Hjt loki smartlinkservice pois!!

Viestiketju Virukset ja haittaohjelmat - HijackThis -logit -osiossa. Ketjun avasi FIN_Kla 03.10.2006.

Viestiketjun tila:
Viestiketju on suljettu.
  1. FIN_Kla

    FIN_Kla Guest

    Logfile of HijackThis v1.99.1
    Scan saved at 21:56:09, on 3.10.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\PROGRA~1\ELISAT~1\backweb\4119343\Program\SERVIC~1.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32st.exe
    C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\program\fsbwsys.exe
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\FSGK32.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMA32.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fssm32.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMB32.EXE
    C:\Program Files\Spyware Doctor\sdhelp.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Common\FCH32.EXE
    C:\WINDOWS\system32\slserv.exe
    C:\Program Files\Elisa Tietoturvapalvelu\Common\FAMEH32.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsrw.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE
    C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\ispnews.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\Program Files\Elisa Tietoturvapalvelu\FWES\Program\fsdfwd.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Common Files\{88B8388E-0B09-1035-1225-030723200166}\Update.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsav32.exe
    C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\Program\fspex.exe
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
    C:\PROGRA~1\ELISAT~1\ANTI-S~1\fsaw.exe
    C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\fsguidll.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Winamp\winamp.exe
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    C:\Program Files\PrintView\pvmodule.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Kaspersky\kavupd.exe
    C:\WINDOWS\system32\taskmgr.exe
    C:\hijack this\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://elisa.net/
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Elisa Tietoturvapalvelu\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\FSSW.EXE" /reboot
    O4 - HKLM\..\Run: [News Service] "C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\ispnews.exe"
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [WinAntiVirusPro2006] "C:\Program Files\WinAntiVirus Pro 2006\WinAV.exe" /min
    O4 - HKLM\..\Run: [PVModule] C:\PROGRA~1\PRINTV~1\pvmodule.exe
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe"
    O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - Global Startup: Elisa Tietoturvapalvelu.lnk = C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\Program\fspex.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
    O8 - Extra context menu item: &Estä tämä kohoikkuna - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\blockpopups.htm
    O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O9 - Extra button: IE-suojaus - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\ieshield.dll
    O9 - Extra 'Tools' menuitem: IE-suojaus... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\ieshield.dll
    O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
    O14 - IERESET.INF: START_PAGE_URL=http://elisa.net/
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: Extensions - C:\WINDOWS\system32\gp20l3fm1.dll (file missing)
    O20 - Winlogon Notify: RunServices - C:\WINDOWS\system32\s0rsla971d.dll
    O23 - Service: Elisa Tietoturvapalvelu (BackWeb Plug-in - 4119343) - BackWeb Technologies Inc. - C:\PROGRA~1\ELISAT~1\backweb\4119343\Program\SERVIC~1.EXE
    O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32st.exe
    O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\program\fsbwsys.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\FWES\Program\fsdfwd.exe
    O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMA32.EXE
    O23 - Service: Firewall service (FWSvc) - Unknown owner - C:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe (file missing)
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
    O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe



    Millä saan tyhjäksi koneen psksta? kiitos
     
  2.  
  3. hannu71

    hannu71 Regular member

    Liittynyt:
    09.02.2006
    Viestejä:
    256
    Kiitokset:
    0
    Pisteet:
    26

    1. Lataa combofix.exe tiedosto työpöydällesi.
    2. Tuplaklikkaa combofix.exe tiedostoa ja seuraa ohjeistuksia.
    3. Kun työkalu on valmis, se tuottaa lokin. Lähetä tämä loki viesti ketjuusi.
    Huom! Älä klikkaile combofixin ikkunaa käytön aikana. Tämä saattaa aiheuttaa ohjelman jumiutumisen.
     
