just4playn HijackThis-loki

Viestiketju Virukset ja haittaohjelmat -osiossa. Ketjun avasi -kemisti- 03.01.2006.

  1. -kemisti-

    -kemisti- Active member

    Liittynyt:
    06.06.2005
    Viestejä:
    6,305
    Kiitokset:
    0
    Pisteet:
    96
    Logfile of HijackThis v1.99.1
    Scan saved at 18:08:40, on 2.1.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
    C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\ATKKBService.exe
    C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
    C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
    C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
    C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
    C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
    C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsrw.exe
    C:\Program Files\F-Secure Internet Security\FSPC\fspc.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
    C:\PROGRA~1\F-SECU~1\ANTI-S~1\fsaw.exe
    C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\hjt\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.accoona.com/search_assistant/accoona_search_assistant....
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.accoona.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.accoona.com/search_assistant/accoona_search_assistant....
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.accoona.com/search?q=%s
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    R3 - Default URLSearchHook is missing
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
    O2 - BHO: Accoona Search Assistant - {944864A5-3916-46E2-96A9-A2E84F3F1208} - C:\Program Files\Accoona\ASearchAssist.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
    O3 - Toolbar: Accoona - {364B6276-C6C1-40B6-A6D7-6C48871FD707} - C:\Program Files\Accoona\atoolbar.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: F-Secure 2006.lnk = C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
    O8 - Extra context menu item: &Estä tämä kohoikkuna - C:\Program Files\F-Secure Internet Security\Anti-Spyware\blockpopups.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
    O9 - Extra button: Web-suodatin - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
    O9 - Extra 'Tools' menuitem: Web-suodatin - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
    O9 - Extra button: IE-suojaus - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
    O9 - Extra 'Tools' menuitem: IE-suojaus... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Broken Internet access because of LSP provider 'winsflt.dll' missing
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31...
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
    O23 - Service: F-Secure 2006 (BackWeb Plug-in - 4476822) - F-Secure Internet Security 2005 - C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
    O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
    O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSPC\fshttps\fshttps.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
     
  2.  
  3. -kemisti-

    -kemisti- Active member

    Liittynyt:
    06.06.2005
    Viestejä:
    6,305
    Kiitokset:
    0
    Pisteet:
    96
    Poista ohjauspaneelista (lisää/poista sovellus):

    Accoona Toolbar

    Fixaa HjT:llä (do a system scan only, merkkaa ja paina fix checked):

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.accoona.com/search_assistant/accoona_search_assistant....
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.accoona.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.accoona.com/search_assistant/accoona_search_assistant....
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.accoona.com/search?q=%s
    R3 - Default URLSearchHook is missing
    O2 - BHO: Accoona Search Assistant - {944864A5-3916-46E2-96A9-A2E84F3F1208} - C:\Program Files\Accoona\ASearchAssist.dll
    O3 - Toolbar: Accoona - {364B6276-C6C1-40B6-A6D7-6C48871FD707} - C:\Program Files\Accoona\atoolbar.dll

    Käynnistä vikasietotilaan (F8 käynnuistyksen yhteydessä) ja poista:

    C:\Program Files\==>Accoona<==

    Käynnistä uudelleen ja lähetä uusi HjT-loki
     
  4. just4play

    just4play Regular member

    Liittynyt:
    31.12.2005
    Viestejä:
    137
    Kiitokset:
    0
    Pisteet:
    26
    eli tässä...

    Logfile of HijackThis v1.99.1
    Scan saved at 0:02:55, on 3.1.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
    C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\WINDOWS\ATKKBService.exe
    C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
    C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
    C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
    C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe
    C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsrw.exe
    C:\Program Files\F-Secure Internet Security\FSPC\fspc.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\PROGRA~1\F-SECU~1\ANTI-S~1\fsaw.exe
    C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\hjt\HijackThis.exe

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.accoona.com/search_assis...urce=wdz&utm_medium=bund&utm_campaign=wdz0605
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: F-Secure 2006.lnk = C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
    O8 - Extra context menu item: &Estä tämä kohoikkuna - C:\Program Files\F-Secure Internet Security\Anti-Spyware\blockpopups.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
    O9 - Extra button: Web-suodatin - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
    O9 - Extra 'Tools' menuitem: Web-suodatin - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
    O9 - Extra button: IE-suojaus - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
    O9 - Extra 'Tools' menuitem: IE-suojaus... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Broken Internet access because of LSP provider 'winsflt.dll' missing
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
    O23 - Service: F-Secure 2006 (BackWeb Plug-in - 4476822) - F-Secure Internet Security 2005 - C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
    O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
    O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSPC\fshttps\fshttps.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

     
  5. aaxxeell

    aaxxeell Regular member

    Liittynyt:
    28.07.2005
    Viestejä:
    2,145
    Kiitokset:
    0
    Pisteet:
    46
    Fixaa vielä HjT:llä (do a system scan only, merkkaa ja paina fix checked):
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.accoona.com/search_assistant/accoona_search_assistant....

    Voit vielä makusi mukaan fixata seuraavat(nopeuttaa konetta):
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    Viimeistele puhdistus ewidon avulla
    -> http://keskustelu.afterdawn.com/thread_view.cfm/269186
    Tee ohjeiden mukaan ja lähetä sen raportti tänne!
     
