Logfile of HijackThis v1.99.1 Scan saved at 18:08:40, on 2.1.2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Creative\Shared Files\CAMTRAY.EXE C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\ATKKBService.exe C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE C:\WINDOWS\system32\svchost.exe C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fsrw.exe C:\Program Files\F-Secure Internet Security\FSPC\fspc.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe C:\PROGRA~1\F-SECU~1\ANTI-S~1\fsaw.exe C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\hjt\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.accoona.com/search_assistant/accoona_search_assistant.... R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.accoona.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.accoona.com/search_assistant/accoona_search_assistant.... R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.accoona.com/search?q=%s R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit R3 - Default URLSearchHook is missing O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll O2 - BHO: Accoona Search Assistant - {944864A5-3916-46E2-96A9-A2E84F3F1208} - C:\Program Files\Accoona\ASearchAssist.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll O3 - Toolbar: Accoona - {364B6276-C6C1-40B6-A6D7-6C48871FD707} - C:\Program Files\Accoona\atoolbar.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: F-Secure 2006.lnk = C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe O8 - Extra context menu item: &Estä tämä kohoikkuna - C:\Program Files\F-Secure Internet Security\Anti-Spyware\blockpopups.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra button: Web-suodatin - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll O9 - Extra 'Tools' menuitem: Web-suodatin - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll O9 - Extra button: IE-suojaus - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll O9 - Extra 'Tools' menuitem: IE-suojaus... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Broken Internet access because of LSP provider 'winsflt.dll' missing O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31... O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe O23 - Service: F-Secure 2006 (BackWeb Plug-in - 4476822) - F-Secure Internet Security 2005 - C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSPC\fshttps\fshttps.exe O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Poista ohjauspaneelista (lisää/poista sovellus): Accoona Toolbar Fixaa HjT:llä (do a system scan only, merkkaa ja paina fix checked): R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.accoona.com/search_assistant/accoona_search_assistant.... R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.accoona.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.accoona.com/search_assistant/accoona_search_assistant.... R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.accoona.com/search?q=%s R3 - Default URLSearchHook is missing O2 - BHO: Accoona Search Assistant - {944864A5-3916-46E2-96A9-A2E84F3F1208} - C:\Program Files\Accoona\ASearchAssist.dll O3 - Toolbar: Accoona - {364B6276-C6C1-40B6-A6D7-6C48871FD707} - C:\Program Files\Accoona\atoolbar.dll Käynnistä vikasietotilaan (F8 käynnuistyksen yhteydessä) ja poista: C:\Program Files\==>Accoona<== Käynnistä uudelleen ja lähetä uusi HjT-loki
eli tässä... Logfile of HijackThis v1.99.1 Scan saved at 0:02:55, on 3.1.2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Creative\Shared Files\CAMTRAY.EXE C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\WINDOWS\ATKKBService.exe C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE C:\WINDOWS\system32\svchost.exe C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE C:\Program Files\F-Secure Internet Security\Anti-Virus\fsrw.exe C:\Program Files\F-Secure Internet Security\FSPC\fspc.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe C:\WINDOWS\system32\wscntfy.exe C:\PROGRA~1\F-SECU~1\ANTI-S~1\fsaw.exe C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\hjt\HijackThis.exe R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.accoona.com/search_assis...urce=wdz&utm_medium=bund&utm_campaign=wdz0605 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: F-Secure 2006.lnk = C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe O8 - Extra context menu item: &Estä tämä kohoikkuna - C:\Program Files\F-Secure Internet Security\Anti-Spyware\blockpopups.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra button: Web-suodatin - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll O9 - Extra 'Tools' menuitem: Web-suodatin - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll O9 - Extra button: IE-suojaus - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll O9 - Extra 'Tools' menuitem: IE-suojaus... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Broken Internet access because of LSP provider 'winsflt.dll' missing O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe O23 - Service: F-Secure 2006 (BackWeb Plug-in - 4476822) - F-Secure Internet Security 2005 - C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSPC\fshttps\fshttps.exe O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Fixaa vielä HjT:llä (do a system scan only, merkkaa ja paina fix checked): R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.accoona.com/search_assistant/accoona_search_assistant.... Voit vielä makusi mukaan fixata seuraavat(nopeuttaa konetta): O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe Viimeistele puhdistus ewidon avulla -> http://keskustelu.afterdawn.com/thread_view.cfm/269186 Tee ohjeiden mukaan ja lähetä sen raportti tänne!