    Viimeksi muokattu: 04.10.2006
  4. FIN_Kla

    FIN_Kla Guest

    Combofixin loki:

    Jufka - 06-10-04 18:18:49.89 Service Pack 2
    ComboFix 06.09.28 - Running from: "C:\Documents and Settings\Jufka\Ty”p”yt„"

    ((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))

    REGISTRY ENTRIES REMOVED:

    [HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}]
    @=""
    "IDEx"="ADDR"

    [HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\InprocServer32]
    @="C:\\WINDOWS\\system32\\wznotify.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\InprocServer32]
    @="C:\\WINDOWS\\system32\\serenacm.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\InprocServer32]
    @="C:\\WINDOWS\\system32\\pbrfts.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\InprocServer32]
    @="C:\\WINDOWS\\system32\\migsvc.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\InprocServer32]
    @="C:\\WINDOWS\\system32\\jvproxy.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\InprocServer32]
    @="C:\\WINDOWS\\system32\\cefgnt.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\InprocServer32]
    @="C:\\WINDOWS\\system32\\kedfi1.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mztext40.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\InprocServer32]
    @="C:\\windows\\system32\\khdcz1.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\InprocServer32]
    @="C:\\WINDOWS\\system32\\kmdusl.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\InprocServer32]
    @="C:\\WINDOWS\\system32\\guard.tmp"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\InprocServer32]
    @="C:\\WINDOWS\\system32\\oncache.dll"
    "ThreadingModel"="Apartment"

    * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


    FILES REMOVED:

    C:\WINDOWS\system32\en06l1ds1.dll
    C:\WINDOWS\system32\f0l00a3med.dll
    C:\WINDOWS\system32\khdcz1.dll
    C:\WINDOWS\system32\oue2nls.dll


    Granting sedebugprivilege to Järjestelmänvalvojat ... successful


    (((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


    C:\Program Files\Inetget2
    C:\Program Files\Common Files\{88B8388E-0B09-1035-1225-030723200166}
    C:\Program Files\PrintView


    ((((((((((((((((((((((((((((((( Files Created from 2006-09-04 to 2006-10-04 ))))))))))))))))))))))))))))))))))


    2006-10-03 22:03 53,248 --a------ C:\WINDOWS\system32\Process.exe
    2006-10-03 22:03 40,960 --a------ C:\WINDOWS\system32\swsc.exe
    2006-10-03 22:03 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
    2006-10-03 22:03 135,168 --a------ C:\WINDOWS\system32\swreg.exe
    2006-09-25 17:47 51,072 --a------ C:\WINDOWS\system32\drivers\ikhlayer.sys
    2006-09-25 17:47 30,592 --a------ C:\WINDOWS\system32\drivers\ikhfile.sys
    2006-09-25 17:37 89,088 --a------ C:\WINDOWS\system32\atl71.dll
    2006-09-25 17:37 8,704 --a------ C:\WINDOWS\system32\SpOrder.dll
    2006-09-25 17:37 6,144 --a------ C:\WINDOWS\system32\stera.exe
    2006-09-24 17:30 73,796 --a------ C:\WINDOWS\system32\slserv.exe
    2006-09-24 17:30 73,796 --a------ C:\WINDOWS\system32\slserv.0xe.exe


    (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


    2006-10-04 18:22 -------- d-------- C:\Program Files\Common Files
    2006-10-04 18:03 -------- d-------- C:\Program Files\Mozilla Firefox
    2006-10-04 17:49 -------- d-------- C:\Program Files\DAEMON Tools
    2006-10-04 11:52 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
    2006-10-03 21:24 -------- d-------- C:\Program Files\Expekt
    2006-10-03 21:23 -------- d-------- C:\Program Files\GustoSoft
    2006-09-28 19:10 -------- d-------- C:\Program Files\MSN Messenger
    2006-09-28 19:10 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
    2006-09-25 18:51 -------- d-------- C:\Program Files\Lavasoft
    2006-09-25 18:19 -------- d-------- C:\Program Files\Spyware Doctor
    2006-09-21 20:24 -------- d-------- C:\Program Files\DC++
    2006-08-21 15:26 16896 --a------ C:\WINDOWS\system32\fltlib.dll
    2006-08-21 12:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
    2006-08-21 12:14 128896 --------- C:\WINDOWS\system32\drivers\fltmgr.sys
    2006-08-10 21:48 -------- d-------- C:\Program Files\Internet Explorer
    2006-07-29 19:32 48936 --a------ C:\WINDOWS\system32\sirenacm.dll
    2006-07-27 16:26 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
    2006-07-21 11:28 72704 --a------ C:\WINDOWS\system32\hlink.dll
    2006-07-04 16:16 855 --a------ C:\Program Files\Ace DivX Player.lnk


