1. Tämä sivusto käyttää keksejä (cookie). Jatkamalla sivuston käyttämistä hyväksyt keksien käyttämisen. Lue lisää.

HjT_loki Muutama troya ei lähde, enkä myöskään saa taustakuvaa vaihdettua .KiitoS

Viestiketju Virukset ja haittaohjelmat - HijackThis -logit -osiossa. Ketjun avasi samipami 26.08.2008.

  1. samipami

    samipami Member

    Liittynyt:
    07.03.2006
    Viestejä:
    55
    Kiitokset:
    0
    Pisteet:
    16
    Tarkistustyyppi Täysi tarkistus (CF)
    Tarkistetut kohteet 84057
    Kulunut aika 30 minute(s), 55 second(s)

    Saastuneita muistiprosesseja 0
    Saastuneita muistimoduuleja 0
    Saastuneita rekisteriavaimia 2
    Saastuneita rekisteriarvoja 4
    Saastuneita rekisterikohteita 0
    Saastuneita hakemistoja 0
    Saastuneita tiedostoja 1

    Saastuneita muistiprosesseja
    (Haitallisia kohteita ei löydetty)

    Saastuneita muistimoduuleja
    (Haitallisia kohteita ei löydetty)

    Saastuneita rekisteriavaimia
    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{a99091b0-d5c1-40df-bf12-8f929063a311} (Trojan.BHO.H) - Delete on reboot.
    HKEY_CLASSES_ROOTCLSID{a99091b0-d5c1-40df-bf12-8f929063a311} (Trojan.BHO.H) - Delete on reboot.

    Saastuneita rekisteriarvoja
    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Settingsbf (Trojan.Agent) - Delete on reboot.
    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Settingsbk (Trojan.Agent) - Delete on reboot.
    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Settingsiu (Trojan.Agent) - Delete on reboot.
    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Settingsmu (Trojan.Agent) - Delete on reboot.

    Saastuneita rekisterikohteita
    (Haitallisia kohteita ei löydetty)

    Saastuneita hakemistoja
    (Haitallisia kohteita ei löydetty)

    Saastuneita tiedostoja
    CDocuments and SettingsSamiLocal SettingsTemporary Internet FilesContent.IE5GACH46F53077htsbdjyf[1].dll (Trojan.BHO.H) - Quarantined and deleted successfully.


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 18:41:12, on 5.9.2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Sygate\SPF\smc.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\PROGRA~1\AVG\AVG8\avgscanx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\rundll32.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
    C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
    C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\WINDOWS\system32\SearchProtocolHost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.telkku.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {A99091B0-D5C1-40DF-BF12-8F929063A311} - C:\Documents and Settings\Sami\Local Settings\Temporary Internet Files\Content.IE5\GACH46F5\3077htsbdjyf[1].dll (file missing)
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
    O4 - HKCU\..\Run: [Steam] "F:\Program Files\Steam\Steam.exe" -silent
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1199268633166
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: avgrsstx.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

    --
    End of file - 5331 bytes
     
  2.  
  3. Hujo

    Hujo Guest

    siellähän se istuu.....
    O2 - BHO: (no name) - {A99091B0-D5C1-40DF-BF12-8F929063A311} - C:\Documents and Settings\Sami\Local Settings\Temporary Internet Files\Content.IE5\GACH46F5\3077htsbdjyf[1].dll (file missing)

    =======================

    Avaa Muistio ja kopioi/liitä quoteboxin sisältö sinne:

    Tallenna se nimellä CFScript.txt

    Sitten raahaa CFScript ComboFix.exeen kuten alla.

    [​IMG]

    Käynnistä tietokone uudelleen pyydettäessä ja lähetä combofix.txt-tiedoston sisältö tänne.

    ====================

    Nyt tuon punasella merkityn laitat tyhjään muistioon
    käynnistä nappi >apuohjelmat > muistio

    Kohde: työpöytä

    sittten vasemmasta ylä reunasta tiedosto > tallenna nimellä CFScript.txt

    tallenusmuoto kaikki tiedostot

    sitten raahaat sen kuvan osoitamalla tavalla

    combofix työstää tulee sininen taulu paina numeroa 1 ja enter

    [​IMG]
     
    Moderaattorin viimeksi muokkaama: 05.09.2008
  4. samipami

    samipami Member

    Liittynyt:
    07.03.2006
    Viestejä:
    55
    Kiitokset:
    0
    Pisteet:
    16
    Kun olen raahannut comboon sen CFScriptin tulee error : CFS nimivirhe Yrititkö ajaa CFScriptin?

    Nimi CFScript on kirjoitettu väärin... Apuuuuva
     
  5. Hujo

    Hujo Guest

    hmmmmm..... mikä siellä nyt mättäää

    noin se tulee CFScript.txt

    ================

    Lataa NoLop työpöydällesi yhdestä seuraavista linkeistä...
    Linkki1
    Linkki2
    Linkki3

    1.Sulje kaikki ohjelmat, koska tämä vaihe vaatii uudelleenkäynnistyksen
    2.Tuplaklikkaa NoLop.exe ajaaksesi sen
    3.Klikkaa nappulaa "Search and Destroy"
    <<Tietokoneesi skannataan saastuneiden tiedostojen osalta>>
    4, Kun skannaus on valmis, sinua pyydetään käynnistämään kone uudestaan, jos infektio löytyy. Klikkaa OK
    5. Klikkaa "REBOOT"-painiketta.
    6. NoLopin pitäisi antaa viesti. Jos ei, tuplaklikkaa ohjelmaa ja se valmistuu. Lähetä C:\NoLop.log-tiedoston sisältö uuden HijackThis-lokin kera.
    -- Jos saat seuraavan virheen, "mscomctl.ocx or one of its dependencies are not correctly registered," lataa mscomctl.ocx ja tallenna se system32-hakemistoosi (yleensä c:\Windows\system32). Tämän jälkeen aja ohjelma uudestaan.
     
    Moderaattorin viimeksi muokkaama: 05.09.2008
  6. samipami

    samipami Member

    Liittynyt:
    07.03.2006
    Viestejä:
    55
    Kiitokset:
    0
    Pisteet:
    16
    ComboFix 08-09-05.02 - Sami 2008-09-07 4:13:48.19 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1035.18.1398 [GMT 3:00]
    Running from: C:\Documents and Settings\Sami\Työpöytä\ComboFix.exe
    Command switches used :: C:\Documents and Settings\Sami\Työpöytä\CFScript.txt
    * Created a new restore point

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-08-07 to 2008-09-07 )))))))))))))))))
    .

