1. Tämä sivusto käyttää keksejä (cookie). Jatkamalla sivuston käyttämistä hyväksyt keksien käyttämisen. Lue lisää.

Outoja juttuja

Viestiketju Virukset ja haittaohjelmat - HijackThis -logit -osiossa. Ketjun avasi juka39 31.03.2007.

  1. juka39

    juka39 Regular member

    Liittynyt:
    20.02.2007
    Viestejä:
    137
    Kiitokset:
    0
    Pisteet:
    26
    Osuin sattumalta Afterdawn uutisia lukiessani tälle viestiketjulle. Kun huomasin, miten ystävällisesti nim. treeltaa opastitte, rohkenen minäkin kääntyä kysymyksineni asiaa tuntevien puoleen. Huom. olen huomattavasti kokemattomampi käyttäjä kuin em.nimimerkki, sen voinee päätellä iästäni, joka puolestaan näkyy omassa nimimerkissäni. Nyt asiaan:
    Itsellani on PC:ssä ( HP iextreme, ikä 4v.) oluut koko ajan F-securen täysohjelmisto ja olen suhteellisen hyvin selvinnyt örkeistä. Nyt viimeisen ohjelmiston asennuksen jälkeen se (siis FS) alkoi temppuilla ja kun sitä yhdessä FS:n tuen henkilöiden kanssa setvittiin ja poistettiin asennusta lisää ja poista ohjelman lisäksi muistakin kohteista (ilmeisesti lähinnä varmuuden vuoksi) poistui samalla Firefox ja Thunderbird, ilmeisesti koko Mic.office paketti (ainakin Word, Works ja Photo Editor, joita käytän säännöllisesti)sekä mm. Spywre Blaster ja jopa Mru Blaster. Helpotus oli suuri, kun sain Mozillat pelaamaan niin, että mitään kirjanmerkkejä, osoitteita tai viestejä ei ollut poistunut. Fs:n täysskannauksessa löytyi yksi eristetty haittaohjelma ja kaksi riskiohjelmaa, joista toinen on hallinnassa (siis tiedossa), mutta toista (NetTool.Win32.PsKill) en tunnista (tulee esille ainakin silloin, kun avaan PC:ni apuohjelman SmartRestoren, jolla ohjekirjan mukaan voisi asentaa ainakin Wordin uudelleen). Mainittakoon, että Mic.office ohjelmat olivat ostohetkellä asennettuna eikä mitään erillista Mic. office asennuspakettia CD:llä ei tullut mukana. Itse kuitenkin tein heti uutena Master levyt.
    Minulla oli aikaisemmin Lavasoftin suomenkielinen Ad-Aware, mutta Fs:n tukikäski sen poistamaan ja käyttämään heidän vastaavaa omaansa (joka mielestäni on yksi yhteen vastaava Lsoftin kanssa). Se ei kuitenkaan ole suomenkielinen ja pitkän saksan lukijana varsinkin tietokonenglantini on todella heikko, joten ohjelman kustomointi ei ole ehkä kohdallaan. Käytän sitä kuitenkin viikottain. Muuta ei ole löytynyt kuin 5-15 kpl mru-list:ja, jotka olen aina poistanut. Voinko kustomoida Fs:n ad-awaren LSoftin suomenkielisen ohjeen mukaan ? vai voinko peräti ottaa sen käyttöön vaikka Fs:n vastaava on koneella.
     
  2.  
  3. juka39

    juka39 Regular member

    Liittynyt:
    20.02.2007
    Viestejä:
    137
    Kiitokset:
    0
    Pisteet:
    26
    Liitänpä lokin vielä tähän oikeaankin viestiketjuun (tuli liitettyä myös menee hermot ketjuun. Aloittelevalle tämä sekoilu suotakoon?Logfile of HijackThis v1.99.1
    Scan saved at 14:39:36, on 31.3.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\apps\ABoard\ABoard.exe
    E:\Tietoturva\Anti-Spyware\Ad-Monitor.exe
    C:\apps\ABoard\AOSD.exe
    C:\Program Files\F-Secure\Common\FSM32.EXE
    C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
    C:\Program Files\F-Secure\Common\FSMA32.EXE
    C:\APPS\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
    C:\Program Files\F-Secure\Common\FSMB32.EXE
    C:\Program Files\F-Secure\Common\FCH32.EXE
    C:\WINDOWS\System32\tcpsvcs.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\ups.exe
    C:\Program Files\F-Secure\Common\FAMEH32.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
    C:\Program Files\F-Secure\FSPC\fspc.exe
    C:\Program Files\F-Secure\FSAUA\program\fsaua.exe
    C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
    C:\Program Files\F-Secure\FSAUA\program\fsus.exe
    C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
    C:\Program Files\F-Secure\FSGUI\fsguidll.exe
    C:\Program Files\Skype\Plugin Manager\skypePM.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
    C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
    C:\Program Files\Mozilla Thunderbird\thunderbird.exe
    C:\HJT\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.jippii.fi/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://saunalahti.fi
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://register.surfeu.fi/signup/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.suomi.net:8080
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\apps\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll (file missing)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
    O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
    O4 - HKLM\..\Run: [CleanEasyImg] c:\apps\easydvd\cleanall.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
    O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
    O4 - HKLM\..\Run: [AWMON] "E:\Tietoturva\Anti-Spyware\Ad-Monitor.exe"
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
    O4 - HKLM\..\Run: [delcab] C:\drivers\deltreew.exe C:\cabs
    O4 - HKCU\..\Run: [LDM] \Program\
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [HDDHealth] C:\Program Files\HDD Health\hddhealth.exe -wl
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - Startup: MRU-Blaster Scheduler.lnk = C:\Program Files\MRU-Blaster\scheduler.exe
    O4 - Startup: MRU-Blaster Silent Clean.lnk = C:\Program Files\MRU-Blaster\mrublaster.exe
    O4 - Startup: OpenOffice.org 2.1.lnk = C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
    O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
    O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\APPS\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: Lapsilukko... - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\FSPC\fspcmsie.dll
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure\FSPC\fspcmsie.dll
    O9 - Extra 'Tools' menuitem: Lapsilukko... - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure\FSPC\fspcmsie.dll
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:\Program Files\FSPC\fspcmsie.dll (file missing)
    O9 - Extra 'Tools' menuitem: &Keskeytä Web-sivujen suodatus - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:\Program Files\FSPC\fspcmsie.dll (file missing)
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:\Program Files\FSPC\fspcmsie.dll (file missing)
    O9 - Extra 'Tools' menuitem: &Kiellä tämä Web-sivusto - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:\Program Files\FSPC\fspcmsie.dll (file missing)
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:\Program Files\FSPC\fspcmsie.dll (file missing)
    O9 - Extra 'Tools' menuitem: &Salli tämä Web-sivusto - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:\Program Files\FSPC\fspcmsie.dll (file missing)
    O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://saunalahti.fi
    O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://D:\content\include\XPPatchInstaller.CAB
    O16 - DPF: {8B1BC605-C593-4865-8F5B-05517F0CD0BB} (MSSecurityAdvisorCD Class) - file://D:\Content\include\msSecUcd.cab
    O18 - Protocol: bw+0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw+0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw-0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw-0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw00 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw00s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw10 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw10s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw20 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw20s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw30 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw30s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw40 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw40s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw50 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw50s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw60 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw60s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw70 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw70s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw80 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw80s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw90 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw90s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwa0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwa0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwb0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwb0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwc0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwc0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwd0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwd0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwe0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwe0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwf0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwf0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwg0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwg0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwh0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwh0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwi0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwi0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwj0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwj0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwk0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwk0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwl0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwl0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwm0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwm0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwn0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwn0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwo0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwo0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwp0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwp0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwq0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwq0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwr0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwr0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bws0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bws0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwt0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwt0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwu0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwu0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwv0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwv0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bww0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bww0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwx0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwx0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwy0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwy0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwz0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwz0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: offline-8876480 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure\FSAUA\program\fsaua.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
    O23 - Service: Machine Debug Manager (MDM) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (file missing)
    O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
    O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - Unknown owner - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe (file missing)