    (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

    *Note* empty entries are not shown

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\\windows\\system32\\ctfmon.exe"
    "BitComet"="\"C:\\Program Files\\BitComet\\BitComet.exe\""
    "msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Wizard"=hex(2):00
    "SoundMan"="SOUNDMAN.EXE"
    "F-Secure Manager"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\Common\\FSM32.EXE\" /splash"
    "F-Secure TNB"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\TNB\\TNBUtil.exe\" /CHECKALL /WAITFORSW"
    "F-Secure Startup Wizard"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\FSGUI\\FSSW.EXE\" /reboot"
    "News Service"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\FSGUI\\ispnews.exe\""
    "WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
    "SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
    "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
    "DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
    "RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
    "!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
    "Installed"="1"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
    "Installed"="1"
    "NoChange"="1"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
    "Installed"="1"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonceex]
    @=""

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
    "DeskHtmlVersion"=dword:00000110
    "DeskHtmlMinorVersion"=dword:00000005
    "Settings"=dword:00000001
    "GeneralFlags"=dword:00000001

    [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
    "Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"

    [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
    "Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
    "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
    "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
    "NoDriveTypeAutoRun"=dword:00000091

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
    "dontdisplaylastusername"=dword:00000000
    "legalnoticecaption"=""
    "legalnoticetext"=""
    "shutdownwithoutlogon"=dword:00000001
    "undockwithoutlogon"=dword:00000001

    [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
    "NoDriveTypeAutoRun"=dword:00000091

    [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

    [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
    "NoDriveTypeAutoRun"=dword:00000091

    [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
    "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
    "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
    "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"


    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
    securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


    Contents of the 'Scheduled Tasks' folder
    C:\windows\tasks\Scheduled scanning task.job

    Completion time: Wed 04.10.2006 18:25:05.89
    ComboFix.txt
    ComboFix2.txt
     
  5. FIN_Kla

    FIN_Kla Guest

    Combofixin loki:

    Jufka - 06-10-04 18:18:49.89 Service Pack 2
    ComboFix 06.09.28 - Running from: "C:\Documents and Settings\Jufka\Ty”p”yt„"

    ((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))

    REGISTRY ENTRIES REMOVED:

    [HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}]
    @=""
    "IDEx"="ADDR"

    [HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\InprocServer32]
    @="C:\\WINDOWS\\system32\\wznotify.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\InprocServer32]
    @="C:\\WINDOWS\\system32\\serenacm.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\InprocServer32]
    @="C:\\WINDOWS\\system32\\pbrfts.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\InprocServer32]
    @="C:\\WINDOWS\\system32\\migsvc.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\InprocServer32]
    @="C:\\WINDOWS\\system32\\jvproxy.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\InprocServer32]
    @="C:\\WINDOWS\\system32\\cefgnt.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\InprocServer32]
    @="C:\\WINDOWS\\system32\\kedfi1.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mztext40.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\InprocServer32]
    @="C:\\windows\\system32\\khdcz1.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\InprocServer32]
    @="C:\\WINDOWS\\system32\\kmdusl.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\InprocServer32]
    @="C:\\WINDOWS\\system32\\guard.tmp"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\InprocServer32]
    @="C:\\WINDOWS\\system32\\oncache.dll"
    "ThreadingModel"="Apartment"

    * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


    FILES REMOVED:

    C:\WINDOWS\system32\en06l1ds1.dll
    C:\WINDOWS\system32\f0l00a3med.dll
    C:\WINDOWS\system32\khdcz1.dll
    C:\WINDOWS\system32\oue2nls.dll