  6. just4play

    just4play Regular member

    Liittynyt:
    31.12.2005
    Viestejä:
    137
    Kiitokset:
    0
    Pisteet:
    26
    yritin fixata tota accoonaa mutta ei se suostunu lähteen vaan tulee aina uudelleen ... tulee vaan ikkuna jossa jotain "this will permanently delete and/or repair what you selected, unless you make a backup." ja kyllä tai ei.

    ---------------------------------------------------------
    ewido anti-malware - Scan report
    ---------------------------------------------------------

    + Created on: 9:33:06, 4.1.2006
    + Report-Checksum: 2FEA6ECB

    + Scan result:

    HKU\S-1-5-21-2182677158-2471696561-3394613557-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000EF1-0786-4633-87C6-1AA7A44296DA} -> Spyware.FavoriteMan : Cleaned with backup
    :mozilla.6:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.7:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.10:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.13:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    :mozilla.14:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    :mozilla.15:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    :mozilla.17:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    :mozilla.18:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    :mozilla.19:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    :mozilla.105:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
    :mozilla.106:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
    :mozilla.107:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.108:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.109:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.116:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
    :mozilla.117:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
    :mozilla.122:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
    :mozilla.123:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
    :mozilla.127:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.128:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.131:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
    :mozilla.132:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.133:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.168:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    :mozilla.178:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
    :mozilla.185:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.188:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
    :mozilla.189:C:\Documents and Settings\Hantta\Application Data\Mozilla\Firefox\Profiles\94zfhwvp.default\cookies.txt -> Spyware.Cookie.Counted : Cleaned with backup
    :mozilla.15:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    :mozilla.23:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
    :mozilla.25:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
    :mozilla.69:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    :mozilla.99:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    :mozilla.102:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.115:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.116:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.117:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
    :mozilla.118:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
    :mozilla.136:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
    :mozilla.142:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
    :mozilla.151:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
    :mozilla.157:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.158:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.160:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.161:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.185:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
    :mozilla.191:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.192:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
    :mozilla.196:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup
    :mozilla.197:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup
    :mozilla.199:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
    :mozilla.200:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
    :mozilla.201:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
    :mozilla.202:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
    :mozilla.215:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
    :mozilla.231:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    :mozilla.232:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    :mozilla.233:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    :mozilla.234:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    :mozilla.235:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
    :mozilla.241:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
    :mozilla.255:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.279:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    :mozilla.282:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.303:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Counted : Cleaned with backup
    :mozilla.304:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Counted : Cleaned with backup
    :mozilla.306:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
    :mozilla.308:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
    :mozilla.311:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
    :mozilla.312:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Adviva : Cleaned with backup
    :mozilla.313:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
    :mozilla.314:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Adviva : Cleaned with backup
    :mozilla.317:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
    :mozilla.326:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
    :mozilla.343:C:\Documents and Settings\Juha\Application Data\Mozilla\Firefox\Profiles\hr7uzj70.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
    C:\Documents and Settings\Juha\Cookies\juha@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    :mozilla.10:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    :mozilla.15:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    :mozilla.26:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    :mozilla.31:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
    :mozilla.32:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
    :mozilla.33:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.35:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    :mozilla.36:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    :mozilla.37:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    :mozilla.38:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    :mozilla.39:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
    :mozilla.44:C:\Documents and Settings\Leena\Application Data\Mozilla\Firefox\Profiles\vayt2f6a.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
    :mozilla.13:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\vjntiy04.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.18:C:\Documents and Settings\Mari\Application Data\Mozilla\Firefox\Profiles\gkpkanj2.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    :mozilla.38:C:\Documents and Settings\Mari\Application Data\Mozilla\Firefox\Profiles\gkpkanj2.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
    :mozilla.22:C:\Documents and Settings\oem\Application Data\Mozilla\Firefox\Profiles\m3yan8sd.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
    :mozilla.35:C:\Documents and Settings\oem\Application Data\Mozilla\Firefox\Profiles\m3yan8sd.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    :mozilla.36:C:\Documents and Settings\oem\Application Data\Mozilla\Firefox\Profiles\m3yan8sd.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    :mozilla.37:C:\Documents and Settings\oem\Application Data\Mozilla\Firefox\Profiles\m3yan8sd.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    :mozilla.46:C:\Documents and Settings\oem\Application Data\Mozilla\Firefox\Profiles\m3yan8sd.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.22:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    :mozilla.23:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    :mozilla.24:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    :mozilla.25:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    :mozilla.26:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
    :mozilla.81:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    :mozilla.98:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.99:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.108:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.111:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
    :mozilla.112:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
    :mozilla.116:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.117:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
    :mozilla.118:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
    :mozilla.130:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
    :mozilla.139:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
    :mozilla.140:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
    :mozilla.161:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
    :mozilla.162:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    :mozilla.163:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    :mozilla.164:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    :mozilla.165:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
    :mozilla.166:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
    :mozilla.175:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
    :mozilla.176:C:\Documents and Settings\Päivi\Application Data\Mozilla\Firefox\Profiles\dxdwlrms.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
    C:\Documents and Settings\Päivi\Cookies\päivi@msnportal.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
    C:\hjt\backups\backup-20060102-233249-163.dll -> Adware.Agent : Cleaned with backup


    ::Report End
     
  7. -kemisti-

    -kemisti- Active member

    Liittynyt:
    06.06.2005
    Viestejä:
    6,305
    Kiitokset:
    0
    Pisteet:
    96
    Fixaa se accoona vikasietotilassa ja katso tuleeko se sitten takaisin.
     