    2008-09-06 21:56 . 2008-09-07 02:15 212 --a------ C:\delete.bat
    2008-09-06 21:11 . 2008-09-06 21:11 <KANSIO> d-------- C:\WINDOWS\LastGood
    2008-09-05 02:40 . 2008-09-05 02:40 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\U3
    2008-09-04 18:44 . 2008-09-04 18:56 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
    2008-09-04 13:45 . 2008-09-05 01:18 <KANSIO> d-------- C:\Program Files\QuickTime
    2008-09-02 08:54 . 2008-09-02 08:54 <KANSIO> d-------- C:\Program Files\Common Files\PCSuite
    2008-09-02 08:54 . 2008-09-02 13:18 <KANSIO> d-------- C:\Program Files\Common Files\Nokia
    2008-09-02 08:53 . 2008-09-02 08:53 <KANSIO> d-------- C:\Program Files\PC Connectivity Solution
    2008-09-02 08:53 . 2007-09-17 15:53 21,632 --a------ C:\WINDOWS\system32\drivers\pccsmcfd.sys
    2008-09-01 17:44 . 2008-09-01 18:03 <KANSIO> d-------- C:\Downloads
    2008-09-01 17:44 . 2008-09-01 18:01 <KANSIO> d-------- C:\Bases
    2008-09-01 17:41 . 2008-09-01 19:26 <KANSIO> d-------- C:\Kaspersky
    2008-08-29 16:26 . 2008-08-29 16:26 <KANSIO> d-------- C:\Program Files\DIFX
    2008-08-29 00:39 . 2008-08-29 00:39 <KANSIO> d-------- C:\Program Files\RegSeeker
    2008-08-29 00:35 . 2008-09-05 02:08 8,192 --ahs---- C:\WINDOWS\system32\Thumbs.db
    2008-08-26 20:56 . 2008-08-29 01:33 98 --a------ C:\index.ini
    2008-08-26 16:35 . 2008-09-02 12:10 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-08-26 16:35 . 2008-09-02 00:16 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
    2008-08-26 16:35 . 2008-09-02 00:16 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
    2008-08-26 12:04 . 2008-08-26 12:04 579,072 --a--c--- C:\WINDOWS\system32\dllcache\user32.dll
    2008-08-26 12:03 . 2008-08-26 12:03 <KANSIO> d-------- C:\WINDOWS\ERUNT
    2008-08-26 01:36 . 2008-08-26 01:36 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\PrevxCSI
    2008-08-26 00:16 . 2008-08-26 00:16 <KANSIO> d-------- C:\Documents and Settings\Sami\Application Data\Malwarebytes
    2008-08-26 00:16 . 2008-08-26 00:16 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-08-25 23:59 . 2008-08-26 12:52 <KANSIO> d-------- C:\Program Files\Spybot - Search & Destroy
    2008-08-25 23:59 . 2008-08-26 12:52 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-08-22 19:00 . 2008-08-22 19:00 <KANSIO> d-------- C:\Program Files\Sygate
    2008-08-22 19:00 . 2004-10-15 18:32 83,096 --a------ C:\WINDOWS\system32\SSSensor.dll
    2008-08-22 19:00 . 2004-10-15 18:17 60,496 --a------ C:\WINDOWS\system32\drivers\Teefer.sys
    2008-08-22 19:00 . 2004-10-15 18:18 21,075 --a------ C:\WINDOWS\system32\drivers\wpsdrvnt.sys
    2008-08-22 19:00 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg6n.sys
    2008-08-22 19:00 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg5n.sys
    2008-08-22 19:00 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg4n.sys
    2008-08-22 19:00 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg3n.sys
    2008-08-22 16:22 . 18,688 C:\WINDOWS\system32\drivers\vlvmrura.dat
    2008-08-22 16:22 . 5,120 C:\WINDOWS\system32\drivers\jkueopxu.dat
    2008-08-17 09:10 . 2008-08-17 09:10 335 --a------ C:\WINDOWS\mozregistry.dat
    2008-08-16 07:58 . 2008-09-06 21:11 <KANSIO> d-------- C:\WINDOWS\system32\drivers\Avg
    2008-08-16 07:58 . 2008-09-07 04:12 <KANSIO> d--h----- C:\$AVG8.VAULT$
    2008-08-16 05:45 . 2008-08-16 07:57 <KANSIO> d-------- C:\Program Files\RegCure
    2008-08-16 00:48 . 2008-08-29 03:12 97,928 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
    2008-08-16 00:48 . 2008-08-22 18:19 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
    2008-08-16 00:48 . 2008-08-22 18:19 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
    2008-08-15 22:01 . 2008-08-15 22:01 <KANSIO> d-------- C:\Documents and Settings\Sami\Application Data\Windows Search
    2008-08-15 22:00 . 2008-08-15 22:00 <KANSIO> d-------- C:\Documents and Settings\Sami\Application Data\Windows Desktop Search
    2008-08-15 21:59 . 2008-08-15 21:59 <KANSIO> d-------- C:\WINDOWS\system32\GroupPolicy
    2008-08-15 21:59 . 2008-08-15 21:59 <KANSIO> d-------- C:\Program Files\Windows Desktop Search
    2008-08-15 21:59 . 2008-07-22 17:52 1,214,526 -----c--- C:\WINDOWS\system32\dllcache\sysmain.sdb
    2008-08-15 21:59 . 2008-07-22 17:52 790,846 -----c--- C:\WINDOWS\system32\dllcache\apph_sp.sdb
    2008-08-15 21:59 . 2008-03-07 20:02 192,000 -----c--- C:\WINDOWS\system32\dllcache\offfilt.dll
    2008-08-15 21:59 . 2008-03-07 20:02 98,304 -----c--- C:\WINDOWS\system32\dllcache\nlhtml.dll
    2008-08-15 21:59 . 2008-03-07 20:02 29,696 -----c--- C:\WINDOWS\system32\dllcache\mimefilt.dll
    2008-08-15 21:59 . 2008-07-22 17:52 9,696 -----c--- C:\WINDOWS\system32\dllcache\drvmain.sdb
    2008-08-15 14:16 . 2008-04-11 22:05 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
    2008-08-15 14:16 . 2008-05-01 17:35 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll
    2008-08-11 16:22 . 2008-09-02 10:20 12,288 --ahs---- C:\WINDOWS\Thumbs.db
    2008-08-07 07:46 . 2008-08-07 07:46 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\RTL Winter Sports 2008
    2008-08-07 01:46 . 2008-08-07 01:46 278,728 --a------ C:\WINDOWS\system32\drivers\atksgt.sys
    2008-08-07 01:46 . 2008-08-07 01:46 25,416 --a------ C:\WINDOWS\system32\drivers\lirsgt.sys