     
  4. Auttaja

    Auttaja Guest

    Avaa hijackthis merkkaa seuraavat rivi(t) ja paina fix checked, sulje muut ohjelmat siksi aikaa

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
    O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
    O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe

    Poista ohjauspaneelista logitech dekstop manager

    ***********

    Lataa AVG Anti-Spyware 7.5 ja tallenna ohjelma työpöydällesi.

    [*]Kun olet ladannut ohjelman, kaksoisklikkaa asennuohjelman pikakuvaketta työpöydälläsi, asennus alkaa.
    [*]Asennuksen jälkeen täytyy ohjelma käynnistää ja sen tunnisteet päivittää.
    [*]Käynnistä AVG Anti-Spyware.
    [*]Klikkaa "Update" kuvaketta päävalikossa. Sen jälkeen klikkaa "Update now" painiketta.
    [*]Sitten klikkaa "Start Update" kuvaketta jolloin päivitys alkaa.
    [*]Kun päivitykset on ladattu, klikkaa "Scanner" kuvaketta ikkunan ylälaidassa. Valitse sitten "Settings" välilehti.
    [*]Kun "Settings" valikko on auennut, klikkaa "Recommended actions" ja sitten valitse "Quarantine".
    [*]Sitten "Reports" valikon alta:
    [*]Laita täppi kohtaan "Automatically generate report after every scan"
    [*]Ota täppi pois kohdasta"Only if threats were found"
    [*]Sitten klikkaa "Shield" kuvaketta ikkunan ylälaidassa
    [*]"Resident shield is", muuta tila active:sta inactive:ksi
    [*]Sulje ohjelma, ÄLÄ skannaa vielä.

    Käynnistä tietokone vikasietotilaan:
    1. Käynnistä tietokone uudelleen.
    2. Kun tietokone käynnistyy, paina F8-näppäintä.
    3. Näyttöön tulee erilaisia käynnistysvaihtoehtoja.
    4. Valitse näppäimistön nuolinäppäinten avulla Vikasietotila.
    5. Paina ENTER-näppäintä.

    Poista nää kansiot

    C:\Program Files\Common Files\GMT\
    C:\Program Files\PrecisionTime\

    HUOM! Älä käytä muita ohjelmia AVG skannauksen aikana, tämä saattaa häiritä skannausta.
    [*]Kun vikasietotilassa, käynnistä AVG Anti-Spyware.
    [*]Klikkaa "Scanner" kuvaketta ikkunan ylälaidassa ja valitse "Scan" välilehti. Sitten klikkaa "Complete System Scan".
    [*]AVG aloittaa nyt tietokoneen skannaamisen, ole kärsivällinen sillä skannaus vie aikaa.
    Kun skannaus on valmis:
    TÄRKEÄÄ : Älä klikkaa "Save Scan Report" ennen kuin klikkaat "Apply all Actions"
    [*]Varmistu, että Set all elements to: näyttää Quarantine (1), jos ei, klikkaa linkkiä ja valitse Quarantine popup-valikosta.
    [*]Sinulta kysytään mitä tehdä jos infektioita löytyi, valitse silloin "Apply all actions"
    [​IMG]
    [*]Sitten klikkaa "Reports" kuvaketta ohjelma yläosasta.
    [*]Klikkaa "Save report as" painiketta ikkunan vasemmassa alalaidassa ja tallenna raportti työpöydälle.
    [*]Sulje ohjelma, käynnistä kone normaalisti ja lähetä AVG:n raportti viestiketjuusi.

    ****



    1. Lataa combofix.exe työpöydällesi jommastakummasta linkistä:
    http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    2. Tuplaklikkaa combofix.exe tiedostoa ja seuraa ohjeistuksia.
    3. Kun työkalu on valmis, se tuottaa lokin. (C:\ComboFix.txt) Lähetä tämä loki viesti ketjuusi.
    Huom! Älä klikkaile combofixin ikkunaa käytön aikana. Tämä saattaa aiheuttaa ohjelman jumiutumisen.