  8. just4play

    just4play Regular member

    Liittynyt:
    31.12.2005
    Viestejä:
    137
    Kiitokset:
    0
    Pisteet:
    26
    jop. poistin vikasietotilassa programfiles -> accoona mutta eipä lähteny tuolta hjt:ltä meneen.

    mitä ne hjt:n backupit on? pitääkö ne poistaa?
     
    Viimeksi muokattu: 04.01.2006
  9. -kemisti-

    -kemisti- Active member

    Liittynyt:
    06.06.2005
    Viestejä:
    6,305
    Kiitokset:
    0
    Pisteet:
    96
  10. aaxxeell

    aaxxeell Regular member

    Liittynyt:
    28.07.2005
    Viestejä:
    2,145
    Kiitokset:
    0
    Pisteet:
    46
    Hjt tallentaa backupit fixaamisen jälkeen jotta voit palauttaa ne jos syystä tai toisesta menee fixaukset väärin.

    Lähetä nyt käynnistyvien ohjelmien listan eli
    Avaa hjt -> open the misc tools section -> sitten sieltä "Generate startuplist log" Ruksaa vielä enne sitä kohdat "list also minor section" & "list empty sections". Lähetä siten lista tänne.
     
  11. just4play

    just4play Regular member

    Liittynyt:
    31.12.2005
    Viestejä:
    137
    Kiitokset:
    0
    Pisteet:
    26
    StartupList report, 4.1.2006, 21:13:25
    StartupList version: 1.52.2
    Started from : C:\hjt\HijackThis.EXE
    Detected: Windows XP SP2 (WinNT 5.01.2600)
    Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    * Using default options
    * Including empty and uninteresting sections
    * Showing rarely important sections
    ==================================================

    Running processes:

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\ATKKBService.exe
    C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
    C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
    C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
    C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
    C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsrw.exe
    C:\Program Files\F-Secure Internet Security\FSPC\fspc.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
    C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
    C:\PROGRA~1\F-SECU~1\ANTI-S~1\fsaw.exe
    C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\ewido anti-malware\ewidoctrl.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\hjt\HijackThis.exe

    --------------------------------------------------

    Listing of startup folders:

    Shell folders Startup:
    [C:\Documents and Settings\oem\Käynnistä-valikko\Ohjelmat\Käynnistys]
    *No files*

    Shell folders AltStartup:
    *Folder not found*

    User shell folders Startup:
    *Folder not found*

    User shell folders AltStartup:
    *Folder not found*

    Shell folders Common Startup:
    [C:\Documents and Settings\All Users\Käynnistä-valikko\Ohjelmat\Käynnistys]
    F-Secure 2006.lnk = C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe

    Shell folders Common AltStartup:
    *Folder not found*

    User shell folders Common Startup:
    *Folder not found*

    User shell folders Alternate Common Startup:
    *Folder not found*

    --------------------------------------------------

    Checking Windows NT UserInit:

    [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    UserInit = C:\WINDOWS\system32\userinit.exe,

    [HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
    *Registry key not found*

    [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    *Registry value not found*

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
    *Registry key not found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    SoundMan = SOUNDMAN.EXE
    Creative WebCam Tray = C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
    F-Secure Manager = "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
    F-Secure TNB = "C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
    F-Secure Startup Wizard = "C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot
    NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    nwiz = nwiz.exe /install
    NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

    *No values found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

    *No values found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

    *Registry key not found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

    *Registry key not found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    *No values found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

    *No values found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

    *Registry key not found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

    *Registry key not found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

    *Registry key not found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

    *Registry key not found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

    *Registry key not found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    *No subkeys found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
    *No subkeys found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
    *No subkeys found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
    *Registry key not found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
    *Registry key not found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    *No subkeys found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
    *No subkeys found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
    *Registry key not found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
    *Registry key not found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
    *Registry key not found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
    *Registry key not found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
    *Registry key not found*

    --------------------------------------------------

    File association entry for .EXE:
    HKEY_CLASSES_ROOT\exefile\shell\open\command

    (Default) = "%1" %*

    --------------------------------------------------

    File association entry for .COM:
    HKEY_CLASSES_ROOT\comfile\shell\open\command

    (Default) = "%1" %*

    --------------------------------------------------

    File association entry for .BAT:
    HKEY_CLASSES_ROOT\batfile\shell\open\command

    (Default) = "%1" %*

    --------------------------------------------------

    File association entry for .PIF:
    HKEY_CLASSES_ROOT\piffile\shell\open\command

    (Default) = "%1" %*

    --------------------------------------------------

    File association entry for .SCR:
    HKEY_CLASSES_ROOT\scrfile\shell\open\command

    (Default) = "%1" /S

    --------------------------------------------------

    File association entry for .HTA:
    HKEY_CLASSES_ROOT\htafile\shell\open\command

    (Default) = C:\WINDOWS\system32\mshta.exe "%1" %*

    --------------------------------------------------

    File association entry for .TXT:
    HKEY_CLASSES_ROOT\txtfile\shell\open\command

