODEC.SYS (manual start)
    Automaattiset päivitykset: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
    Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Verkon käyttöönottopalvelu: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)


    --------------------------------------------------

    Enumerating Windows NT logon/logoff scripts:
    *No scripts set to run*

    Windows NT checkdisk command:
    BootExecute = autocheck autochk *

    Windows NT 'Wininit.ini':
    PendingFileRenameOperations: *Registry value not found*

    --------------------------------------------------

    Enumerating ShellServiceObjectDelayLoad items:

    PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
    CDBurn: C:\WINDOWS\system32\SHELL32.dll
    WebCheck: C:\WINDOWS\system32\webcheck.dll
    SysTray: C:\WINDOWS\system32\stobject.dll

    --------------------------------------------------
    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

    *Registry key not found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

    *Registry key not found*

    --------------------------------------------------

    End of report, 37 144 bytes
    Report generated in 0,188 seconds

    Command line options:
    /verbose - to add additional info on each section
    /complete - to include empty sections and unsuspicious data
    /full - to include several rarely-important sections
    /force9x - to include Win9x-only startups even if running on WinNT
    /forcent - to include WinNT-only startups even if running on Win9x
    /forceall - to include all Win9x and WinNT startups, regardless of platform
    /history - to list version history only
     
  12. -kemisti-

    -kemisti- Active member

    Liittynyt:
    06.06.2005
    Viestejä:
    6,305
    Kiitokset:
    0
    Pisteet:
    96
    Ei tossa mitään outoa näy. Onko siis vielä ongelmia?
     
  13. kammo

    kammo Member

    Liittynyt:
    24.10.2005
    Viestejä:
    6
    Kiitokset:
    0
    Pisteet:
    11
    Ongelma hävis ja kone toimii,kiitos.
     

Jaa tämä sivu