    Granting sedebugprivilege to Järjestelmänvalvojat ... successful


    (((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


    C:\Program Files\Inetget2
    C:\Program Files\Common Files\{88B8388E-0B09-1035-1225-030723200166}
    C:\Program Files\PrintView


    ((((((((((((((((((((((((((((((( Files Created from 2006-09-04 to 2006-10-04 ))))))))))))))))))))))))))))))))))


    2006-10-03 22:03 53,248 --a------ C:\WINDOWS\system32\Process.exe
    2006-10-03 22:03 40,960 --a------ C:\WINDOWS\system32\swsc.exe
    2006-10-03 22:03 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
    2006-10-03 22:03 135,168 --a------ C:\WINDOWS\system32\swreg.exe
    2006-09-25 17:47 51,072 --a------ C:\WINDOWS\system32\drivers\ikhlayer.sys
    2006-09-25 17:47 30,592 --a------ C:\WINDOWS\system32\drivers\ikhfile.sys
    2006-09-25 17:37 89,088 --a------ C:\WINDOWS\system32\atl71.dll
    2006-09-25 17:37 8,704 --a------ C:\WINDOWS\system32\SpOrder.dll
    2006-09-25 17:37 6,144 --a------ C:\WINDOWS\system32\stera.exe
    2006-09-24 17:30 73,796 --a------ C:\WINDOWS\system32\slserv.exe
    2006-09-24 17:30 73,796 --a------ C:\WINDOWS\system32\slserv.0xe.exe


    (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


    2006-10-04 18:22 -------- d-------- C:\Program Files\Common Files
    2006-10-04 18:03 -------- d-------- C:\Program Files\Mozilla Firefox
    2006-10-04 17:49 -------- d-------- C:\Program Files\DAEMON Tools
    2006-10-04 11:52 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
    2006-10-03 21:24 -------- d-------- C:\Program Files\Expekt
    2006-10-03 21:23 -------- d-------- C:\Program Files\GustoSoft
    2006-09-28 19:10 -------- d-------- C:\Program Files\MSN Messenger
    2006-09-28 19:10 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
    2006-09-25 18:51 -------- d-------- C:\Program Files\Lavasoft
    2006-09-25 18:19 -------- d-------- C:\Program Files\Spyware Doctor
    2006-09-21 20:24 -------- d-------- C:\Program Files\DC++
    2006-08-21 15:26 16896 --a------ C:\WINDOWS\system32\fltlib.dll
    2006-08-21 12:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
    2006-08-21 12:14 128896 --------- C:\WINDOWS\system32\drivers\fltmgr.sys
    2006-08-10 21:48 -------- d-------- C:\Program Files\Internet Explorer
    2006-07-29 19:32 48936 --a------ C:\WINDOWS\system32\sirenacm.dll
    2006-07-27 16:26 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
    2006-07-21 11:28 72704 --a------ C:\WINDOWS\system32\hlink.dll
    2006-07-04 16:16 855 --a------ C:\Program Files\Ace DivX Player.lnk


    (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

    *Note* empty entries are not shown

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\\windows\\system32\\ctfmon.exe"
    "BitComet"="\"C:\\Program Files\\BitComet\\BitComet.exe\""
    "msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Wizard"=hex(2):00
    "SoundMan"="SOUNDMAN.EXE"
    "F-Secure Manager"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\Common\\FSM32.EXE\" /splash"
    "F-Secure TNB"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\TNB\\TNBUtil.exe\" /CHECKALL /WAITFORSW"
    "F-Secure Startup Wizard"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\FSGUI\\FSSW.EXE\" /reboot"
    "News Service"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\FSGUI\\ispnews.exe\""
    "WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
    "SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
    "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
    "DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
    "RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
    "!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
    "Installed"="1"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
    "Installed"="1"
    "NoChange"="1"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
    "Installed"="1"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonceex]
    @=""

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
    "DeskHtmlVersion"=dword:00000110
    "DeskHtmlMinorVersion"=dword:00000005
    "Settings"=dword:00000001
    "GeneralFlags"=dword:00000001

    [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
    "Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"