    ****

    Uusin hjtlogi

     
  5. juka39

    juka39 Regular member

    Liittynyt:
    20.02.2007
    Viestejä:
    137
    Kiitokset:
    0
    Pisteet:
    26
    Ikävä kyllä, en pääse alkua pidemmälle. Jos valitsen maalalla yhden rivin, poistuu samalla toinen. Olen yrittänyt maalatessa pitää ctrl/ sifhtiä alhaalla. Ei onnistu. Toisekseen kun painan viestissä olevaa Hijack This sinistä tunnistetta, avaa se lataussivun. Latasin ja se on nyt kansiossa "omat lataukset". Jos saan neuvon, miten saan rivit valittua, pitääkö sen jälkeen valita em. kansiosta Hijack This asennus ja siitä sitten eteenpäin.

    Ymmärrän, että on tuskastuttavaa toimia näin tumpelon käyttäjän kanssa. Ehkä siinä on kuitenkin Sinullekin haastetta. Minulle on ainakin. Ihan tulee kylmät väreet, kun puhutaan vikasietotilasta!
     
  6. Hujo

    Hujo Guest

    ai noiten fixsattavien kanssa tuskailet
    laita rivien eteen pikkuseen neliöön ruksi mitkä on annettu sitten painat Fix checked
     
    Moderaattorin viimeksi muokkaama: 31.03.2007
  7. juka39

    juka39 Regular member

    Liittynyt:
    20.02.2007
    Viestejä:
    137
    Kiitokset:
    0
    Pisteet:
    26
    No niin, nyt hukkasin aloittani vastauksen, mutt aloitetaanpa alusta.
    1. Ohjauspaneeli>lisää poista sovellus valikossa ei ollut Logitech Desktop Manager. Vastaava messenger oli, mutta se ei poistunut, vastasi ilmoituksella RUNDLL (ilmoituksen otsake) ja viesti jotain, että virhe ladattaessa määriteltyä asemaa... Jätin homman sikseen.
    2. AVG:n lataus ja asennus sekä vaadittavat määrittelyt onnistuivat.
    3. Vikasietotilaan meno onnistui vaikka kävin siellä eka kertaa elämässäni. Mitä se tila tarkoittaa ja miksi sitä käytetään?
    4. Poistettavaksi määrättyjä kansioita ei löytynyt.
    5. Skannaus kesti toista tuntia. Lopputulos oli että 5 cookies tiedostoa löytyi (medium risk) ja 5 infektoitunutta objektia mutta jostain syystä ei antanut raporttia vaan ilmoitti no raport available. Suljin AGG:n OK:lla, toinen vaihtoehto oli ymmärtääkseni täydellinensulkeminen (tai poisto).
    6. Combofix raportti on oheisena."Kaimio Juhani" - 07-03-31 20:44:12 Service Pack 2
    ComboFix 07-03-27.4.2 - Running from: "C:\Documents and Settings\Kaimio Juhani"


    ((((((((((((((((((((((((((((((( Files Created from 2007-02-28 to 2007-03-31 ))))))))))))))))))))))))))))))))))


    2007-03-31 19:00 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
    2007-03-31 14:23 <KANSIO> d-------- C:\HJT
    2007-03-29 19:05 <KANSIO> d-------- C:\DOCUME~1\KAIMIO~1\APPLIC~1\OpenOffice.org2
    2007-03-29 18:55 <KANSIO> d-------- C:\Program Files\OpenOffice.org 2.1
    2007-03-27 16:37 <KANSIO> d-------- C:\Sukujut
    2007-03-21 19:52 18,944 --a------ C:\WINDOWS\system32\simptcp.dll
    2007-03-21 14:47 <KANSIO> d-------- C:\Program Files\Java
    2007-03-21 14:46 <KANSIO> d-------- C:\Program Files\Common Files\Java
    2007-03-20 20:54 <KANSIO> d-------- C:\Program Files\Common Files\Adobe
    2007-03-19 12:07 50,080 --a------ C:\WINDOWS\system32\drivers\fsdfw.sys
    2007-03-19 12:07 29,472 --a------ C:\WINDOWS\system32\drivers\fsndis5.sys
    2007-03-19 12:06 <KANSIO> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\F-Secure
    2007-03-19 12:04 <KANSIO> d-------- C:\Program Files\F-Secure
    2007-03-17 10:22 <KANSIO> d-------- C:\Program Files\Common Files\Skype
    2007-03-17 10:21 <KANSIO> d-------- C:\Program Files\Skype
    2007-03-16 19:38 <KANSIO> d-------- C:\Program Files\Mozilla Thunderbird
    2007-03-16 12:52 786,432 --ah----- C:\DOCUME~1\JRJEST~1\NTUSER.DAT
    2007-03-16 12:52 <KANSIO> dr------- C:\DOCUME~1\JRJEST~1\Ty”p”yt„
    2007-03-16 12:52 <KANSIO> dr------- C:\DOCUME~1\JRJEST~1\Suosikit
    2007-03-16 12:52 <KANSIO> dr------- C:\DOCUME~1\JRJEST~1\Omat tiedostot
    2007-03-16 12:52 <KANSIO> dr------- C:\DOCUME~1\JRJEST~1\K„ynnist„-valikko
    2007-03-16 12:52 <KANSIO> d--h----- C:\DOCUME~1\JRJEST~1\Verkkoymp„rist”
    2007-03-16 12:52 <KANSIO> d--h----- C:\DOCUME~1\JRJEST~1\Tulostinymp„rist”
    2007-03-16 12:52 <KANSIO> d--h----- C:\DOCUME~1\JRJEST~1\Mallit
    2007-03-16 12:52 <KANSIO> d-------- C:\DOCUME~1\JRJEST~1\WINDOWS
    2007-03-16 12:52 <KANSIO> d-------- C:\DOCUME~1\JRJEST~1\APPLIC~1\Real
    2007-03-16 12:52 <KANSIO> d-------- C:\DOCUME~1\JRJEST~1\APPLIC~1\InterTrust
    2007-03-16 12:52 <KANSIO> d-------- C:\DOCUME~1\JRJEST~1\APPLIC~1\Adobe
    2007-03-16 11:30 <KANSIO> d-------- C:\DOCUME~1\KAIMIO~1\APPLIC~1\F-Secure
    2007-03-16 11:29 <KANSIO> d-------- C:\Program Files\microsoft frontpage