    .
    (((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-09-05 13:50 --------- d-----w C:\Program Files\CCleaner
    2008-09-04 10:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
    2008-09-04 04:34 --------- d-----w C:\Program Files\Nokia
    2008-09-02 10:49 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
    2008-09-02 10:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
    2008-09-02 09:05 --------- d-----w C:\Documents and Settings\Sami\Application Data\Nokia
    2008-08-26 15:15 --------- d-----w C:\Program Files\Java
    2008-08-22 15:59 --------- d-----w C:\Program Files\Microsoft Silverlight
    2008-08-22 15:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
    2008-08-16 22:54 --------- d-----w C:\Program Files\real
    2008-08-16 04:58 --------- d-----w C:\Program Files\Skype
    2008-08-11 13:22 --------- d-----w C:\Program Files\Windows Media Connect
    2008-08-07 05:50 --------- d-----w C:\Documents and Settings\Sami\Application Data\Skype
    2008-08-07 05:35 --------- d-----w C:\Documents and Settings\Sami\Application Data\skypePM
    2008-08-07 03:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-08-06 15:55 --------- d-----w C:\Documents and Settings\Sami\Application Data\U3
    2008-08-05 16:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\ATI
    2008-08-05 15:54 --------- d-----w C:\Program Files\ATI Technologies
    2008-08-05 15:54 --------- d-----w C:\Program Files\ATI
    2008-08-05 15:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\ATI(2)
    2008-08-05 15:53 --------- d-----w C:\Program Files\Sygate(2)
    2008-08-02 17:46 --------- d-----w C:\Program Files\Common Files\AVSMedia
    2008-08-01 02:54 --------- d-----w C:\Documents and Settings\Sami\Application Data\PC Suite
    2008-07-25 04:11 --------- d-----w C:\Program Files\Common Files\Blizzard Entertainment
    2008-07-24 21:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Disk Cleaner
    2008-07-18 19:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
    2008-07-18 19:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
    2008-07-18 19:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
    2008-07-18 19:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
    2008-07-18 19:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
    2008-07-18 19:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
    2008-07-18 19:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
    2008-07-18 19:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
    2008-07-18 19:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
    2008-07-18 19:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
    2008-07-07 20:28 253,952 ----a-w C:\WINDOWS\system32\es.dll
    2008-06-24 16:44 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
    2008-06-23 16:29 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
    2008-06-20 17:47 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll
    2008-05-19 16:10 94,208 ----a-w C:\Documents and Settings\Sami\Application Data\ezplay.sys
    2008-05-19 16:09 47,360 ----a-w C:\Documents and Settings\Sami\Application Data\pcouffin.sys
    2008-01-28 00:19 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
    2008-05-14 00:06 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Sivuhistoria\History.IE5\MSHist012008051420080515\index.dat
    .

    ((((((((((((((((((((((((((((( snapshot@2008-09-05_20.34.41.96 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2007-07-30 17:19:10 271,224 ----a-w C:\WINDOWS\LastGood\system32\mucltui.dll
    + 2007-07-30 17:19:04 207,736 ----a-w C:\WINDOWS\LastGood\system32\muweb.dll
    .
    (((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
    REGEDIT4

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A99091B0-D5C1-40DF-BF12-8F929063A311}]
    C:\Documents and Settings\Sami\Local Settings\Temporary Internet Files\Content.IE5\GACH46F5\3077htsbdjyf[1].dll [BU]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
    "PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-08-11 1124352]
    "Steam"="F:\Program Files\Steam\Steam.exe" [2008-09-04 1271032]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
    "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-29 1235736]
    "SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 2577632]
    "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 413696]
    "BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 C:\WINDOWS\system32\bthprops.cpl]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=avgrsstx.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
    SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Käynnistä-valikko^Ohjelmat^Käynnistys^LaunchU3.exe.lnk]
    path=C:\Documents and Settings\All Users\Käynnistä-valikko\Ohjelmat\Käynnistys\LaunchU3.exe.lnk
    backup=C:\WINDOWS\pss\LaunchU3.exe.lnkCommon Startup

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "C:\\Program Files\\Messenger\\msmsgs.exe"=
    "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "C:\\Program Files\\Windows Media Player\\wmplayer.exe"=
    "C:\\WINDOWS\\system32\\dpvsetup.exe"=
    "C:\\WINDOWS\\system32\\dxdiag.exe"=
    "C:\\WINDOWS\\system32\\dpnsvr.exe"=
    "F:\\Pelit\\Return to Castle Wolfenstein\\WolfMP.exe"=
    "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
    "C:\\Kaspersky\\kavupd.exe"=
    "C:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
    "C:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "22556:TCP"= 22556:TCP:BitCometBeta 22556 TCP
    "22556:UDP"= 22556:UDP:BitCometBeta 22556 UDP
    "13824:TCP"= 13824:TCP:BitCometBeta 13824 TCP
    "13824:UDP"= 13824:UDP:BitCometBeta 13824 UDP
    "8973:TCP"= 8973:TCP:BitComet 8973 TCP
    "8973:UDP"= 8973:UDP:BitComet 8973 UDP
    "14519:TCP"= 14519:TCP:BitComet 14519 TCP
    "14519:UDP"= 14519:UDP:BitComet 14519 UDP

    R0 kkgutnpm;kkgutnpm;C:\WINDOWS\system32\drivers\vlvmrura.dat [ ]
    R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-29 97928]
    R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-29 875288]
    R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-29 231704]
    R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-08-22 76040]
    S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;C:\WINDOWS\system32\DRIVERS\ADM8511.SYS [2001-08-17 20160]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f5b062a5-2f54-11dd-a797-00508dc84ead}]
    \Shell\AutoRun\command - H:\LaunchU3.exe -a
    .
    'Ajoitetut tehtävät'-kansion sisältö
    .

    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-09-07 04:15:35
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\kkgutnpm]
    "ImagePath"="system32\drivers\vlvmrura.dat"

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\vsdatant]
    "ImagePath"=""
    .
    Completion time: 2008-09-07 4:16:27
    ComboFix-quarantined-files.txt 2008-09-07 01:16:22
    ComboFix2.txt 2008-09-07 00:44:22
    ComboFix3.txt 2008-09-07 00:36:32
    ComboFix4.txt 2008-09-06 19:22:24
    ComboFix5.txt 2008-09-07 00:56:37

    Pre-Run: 15,830,437,888 tavua vapaana
    Post-Run: 15,817,003,008 tavua vapaana

    207 --- E O F --- 2008-08-22 15:59:47
     
  7. samipami

    samipami Member

    Liittynyt:
    07.03.2006
    Viestejä:
    55
    Kiitokset:
    0
    Pisteet:
    16
    Hujoooooo ApuaaaaA oon hukassa tän koneen kanssa
     
  8. Hujo

    Hujo Guest

    Lataa OTMoveIt
    OTMoveIt ja tallenna se työpöydällesi.

    Tuplaklikkaa OTMoveIt.exe.
    Klikkaa CleanUp!.
    Valitse Yes kun kysytään "Begin cleanup Process?".
    Jos pyydetään, että saako koneen käynnistää uudeelleen, valitse Yes.OTMoveIt poistaa itsensä kun se on valmis, jos näin ei käy poista se itse.