    (Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

    --------------------------------------------------

    Enumerating Active Setup stub paths:
    HKLM\Software\Microsoft\Active Setup\Installed Components
    (* = disabled by HKCU twin)

    [>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
    StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

    [>{26923b43-4d38-484f-9b9e-de460746276c}] *
    StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE

    [>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
    StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

    [>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
    StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

    [{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
    StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

    [{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
    StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

    [{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
    StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

    [{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
    StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser

    [{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
    StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub

    [{7790769C-0471-11d2-AF11-00C04FA35D02}] *
    StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

    [{89820200-ECBD-11cf-8B85-00AA005B4340}] *
    StubPath = regsvr32.exe /s /n /i:U shell32.dll

    [{89820200-ECBD-11cf-8B85-00AA005B4383}] *
    StubPath = %SystemRoot%\system32\ie4uinit.exe

    --------------------------------------------------

    Enumerating ICQ Agent Autostart apps:
    HKCU\Software\Mirabilis\ICQ\Agent\Apps

    *Registry key not found*

    --------------------------------------------------

    Load/Run keys from C:\WINDOWS\WIN.INI:

    load=*INI section not found*
    run=*INI section not found*

    Load/Run keys from Registry:

    HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
    HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
    HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
    HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
    HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
    HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
    HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
    HKCU\..\Windows NT\CurrentVersion\Windows: load=
    HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

    --------------------------------------------------

    Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

    Shell=*INI section not found*
    SCRNSAVE.EXE=*INI section not found*
    drivers=*INI section not found*

    Shell & screensaver key from Registry:

    Shell=Explorer.exe
    SCRNSAVE.EXE=C:\WINDOWS\system32\ssmypics.scr
    drivers=*Registry value not found*

    Policies Shell key:

    HKCU\..\Policies: Shell=*Registry key not found*
    HKLM\..\Policies: Shell=*Registry value not found*

    --------------------------------------------------

    Checking for EXPLORER.EXE instances:

    C:\WINDOWS\Explorer.exe: PRESENT!

    C:\Explorer.exe: not present
    C:\WINDOWS\Explorer\Explorer.exe: not present
    C:\WINDOWS\System\Explorer.exe: not present
    C:\WINDOWS\System32\Explorer.exe: not present
    C:\WINDOWS\Command\Explorer.exe: not present
    C:\WINDOWS\Fonts\Explorer.exe: not present

    --------------------------------------------------

    Checking for superhidden extensions:

    .lnk: HIDDEN! (arrow overlay: yes)
    .pif: HIDDEN! (arrow overlay: yes)
    .exe: not hidden
    .com: not hidden
    .bat: not hidden
    .hta: not hidden
    .scr: not hidden
    .shs: HIDDEN!
    .shb: HIDDEN!
    .vbs: not hidden
    .vbe: not hidden
    .wsh: not hidden
    .scf: HIDDEN! (arrow overlay: NO!)
    .url: HIDDEN! (arrow overlay: yes)
    .js: not hidden
    .jse: not hidden

    --------------------------------------------------

    Verifying REGEDIT.EXE integrity:

    - Regedit.exe found in C:\WINDOWS
    - .reg open command is normal (regedit.exe %1)
    - Regedit.exe has no CompanyName property! It is either missing or named something else.
    - Regedit.exe has no OriginalFilename property! It is either missing or named something else.
    - Regedit.exe has no FileDescription property! It is either missing or named something else.

    Registry check failed!

    --------------------------------------------------

    Enumerating Browser Helper Objects:

    (no name) - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
    (no name) - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll - {9394EDE7-C8B5-483E-8773-474BF36AF6E4}
    (no name) - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}

    --------------------------------------------------

    Enumerating Task Scheduler jobs:

    Scheduled scanning task.job

    --------------------------------------------------

    Enumerating Download Program Files:

    [Checkers Class]
    InProcServer32 = C:\WINDOWS\Downloaded Program Files\msgrchkr.dll
    CODEBASE = http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

    [MessengerStatsClient Class]
    InProcServer32 = C:\WINDOWS\Downloaded Program Files\MessengerStatsPAClient.dll
    CODEBASE = http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab

    [Shockwave ActiveX Control]
    InProcServer32 = C:\WINDOWS\system32\Macromed\Director\SwDir.dll
    CODEBASE = http://active.macromedia.com/director/cabs/sw.cab

    [Windows Genuine Advantage Validation Tool]
    InProcServer32 = C:\WINDOWS\system32\LegitCheckControl.DLL
    CODEBASE = http://go.microsoft.com/fwlink/?linkid=39204

    [Java Plug-in 1.5.0_01]
    InProcServer32 = C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
    CODEBASE = http://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab

    [MessengerStatsClient Class]
    InProcServer32 = C:\WINDOWS\Downloaded Program Files\messengerstatsclient.dll
    CODEBASE = http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab

    [MsnMessengerSetupDownloadControl Class]
    InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.ocx
    CODEBASE = http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab

    [ZoneIntro Class]
    InProcServer32 = C:\WINDOWS\Downloaded Program Files\ZIntro.ocx
    CODEBASE = http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab

    [CBreakshotControl Class]
    InProcServer32 = C:\WINDOWS\Downloaded Program Files\Banksht2.dll
    CODEBASE = http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab

    [Java Plug-in 1.5.0_01]
    InProcServer32 = C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
    CODEBASE = http://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab

    [Shockwave Flash Object]
    InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx
    CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    --------------------------------------------------

    Enumerating Winsock LSP files:

    NameSpace #1: C:\WINDOWS\System32\mswsock.dll
    NameSpace #2: C:\WINDOWS\System32\winrnr.dll
    NameSpace #3: C:\WINDOWS\System32\mswsock.dll
    Protocol #1: winsflt.dll (file MISSING)
    Protocol #2: winsflt.dll (file MISSING)
    Protocol #3: winsflt.dll (file MISSING)
    Protocol #4: winsflt.dll (file MISSING)
    Protocol #5: winsflt.dll (file MISSING)
    Protocol #6: C:\WINDOWS\system32\mswsock.dll
    Protocol #7: C:\WINDOWS\system32\mswsock.dll
    Protocol #8: C:\WINDOWS\system32\mswsock.dll
    Protocol #9: C:\WINDOWS\system32\rsvpsp.dll
    Protocol #10: C:\WINDOWS\system32\rsvpsp.dll
    Protocol #11: C:\WINDOWS\system32\mswsock.dll
    Protocol #12: C:\WINDOWS\system32\mswsock.dll
    Protocol #13: C:\WINDOWS\system32\mswsock.dll
    Protocol #14: C:\WINDOWS\system32\mswsock.dll
    Protocol #15: C:\WINDOWS\system32\mswsock.dll
    Protocol #16: C:\WINDOWS\system32\mswsock.dll
    Protocol #17: C:\WINDOWS\system32\mswsock.dll
    Protocol #18: C:\WINDOWS\system32\mswsock.dll
    Protocol #19: C:\WINDOWS\system32\mswsock.dll
    Protocol #20: C:\WINDOWS\system32\mswsock.dll
    Protocol #21: winsflt.dll (file MISSING)