    [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
    "Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
    "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
    "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
    "NoDriveTypeAutoRun"=dword:00000091

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
    "dontdisplaylastusername"=dword:00000000
    "legalnoticecaption"=""
    "legalnoticetext"=""
    "shutdownwithoutlogon"=dword:00000001
    "undockwithoutlogon"=dword:00000001

    [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
    "NoDriveTypeAutoRun"=dword:00000091

    [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

    [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
    "NoDriveTypeAutoRun"=dword:00000091

    [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
    "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
    "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
    "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"


    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
    securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


    Contents of the 'Scheduled Tasks' folder
    C:\windows\tasks\Scheduled scanning task.job

    Completion time: Wed 04.10.2006 18:25:05.89
    ComboFix.txt
    ComboFix2.txt
     
  6. FIN_Kla

    FIN_Kla Guest

    Combofixin loki:

    Jufka - 06-10-04 18:18:49.89 Service Pack 2
    ComboFix 06.09.28 - Running from: "C:\Documents and Settings\Jufka\Ty”p”yt„"

    ((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))

    REGISTRY ENTRIES REMOVED:

    [HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}]
    @=""
    "IDEx"="ADDR"

    [HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\InprocServer32]
    @="C:\\WINDOWS\\system32\\wznotify.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\InprocServer32]
    @="C:\\WINDOWS\\system32\\serenacm.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\InprocServer32]
    @="C:\\WINDOWS\\system32\\pbrfts.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\InprocServer32]
    @="C:\\WINDOWS\\system32\\migsvc.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\InprocServer32]
    @="C:\\WINDOWS\\system32\\jvproxy.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\InprocServer32]
    @="C:\\WINDOWS\\system32\\cefgnt.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\InprocServer32]
    @="C:\\WINDOWS\\system32\\kedfi1.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mztext40.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\InprocServer32]
    @="C:\\windows\\system32\\khdcz1.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\InprocServer32]
    @="C:\\WINDOWS\\system32\\kmdusl.dll"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\InprocServer32]
    @="C:\\WINDOWS\\system32\\guard.tmp"
    "ThreadingModel"="Apartment"

    [HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\InprocServer32]
    @="C:\\WINDOWS\\system32\\oncache.dll"
    "ThreadingModel"="Apartment"

    * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


    FILES REMOVED:

    C:\WINDOWS\system32\en06l1ds1.dll
    C:\WINDOWS\system32\f0l00a3med.dll
    C:\WINDOWS\system32\khdcz1.dll
    C:\WINDOWS\system32\oue2nls.dll


    Granting sedebugprivilege to Järjestelmänvalvojat ... successful


    (((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


    C:\Program Files\Inetget2
    C:\Program Files\Common Files\{88B8388E-0B09-1035-1225-030723200166}
    C:\Program Files\PrintView


    ((((((((((((((((((((((((((((((( Files Created from 2006-09-04 to 2006-10-04 ))))))))))))))))))))))))))))))))))


    2006-10-03 22:03 53,248 --a------ C:\WINDOWS\system32\Process.exe
    2006-10-03 22:03 40,960 --a------ C:\WINDOWS\system32\swsc.exe
    2006-10-03 22:03 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
    2006-10-03 22:03 135,168 --a------ C:\WINDOWS\system32\swreg.exe
    2006-09-25 17:47 51,072 --a------ C:\WINDOWS\system32\drivers\ikhlayer.sys
    2006-09-25 17:47 30,592 --a------ C:\WINDOWS\system32\drivers\ikhfile.sys
    2006-09-25 17:37 89,088 --a------ C:\WINDOWS\system32\atl71.dll
    2006-09-25 17:37 8,704 --a------ C:\WINDOWS\system32\SpOrder.dll
    2006-09-25 17:37 6,144 --a------ C:\WINDOWS\system32\stera.exe
    2006-09-24 17:30 73,796 --a------ C:\WINDOWS\system32\slserv.exe
    2006-09-24 17:30 73,796 --a------ C:\WINDOWS\system32\slserv.0xe.exe