yritin fixata tota accoonaa mutta ei se suostunu lähteen vaan tulee aina uudelleen ... tulee vaan ikkuna jossa jotain "this will permanently delete and/or repair what you selected, unless you make a backup." ja kyllä tai ei. --------------------------------------------------------- ewido anti-malware - Scan report --------------------------------------------------------- + Created on: 9:33:06, 4.1.2006 + Report-Checksum: 2FEA6ECB + Scan result: HKU\S-1-5-21-2182677158-2471696561-3394613557-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000EF1-0786-4633-87C6-1AA7A44296DA} -> Spyware.FavoriteMan : Cleaned with backup :mozilla.6:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.7:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.10:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.13:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.14:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.15:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.17:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.18:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.19:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.105:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup :mozilla.106:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup :mozilla.107:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.108:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.109:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.116:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.117:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.122:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.123:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.127:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.128:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.131:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup :mozilla.132:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.133:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.168:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.178:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.185:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.188:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.189:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Counted : Cleaned with backup :mozilla.15:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.23:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup :mozilla.25:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup :mozilla.69:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.99:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.102:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.115:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.116:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.117:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup :mozilla.118:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup :mozilla.136:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.142:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.151:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup :mozilla.157:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.158:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.160:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.161:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.185:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup :mozilla.191:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.192:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.196:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup :mozilla.197:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup :mozilla.199:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.200:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.201:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.202:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.215:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.231:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.232:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.233:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.234:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.235:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup :mozilla.241:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.255:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.279:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.282:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.303:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Counted : Cleaned with backup :mozilla.304:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Counted : Cleaned with backup :mozilla.306:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.308:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.311:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.312:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Adviva : Cleaned with backup :mozilla.313:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup :mozilla.314:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Adviva : Cleaned with backup :mozilla.317:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.326:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup :mozilla.343:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Juha\Cookies\juha@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.10:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.15:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.26:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.31:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup :mozilla.32:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup :mozilla.33:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.35:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.36:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.37:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.38:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.39:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.44:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup :mozilla.13:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\vjntiy04.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.18:C:\Documents and Settings\Mari\Application Data\Mozilla\Firefox\Profiles\gkpkanj2.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.38:C:\Documents and Settings\Mari\Application Data\Mozilla\Firefox\Profiles\gkpkanj2.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.22:C:\Documents and Settings\oem\Application Data\Mozilla\Firefox\Profiles\m3yan8sd.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.35:C:\Documents and Settings\oem\Application Data\Mozilla\Firefox\Profiles\m3yan8sd.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.36:C:\Documents and Settings\oem\Application Data\Mozilla\Firefox\Profiles\m3yan8sd.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.37:C:\Documents and Settings\oem\Application Data\Mozilla\Firefox\Profiles\m3yan8sd.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.46:C:\Documents and Settings\oem\Application Data\Mozilla\Firefox\Profiles\m3yan8sd.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.22:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.23:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.24:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.25:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.26:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup :mozilla.81:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.98:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.99:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.108:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.111:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup :mozilla.112:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup :mozilla.116:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.117:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.118:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.130:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.139:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.140:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup :mozilla.161:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.162:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.163:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.164:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.165:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.166:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.175:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup :mozilla.176:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup C:\Documents and Settings\Päivi\Cookies\päivi@msnportal.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup C:\hjt\backups\backup-20060102-233249-163.dll -> Adware.Agent : Cleaned with backup ::Report End
jop. poistin vikasietotilassa programfiles -> accoona mutta eipä lähteny tuolta hjt:ltä meneen. mitä ne hjt:n backupit on? pitääkö ne poistaa?
Siis fixasitko tämän rivin HjT:llä vikasiedossa? R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.accoona.com/search_assistant/accoona_search_assistant.... Jos et, niin tee se nyt.
Hjt tallentaa backupit fixaamisen jälkeen jotta voit palauttaa ne jos syystä tai toisesta menee fixaukset väärin. Lähetä nyt käynnistyvien ohjelmien listan eli Avaa hjt -> open the misc tools section -> sitten sieltä "Generate startuplist log" Ruksaa vielä enne sitä kohdat "list also minor section" & "list empty sections". Lähetä siten lista tänne.