    (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


    2007-03-31 20:48 -------- d-------- C:\DOCUME~1\KAIMIO~1\APPLIC~1\skype
    2007-03-27 16:41 249856 --------- C:\WINDOWS\setup1.exe
    2007-03-27 16:39 73216 --a------ C:\WINDOWS\st6unst.exe
    2007-03-25 09:12 59188 --a------ C:\WINDOWS\system32\perfc00b.dat
    2007-03-25 09:12 308798 --a------ C:\WINDOWS\system32\perfh00b.dat
    2007-03-21 14:48 11582 --a------ C:\WINDOWS\mozver.dat
    2007-03-16 11:26 -------- d-------- C:\Program Files\movie maker
    2007-03-16 11:25 -------- d-------- C:\Program Files\windows nt
    2007-02-25 20:28 3580 --a------ C:\WINDOWS\system32\d3d9caps.dat
    2007-02-22 18:20 -------- d-------- C:\DOCUME~1\KAIMIO~1\APPLIC~1\real


    (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

    *Note* empty entries & legit default entries are not shown

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
    "LDM"="\\Program\\"
    "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
    "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
    "HDDHealth"="C:\\Program Files\\HDD Health\\hddhealth.exe -wl"
    "Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
    "ATIModeChange"="Ati2mdxx.exe"
    "ATIPTA"="C:\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
    "ACTIVBOARD"="c:\\apps\\ABoard\\ABoard.exe"
    "VCSPlayer"="\"C:\\Program Files\\Virtual CD v4 SDK\\system\\vcsplay.exe\""
    "CleanEasyImg"="c:\\apps\\easydvd\\cleanall.exe"
    "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
    "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
    "zBrowser Launcher"="C:\\Program Files\\Logitech\\iTouch\\iTouch.exe"
    "Logitech Utility"="Logi_MwX.Exe"
    "AWMON"="\"E:\\Tietoturva\\Anti-Spyware\\Ad-Monitor.exe\""
    "F-Secure Manager"="\"C:\\Program Files\\F-Secure\\Common\\FSM32.EXE\" /splash"
    "F-Secure TNB"="\"C:\\Program Files\\F-Secure\\FSGUI\\TNBUtil.exe\" /CHECKALL /WAITFORSW"
    "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
    "!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
    "Installed"="1"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
    "Installed"="1"
    "NoChange"="1"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
    "Installed"="1"


    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
    "{81559C35-8464-49F7-BB0E-07A383BEF910}"="SpywareGuard"
    "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
    "UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "NoCDBurning"=dword:00000000

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]

    [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
    Source REG_SZ C:\Documents and Settings\Kaimio Juhani\Työpöytä\frame.php.htm

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
    "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
    LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
    NetworkService REG_MULTI_SZ DnsCache\0\0
    rpcss REG_MULTI_SZ RpcSs\0\0
    imgsvc REG_MULTI_SZ StiSvc\0\0
    termsvcs REG_MULTI_SZ TermService\0\0
    HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
    DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
    p2psvc REG_MULTI_SZ p2psvc\0p2pimsvc\0p2pgasvc\0PNRPSvc\0\0



    Contents of the 'Scheduled Tasks' folder
    C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    C:\WINDOWS\tasks\Rekister”intimuistutus 3.job
    C:\WINDOWS\tasks\UPS-j„rjestelm„n sammutusohjelma.job


    ********************************************************************

    catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
    http://www.gmer.net

    scanning hidden processes ...

    scanning hidden services ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden processes: 0
    hidden services: 0
    hidden files: 0

    ********************************************************************

    Completion time: 07-03-31 20:49:39
     
  8. Auttaja

    Auttaja Guest

    "Lopputulos oli että 5 cookies tiedostoa löytyi (medium risk) ja 5 infektoitunutta objektia mutta jostain syystä ei antanut raporttia vaan ilmoitti no raport available"

    Painoitko kuitenkin apply all actions?

    ********

    Varmistellaan:

    Lataa Intermuten CWShredder:
    http://cwshredder.net/bin/CWShredder.exe
    Tallenna se työpöydälle, mutta ÄLÄ aja sitä vielä.

    Lataa About:Buster:
    http://www.malwarebytes.org/AboutBuster.zip
    Pura se työpöydälle, mutta ÄLÄ skannaa vielä.

    Käynnistä kone vikasietotilaan seuraavien ohjeiden mukaisesti:
    1) Käynnistä tietokone
    2) Kun kuulet koneen piippaavan, paina F8, kuitenkin ennen Windowsin logon esiintuloa
    3) Seuraavaksi pitäisi ilmestyä valikko
    4) Valitse valikosta vikasietotila.

    Vikasietotilassa käynnistä CWShredder ja paina Fix.

    Käynnistä nyt AboutBuster -> Begin Removal -> OK -> Kyllä/Yes -> OK -> Exit -> OK. Skannaa kahdesti. Lokitiedosto "AB Logfile.txt" tallentuu automaattisesti AboutBusterin hakemistoon , josta ajoitkin AboutBuster.exen.

    Lähetä HijackThis-logi ja AboutBusterin loki

    ************

    Avaa omatietokone
    Paina oikealla napilla C: asemaa
    ->valitse ominaisuudet
    Avaa työkalut välilehti
    ->aja virheen etsintä
    *molemmat kohdat, siis etsi ja korjaa
    ->eheytä kiintolevy

    ******

    Lataa tuosta CCleaner ja asenna se: http://ccleaner.com/download/downloadpage.aspx?1
    Kun asennat tätä ohjelmaa niin älä asenna sen mukana tulevaa yahoo-toolbaria. Tämä ohjelma
    etsii ja poistaa ns. turhia tiedostoja koneeltasi eli esim: temp tiedostot ja tällä saat myös
    puhdistettua rekisterisi. -korjaa automaattisesti tiedostojärjestelmän virheet¨
    -etsi ja yritä korjata virheelliset sektorit