    HUOM: Jos palomuurisi tai joku muu tietoturvaohjelma varoittaa, että OTMoveIt yrittää päästä nettin, niin anna sen päästä sinne.


     
  9. samipami

    samipami Member

    Liittynyt:
    07.03.2006
    Viestejä:
    55
    Kiitokset:
    0
    Pisteet:
    16
    Eli ei auttanut valitettavasti. Ccleaner ilmoittaa asian esim : InProcServer32\C:\Documents and Settings\Sami\Local Settings\Temporary Internet Files\Content.IE5\GACH46F5\3077htsbdjyf[1].dll

    Ja Hjt tekstin näin : BHO: (no name) - {A99091B0-D5C1-40DF-BF12-8F929063A311} - C:\Documents and Settings\Sami\Local Settings\Temporary Internet Files\Content.IE5\GACH46F5\3077htsbdjyf[1].dll (file missing)
     
  10. Hujo

    Hujo Guest

    Mites se kone noin muuten toimii
     
  11. samipami

    samipami Member

    Liittynyt:
    07.03.2006
    Viestejä:
    55
    Kiitokset:
    0
    Pisteet:
    16
    Siis en ymmärtänyt .... Voisitko tarkentaa asian " miten kone noin toimi "
     
  12. Hujo

    Hujo Guest

    Tarkista Kaspersky Online Skannerilla

    1. Lue läpi vaatimukset ja yksityisyyssäännökset ja klikkaa Accept.
    2. Skannerin ja virustietokannan lataus alkaa. Sinulta kysytään sallitko Kasperskyltä tulevan ohjelman asentamisen. Klikkaa Aja/Run.
    3. Kun lataus on valmis, klikkaa Settings.
    4. Varmistu, että seuraavat kohdat on valittu. Jos ne eivät ole, valitse ne ja klikkaa Save:
    Spyware, Adware, Dialers, and other potentially dangerous programs
    Archives
    Mail databases

    5. Klikkaa Oma Tietokone, My Computer Scan-kohdan alapuolelta.
    6. Kun tarkistus on valmis, tulokset näytetään. Klikkaa View Scan Report.
    7. Näet listan saastuneista kohteista. Klikkaa Save Report As....
    8. Tallenna tiedosto työpöydällesi. Muuta Tiedostotyyppi/Files of type muotoon Tekstitiedosto/Text file(.txt) ennen kuin klikkaat Save.
    9. Kopioi ja liitä tiedoston sisältö seuraavaan vastaukseesi uuden HijackThis-lokin kera
     
  13. samipami

    samipami Member

    Liittynyt:
    07.03.2006
    Viestejä:
    55
    Kiitokset:
    0
    Pisteet:
    16
    Moro... en saaanut sitä raporttia ulos jokin tökkii, lähetän alkuun minkä viruksen kuitenkin löytää ja miten se sen esittää........yritän saada online kaspeskya mut jokin mättää aina.....


    Threat name Threats count
    C:\WINDOWS\system32\drivers\xsvoucon.sys Infected: Hoax.Win32.Agent.fu 1
    The selected area was scanned.



    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 18:08:15, on 14.9.2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Sygate\SPF\smc.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\WINDOWS\StartupMonitor.exe
    C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
    C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
    C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\WINDOWS\system32\SearchProtocolHost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.telkku.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {A99091B0-D5C1-40DF-BF12-8F929063A311} - C:\Documents and Settings\Sami\Local Settings\Temporary Internet Files\Content.IE5\GACH46F5\3077htsbdjyf[1].dll (file missing)
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
    O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1199268633166
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: avgrsstx.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

    --
    End of file - 5391 bytes

     
  14. samipami

    samipami Member

    Liittynyt:
    07.03.2006
    Viestejä:
    55
    Kiitokset:
    0
    Pisteet:
    16
    Ja mites tuon Malwarebytesin kanssa tehdään? Se löytää aina samat 7 saastunuttta kohtaa, ja kaksi eri virusta....Vai ei vielä mitään
     
  15. Hujo

    Hujo Guest

    joku sitten niitä tuo sinne koko ajan.

    Formatoi kone ja asenna kaikki uudelleen.
     
  16. samipami

    samipami Member

    Liittynyt:
    07.03.2006
    Viestejä:
    55
    Kiitokset:
    0
    Pisteet:
    16
    Eli olen sanonut Malwaverebytesin ongelmasta jokusen kertaan.... otanko siiitä login koska se on näköjään ainoa ohjelma joka löytää mitään...

    + Esim HJT:SSä esiintyvä

    BHO: (no name) - {A99091B0-D5C1-40DF-BF12-8F929063A311} - C:\Documents and Settings\Sami\Local Settings\Temporary Internet Files\Content.IE5\GACH46F5\3077htsbdjyf[1].dll (file missing)
    Ja tämä ei lähde kun hetkeksi,vaikka käytän Fixchecked tai vaikka regseeekeriä / Cleaneriä

    Täsä Kaspersky ja HJT

    KASPERSKY ONLINE SCANNER 7 REPORT
    Monday, September 15, 2008
    Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
    Kaspersky Online Scanner 7 version: 7.0.25.0
    Program database last update: Sunday, September 14, 2008 23:36:45
    Records in database: 1230716
    --------------------------------------------------------------------------------

    Scan settings:
    Scan using the following database: extended
    Scan archives: yes
    Scan mail databases: yes

    Scan area - My Computer:
    A:\
    C:\
    D:\
    E:\
    F:\

    Scan statistics:
    Files scanned: 42760
    Threat name: 0
    Infected objects: 0
    Suspicious objects: 0
    Duration of the scan: 01:30:10

    No malware has been detected. The scan area is clean.

    The selected area was scanned.


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:11:12, on 15.9.2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Sygate\SPF\smc.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\WINDOWS\StartupMonitor.exe
    C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
    C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
    C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\AVG\AVG8\avgui.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.telkku.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {A99091B0-D5C1-40DF-BF12-8F929063A311} - C:\Documents and Settings\Sami\Local Settings\Temporary Internet Files\Content.IE5\GACH46F5\3077htsbdjyf[1].dll (file missing)
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
    O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve')
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1199268633166
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: avgrsstx.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

    --
    End of file - 5672 bytes




    Kiitos taas Hujo ja laitahan mulle hommia vaan :)

     
  17. yaht

    yaht Regular member

    Liittynyt:
    07.12.2005
    Viestejä:
    2,261
    Kiitokset:
    0
    Pisteet:
    46
    Moro pistän tähän väliin vähän ohjeita eli otetaan vähän enemmän selvää mitä kaikkea sieltä koneelta löytyy.