StartupList report, 4.1.2006, 21:13:25 StartupList version: 1.52.2 Started from : C:\hjt\HijackThis.EXE Detected: Windows XP SP2 (WinNT 5.01.2600) Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180) * Using default options * Including empty and uninteresting sections * Showing rarely important sections ================================================== Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\ATKKBService.exe C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fsrw.exe C:\Program Files\F-Secure Internet Security\FSPC\fspc.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe C:\PROGRA~1\F-SECU~1\ANTI-S~1\fsaw.exe C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\Skype\Phone\Skype.exe C:\hjt\HijackThis.exe -------------------------------------------------- Listing of startup folders: Shell folders Startup: [C:\Documents and Settings\oem\Käynnistä-valikko\Ohjelmat\Käynnistys] *No files* Shell folders AltStartup: *Folder not found* User shell folders Startup: *Folder not found* User shell folders AltStartup: *Folder not found* Shell folders Common Startup: [C:\Documents and Settings\All Users\Käynnistä-valikko\Ohjelmat\Käynnistys] F-Secure 2006.lnk = C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe Shell folders Common AltStartup: *Folder not found* User shell folders Common Startup: *Folder not found* User shell folders Alternate Common Startup: *Folder not found* -------------------------------------------------- Checking Windows NT UserInit: [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] UserInit = C:\WINDOWS\system32\userinit.exe, [HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon] *Registry key not found* [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] *Registry value not found* [HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon] *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run SoundMan = SOUNDMAN.EXE Creative WebCam Tray = C:\Program Files\Creative\Shared Files\CAMTRAY.EXE F-Secure Manager = "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash F-Secure TNB = "C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW F-Secure Startup Wizard = "C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup nwiz = nwiz.exe /install NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce *No values found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx *No values found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run *No values found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce *No values found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\Run *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\Run *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run *Registry key not found* -------------------------------------------------- File association entry for .EXE: HKEY_CLASSES_ROOT\exefile\shell\open\command (Default) = "%1" %* -------------------------------------------------- File association entry for .COM: HKEY_CLASSES_ROOT\comfile\shell\open\command (Default) = "%1" %* -------------------------------------------------- File association entry for .BAT: HKEY_CLASSES_ROOT\batfile\shell\open\command (Default) = "%1" %* -------------------------------------------------- File association entry for .PIF: HKEY_CLASSES_ROOT\piffile\shell\open\command (Default) = "%1" %* -------------------------------------------------- File association entry for .SCR: HKEY_CLASSES_ROOT\scrfile\shell\open\command (Default) = "%1" /S -------------------------------------------------- File association entry for .HTA: HKEY_CLASSES_ROOT\htafile\shell\open\command (Default) = C:\WINDOWS\system32\mshta.exe "%1" %* -------------------------------------------------- File association entry for .TXT: HKEY_CLASSES_ROOT\txtfile\shell\open\command (Default) = %SystemRoot%\system32\NOTEPAD.EXE %1 -------------------------------------------------- Enumerating Active Setup stub paths: HKLM\Software\Microsoft\Active Setup\Installed Components (* = disabled by HKCU twin) [>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP [>{26923b43-4d38-484f-9b9e-de460746276c}] * StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE [>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] * StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP [>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] * StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE [{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] * StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll [{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] * StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install [{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] * StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT [{5945c046-1e7d-11d1-bc44-00c04fd912be}] * StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser [{6BF52A52-394A-11d3-B153-00C04F79FAA6}] * StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub [{7790769C-0471-11d2-AF11-00C04FA35D02}] * StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install [{89820200-ECBD-11cf-8B85-00AA005B4340}] * StubPath = regsvr32.exe /s /n /i:U shell32.dll [{89820200-ECBD-11cf-8B85-00AA005B4383}] * StubPath = %SystemRoot%\system32\ie4uinit.exe -------------------------------------------------- Enumerating ICQ Agent Autostart apps: HKCU\Software\Mirabilis\ICQ\Agent\Apps *Registry key not found* -------------------------------------------------- Load/Run keys from C:\WINDOWS\WIN.INI: load=*INI section not found* run=*INI section not found* Load/Run keys from Registry: HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found* HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found* HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found* HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found* HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found* HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found* HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found* HKCU\..\Windows NT\CurrentVersion\Windows: load= HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs= -------------------------------------------------- Shell & screensaver key from C:\WINDOWS\SYSTEM.INI: Shell=*INI section not found* SCRNSAVE.EXE=*INI section not found* drivers=*INI section not found* Shell & screensaver key from Registry: Shell=Explorer.exe SCRNSAVE.EXE=C:\WINDOWS\system32\ssmypics.scr drivers=*Registry value not found* Policies Shell key: HKCU\..\Policies: Shell=*Registry key not found* HKLM\..\Policies: Shell=*Registry value not found* -------------------------------------------------- Checking for EXPLORER.EXE instances: C:\WINDOWS\Explorer.exe: PRESENT! C:\Explorer.exe: not present C:\WINDOWS\Explorer\Explorer.exe: not present C:\WINDOWS\System\Explorer.exe: not present C:\WINDOWS\System32\Explorer.exe: not present C:\WINDOWS\Command\Explorer.exe: not present C:\WINDOWS\Fonts\Explorer.exe: not present -------------------------------------------------- Checking for superhidden extensions: .lnk: HIDDEN! (arrow overlay: yes) .pif: HIDDEN! (arrow overlay: yes) .exe: not hidden .com: not hidden .bat: not hidden .hta: not hidden .scr: not hidden .shs: HIDDEN! .shb: HIDDEN! .vbs: not hidden .vbe: not hidden .wsh: not hidden .scf: HIDDEN! (arrow overlay: NO!) .url: HIDDEN! (arrow overlay: yes) .js: not hidden .jse: not hidden -------------------------------------------------- Verifying REGEDIT.EXE integrity: - Regedit.exe found in C:\WINDOWS - .reg open command is normal (regedit.exe %1) - Regedit.exe has no CompanyName property! It is either missing or named something else. - Regedit.exe has no OriginalFilename property! It is either missing or named something else. - Regedit.exe has no FileDescription property! It is either missing or named something else. Registry check failed! -------------------------------------------------- Enumerating Browser Helper Objects: (no name) - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (no name) - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} (no name) - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} -------------------------------------------------- Enumerating Task Scheduler jobs: Scheduled scanning task.job -------------------------------------------------- Enumerating Download Program Files: [Checkers Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\msgrchkr.dll CODEBASE = http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab [MessengerStatsClient Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\MessengerStatsPAClient.dll CODEBASE = http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab [Shockwave ActiveX Control] InProcServer32 = C:\WINDOWS\system32\Macromed\Director\SwDir.dll CODEBASE = http://active.macromedia.com/director/cabs/sw.cab [Windows Genuine Advantage Validation Tool] InProcServer32 = C:\WINDOWS\system32\LegitCheckControl.DLL CODEBASE = http://go.microsoft.com/fwlink/?linkid=39204 [Java Plug-in 1.5.0_01] InProcServer32 = C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll CODEBASE = http://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab [MessengerStatsClient Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\messengerstatsclient.dll CODEBASE = http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab [MsnMessengerSetupDownloadControl Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.ocx CODEBASE = http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab [ZoneIntro Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\ZIntro.ocx CODEBASE = http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab [CBreakshotControl Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\Banksht2.dll CODEBASE = http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab [Java Plug-in 1.5.0_01] InProcServer32 = C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll CODEBASE = http://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab [Shockwave Flash Object] InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab -------------------------------------------------- Enumerating Winsock LSP files: NameSpace #1: C:\WINDOWS\System32\mswsock.dll NameSpace #2: C:\WINDOWS\System32\winrnr.dll NameSpace #3: C:\WINDOWS\System32\mswsock.dll Protocol #1: winsflt.dll (file MISSING) Protocol #2: winsflt.dll (file MISSING) Protocol #3: winsflt.dll (file MISSING) Protocol #4: winsflt.dll (file MISSING) Protocol #5: winsflt.dll (file MISSING) Protocol #6: C:\WINDOWS\system32\mswsock.dll Protocol #7: C:\WINDOWS\system32\mswsock.dll Protocol #8: C:\WINDOWS\system32\mswsock.dll Protocol #9: C:\WINDOWS\system32\rsvpsp.dll Protocol #10: C:\WINDOWS\system32\rsvpsp.dll Protocol #11: C:\WINDOWS\system32\mswsock.dll Protocol #12: C:\WINDOWS\system32\mswsock.dll Protocol #13: C:\WINDOWS\system32\mswsock.dll Protocol #14: C:\WINDOWS\system32\mswsock.dll Protocol #15: C:\WINDOWS\system32\mswsock.dll Protocol #16: C:\WINDOWS\system32\mswsock.dll Protocol #17: C:\WINDOWS\system32\mswsock.dll Protocol #18: C:\WINDOWS\system32\mswsock.dll Protocol #19: C:\WINDOWS\system32\mswsock.dll Protocol #20: C:\WINDOWS\system32\mswsock.dll Protocol #21: winsflt.dll (file MISSING) -------------------------------------------------- Enumerating Windows NT/2000/XP services AC2003: System32\Drivers\AC2003.sys (manual start) Microsoft ACPI Driver: system32\DRIVERS\ACPI.sys (system) Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start) AFD: \SystemRoot\System32\drivers\afd.sys (system) Intel AGP Bus Filter: system32\DRIVERS\agp440.sys (system) Service for WDM 3D Audio Driver: system32\drivers\ALCXSENS.SYS (manual start) Service for Realtek AC97 Audio (WDM): system32\drivers\ALCXWDM.SYS (manual start) Hälytys: %SystemRoot%\system32\svchost.exe -k LocalService (disabled) Sovelluskerroksen yhdyskäytäväpalvelu: %SystemRoot%\System32\alg.exe (manual start) Sovellusten hallinta: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start) 1394 ARP -asiakasprotokolla: system32\DRIVERS\arp1394.sys (manual start) Enhanced Display Driver Helper Service: system32\drivers\atkkbnt.sys (system) RAS Asynchronous Media Driver: system32\DRIVERS\asyncmac.sys (manual start) Standardi IDE/ESDI-kiintolevyohjain: system32\DRIVERS\atapi.sys (system) ATK Keyboard Service: C:\WINDOWS\ATKKBService.exe (autostart) ATM ARP Client -protokolla: system32\DRIVERS\atmarpc.sys (manual start) Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Audio Stub Driver: system32\DRIVERS\audstub.sys (manual start) F-Secure 2006: C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE (autostart) BITS-tausta-ajo (Background Intelligent Transfer Service): %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Tietokoneiden selaus: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Closed Caption Decoder: system32\DRIVERS\CCDECODE.sys (manual start) CD-ROM-ohjain: system32\DRIVERS\cdrom.sys (system) Indeksointipalvelu: %SystemRoot%\system32\cisvc.exe (manual start) Leikekirja: %SystemRoot%\system32\clipsrv.exe (disabled) COM+-järjestelmäsovellus: C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start) Salauspalvelut: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) DCOM-palvelinprosessin käynnistys: %SystemRoot%\system32\svchost -k DcomLaunch (autostart) DHCP-asiakas: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Levyohjain: system32\DRIVERS\disk.sys (system) Loogisen levyn hallinnan valvontapalvelu: %SystemRoot%\System32\dmadmin.exe /com (manual start) dmboot: System32\drivers\dmboot.sys (disabled) dmio: System32\drivers\dmio.sys (disabled) dmload: System32\drivers\dmload.sys (disabled) Loogisen levyn hallinta: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start) DNS-asiakas: %SystemRoot%\system32\svchost.exe -k NetworkService (autostart) Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start) EIO: \??\C:\WINDOWS\system32\drivers\EIO.sys (autostart) ENTECH: \??\C:\WINDOWS\system32\DRIVERS\ENTECH.SYS (manual start) Virheraportointipalvelut: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Tapahtumaloki: %SystemRoot%\system32\services.exe (autostart) COM+-tapahtumajärjestelmä: C:\WINDOWS\system32\svchost.exe -k netsvcs (manual start) ewido security suite control: C:\Program Files\ewido anti-malware\ewidoctrl.exe (autostart) F-Secure File System Filter: \??\C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSfilter.sys (autostart) F-Secure Gatekeeper: \??