     
  9. juka39

    juka39 Regular member

    Liittynyt:
    20.02.2007
    Viestejä:
    137
    Kiitokset:
    0
    Pisteet:
    26
    Tässä vielä uusin hjtloki. Kiitoksia tähänastisesta ja hyvää yötä.Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 21:33:34, on 31.3.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\apps\ABoard\ABoard.exe
    E:\Tietoturva\Anti-Spyware\Ad-Monitor.exe
    C:\apps\ABoard\AOSD.exe
    C:\Program Files\F-Secure\Common\FSM32.EXE
    C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\APPS\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    C:\Program Files\F-Secure\Common\FSMA32.EXE
    C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
    C:\Program Files\F-Secure\Common\FSMB32.EXE
    C:\WINDOWS\System32\tcpsvcs.exe
    C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
    C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
    C:\WINDOWS\system32\slserv.exe
    C:\Program Files\F-Secure\Common\FCH32.EXE
    C:\WINDOWS\System32\ups.exe
    C:\Program Files\F-Secure\Common\FAMEH32.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
    C:\Program Files\F-Secure\FSPC\fspc.exe
    C:\Program Files\F-Secure\FSAUA\program\fsaua.exe
    C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
    C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
    C:\Program Files\Skype\Plugin Manager\skypePM.exe
    C:\Program Files\F-Secure\FSGUI\fsguidll.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Documents and Settings\Kaimio Juhani\Omat tiedostot\omat lataukset\HiJackThis_v2.0.0.0.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://saunalahti.fi
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://register.surfeu.fi/signup/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.suomi.net:8080
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\apps\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll (file missing)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
    O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
    O4 - HKLM\..\Run: [CleanEasyImg] c:\apps\easydvd\cleanall.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
    O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
    O4 - HKLM\..\Run: [AWMON] "E:\Tietoturva\Anti-Spyware\Ad-Monitor.exe"
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [LDM] \Program\
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [HDDHealth] C:\Program Files\HDD Health\hddhealth.exe -wl
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Startup: MRU-Blaster Scheduler.lnk = C:\Program Files\MRU-Blaster\scheduler.exe
    O4 - Startup: MRU-Blaster Silent Clean.lnk = C:\Program Files\MRU-Blaster\mrublaster.exe
    O4 - Startup: OpenOffice.org 2.1.lnk = C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
    O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\APPS\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: Lapsilukko... - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\FSPC\fspcmsie.dll
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure\FSPC\fspcmsie.dll
    O9 - Extra 'Tools' menuitem: Lapsilukko... - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure\FSPC\fspcmsie.dll
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:\Program Files\FSPC\fspcmsie.dll (file missing)
    O9 - Extra 'Tools' menuitem: &Keskeytä Web-sivujen suodatus - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:\Program Files\FSPC\fspcmsie.dll (file missing)
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:\Program Files\FSPC\fspcmsie.dll (file missing)
    O9 - Extra 'Tools' menuitem: &Kiellä tämä Web-sivusto - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:\Program Files\FSPC\fspcmsie.dll (file missing)
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:\Program Files\FSPC\fspcmsie.dll (file missing)
    O9 - Extra 'Tools' menuitem: &Salli tämä Web-sivusto - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:\Program Files\FSPC\fspcmsie.dll (file missing)
    O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://saunalahti.fi
    O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://D:\content\include\XPPatchInstaller.CAB
    O16 - DPF: {8B1BC605-C593-4865-8F5B-05517F0CD0BB} (MSSecurityAdvisorCD Class) - file://D:\Content\include\msSecUcd.cab
    O18 - Protocol: bw+0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw+0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw-0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw-0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw00 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw00s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw10 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw10s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw20 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw20s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw30 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw30s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw40 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw40s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw50 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw50s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw60 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw60s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw70 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw70s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw80 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw80s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw90 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw90s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwa0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwa0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwb0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwb0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwc0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwc0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwd0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwd0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwe0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwe0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwf0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwf0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwg0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwg0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwh0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwh0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwi0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwi0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwj0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwj0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwk0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwk0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwl0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwl0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwm0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwm0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwn0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwn0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwo0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwo0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwp0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwp0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwq0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwq0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwr0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwr0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bws0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bws0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwt0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwt0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwu0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwu0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwv0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwv0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bww0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bww0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwx0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwx0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwy0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwy0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwz0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwz0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: offline-8876480 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: Loogisen levyn hallinnan valvontapalvelu (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
    O23 - Service: Tapahtumaloki (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
    O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - Unknown owner - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure\FSAUA\program\fsaua.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
    O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu (ImapiService) - Unknown owner - C:\WINDOWS\System32\imapi.exe
    O23 - Service: Machine Debug Manager (MDM) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (file missing)
    O23 - Service: NetMeeting etätyöpöydän jakaminen (mnmsrvc) - Unknown owner - C:\WINDOWS\System32\mnmsrvc.exe
    O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
    O23 - Service: Etätyöpöydän ohjeen istunnonhallinta (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
    O23 - Service: Älykortti (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
    O23 - Service: Resurssilokit ja -hälytykset (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
    O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - Unknown owner - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe (file missing)
    O23 - Service: Aseman tilannevedos (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
    O23 - Service: WMI resurssisovitin (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe
    O24 - Desktop Component 1: (no name) - C:\Documents and Settings\Kaimio Juhani\Työpöytä\frame.php.htm

    --
    End of file - 23369 bytes
     
  10. Auttaja

    Auttaja Guest

    Avaa hijackthis merkkaa seuraavat rivi(t) ja paina fix checked, sulje muut ohjelmat siksi aikaa

    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll (file missing)
    O4 - HKCU\..\Run: [LDM] \Program\


    Laita uusi HijackThis logi, kysyttävää?
     