    (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


    2006-10-04 18:22 -------- d-------- C:\Program Files\Common Files
    2006-10-04 18:03 -------- d-------- C:\Program Files\Mozilla Firefox
    2006-10-04 17:49 -------- d-------- C:\Program Files\DAEMON Tools
    2006-10-04 11:52 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
    2006-10-03 21:24 -------- d-------- C:\Program Files\Expekt
    2006-10-03 21:23 -------- d-------- C:\Program Files\GustoSoft
    2006-09-28 19:10 -------- d-------- C:\Program Files\MSN Messenger
    2006-09-28 19:10 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
    2006-09-25 18:51 -------- d-------- C:\Program Files\Lavasoft
    2006-09-25 18:19 -------- d-------- C:\Program Files\Spyware Doctor
    2006-09-21 20:24 -------- d-------- C:\Program Files\DC++
    2006-08-21 15:26 16896 --a------ C:\WINDOWS\system32\fltlib.dll
    2006-08-21 12:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
    2006-08-21 12:14 128896 --------- C:\WINDOWS\system32\drivers\fltmgr.sys
    2006-08-10 21:48 -------- d-------- C:\Program Files\Internet Explorer
    2006-07-29 19:32 48936 --a------ C:\WINDOWS\system32\sirenacm.dll
    2006-07-27 16:26 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
    2006-07-21 11:28 72704 --a------ C:\WINDOWS\system32\hlink.dll
    2006-07-04 16:16 855 --a------ C:\Program Files\Ace DivX Player.lnk


    (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

    *Note* empty entries are not shown

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\\windows\\system32\\ctfmon.exe"
    "BitComet"="\"C:\\Program Files\\BitComet\\BitComet.exe\""
    "msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Wizard"=hex(2):00
    "SoundMan"="SOUNDMAN.EXE"
    "F-Secure Manager"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\Common\\FSM32.EXE\" /splash"
    "F-Secure TNB"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\TNB\\TNBUtil.exe\" /CHECKALL /WAITFORSW"
    "F-Secure Startup Wizard"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\FSGUI\\FSSW.EXE\" /reboot"
    "News Service"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\FSGUI\\ispnews.exe\""
    "WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
    "SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
    "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
    "DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
    "RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
    "!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
    "Installed"="1"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
    "Installed"="1"
    "NoChange"="1"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
    "Installed"="1"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonceex]
    @=""

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
    "DeskHtmlVersion"=dword:00000110
    "DeskHtmlMinorVersion"=dword:00000005
    "Settings"=dword:00000001
    "GeneralFlags"=dword:00000001

    [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
    "Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"

    [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
    "Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
    "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
    "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
    "NoDriveTypeAutoRun"=dword:00000091

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
    "dontdisplaylastusername"=dword:00000000
    "legalnoticecaption"=""
    "legalnoticetext"=""
    "shutdownwithoutlogon"=dword:00000001
    "undockwithoutlogon"=dword:00000001

    [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
    "NoDriveTypeAutoRun"=dword:00000091

    [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

    [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
    "NoDriveTypeAutoRun"=dword:00000091

    [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
    "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
    "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
    "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"


    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
    securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


    Contents of the 'Scheduled Tasks' folder
    C:\windows\tasks\Scheduled scanning task.job

    Completion time: Wed 04.10.2006 18:25:05.89
    ComboFix.txt
    ComboFix2.txt
     
  7. hannu71

    hannu71 Regular member

    Liittynyt:
    09.02.2006
    Viestejä:
    256
    Kiitokset:
    0
    Pisteet:
    26
    lopeta tehtävien hallinnasta (ctrl+alt+delete) seuraavat:
    pvmodule.exe

    Poista ohjauspaneelista seuraavat:
    WinAntiVirus Pro 2006
    Save tai whenUsave tai vastaava

    Avaa HijackThis, klikkaa do a system scan only, merkkaa nämä rivit. Sitten sulje kaikki muut ikkunat ja paina fix checked.
    O4 - HKLM\..\Run: [WinAntiVirusPro2006] "C:\Program Files\WinAntiVirus Pro 2006\WinAV.exe" /min
    O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe
    O23 - Service: Firewall service (FWSvc) - Unknown owner - C:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe (file missing)

    Kopioi/liitä seuraava teksti lainausboksista alapuolella tyhjään
    muistiofiluun. Varmista että tiedostotyyppi on "All Files" ja
    tallenna se Poisto.bat. nimisenä työpöydällesi.