    * Lataa tästä random's system information tool (RSIT) by random/random ja tallenna se työpöydälle
    * Tuplaklikkaa RSIT.exeä ajaaksesi RSITin.
    * Klikkaa Continue.
    * Kun RSIT on valmis, kaksi lokia avautuu muistioon. Lähetä sekä log.txt:n (<<avautuu suurennettuna) että info.txt:n (<<avautuu pienennettynä) sisältö seuraavassa viestissäsi.



    Lataa ja tallenna Blacklight työpöydällesi;

    Tupla-klikkaa fsbl.exe, hyväksy sopimus, klikkaa > Scan, sitten > Next

    Näet listan kaikesta mitä löytyi. Työpöydällesi myös ilmestyy loki jonka nimi on fsbl.xxxxxxx.log (xxxxxxx;n tilalla on luultavimmin numeroita).

    Kopioi ja liitä tämä loki seuraavaan vastaukseesi. Älä valitse "Rename" optiota vielä! Haluamme nähdä login ensin, koska hyviä tiedostoja saattaa olla mukana, kuten "wbemtest.exe".
     
    Viimeksi muokattu: 15.09.2008
  18. samipami

    samipami Member

    Liittynyt:
    07.03.2006
    Viestejä:
    55
    Kiitokset:
    0
    Pisteet:
    16
    Logfile of random's system information tool 1.01 (written by random/random)
    Run by Sami at 2008-09-15 15:14:48
    Microsoft Windows XP Home Edition Service Pack 3
    System drive C: has 16 GB (52%) free of 30 GB
    Total RAM: 2047 MB (69% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 15:14:56, on 15.9.2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Sygate\SPF\smc.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\WINDOWS\StartupMonitor.exe
    C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
    C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
    C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Secunia\PSI (RC3)\psi.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Sami\Työpöytä\RSIT.exe
    C:\Program Files\Trend Micro\HijackThis\Sami.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.telkku.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {A99091B0-D5C1-40DF-BF12-8F929063A311} - C:\Documents and Settings\Sami\Local Settings\Temporary Internet Files\Content.IE5\GACH46F5\3077htsbdjyf[1].dll (file missing)
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
    O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve')
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1199268633166
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: avgrsstx.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

    --
    End of file - 5616 bytes

    Scheduled tasks folder

    C:\WINDOWS\tasks\RegCure Program Check.job
    C:\WINDOWS\tasks\RegCure.job

    Registry dump

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
    AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2008-08-29 455960]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
    Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2008-07-07 1562448]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
    Windows Liven kirjautumisapuohjelma - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A99091B0-D5C1-40DF-BF12-8F929063A311}]
    C:\Documents and Settings\Sami\Local Settings\Temporary Internet Files\Content.IE5\GACH46F5\3077htsbdjyf[1].dll []

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "BluetoothAuthenticationAgent"=C:\WINDOWS\system32\bthprops.cpl [2008-04-14 110592]
    "StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-01-21 61440]
    "AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-08-29 1235736]
    "SmcService"=C:\PROGRA~1\Sygate\SPF\smc.exe [2004-10-15 2577632]
    "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-05-27 413696]
    "Run StartupMonitor"=C:\WINDOWS\StartupMonitor.exe [2000-05-20 86016]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2008-08-11 1124352]
    "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
    C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
    F:\Program Files\Steam\Steam.exe [2008-09-04 1271032]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Käynnistä-valikko^Ohjelmat^Käynnistys^LaunchU3.exe.lnk]
    C:\WINDOWS\INSTAL~1\{D8E36~1\_294823.exe [2008-09-05 22486]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLS"="avgrsstx.dll"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
    C:\WINDOWS\system32\Ati2evxx.dll [2008-06-03 139264]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2008-05-26 304128]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000"
    "C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
    "C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
    "C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox"
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
    "C:\Program Files\Windows Media Player\wmplayer.exe"="C:\Program Files\Windows Media Player\wmplayer.exe:*:Enabled:Windows Media Player"
    "C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
    "C:\WINDOWS\system32\dxdiag.exe"="C:\WINDOWS\system32\dxdiag.exe:*:Enabled:Microsoft DirectX Diagnostic Tool"
    "C:\WINDOWS\system32\dpnsvr.exe"="C:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server"
    "F:\Pelit\Return to Castle Wolfenstein\WolfMP.exe"="F:\Pelit\Return to Castle Wolfenstein\WolfMP.exe:*:Enabled:WolfMP"
    "C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
    "C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
    "C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe"="C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Disabled:Nokia Software Updater"
    "C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe"="C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process "

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000"
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f5b062a5-2f54-11dd-a797-00508dc84ead}]
    shell\AutoRun\command - H:\LaunchU3.exe -a