\C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSgk.sys (autostart) FSGKHS: "C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe" (autostart) F-Secure File System Recognizer: \??\C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSrec.sys (autostart) Nopean käyttäjän vaihdon yhteensopivuus: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) Levykeaseman ohjain: system32\DRIVERS\fdc.sys (manual start) Levykeasemaohjain: system32\DRIVERS\flpydisk.sys (manual start) FltMgr: system32\DRIVERS\fltMgr.sys (system) fsbwsys: "C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe" (autostart) F-Secure Anti-Virus Firewall Daemon: "C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe" (manual start) F-Secure Firewall Driver: System32\drivers\fsdfw.sys (system) F-Secure HTTP Server: "C:\Program Files\F-Secure Internet Security\FSPC\fshttps\fshttps.exe" (manual start) F-Secure Management Agent: "C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE" (autostart) Volume Manager -ohjain: system32\DRIVERS\ftdisk.sys (system) GEAR CDRom Filter: SYSTEM32\DRIVERS\GEARAspiWDM.sys (manual start) Yleinen paketinmääritys: system32\DRIVERS\msgpc.sys (manual start) Ohjeet ja tuotetuki: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) HID (Human Interface Device) -liittymä: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled) Microsoft HID -luokkaohjain: system32\DRIVERS\hidusb.sys (manual start) HTTP: System32\Drivers\HTTP.sys (manual start) HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start) i8042-näppäimistö ja PS/2-hiiriohjain: system32\DRIVERS\i8042prt.sys (system) CD-Burning Filter Driver: system32\DRIVERS\imapi.sys (system) CD-levyjen kirjoittamisen IMAPI COM -palvelu: C:\WINDOWS\system32\imapi.exe (manual start) IntelIde: system32\DRIVERS\intelide.sys (system) Intel-suoritinohjain: system32\DRIVERS\intelppm.sys (system) Windowsin IPv6-palomuurin ohjain: system32\DRIVERS\Ip6Fw.sys (manual start) IP Traffic Filter Driver: system32\DRIVERS\ipfltdrv.sys (manual start) IP in IP Tunnel Driver: system32\DRIVERS\ipinip.sys (manual start) IP Network Address Translator: system32\DRIVERS\ipnat.sys (manual start) iPod Service: "C:\Program Files\iPod\bin\iPodService.exe" (manual start) IPSEC-ohjain: system32\DRIVERS\ipsec.sys (system) IR Enumerator Service: system32\DRIVERS\irenum.sys (manual start) PnP ISA/EISA -väyläohjain: system32\DRIVERS\isapnp.sys (system) jnv4_mib: \??\C:\DOCUME~1\oem\LOCALS~1\Temp\jnv4_mib.sys (manual start) Näppäimistön luokkaohjain: system32\DRIVERS\kbdclass.sys (system) Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start) Palvelin: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Työasema: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) LexBce Server: C:\WINDOWS\system32\LEXBCES.EXE (autostart) TCP/IP NetBIOS Helper: %SystemRoot%\system32\svchost.exe -k LocalService (autostart) Viestinvälitys: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled) NetMeeting etätyöpöydän jakaminen: C:\WINDOWS\system32\mnmsrvc.exe (manual start) Hiiren luokkaohjain: system32\DRIVERS\mouclass.sys (system) Hiiren HID-ohjain: system32\DRIVERS\mouhid.sys (manual start) WebDav Client Redirector: system32\DRIVERS\mrxdav.sys (manual start) MRXSMB: system32\DRIVERS\mrxsmb.sys (system) Distributed Transaction Coordinator: C:\WINDOWS\system32\msdtc.exe (manual start) Windows Installer -ohjelma: C:\WINDOWS\system32\msiexec.exe /V (manual start) Microsoft Streaming Service -välityspalvelin: system32\drivers\MSKSSRV.sys (manual start) Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start) Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start) Microsoft-järjestelmänhallinnan BIOS-ohjain: system32\DRIVERS\mssmbios.sys (manual start) Microsoft Streaming Tee/Sink-to-Sink -muunnin: system32\drivers\MSTEE.sys (manual start) NABTS/FEC VBI Codec: system32\DRIVERS\NABTSFEC.sys (manual start) Microsoft TV/Video Connection: system32\DRIVERS\NdisIP.sys (manual start) Remote Access NDIS TAPI Driver: system32\DRIVERS\ndistapi.sys (manual start) NDIS Usermode I/O -protokolla: system32\DRIVERS\ndisuio.sys (manual start) Remote Access NDIS WAN Driver: system32\DRIVERS\ndiswan.sys (manual start) NetBIOS-käyttöliittymä: system32\DRIVERS\netbios.sys (system) NetBIOS TCP/IP:n päällä: system32\DRIVERS\netbt.sys (system) Verkon DDE: %SystemRoot%\system32\netdde.exe (disabled) Verkon DDE DSDM: %SystemRoot%\system32\netdde.exe (disabled) Verkkokirjautuminen: %SystemRoot%\system32\lsass.exe (manual start) Verkkoyhteydet: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) 1394-verkko-ohjain: system32\DRIVERS\nic1394.sys (manual start) NLA-nimiavaruus (Network Location Awareness): %SystemRoot%\system32\svchost.exe -k netsvcs (manual start) NT LM -suojaustuen toimittaja: %SystemRoot%\system32\lsass.exe (manual start) Siirrettävät tallennusvälineet: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start) nv: system32\DRIVERS\nv4_mini.sys (manual start) NVIDIA Display Driver Service: %SystemRoot%\system32\nvsvc32.exe (autostart) IPX Traffic Filter Driver: system32\DRIVERS\nwlnkflt.sys (manual start) IPX Traffic Forwarder Driver: system32\DRIVERS\nwlnkfwd.sys (manual start) Texas Instruments OHCI Compliant IEEE 1394 Host Controller: system32\DRIVERS\ohci1394.sys (system) Rinnakkaisporttiohjain: system32\DRIVERS\parport.sys (manual start) PCI-väyläohjain: system32\DRIVERS\pci.sys (system) PCIIde: system32\DRIVERS\pciide.sys (system) Creative WebCam Instant: system32\DRIVERS\P0620Vid.sys (manual start) Padus ASPI Shell: system32\drivers\pfc.sys (manual start) Plug and Play: %SystemRoot%\system32\services.exe (autostart) IPSEC-palvelut: %SystemRoot%\system32\lsass.exe (autostart) WAN Miniport (PPTP): system32\DRIVERS\raspptp.sys (manual start) Suojattu tallennuspaikka: %SystemRoot%\system32\lsass.exe (autostart) QoS-paketinajoitus: system32\DRIVERS\psched.sys (manual start) Direct Parallel Link Driver: system32\DRIVERS\ptilink.sys (manual start) PxHelp20: System32\Drivers\PxHelp20.sys (system) Remote Access Auto Connection -ohjain: system32\DRIVERS\rasacd.sys (system) Remote Access Auto Connection -hallinta: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start) WAN Miniport (L2TP): system32\DRIVERS\rasl2tp.sys (manual start) Etäkäytön (RAS) yhteyksienhallinta: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start) Remote Access PPPOE Driver: system32\DRIVERS\raspppoe.sys (manual start) Suora rinnakkainen: system32\DRIVERS\raspti.sys (manual start) Rdbss: system32\DRIVERS\rdbss.sys (system) RDPCDD: System32\DRIVERS\RDPCDD.sys (system) Etätyöpöydän ohjeen istunnonhallinta: C:\WINDOWS\system32\sessmgr.exe (manual start) Digital CD Audio Playback Filter Driver: system32\DRIVERS\redbook.sys (system) Reititys ja etäkäyttö: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled) Etäproseduurikutsujen (RPC) paikannin: %SystemRoot%\system32\locator.exe (manual start) Etäproseduurikutsu (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart) QoS RSVP: %SystemRoot%\system32\rsvp.exe (manual start) Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver: system32\DRIVERS\RTL8139.SYS (manual start) Käyttöoikeustilien hallinta: %SystemRoot%\system32\lsass.exe (autostart) Älykortti: %SystemRoot%\System32\SCardSvr.exe (manual start) Tehtävien ajoitus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Secdrv: system32\DRIVERS\secdrv.sys (autostart) Toissijainen kirjautuminen: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Järjestelmätapahtuman ilmoitus: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Serenum Filter -ohjain: system32\DRIVERS\serenum.sys (manual start) Sarjaporttiohjain: system32\DRIVERS\serial.sys (system) Windowsin palomuuri / Internet-yhteyden jakaminen (ICS): %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Käyttöliittymän laitteistotunnistus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) BDA Slip De-Framer: system32\DRIVERS\SLIP.sys (manual start) Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start) Taustatulostusohjain: %SystemRoot%\system32\spoolsv.exe (autostart) Järjestelmän palautussuodatin -ohjain: system32\DRIVERS\sr.sys (system) Järjestelmän palauttaminen -palvelu: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Srv: system32\DRIVERS\srv.sys (manual start) SSDP-palvelu (Simple Service Discovery Protocol): %SystemRoot%\system32\svchost.exe -k LocalService (manual start) WIA (Windows Image Acquisition): %SystemRoot%\system32\svchost.exe -k imgsvc (autostart) BDA IPSink: system32\DRIVERS\StreamIP.sys (manual start) Ohjelmistoväyläohjain: system32\DRIVERS\swenum.sys (manual start) Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start) MS Software Shadow Copy Provider: C:\WINDOWS\system32\dllhost.exe /Processid:{C1E5BD71-2CAE-4B6C-9657-F90964EBF7D3} (manual start) Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start) Resurssilokit ja -hälytykset: %SystemRoot%\system32\smlogsvc.exe (manual start) Puhelin: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) TCP/IP-protokollaohjain: system32\DRIVERS\tcpip.sys (system) Päätelaiteohjain: system32\DRIVERS\termdd.sys (system) Päätepalvelut: %SystemRoot%\System32\svchost -k DComLaunch (manual start) Teemat: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Tiedostolinkkijäljityksen asiakas: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Windows User Mode Driver Framework: C:\WINDOWS\system32\wdfmgr.exe (autostart) Microcode Update -ohjain: system32\DRIVERS\update.sys (manual start) Universal Plug & Play -laiteisäntä: %SystemRoot%\system32\svchost.exe -k LocalService (manual start) UPS: %SystemRoot%\System32\ups.exe (manual start) USB-ääniohjain (WDM): system32\drivers\usbaudio.sys (manual start) Microsoft USB Generic Parent Driver: system32\DRIVERS\usbccgp.sys (manual start) Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: system32\DRIVERS\usbehci.sys (manual start) USB2 Enabled Hub: system32\DRIVERS\usbhub.sys (manual start) Microsoft USB PRINTER -luokka: system32\DRIVERS\usbprint.sys (manual start) USB Scanner Driver: system32\DRIVERS\usbscan.sys (manual start) USB-massamuistiohjain: system32\DRIVERS\USBSTOR.SYS (manual start) Microsoft USB Universal Host Controller Miniport Driver: system32\DRIVERS\usbuhci.sys (manual start) USB-videolaite (WDM): System32\Drivers\usbvideo.sys (manual start) VgaSave: \SystemRoot\System32\drivers\vga.sys (system) Aseman tilannevedos: %SystemRoot%\System32\vssvc.exe (manual start) Windows Time: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Remote Access IP ARP Driver: system32\DRIVERS\wanarp.sys (manual start) Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start) WebClient: %SystemRoot%\system32\svchost.exe -k LocalService (autostart) WMI-palvelu (Windows Management Instrumentation): %systemroot%\system32\svchost.exe -k netsvcs (autostart) Kannettavan mediasoittimen sarjanumeropalvelu: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) WMI resurssisovitin: C:\WINDOWS\system32\wbem\wmiapsrv.exe (manual start) Windows Socket 2.0:n tukiympäristö ei-IFS-järjestelmiä varten: \SystemRoot\System32\drivers\ws2ifsl.sys (system) Tietoturvakeskus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) World Standard Teletext Codec: system32\DRIVERS\WSTCODEC.SYS (manual start) Automaattiset päivitykset: %systemroot%\system32\svchost.exe -k netsvcs (autostart) Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Verkon käyttöönottopalvelu: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) -------------------------------------------------- Enumerating Windows NT logon/logoff scripts: *No scripts set to run* Windows NT checkdisk command: BootExecute = autocheck autochk * Windows NT 'Wininit.ini': PendingFileRenameOperations: C:\DOCUME~1\oem\LOCALS~1\Temp\~f51e43.tmp|||L -------------------------------------------------- Enumerating ShellServiceObjectDelayLoad items: PostBootReminder: C:\WINDOWS\system32\SHELL32.dll CDBurn: C:\WINDOWS\system32\SHELL32.dll WebCheck: C:\WINDOWS\system32\webcheck.dll SysTray: C:\WINDOWS\system32\stobject.dll -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run *Registry key not found* -------------------------------------------------- End of report, 35 654 bytes Report generated in 0,156 seconds Command line options: /verbose - to add additional info on each section /complete - to include empty sections and unsuspicious data /full - to include several rarely-important sections /force9x - to include Win9x-only startups even if running on WinNT /forcent - to include WinNT-only startups even if running on Win9x /forceall - to include all Win9x and WinNT startups, regardless of platform /history - to list version history only
tässä on vikasietotilassa tehdyn tarkastuksen jälkeinen logi! Logfile of HijackThis v1.99.1 Scan saved at 21:31:58, on 4.1.2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\ATKKBService.exe C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fsrw.exe C:\Program Files\F-Secure Internet Security\FSPC\fspc.exe C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Creative\Shared Files\CAMTRAY.EXE C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE C:\PROGRA~1\F-SECU~1\ANTI-S~1\fsaw.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\hjt\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - Global Startup: F-Secure 2006.lnk = C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe O8 - Extra context menu item: &Estä tämä kohoikkuna - C:\Program Files\F-Secure Internet Security\Anti-Spyware\blockpopups.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra button: Web-suodatin - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll O9 - Extra 'Tools' menuitem: Web-suodatin - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll O9 - Extra button: IE-suojaus - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll O9 - Extra 'Tools' menuitem: IE-suojaus... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Broken Internet access because of LSP provider 'winsflt.dll' missing O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe O23 - Service: F-Secure 2006 (BackWeb Plug-in - 4476822) - F-Secure Internet Security 2005 - C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSPC\fshttps\fshttps.exe O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Nonniin lähtihän se sieltä, eli ei accoonaa enään näy ja kotisivu on tuttu ja turvallinen? =) Loki on kunnossa.