    Moderaattorin viimeksi muokkaama: 31.03.2007
  11. juka39

    juka39 Regular member

    Liittynyt:
    20.02.2007
    Viestejä:
    137
    Kiitokset:
    0
    Pisteet:
    26
    Vastaus nim. Auttajan viestiin 31.3.2007 klo 13:44

    Toimin ohjeen mukaan, mutta en ole varma, tuliko AboutBuster ajettua kahteen kertaan. Tilanne meni "ohi" niin nopeasti ja loki tallentui. En huomannut lähettää po. lokeja tässä vaiheessa, vaan menin vikasietotilassa C:asemalle ja yritin ajaa virheen etsinnän, mutta ei hyvksynyt komentoa, joten suljin koneen ja em. toiminta alkoikin etsimään. Teki 5 hakua. Ymmärsin, että lopputulos oli hyvä.Nyt aioin lähettää ne kaksi lokia (AboutB ja Hijk). Toivottavasti jäkimmäinenkin kelpaa, vaikka on ajettu virjeen etsinnän jälkeen.
    Muutoin kovalevylläni on myös erillinen pieni (n. 2 gigaa) E asema. Pitäisikö sille tehdä jotain?
    Seuraavaksi aioin eheyttää kiintolevyn ja ladataCCleanerin ja sitten vielä ajaa Hijackin ja merkata ja laittaa uuden lokin.AboutBuster 6.06
    Scan started on [1.4.2007] at [9:06:35]
    -------------------------------------------------------------
    Internet Explorer Instances Terminated!
    HomeSearch Service stopped if present
    -------------------------------------------------------------
    No Ads Found!
    -------------------------------------------------------------
    No Files Found!
    -------------------------------------------------------------
    Scan was COMPLETED SUCCESSFULLY at 9:09:15


    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 10:25:47, on 1.4.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\apps\ABoard\ABoard.exe
    C:\apps\ABoard\AOSD.exe
    C:\Program Files\F-Secure\Common\FSM32.EXE
    C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
    C:\Program Files\F-Secure\Common\FSMA32.EXE
    C:\Program Files\F-Secure\Common\FSMB32.EXE
    C:\WINDOWS\System32\tcpsvcs.exe
    C:\Program Files\F-Secure\Common\FCH32.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
    C:\Program Files\F-Secure\Common\FAMEH32.EXE
    C:\APPS\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
    C:\Program Files\F-Secure\FSPC\fspc.exe
    C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
    C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
    C:\Program Files\F-Secure\FSAUA\program\fsaua.exe
    C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
    C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    C:\Program Files\Skype\Plugin Manager\skypePM.exe
    C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
    C:\Program Files\F-Secure\FSGUI\fsguidll.exe
    C:\Documents and Settings\Kaimio Juhani\Omat tiedostot\omat lataukset\HiJackThis_v2.0.0.0.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://saunalahti.fi
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://register.surfeu.fi/signup/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.suomi.net:8080
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\apps\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll (file missing)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
    O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
    O4 - HKLM\..\Run: [CleanEasyImg] c:\apps\easydvd\cleanall.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
    O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
    O4 - HKLM\..\Run: [AWMON] "E:\Tietoturva\Anti-Spyware\Ad-Monitor.exe"
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [LDM] \Program\
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [HDDHealth] C:\Program Files\HDD Health\hddhealth.exe -wl
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Startup: MRU-Blaster Scheduler.lnk = C:\Program Files\MRU-Blaster\scheduler.exe
    O4 - Startup: MRU-Blaster Silent Clean.lnk = C:\Program Files\MRU-Blaster\mrublaster.exe
    O4 - Startup: OpenOffice.org 2.1.lnk = C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
    O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\APPS\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: Lapsilukko... - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\FSPC\fspcmsie.dll
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure\FSPC\fspcmsie.dll
    O9 - Extra 'Tools' menuitem: Lapsilukko... - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure\FSPC\fspcmsie.dll
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:\Program Files\FSPC\fspcmsie.dll (file missing)
    O9 - Extra 'Tools' menuitem: &Keskeytä Web-sivujen suodatus - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:\Program Files\FSPC\fspcmsie.dll (file missing)
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:\Program Files\FSPC\fspcmsie.dll (file missing)
    O9 - Extra 'Tools' menuitem: &Kiellä tämä Web-sivusto - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:\Program Files\FSPC\fspcmsie.dll (file missing)
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:\Program Files\FSPC\fspcmsie.dll (file missing)
    O9 - Extra 'Tools' menuitem: &Salli tämä Web-sivusto - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:\Program Files\FSPC\fspcmsie.dll (file missing)
    O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://saunalahti.fi
    O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://D:\content\include\XPPatchInstaller.CAB
    O16 - DPF: {8B1BC605-C593-4865-8F5B-05517F0CD0BB} (MSSecurityAdvisorCD Class) - file://D:\Content\include\msSecUcd.cab
    O18 - Protocol: bw+0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw+0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw-0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw-0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw00 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw00s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw10 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw10s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw20 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw20s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw30 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw30s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw40 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw40s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw50 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw50s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw60 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw60s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw70 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw70s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw80 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw80s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw90 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bw90s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwa0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwa0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwb0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwb0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwc0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwc0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwd0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwd0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwe0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwe0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwf0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwf0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwg0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwg0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwh0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwh0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwi0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwi0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwj0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwj0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwk0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwk0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwl0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwl0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwm0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwm0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwn0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwn0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwo0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwo0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwp0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwp0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwq0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwq0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwr0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwr0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bws0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bws0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwt0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwt0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwu0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwu0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwv0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwv0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bww0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bww0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwx0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwx0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwy0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwy0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwz0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: bwz0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: offline-8876480 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: Loogisen levyn hallinnan valvontapalvelu (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
    O23 - Service: Tapahtumaloki (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
    O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - Unknown owner - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure\FSAUA\program\fsaua.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
    O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu (ImapiService) - Unknown owner - C:\WINDOWS\System32\imapi.exe
    O23 - Service: Machine Debug Manager (MDM) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (file missing)
    O23 - Service: NetMeeting etätyöpöydän jakaminen (mnmsrvc) - Unknown owner - C:\WINDOWS\System32\mnmsrvc.exe
    O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
    O23 - Service: Etätyöpöydän ohjeen istunnonhallinta (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
    O23 - Service: Älykortti (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
    O23 - Service: Resurssilokit ja -hälytykset (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
    O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - Unknown owner - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe (file missing)
    O23 - Service: Aseman tilannevedos (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
    O23 - Service: WMI resurssisovitin (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe
    O24 - Desktop Component 1: (no name) - C:\Documents and Settings\Kaimio Juhani\Työpöytä\frame.php.htm