    --------------------------------------------------

    Enumerating Windows NT/2000/XP services

    AC2003: System32\Drivers\AC2003.sys (manual start)
    Microsoft ACPI Driver: system32\DRIVERS\ACPI.sys (system)
    Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
    AFD: \SystemRoot\System32\drivers\afd.sys (system)
    Intel AGP Bus Filter: system32\DRIVERS\agp440.sys (system)
    Service for WDM 3D Audio Driver: system32\drivers\ALCXSENS.SYS (manual start)
    Service for Realtek AC97 Audio (WDM): system32\drivers\ALCXWDM.SYS (manual start)
    Hälytys: %SystemRoot%\system32\svchost.exe -k LocalService (disabled)
    Sovelluskerroksen yhdyskäytäväpalvelu: %SystemRoot%\System32\alg.exe (manual start)
    Sovellusten hallinta: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
    1394 ARP -asiakasprotokolla: system32\DRIVERS\arp1394.sys (manual start)
    Enhanced Display Driver Helper Service: system32\drivers\atkkbnt.sys (system)
    RAS Asynchronous Media Driver: system32\DRIVERS\asyncmac.sys (manual start)
    Standardi IDE/ESDI-kiintolevyohjain: system32\DRIVERS\atapi.sys (system)
    ATK Keyboard Service: C:\WINDOWS\ATKKBService.exe (autostart)
    ATM ARP Client -protokolla: system32\DRIVERS\atmarpc.sys (manual start)
    Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Audio Stub Driver: system32\DRIVERS\audstub.sys (manual start)
    F-Secure 2006: C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE (autostart)
    BITS-tausta-ajo (Background Intelligent Transfer Service): %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    Tietokoneiden selaus: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    Closed Caption Decoder: system32\DRIVERS\CCDECODE.sys (manual start)
    CD-ROM-ohjain: system32\DRIVERS\cdrom.sys (system)
    Indeksointipalvelu: %SystemRoot%\system32\cisvc.exe (manual start)
    Leikekirja: %SystemRoot%\system32\clipsrv.exe (disabled)
    COM+-järjestelmäsovellus: C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
    Salauspalvelut: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    DCOM-palvelinprosessin käynnistys: %SystemRoot%\system32\svchost -k DcomLaunch (autostart)
    DHCP-asiakas: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    Levyohjain: system32\DRIVERS\disk.sys (system)
    Loogisen levyn hallinnan valvontapalvelu: %SystemRoot%\System32\dmadmin.exe /com (manual start)
    dmboot: System32\drivers\dmboot.sys (disabled)
    dmio: System32\drivers\dmio.sys (disabled)
    dmload: System32\drivers\dmload.sys (disabled)
    Loogisen levyn hallinta: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
    DNS-asiakas: %SystemRoot%\system32\svchost.exe -k NetworkService (autostart)
    Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
    EIO: \??\C:\WINDOWS\system32\drivers\EIO.sys (autostart)
    ENTECH: \??\C:\WINDOWS\system32\DRIVERS\ENTECH.SYS (manual start)
    Virheraportointipalvelut: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Tapahtumaloki: %SystemRoot%\system32\services.exe (autostart)
    COM+-tapahtumajärjestelmä: C:\WINDOWS\system32\svchost.exe -k netsvcs (manual start)
    ewido security suite control: C:\Program Files\ewido anti-malware\ewidoctrl.exe (autostart)
    F-Secure File System Filter: \??\C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSfilter.sys (autostart)
    F-Secure Gatekeeper: \??\C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSgk.sys (autostart)
    FSGKHS: "C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe" (autostart)
    F-Secure File System Recognizer: \??\C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSrec.sys (autostart)
    Nopean käyttäjän vaihdon yhteensopivuus: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    Levykeaseman ohjain: system32\DRIVERS\fdc.sys (manual start)
    Levykeasemaohjain: system32\DRIVERS\flpydisk.sys (manual start)
    FltMgr: system32\DRIVERS\fltMgr.sys (system)
    fsbwsys: "C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe" (autostart)
    F-Secure Anti-Virus Firewall Daemon: "C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe" (manual start)
    F-Secure Firewall Driver: System32\drivers\fsdfw.sys (system)
    F-Secure HTTP Server: "C:\Program Files\F-Secure Internet Security\FSPC\fshttps\fshttps.exe" (manual start)
    F-Secure Management Agent: "C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE" (autostart)
    Volume Manager -ohjain: system32\DRIVERS\ftdisk.sys (system)
    GEAR CDRom Filter: SYSTEM32\DRIVERS\GEARAspiWDM.sys (manual start)
    Yleinen paketinmääritys: system32\DRIVERS\msgpc.sys (manual start)
    Ohjeet ja tuotetuki: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    HID (Human Interface Device) -liittymä: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
    Microsoft HID -luokkaohjain: system32\DRIVERS\hidusb.sys (manual start)
    HTTP: System32\Drivers\HTTP.sys (manual start)
    HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start)
    i8042-näppäimistö ja PS/2-hiiriohjain: system32\DRIVERS\i8042prt.sys (system)
    CD-Burning Filter Driver: system32\DRIVERS\imapi.sys (system)
    CD-levyjen kirjoittamisen IMAPI COM -palvelu: C:\WINDOWS\system32\imapi.exe (manual start)
    IntelIde: system32\DRIVERS\intelide.sys (system)
    Intel-suoritinohjain: system32\DRIVERS\intelppm.sys (system)
    Windowsin IPv6-palomuurin ohjain: system32\DRIVERS\Ip6Fw.sys (manual start)
    IP Traffic Filter Driver: system32\DRIVERS\ipfltdrv.sys (manual start)
    IP in IP Tunnel Driver: system32\DRIVERS\ipinip.sys (manual start)
    IP Network Address Translator: system32\DRIVERS\ipnat.sys (manual start)
    iPod Service: "C:\Program Files\iPod\bin\iPodService.exe" (manual start)
    IPSEC-ohjain: system32\DRIVERS\ipsec.sys (system)
    IR Enumerator Service: system32\DRIVERS\irenum.sys (manual start)
    PnP ISA/EISA -väyläohjain: system32\DRIVERS\isapnp.sys (system)
    jnv4_mib: \??\C:\DOCUME~1\oem\LOCALS~1\Temp\jnv4_mib.sys (manual start)
    Näppäimistön luokkaohjain: system32\DRIVERS\kbdclass.sys (system)
    Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
    Palvelin: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    Työasema: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    LexBce Server: C:\WINDOWS\system32\LEXBCES.EXE (autostart)
    TCP/IP NetBIOS Helper: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
    Viestinvälitys: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
    NetMeeting etätyöpöydän jakaminen: C:\WINDOWS\system32\mnmsrvc.exe (manual start)
    Hiiren luokkaohjain: system32\DRIVERS\mouclass.sys (system)
    Hiiren HID-ohjain: system32\DRIVERS\mouhid.sys (manual start)
    WebDav Client Redirector: system32\DRIVERS\mrxdav.sys (manual start)
    MRXSMB: system32\DRIVERS\mrxsmb.sys (system)
    Distributed Transaction Coordinator: C:\WINDOWS\system32\msdtc.exe (manual start)
    Windows Installer -ohjelma: C:\WINDOWS\system32\msiexec.exe /V (manual start)
    Microsoft Streaming Service -välityspalvelin: system32\drivers\MSKSSRV.sys (manual start)
    Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
    Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
    Microsoft-järjestelmänhallinnan BIOS-ohjain: system32\DRIVERS\mssmbios.sys (manual start)
    Microsoft Streaming Tee/Sink-to-Sink -muunnin: system32\drivers\MSTEE.sys (manual start)
    NABTS/FEC VBI Codec: system32\DRIVERS\NABTSFEC.sys (manual start)
    Microsoft TV/Video Connection: system32\DRIVERS\NdisIP.sys (manual start)
    Remote Access NDIS TAPI Driver: system32\DRIVERS\ndistapi.sys (manual start)
    NDIS Usermode I/O -protokolla: system32\DRIVERS\ndisuio.sys (manual start)