    List of files/folders created in the last three months

    2008-09-15 15:03:35 ----D---- C:\rsit
    2008-09-15 14:37:12 ----D---- C:\Program Files\Secunia
    2008-09-15 14:36:55 ----D---- C:\WINDOWS\LastGood
    2008-09-15 14:19:19 ----D---- C:\Avenger
    2008-09-15 14:19:18 ----A---- C:\avenger.txt
    2008-09-15 11:46:27 ----D---- C:\Documents and Settings\Sami\Application Data\Apple Computer
    2008-09-15 10:16:47 ----D---- C:\Documents and Settings\Sami\Application Data\KC Softwares
    2008-09-15 10:16:00 ----D---- C:\Program Files\KC Softwares
    2008-09-11 11:53:44 ----SHD---- C:\Config.Msi
    2008-09-11 04:43:29 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
    2008-09-11 04:42:55 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
    2008-09-08 17:50:43 ----SHD---- C:\RECYCLER
    2008-09-07 04:16:30 ----D---- C:\WINDOWS\temp
    2008-09-05 02:40:25 ----D---- C:\Documents and Settings\All Users\Application Data\U3
    2008-09-04 13:45:54 ----D---- C:\Program Files\QuickTime
    2008-09-02 11:57:06 ----A---- C:\WINDOWS\ModemLog_Tavallinen modeemi Bluetooth-linkin kautta.txt
    2008-09-02 08:54:53 ----D---- C:\Program Files\Common Files\PCSuite
    2008-09-02 08:54:51 ----D---- C:\Program Files\Common Files\Nokia
    2008-09-02 08:53:38 ----D---- C:\Program Files\PC Connectivity Solution
    2008-09-01 17:44:29 ----D---- C:\Downloads
    2008-08-29 16:26:12 ----D---- C:\Program Files\DIFX
    2008-08-29 00:39:46 ----D---- C:\Program Files\RegSeeker
    2008-08-26 20:56:13 ----A---- C:\index.ini
    2008-08-26 18:15:55 ----A---- C:\WINDOWS\system32\javaws.exe
    2008-08-26 18:15:55 ----A---- C:\WINDOWS\system32\javaw.exe
    2008-08-26 18:15:55 ----A---- C:\WINDOWS\system32\java.exe
    2008-08-26 16:35:24 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
    2008-08-26 12:03:16 ----D---- C:\WINDOWS\ERUNT
    2008-08-26 01:46:13 ----D---- C:\WINDOWS\erdnt
    2008-08-26 01:36:24 ----D---- C:\Documents and Settings\All Users\Application Data\PrevxCSI
    2008-08-26 00:16:05 ----D---- C:\Documents and Settings\Sami\Application Data\Malwarebytes
    2008-08-26 00:16:01 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-08-25 23:59:59 ----D---- C:\Program Files\Spybot - Search & Destroy
    2008-08-25 23:59:59 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-08-22 19:00:51 ----A---- C:\WINDOWS\system32\SSSensor.dll
    2008-08-22 19:00:48 ----D---- C:\Program Files\Sygate
    2008-08-16 07:58:34 ----HD---- C:\$AVG8.VAULT$
    2008-08-16 05:45:10 ----D---- C:\Program Files\RegCure
    2008-08-16 00:51:54 ----A---- C:\WINDOWS\system32\5ffb078d-.txt
    2008-08-16 00:48:59 ----A---- C:\WINDOWS\system32\avgrsstx.dll
    2008-08-15 22:01:00 ----D---- C:\Documents and Settings\Sami\Application Data\Windows Search
    2008-08-15 22:00:34 ----HDC---- C:\WINDOWS\$NtUninstallKB951618-v2$
    2008-08-15 22:00:29 ----D---- C:\Documents and Settings\Sami\Application Data\Windows Desktop Search
    2008-08-15 21:59:52 ----D---- C:\Program Files\Windows Desktop Search
    2008-08-15 21:59:51 ----D---- C:\WINDOWS\system32\GroupPolicy
    2008-08-15 21:59:33 ----HDC---- C:\WINDOWS\$NtUninstallKB940157$
    2008-08-15 21:59:26 ----HDC---- C:\WINDOWS\$NtUninstallKB915800-v4$
    2008-08-15 18:13:00 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
    2008-08-15 18:12:54 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
    2008-08-15 18:12:47 ----HDC---- C:\WINDOWS\$NtUninstallKB953839$
    2008-08-15 18:12:40 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
    2008-08-15 18:11:24 ----HDC---- C:\WINDOWS\$NtUninstallKB951072-v2$
    2008-08-15 18:11:17 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
    2008-08-15 18:10:44 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
    2008-08-07 07:46:21 ----D---- C:\Documents and Settings\All Users\Application Data\RTL Winter Sports 2008
    2008-08-05 19:04:10 ----D---- C:\Documents and Settings\All Users\Application Data\ATI
    2008-08-01 05:53:25 ----D---- C:\Documents and Settings\Sami\Application Data\Nokia
    2008-08-01 05:53:22 ----D---- C:\Documents and Settings\Sami\Application Data\PC Suite
    2008-08-01 05:28:16 ----D---- C:\Program Files\Nokia
    2008-07-31 12:17:52 ----D---- C:\Program Files\Sygate(2)
    2008-07-25 07:11:42 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
    2008-07-25 03:23:36 ----D---- C:\Documents and Settings\All Users\Application Data\ATI(2)
    2008-07-25 03:20:41 ----D---- C:\Program Files\ATI
    2008-07-25 00:13:15 ----D---- C:\Documents and Settings\All Users\Application Data\Disk Cleaner
    2008-07-09 13:08:23 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
    2008-07-09 13:07:31 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
    2008-07-07 19:04:37 ----D---- C:\WINDOWS\Logs
    2008-07-05 09:20:28 ----A---- C:\WINDOWS\ATICIM.INI
    2008-07-05 06:05:23 ----D---- C:\Documents and Settings\All Users\Application Data\Registry Helper
    2008-07-02 23:50:49 ----D---- C:\Documents and Settings\Sami\Application Data\OpenOffice.org2
    2008-07-02 23:49:48 ----D---- C:\Program Files\OpenOffice.org 2.4
    2008-06-26 22:32:04 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
    2008-06-17 09:26:28 ----A---- C:\WINDOWS\Alcmtr.exe
    2008-06-16 21:09:19 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
    2008-06-16 21:09:18 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
    2008-06-16 21:09:17 ----A---- C:\WINDOWS\system32\xinput1_3.dll
    2008-06-16 21:09:17 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
    2008-06-16 21:09:17 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
    2008-06-16 21:09:17 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
    2008-06-16 21:09:16 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
    2008-06-16 21:09:16 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
    2008-06-16 21:09:15 ----A---- C:\WINDOWS\system32\xinput1_2.dll
    2008-06-16 21:09:15 ----A---- C:\WINDOWS\system32\xinput1_1.dll
    2008-06-16 21:09:15 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
    2008-06-16 21:09:14 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
    2008-06-16 21:09:07 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
    2008-06-16 21:09:06 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
    2008-06-16 21:09:06 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
    2008-06-16 21:09:05 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
    2008-06-16 21:09:05 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
    2008-06-16 21:09:04 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
    2008-06-16 21:09:04 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
    2008-06-16 21:09:03 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
    2008-06-16 21:09:03 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
    2008-06-16 21:09:01 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
    2008-06-16 21:01:38 ----D---- C:\Documents and Settings\Sami\Application Data\DAEMON Tools
    2008-06-16 12:35:01 ----D---- C:\Documents and Settings\Sami\Application Data\Ashampoo