    --
    End of file - 23199 bytes
     
  12. Jarska92

    Jarska92 Regular member

    Liittynyt:
    27.10.2006
    Viestejä:
    1,132
    Kiitokset:
    0
    Pisteet:
    46
    kun täällä kerran puhutaan oudoista ongelmista niin osaisiko joku auttaa minuakin? :) ongelmia on monia, ensinnäkin kun avaan koneen niin sygate personal firewall kysyy aina että päästetäänkö "NT ydin ja järjestelmä" internettiin, painan aina ei. eli ulosmenevä yhteys kyseessä. ja jo pari kertaa joku "Sohanad.AE" virus pääsee palomuurin läpi ja antivir ilmoittaa siitä. sitten kun katson infosta mitä se tekee niin. alentaa virusturvan suojaustasoa, lataa tiedostoja internetistä, ja jotain muuta. sitten kotiväen koneella alko tuleen kans tuo NT ydin ja järjestelmä kysely joka käynnistyksessä, nettiin pääsee vaikka painais että ei. mutta siihenkin on alkanut tulemaan jotain viruksia ja niistä antivir info ei edes tiedä mitään...ja outoa että ne virukset tulee aina kun scannaan konetta viruksilta tai spywareilta. ja aina ne virukset menee sinne "system volume information" paikkaan josta ne voi poistaa vaan virusturvalla.

    EDIT: niin ja vielä lähes joka käynnistyksessä windows sanoo että "laite ei asentunut oikein" tai jotain tommosta ja näppäimistö ei toimi, aina pitää ottaa näppäimistö liitännästään irti ja pistää takas, itse näppäimistö ei pitäisi olla rikki koska sen vasta pari kuukautta sitten ostin ja hyvin toimii...
     
    Viimeksi muokattu: 01.04.2007
  13. juka39

    juka39 Regular member

    Liittynyt:
    20.02.2007
    Viestejä:
    137
    Kiitokset:
    0
    Pisteet:
    26
    Eheytin C ja E asemat. C:ssä olikin paljon pirstoutuneisuutta. Lisäksi vielä etsin virheitä E: asemalta. Ei ilmeisesti ollut.
    Latasin Ccleanerin, mutta ei ole varmaa,osasinko käyttää sitä. Kokeilin monenlaisia ajoa, mm. rekisterin eheytys ,jossa oli paljon "Puuttuvia jaettuja DLL kirjastoja" ja jotain Active X. Annoin poistaa kaikki. En tosiaan ymmärtänyt Cleanerin käyttöä. Toivottavasti ei tullut pahoja virheita. Avasin Hjakin merkkasin ja fiksasin viestissäsi mainitut rivit. Kyseli ainakin pariin kertaan, ennekuin suostui poistamaan. Tässä uusin HjakLogfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 11:46:10, on 1.4.2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\apps\ABoard\ABoard.exe
    C:\apps\ABoard\AOSD.exe
    C:\Program Files\F-Secure\Common\FSM32.EXE
    C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
    C:\Program Files\F-Secure\Common\FSMA32.EXE
    C:\Program Files\F-Secure\Common\FSMB32.EXE
    C:\WINDOWS\System32\tcpsvcs.exe
    C:\Program Files\F-Secure\Common\FCH32.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
    C:\Program Files\F-Secure\Common\FAMEH32.EXE
    C:\APPS\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
    C:\Program Files\F-Secure\FSPC\fspc.exe
    C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
    C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
    C:\Program Files\F-Secure\FSAUA\program\fsaua.exe
    C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
    C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    C:\Program Files\Skype\Plugin Manager\skypePM.exe
    C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
    C:\Program Files\F-Secure\FSGUI\fsguidll.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\Documents and Settings\Kaimio Juhani\Omat tiedostot\omat lataukset\HiJackThis_v2.0.0.0.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://saunalahti.fi
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://register.surfeu.fi/signup/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.suomi.net:8080
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\apps\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
    O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
    O4 - HKLM\..\Run: [CleanEasyImg] c:\apps\easydvd\cleanall.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
    O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
    O4 - HKLM\..\Run: [AWMON] "E:\Tietoturva\Anti-Spyware\Ad-Monitor.exe"
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [HDDHealth] C:\Program Files\HDD Health\hddhealth.exe -wl
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Startup: MRU-Blaster Scheduler.lnk = C:\Program Files\MRU-Blaster\scheduler.exe
    O4 - Startup: MRU-Blaster Silent Clean.lnk = C:\Program Files\MRU-Blaster\mrublaster.exe
    O4 - Startup: OpenOffice.org 2.1.lnk = C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
    O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\APPS\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: Lapsilukko... - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\FSPC\fspcmsie.dll
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure\FSPC\fspcmsie.dll
    O9 - Extra 'Tools' menuitem: Lapsilukko... - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure\FSPC\fspcmsie.dll
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: &Keskeytä Web-sivujen suodatus - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: &Kiellä tämä Web-sivusto - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: &Salli tämä Web-sivusto - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://saunalahti.fi
    O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://D:\content\include\XPPatchInstaller.CAB
    O16 - DPF: {8B1BC605-C593-4865-8F5B-05517F0CD0BB} (MSSecurityAdvisorCD Class) - file://D:\Content\include\msSecUcd.cab
    O18 - Protocol: bw+0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw+0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw-0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw-0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw00 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw00s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw10 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw10s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw20 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw20s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw30 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw30s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw40 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw40s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw50 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw50s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw60 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw60s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw70 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw70s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw80 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw80s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw90 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw90s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwa0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwa0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwb0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwb0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwc0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwc0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwd0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwd0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwe0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwe0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwf0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwf0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - (no file)
    O18 - Protocol: bwg0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwg0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwh0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwh0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwi0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwi0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwj0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwj0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwk0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwk0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwl0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwl0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwm0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwm0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwn0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwn0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwo0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwo0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwp0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwp0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwq0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwq0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwr0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwr0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bws0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bws0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwt0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwt0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwu0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwu0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwv0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwv0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bww0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bww0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwx0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwx0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwy0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwy0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwz0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwz0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: offline-8876480 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: Loogisen levyn hallinnan valvontapalvelu (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
    O23 - Service: Tapahtumaloki (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
    O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - Unknown owner - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure\FSAUA\program\fsaua.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
    O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu (ImapiService) - Unknown owner - C:\WINDOWS\System32\imapi.exe
    O23 - Service: Machine Debug Manager (MDM) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (file missing)
    O23 - Service: NetMeeting etätyöpöydän jakaminen (mnmsrvc) - Unknown owner - C:\WINDOWS\System32\mnmsrvc.exe
    O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
    O23 - Service: Etätyöpöydän ohjeen istunnonhallinta (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
    O23 - Service: Älykortti (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
    O23 - Service: Resurssilokit ja -hälytykset (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
    O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - Unknown owner - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe (file missing)
    O23 - Service: Aseman tilannevedos (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
    O23 - Service: WMI resurssisovitin (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe
    O24 - Desktop Component 1: (no name) - C:\Documents and Settings\Kaimio Juhani\Työpöytä\frame.php.htm