    Remote Access NDIS WAN Driver: system32\DRIVERS\ndiswan.sys (manual start)
    NetBIOS-käyttöliittymä: system32\DRIVERS\netbios.sys (system)
    NetBIOS TCP/IP:n päällä: system32\DRIVERS\netbt.sys (system)
    Verkon DDE: %SystemRoot%\system32\netdde.exe (disabled)
    Verkon DDE DSDM: %SystemRoot%\system32\netdde.exe (disabled)
    Verkkokirjautuminen: %SystemRoot%\system32\lsass.exe (manual start)
    Verkkoyhteydet: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    1394-verkko-ohjain: system32\DRIVERS\nic1394.sys (manual start)
    NLA-nimiavaruus (Network Location Awareness): %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
    NT LM -suojaustuen toimittaja: %SystemRoot%\system32\lsass.exe (manual start)
    Siirrettävät tallennusvälineet: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
    nv: system32\DRIVERS\nv4_mini.sys (manual start)
    NVIDIA Display Driver Service: %SystemRoot%\system32\nvsvc32.exe (autostart)
    IPX Traffic Filter Driver: system32\DRIVERS\nwlnkflt.sys (manual start)
    IPX Traffic Forwarder Driver: system32\DRIVERS\nwlnkfwd.sys (manual start)
    Texas Instruments OHCI Compliant IEEE 1394 Host Controller: system32\DRIVERS\ohci1394.sys (system)
    Rinnakkaisporttiohjain: system32\DRIVERS\parport.sys (manual start)
    PCI-väyläohjain: system32\DRIVERS\pci.sys (system)
    PCIIde: system32\DRIVERS\pciide.sys (system)
    Creative WebCam Instant: system32\DRIVERS\P0620Vid.sys (manual start)
    Padus ASPI Shell: system32\drivers\pfc.sys (manual start)
    Plug and Play: %SystemRoot%\system32\services.exe (autostart)
    IPSEC-palvelut: %SystemRoot%\system32\lsass.exe (autostart)
    WAN Miniport (PPTP): system32\DRIVERS\raspptp.sys (manual start)
    Suojattu tallennuspaikka: %SystemRoot%\system32\lsass.exe (autostart)
    QoS-paketinajoitus: system32\DRIVERS\psched.sys (manual start)
    Direct Parallel Link Driver: system32\DRIVERS\ptilink.sys (manual start)
    PxHelp20: System32\Drivers\PxHelp20.sys (system)
    Remote Access Auto Connection -ohjain: system32\DRIVERS\rasacd.sys (system)
    Remote Access Auto Connection -hallinta: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
    WAN Miniport (L2TP): system32\DRIVERS\rasl2tp.sys (manual start)
    Etäkäytön (RAS) yhteyksienhallinta: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
    Remote Access PPPOE Driver: system32\DRIVERS\raspppoe.sys (manual start)
    Suora rinnakkainen: system32\DRIVERS\raspti.sys (manual start)
    Rdbss: system32\DRIVERS\rdbss.sys (system)
    RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
    Etätyöpöydän ohjeen istunnonhallinta: C:\WINDOWS\system32\sessmgr.exe (manual start)
    Digital CD Audio Playback Filter Driver: system32\DRIVERS\redbook.sys (system)
    Reititys ja etäkäyttö: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
    Etäproseduurikutsujen (RPC) paikannin: %SystemRoot%\system32\locator.exe (manual start)
    Etäproseduurikutsu (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
    QoS RSVP: %SystemRoot%\system32\rsvp.exe (manual start)
    Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver: system32\DRIVERS\RTL8139.SYS (manual start)
    Käyttöoikeustilien hallinta: %SystemRoot%\system32\lsass.exe (autostart)
    Älykortti: %SystemRoot%\System32\SCardSvr.exe (manual start)
    Tehtävien ajoitus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Secdrv: system32\DRIVERS\secdrv.sys (autostart)
    Toissijainen kirjautuminen: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Järjestelmätapahtuman ilmoitus: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    Serenum Filter -ohjain: system32\DRIVERS\serenum.sys (manual start)
    Sarjaporttiohjain: system32\DRIVERS\serial.sys (system)
    Windowsin palomuuri / Internet-yhteyden jakaminen (ICS): %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    Käyttöliittymän laitteistotunnistus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    BDA Slip De-Framer: system32\DRIVERS\SLIP.sys (manual start)
    Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
    Taustatulostusohjain: %SystemRoot%\system32\spoolsv.exe (autostart)
    Järjestelmän palautussuodatin -ohjain: system32\DRIVERS\sr.sys (system)
    Järjestelmän palauttaminen -palvelu: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    Srv: system32\DRIVERS\srv.sys (manual start)
    SSDP-palvelu (Simple Service Discovery Protocol): %SystemRoot%\system32\svchost.exe -k LocalService (manual start)
    WIA (Windows Image Acquisition): %SystemRoot%\system32\svchost.exe -k imgsvc (autostart)
    BDA IPSink: system32\DRIVERS\StreamIP.sys (manual start)
    Ohjelmistoväyläohjain: system32\DRIVERS\swenum.sys (manual start)
    Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
    MS Software Shadow Copy Provider: C:\WINDOWS\system32\dllhost.exe /Processid:{C1E5BD71-2CAE-4B6C-9657-F90964EBF7D3} (manual start)
    Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
    Resurssilokit ja -hälytykset: %SystemRoot%\system32\smlogsvc.exe (manual start)
    Puhelin: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    TCP/IP-protokollaohjain: system32\DRIVERS\tcpip.sys (system)
    Päätelaiteohjain: system32\DRIVERS\termdd.sys (system)
    Päätepalvelut: %SystemRoot%\System32\svchost -k DComLaunch (manual start)
    Teemat: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Tiedostolinkkijäljityksen asiakas: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    Windows User Mode Driver Framework: C:\WINDOWS\system32\wdfmgr.exe (autostart)
    Microcode Update -ohjain: system32\DRIVERS\update.sys (manual start)
    Universal Plug & Play -laiteisäntä: %SystemRoot%\system32\svchost.exe -k LocalService (manual start)
    UPS: %SystemRoot%\System32\ups.exe (manual start)
    USB-ääniohjain (WDM): system32\drivers\usbaudio.sys (manual start)
    Microsoft USB Generic Parent Driver: system32\DRIVERS\usbccgp.sys (manual start)
    Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: system32\DRIVERS\usbehci.sys (manual start)
    USB2 Enabled Hub: system32\DRIVERS\usbhub.sys (manual start)
    Microsoft USB PRINTER -luokka: system32\DRIVERS\usbprint.sys (manual start)
    USB Scanner Driver: system32\DRIVERS\usbscan.sys (manual start)
    USB-massamuistiohjain: system32\DRIVERS\USBSTOR.SYS (manual start)
    Microsoft USB Universal Host Controller Miniport Driver: system32\DRIVERS\usbuhci.sys (manual start)
    USB-videolaite (WDM): System32\Drivers\usbvideo.sys (manual start)
    VgaSave: \SystemRoot\System32\drivers\vga.sys (system)
    Aseman tilannevedos: %SystemRoot%\System32\vssvc.exe (manual start)
    Windows Time: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Remote Access IP ARP Driver: system32\DRIVERS\wanarp.sys (manual start)
    Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
    WebClient: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
    WMI-palvelu (Windows Management Instrumentation): %systemroot%\system32\svchost.exe -k netsvcs (autostart)
    Kannettavan mediasoittimen sarjanumeropalvelu: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    WMI resurssisovitin: C:\WINDOWS\system32\wbem\wmiapsrv.exe (manual start)
    Windows Socket 2.0:n tukiympäristö ei-IFS-järjestelmiä varten: \SystemRoot\System32\drivers\ws2ifsl.sys (system)
    Tietoturvakeskus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    World Standard Teletext Codec: system32\DRIVERS\WSTCODEC.SYS (manual start)
    Automaattiset päivitykset: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
    Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Verkon käyttöönottopalvelu: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)