    List of drivers

    R1 AvgLdx86;AVG AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-08-29 97928]
    R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2008-08-22 26824]
    R1 kbdhid;Näppäimistön HID-ohjain; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
    R1 wpsdrvnt;wpsdrvnt; \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys []
    R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2008-08-07 278728]
    R2 AvgTdiX;AVG8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2008-08-22 76040]
    R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2008-08-07 25416]
    R2 tmcomm;tmcomm; \??\C:\WINDOWS\system32\drivers\tmcomm.sys []
    R2 wg3n;SyGate for NT, wg3n; C:\WINDOWS\SYSTEM32\Drivers\wg3n.sys [2004-10-15 14568]
    R2 wg4n;SyGate for NT, wg4n; C:\WINDOWS\SYSTEM32\Drivers\wg4n.sys [2004-10-15 14568]
    R2 wg5n;SyGate for NT, wg5n; C:\WINDOWS\SYSTEM32\Drivers\wg5n.sys [2004-10-15 14568]
    R2 wg6n;SyGate for NT, wg6n; C:\WINDOWS\SYSTEM32\Drivers\wg6n.sys [2004-10-15 14568]
    R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-06-03 3100160]
    R3 ATIAVAIW;ATI T200 Unified AVStream service; C:\WINDOWS\system32\DRIVERS\atinavt2.sys [2008-05-15 171520]
    R3 BthEnum;Bluetooth-pyyntölohkojen ohjain; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
    R3 BTHMODEM;Bluetooth-modeemiyhteyden ohjain; C:\WINDOWS\system32\DRIVERS\bthmodem.sys [2008-04-13 37888]
    R3 BthPan;Bluetooth-laite (henkilökohtainen lähiverkko); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
    R3 BTHUSB;Bluetooth-radion USB-ohjain; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
    R3 HDAudBus;Microsoft UAA -väyläohjain (High Definition Audio); C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
    R3 HidUsb;Microsoft HID -luokkaohjain; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
    R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-06-02 4752384]
    R3 mouhid;Hiiren HID-ohjain; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-05 12160]
    R3 NTIDrvr;Upper Class Filter Driver; C:\WINDOWS\system32\DRIVERS\NTIDrvr.sys [2008-05-16 6912]
    R3 PSI;PSI; C:\WINDOWS\system32\DRIVERS\psi_mf.sys [2008-06-16 7808]
    R3 RFCOMM;Bluetooth-laite (RFCOMM-protokollan TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
    R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2008-01-02 85120]
    R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
    R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
    R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
    R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
    R3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688]
    S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter; C:\WINDOWS\system32\DRIVERS\ADM8511.SYS [2001-08-17 20160]
    S3 BTHPORT;Bluetooth-porttiohjain; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 272128]
    S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
    S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys []
    S3 ezplay;VSO Software ezplay; C:\WINDOWS\System32\Drivers\ezplay.sys [2008-05-19 94208]
    S3 MPE;BDA MPE Filter; C:\WINDOWS\system32\DRIVERS\MPE.sys [2008-04-13 15232]
    S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink -muunnin; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
    S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
    S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
    S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
    S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2008-05-19 47360]
    S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
    S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
    S3 TVICHW32;TVICHW32; \??\C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS []
    S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys []
    S3 USBSTOR;USB-massamuistiohjain; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
    S3 w810bus;Sony Ericsson W810 Driver driver (WDM); C:\WINDOWS\system32\DRIVERS\w810bus.sys [2008-02-15 58288]
    S3 w810mdfl;Sony Ericsson W810 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\w810mdfl.sys [2008-02-15 8336]
    S3 w810mdm;Sony Ericsson W810 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\w810mdm.sys [2008-02-15 94064]
    S3 w810mgmt;Sony Ericsson W810 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\w810mgmt.sys [2008-02-15 85408]
    S3 w810obex;Sony Ericsson W810 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\w810obex.sys [2008-02-15 83344]
    S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
    S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
    S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
    S4 vsdatant;vsdatant; C:\WINDOWS\system32\drivers\vsdatant.sys []

    List of services

    R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-06-03 552960]
    R2 avg8emc;AVG8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-29 875288]
    R2 avg8wd;AVG8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-29 231704]
    R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
    R2 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
    R2 SmcService;Sygate Personal Firewall; C:\Program Files\Sygate\SPF\smc.exe [2004-10-15 2577632]
    R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
    R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
    R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-08-07 575488]
    S3 aspnet_state;ASP.NET-tilapalvelu; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
    S3 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2008-06-02 593920]
    S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
    S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
    S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
    S3 usnjsvc;Messengerin jaettavien kansioiden USN Journal -lokin lukupalvelu; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
    S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
    S3 WMPNetworkSvc;Windows Media Playerin verkkojakamispalvelu; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-15 913920]
    S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]

    -----------------EOF-----------------








     
  19. samipami

    samipami Member

    Liittynyt:
    07.03.2006
    Viestejä:
    55
    Kiitokset:
    0
    Pisteet:
    16
    info.txt logfile of random's system information tool 1.01 2008-09-15 15:03:47