    Lainaus
    ------------------
    @echo off
    sc stop FWSvc
    sc delete FWSvc
    ------------------

    Sitten aja työpöydällä oleva Poisto.bat-tiedosto.

    laita tarvittaessa piilotiedostot näkyviin. ohje==> http://keskustelu.afterdawn.com/thread_view.cfm/248944
    mene vikasietotilaan. ohje==>
    http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406

    poista seuraavat:
    C:\Program Files\==>WinAntiVirus Pro 2006<==
    C:\Program Files\==>Save<==

    käynnistä kone normaali tilaan ja laita piilotiedostot takaisin piiloon.

    Javan päivitys ja välimuistin tyhjennys
    1. Klikkaa Käynnistä > Ohjauspaneeli ja tupla-klikkaa Lisää tai poista sovellus Ohjauspaneelissa.
    2. Etsi listasta kaikki entiset Java versiosi. (J2SE Runtime Environment.... )
    Niissä pitäisi olla seuraava kuva vieressä:
    3. Valitse kaikki entiset Java versiosi ja valitse Poista.
    4. Asenna uusin Java päivitys seuraavasta linkistä..
    5. Käynnistä kone uudelleen asennuksen jälkeen:

    http://java.sun.com/javase/downloads/index.jsp

    6. Käynnistyksen jälkeen, mene takaisin Ohjauspaneeliin ja avaa Java asetuksesi (Muita Ohjauspaneelin asetuksia -> Java kahvikuppi).
    7. Temporary Internet Files -osion alla, klikkaa Delete Files nappia.
    8. Varmista että kaikki kolme valintaa ovat rastitettuja:

    Downloaded Applets
    Downloaded Applications
    Other Files

    9. Klikkaa OK "Delete Temporary Internet Files" -ikkunassasi.
    Huomaa: Tämä poistaa kaikki ladatut sovellukset ja appletit VÄLIMUISTISTA.
    10. Klikkaa OK jättääksesi Java asetusikkunasi.


    Lataa Killbox http://www.downloads.subratam.org/KillBox.zip
    Huomaa: Jos sinulla on jo Killbox, tämä on uusi versio joka sinun tulee asentaa. Poista aikaisempi.

    * Tallenna työpöydällesi.
    * Tupla-klikkaa Killbox.exe ajaaksesi ohjelman.
    * Valitse:
    o Delete on Reboot
    o sitten klikkaa All Files valintaa.

    * Kopioi ja liitä alapuolella olevat tiedostopolut leikepöydälle mustaamalla KAIKKI ne ja painamalla CTRL + C (tai, mustaamisen jälkeen, oikea klikki hiirellä ja valitse kopioi):

    C:\WINDOWS\system32\stera.exe
    C:\WINDOWS\system32\slserv.0xe.exe

    * Palaa Killboxiin, mene File valikkoon, ja valitse Paste from Clipboard.

    * Klikkaa puna-valkoista Delete File valintaa. Klikkaa Yes "Delete on Reboot" pyyntöön. Klikkaa OK mihin vain PendingFileRenameOperations pyyntöön (ja anna fixaajan tietää jos jokin tälläinen tulee!).


    Käynnistä koneesi itse jos se ei sitä automaattisesti tee.

    Jos saat tälläisen viestin: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." Kun yrität ajaa KillBoxia, klikkaa http://www.eudaemonia.me.uk/downloads/Files/missingfilesetup.exe ladataksesi ja ajaaksesi Missingfilessetup.exe;n. Sitten koita KillBoxia uudestaan.

    lähetä uusi hjt-loki
     
Viestiketjun tila:
Viestiketju on suljettu.

Jaa tämä sivu