    --------------------------------------------------

    Enumerating Windows NT logon/logoff scripts:
    *No scripts set to run*

    Windows NT checkdisk command:
    BootExecute = autocheck autochk *

    Windows NT 'Wininit.ini':
    PendingFileRenameOperations: C:\DOCUME~1\oem\LOCALS~1\Temp\~f51e43.tmp|||L

    --------------------------------------------------

    Enumerating ShellServiceObjectDelayLoad items:

    PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
    CDBurn: C:\WINDOWS\system32\SHELL32.dll
    WebCheck: C:\WINDOWS\system32\webcheck.dll
    SysTray: C:\WINDOWS\system32\stobject.dll

    --------------------------------------------------
    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

    *Registry key not found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

    *Registry key not found*

    --------------------------------------------------

    End of report, 35 654 bytes
    Report generated in 0,156 seconds

    Command line options:
    /verbose - to add additional info on each section
    /complete - to include empty sections and unsuspicious data
    /full - to include several rarely-important sections
    /force9x - to include Win9x-only startups even if running on WinNT
    /forcent - to include WinNT-only startups even if running on Win9x
    /forceall - to include all Win9x and WinNT startups, regardless of platform
    /history - to list version history only
     
  12. just4play

    just4play Regular member

    Liittynyt:
    31.12.2005
    Viestejä:
    137
    Kiitokset:
    0
    Pisteet:
    26
    tässä on vikasietotilassa tehdyn tarkastuksen jälkeinen logi!

    Logfile of HijackThis v1.99.1
    Scan saved at 21:31:58, on 4.1.2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\ATKKBService.exe
    C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
    C:\Program Files\ewido anti-malware\ewidoctrl.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
    C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
    C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
    C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
    C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsrw.exe
    C:\Program Files\F-Secure Internet Security\FSPC\fspc.exe
    C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
    C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
    C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
    C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE
    C:\PROGRA~1\F-SECU~1\ANTI-S~1\fsaw.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
    C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\hjt\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - Global Startup: F-Secure 2006.lnk = C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
    O8 - Extra context menu item: &Estä tämä kohoikkuna - C:\Program Files\F-Secure Internet Security\Anti-Spyware\blockpopups.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
    O9 - Extra button: Web-suodatin - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
    O9 - Extra 'Tools' menuitem: Web-suodatin - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
    O9 - Extra button: IE-suojaus - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
    O9 - Extra 'Tools' menuitem: IE-suojaus... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Broken Internet access because of LSP provider 'winsflt.dll' missing
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
    O23 - Service: F-Secure 2006 (BackWeb Plug-in - 4476822) - F-Secure Internet Security 2005 - C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
    O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
    O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSPC\fshttps\fshttps.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

     
  13. aaxxeell

    aaxxeell Regular member

    Liittynyt:
    28.07.2005
    Viestejä:
    2,145
    Kiitokset:
    0
    Pisteet:
    46
    Nonniin lähtihän se sieltä, eli ei accoonaa enään näy ja kotisivu on tuttu ja turvallinen? =)
    Loki on kunnossa.
     

Jaa tämä sivu