    Uninstall list

    -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
    Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
    Adobe Reader 8.1.2 - Suomi-->MsiExec.exe /I{AC76BA86-7AD7-1035-7B44-A81200000003}
    ATI - Software Uninstall Utility-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
    ATI Catalyst Control Center-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{055EE59D-217B-43A7-ABFF-507B966405D8}\setup.exe" -l0x6974
    ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
    AVG Free 8.0-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
    CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
    DriverAgent by TouchStone Software-->RunDll32.exe advpack.dll,LaunchINFSection driveragent_exe.inf,TVICHW32Remove
    DriverAgent Plugin for Netscape by TouchStone Software-->RunDll32.exe advpack.dll, LaunchINFSection driveragent_np.inf,TVICHW32Remove
    Full Tilt Poker-->"C:\Program Files\InstallShield Installation Information\{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}\setup.exe" -runfromtemp -l0x0009 -removeonly
    GTA San Andreas-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\setup.exe" -l0x9 -removeonly
    Half-Life-->"F:\Program Files\Steam\steam.exe" steam://uninstall/70
    High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
    HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
    Hotfix for Microsoft .NET Framework 3.0 (KB932471)-->C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {ECD292A0-0347-4244-8C24-5DBCE990FB40} /package {BAF78226-3200-4DB4-BE33-4D922A799840}
    Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
    Hotfix for Windows XP (KB915800-v4)-->"C:\WINDOWS\$NtUninstallKB915800-v4$\spuninst\spuninst.exe"
    Hotfix-korjauspäivitys Windows Media Player 11:lle (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
    Hotfix-päivitys Windows Internet Explorer 7:lle (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
    Hotfix-päivitys Windows XP:lle (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
    IrfanView (remove only)-->C:\Program Files\IrfanView\iv_uninstall.exe
    Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
    KC Softwares KCleaner-->"C:\Program Files\KC Softwares\KCleaner\unins000.exe"
    Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
    Microsoft .NET Framework 1.1 Finnish Language Pack-->MsiExec.exe /X{4538A1AF-6894-4F10-ABDA-6CB9E6ACF8B6}
    Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
    Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    Microsoft .NET Framework 2.0 Language Pack - FIN-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FIN\install.exe
    Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
    Microsoft .NET Framework 3.0 Finnish Language Pack-->MsiExec.exe /X{0836C2CD-3695-40CA-9491-4CB1C697FF84}
    Microsoft .NET Framework 3.0 Service Pack 1-->MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783}
    Microsoft .NET Framework 3.0:n suomen kielipaketti-->c:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 Finnish Language Pack\setup.exe
    Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
    Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
    Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
    Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
    Microsoft User-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWudf01005$\spuninst\spuninst.exe"
    Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
    Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
    Mozilla Firefox (3.0.1)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
    MSVC80_x86-->MsiExec.exe /I{212748BB-0DA5-46DE-82A1-403736DC9F27}
    MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
    MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
    Nokia Connectivity Cable Driver-->MsiExec.exe /X{C3F19A5F-35A8-4FDB-A6ED-0F4CE398DA48}
    Nokia Flashing Cable Driver-->MsiExec.exe /X{2A0A6470-FD0F-4F45-9B11-85F3167DB943}
    Nokia PC Suite-->C:\Documents and Settings\All Users\Application Data\Installations\{A8C3710A-0BCA-4F10-9EC3-A302A1F1FA82}\Nokia_PC_Suite_rel_7_0_8_2_fin.exe
    Nokia PC Suite-->MsiExec.exe /I{A8C3710A-0BCA-4F10-9EC3-A302A1F1FA82}
    Nokia Software Updater-->MsiExec.exe /X{48110A46-A3A4-481E-8230-7873B7F4C696}
    PC Connectivity Solution-->MsiExec.exe /I{1A524CFE-DF85-4555-8BC2-0C89DBD8BC2C}
    Päivitys Windows XP:lle (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
    Päivitys Windows XP:lle (KB951618-v2)-->"C:\WINDOWS\$NtUninstallKB951618-v2$\spuninst\spuninst.exe"
    Päivitys Windows XP:lle (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
    QuickTime-->MsiExec.exe /I{08CA9554-B5FE-4313-938F-D4A417B81175}
    REALTEK GbE & FE Ethernet PCI NIC Driver-->C:\Program Files\InstallShield Installation Information\{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}\setup.exe -runfromtemp -l0x000b -removeonly
    Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0xb -removeonly
    RTL Winter Sports 2008-->"F:\Pelit\RTL Winter Sports 2008\Uninstall.exe"
    Secunia NSI-->"C:\Program Files\Secunia\NSI\uninstall.exe"
    Secunia PSI (RC3)-->"C:\Program Files\Secunia\PSI (RC3)\uninstall.exe"
    Skype™ 3.6-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
    Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
    StartupMonitor-->MsiExec.exe /I{76EFAC4F-1712-401F-B2AE-590B170C9BCE}
    Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
    Suojauspäivitys ohjelmistolle Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
    Suojauspäivitys Windows Internet Explorer 7:lle (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
    Suojauspäivitys Windows Internet Explorer 7:lle (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
    Suojauspäivitys Windows Internet Explorer 7:lle (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
    Suojauspäivitys Windows Internet Explorer 7:lle (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
    Suojauspäivitys Windows Internet Explorer 7:lle (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
    Suojauspäivitys Windows Media Player 11:lle (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
    Suojauspäivitys Windows Media Player 11:lle (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
    Suojauspäivitys Windows XP:lle (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
    Suojauspäivitys Windows XP:lle (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
    Suojauspäivitys Windows XP:lle (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
    Suojauspäivitys Windows XP:lle (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
    Suojauspäivitys Windows XP:lle (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
    Suojauspäivitys Windows XP:lle (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
    Suojauspäivitys Windows XP:lle (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
    Suojauspäivitys Windows XP:lle (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
    Suojauspäivitys Windows XP:lle (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
    Suojauspäivitys Windows XP:lle (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
    Suojauspäivitys Windows XP:lle (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
    Suojauspäivitys Windows XP:lle (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
    Suojauspäivitys Windows XP:lle (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
    Sygate Personal Firewall-->MsiExec.exe /I{F34D9A5F-484A-4E31-A9D3-908CB265B289}
    Terrorist Takedown 2 (1.01)-->"F:\Pelit\Terrorist Takedown 2\unins000.exe"
    U3Launcher-->MsiExec.exe /I{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}
    Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
    Windows Live installer-->MsiExec.exe /X{5C29C5F5-A9C9-4E89-A606-13E165E7C55F}
    Windows Live Messenger-->MsiExec.exe /X{A9174A72-1B46-445B-B3CF-90ED2C63D83B}
    Windows Liven kirjautumisavustaja-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
    Windows Liven sähköposti-->MsiExec.exe /I{9F7ABBFD-53FB-4D36-891E-8A9E753CF65F}
    Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
    Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
    Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
    Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
    Windows Presentation Foundation Language Pack (FIN)-->MsiExec.exe /X{935FADCB-C25B-4F62-B9B4-F22C40431642}
    Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
    Windows Search 4.0-->"C:\WINDOWS\$NtUninstallKB940157$\spuninst\spuninst.exe"
    Windows Workflow Foundation FI Language Pack-->MsiExec.exe /I{8E5D0B52-BB72-46C6-8AB8-2B041D959594}
    Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
    Windowsin ohjainpaketti - Nokia Modem (05/22/2008 3.8)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokia_blue_6F90B0F4A73A2F780A1010B5D6CB5DDFB098181E\nokia_bluetooth.inf
    Windowsin ohjainpaketti - Nokia Modem (05/22/2008 7.00.0.1)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokbtmdm_E68D50F7E25BFE399D47C864C3B52557346242A9\nokbtmdm.inf
    Windowsin ohjainpaketti - Nokia pccsmcfd (10/12/2007 6.85.4.0)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccsmcfd_4A1E30386F4D0DEC8F5DF262CFBD8845EEBAB175\pccsmcfd.inf
    WinRAR-pakkausohjelma-->C:\Program Files\WinRAR\uninstall.exe
    XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"

    Hosts File

    127.0.0.1 localhost

    Security center information

    AV: AVG Anti-Virus Free
    FW: Sygate Personal Firewall

    Environment variables

    "ComSpec"=%SystemRoot%\system32\cmd.exe
    "FP_NO_HOST_CHECK"=NO
    "NUMBER_OF_PROCESSORS"=2
    "OS"=Windows_NT
    "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\PC Connectivity Solution;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files\QuickTime\QTSystem
    "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    "PROCESSOR_ARCHITECTURE"=x86
    "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 6 Stepping 2, GenuineIntel
    "PROCESSOR_LEVEL"=15
    "PROCESSOR_REVISION"=0602
    "TEMP"=%SystemRoot%\TEMP
    "TMP"=%SystemRoot%\TEMP
    "windir"=%SystemRoot%
    "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
    "QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

    -----------------EOF-----------------
     
  20. samipami

    samipami Member

    Liittynyt:
    07.03.2006
    Viestejä:
    55
    Kiitokset:
    0
    Pisteet:
    16
    09/15/08 15:39:17 [Info]: BlackLight Engine 1.0.70 initialized
    09/15/08 15:39:17 [Info]: OS: 5.1 build 2600 (Service Pack 3)
    09/15/08 15:39:17 [Note]: 7019 4
    09/15/08 15:39:17 [Note]: 7005 0
    09/15/08 15:39:48 [Note]: 7006 0
    09/15/08 15:39:48 [Note]: 7011 204
    09/15/08 15:39:48 [Note]: 7035 0
    09/15/08 15:39:48 [Note]: 7026 0
    09/15/08 15:39:48 [Note]: 7026 0
    09/15/08 15:39:52 [Note]: FSRAW library version 1.7.1024
     
  21. samipami

    samipami Member

    Liittynyt:
    07.03.2006
    Viestejä:
    55
    Kiitokset:
    0
    Pisteet:
    16
    Voisiko joku auttaa kiitos.....
     

Jaa tämä sivu