    --
    End of file - 15767 bytes
    Kysymyksiä on uudessa viestissä, koska tähän ei enää mahdu. Kiitos tähänastisesta.
     
  14. Hujo

    Hujo Guest

    Jarska92
    Omat aloitukset ja niihin lokit.
     
    Moderaattorin viimeksi muokkaama: 01.04.2007
  15. juka39

    juka39 Regular member

    Liittynyt:
    20.02.2007
    Viestejä:
    137
    Kiitokset:
    0
    Pisteet:
    26
    Tässä vielä muutama kysymys:
    Voiko AVG:tä käyttää normaali (ei vikasieto) tilassa ja F-securen Ad- Awaren (joka ilmeisesti on sama kuin Lavasoftin vastaava) ohella tai tilalla?
    Jäivätköhän eilen siihen ohjeittesi mukaan tekemäni asetukset muistiin?
    Kannattako Ccleaneria käyttää säännöllisesti? Onko sen käyttämisestä jostain täsmällisiä ohjeita, ettei synny vaaratilanteita.
    Jos ystävällisesti luet vielä tämän ketjun aloitusviestini, niin huomaat, että Windowsiin sisältyvä Office paketti on viallinen. Tietokoneeni (Packard Bell iextreme) käyttöohjeessa mainitaan, että koneen apuohjelman Smart Restoren avulla voisi ainakin Wordin uudeleenasennusta yrittää. Voiko tähän askareeseen saada apua tarvittaessa tämän keskustelupalstan joltakin alueelta, jollei tältä?
     
  16. juka39

    juka39 Regular member

    Liittynyt:
    20.02.2007
    Viestejä:
    137
    Kiitokset:
    0
    Pisteet:
    26
    Jos tuo oli minulle tarkoitettu, en valitettavasti ymmärrä, mitä pitäisi tehdä.
     
  17. Hujo

    Hujo Guest

    eipä ollut sulle

    scannaa hjt:llä merkkaa paina Fix checked

    O18 - Protocol: bw+0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw+0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw-0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw-0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw00 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw00s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw10 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw10s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw20 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw20s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw30 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw30s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw40 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw40s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw50 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw50s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw60 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw60s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw70 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw70s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw80 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw80s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw90 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bw90s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwa0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwa0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwb0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwb0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwc0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwc0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwd0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwd0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwe0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwe0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwf0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwf0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - (no file)
    O18 - Protocol: bwg0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwg0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwh0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwh0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwi0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwi0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwj0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwj0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwk0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwk0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwl0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwl0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwm0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwm0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwn0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwn0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwo0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwo0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwp0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwp0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwq0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwq0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwr0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwr0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bws0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bws0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwt0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwt0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwu0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwu0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwv0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwv0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bww0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bww0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwx0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwx0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwy0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwy0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwz0 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: bwz0s - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)
    O18 - Protocol: offline-8876480 - {9EBC5CA5-3ABB-4DD4-A7CC-79AE5EFF5FBA} - (no file)


    Tuosta Beetta versiosta tulee näppylöitä
    poista se lisää poista sovelutuksesta
    HiJackThis_v2.0.0.0.exe


    lataa tuo 1.99.1 versio koneelle ota sillä uusi hjt:n loki

    Lataa hjt:n tuosta http://koti.mbnet.fi/pattaya1/lataus/hijackthis_self.exe

    asenna naputtele numero järjestyksessä

    1.Unzip
    2.OK
    3.Close

    scannaa paina tuosta > Do a system scan and save a logfile

    Kopioi ponnahtava muistio hjt loki ja laita tänne.
     
    Moderaattorin viimeksi muokkaama: 01.04.2007
  18. Jarska92

    Jarska92 Regular member

    Liittynyt:
    27.10.2006
    Viestejä:
    1,132
    Kiitokset:
    0
    Pisteet:
    46
    joo, en nyt uutta viestiketjua aloittanut kun täällä puhuttiin vähän kaikista oudoista jutuista niin ajattelin nyt että jos joku täällä tietäis mitä tehdä. mutta windowsin asennan uusiksi kun muutenkin niin sekaisin niin eiköhän siitä selvitä...
     
  19. Hujo

    Hujo Guest

    Jarska92
    Noin pienellä muistilla 512 Mb suuria tehdä
     
  20. Jarska92

    Jarska92 Regular member

    Liittynyt:
    27.10.2006
    Viestejä:
    1,132
    Kiitokset:
    0
    Pisteet:
    46
    tiedän ettei sillä paljoa tehdä :D mutta oonkin jo päivittämässä konetta, rahoja kasaamassa. kohta tilaan uuden emolevyn ja sitten intelin core 2 duo e6300:sen ja sitä myötä ostan gigan muistia lisää. että eiköhän sillä pärjätä vähän pitemmälle.
     
  21. juka39

    juka39 Regular member

    Liittynyt:
    20.02.2007
    Viestejä:
    137
    Kiitokset:
    0
    Pisteet:
    26
    Vastaus Hujon viestiin aprillipäivänä 2007 klo5:52

    Ennenkuin teen mitään kysyn olenko varmasti ymmärtänyt oikein: tarkoititko, että skannaan tällä Betaversion Hjt:lla ja poistan kaikki nuo 018 rivit?

    Sen jälkeen poistan betaversion ja lataan uuden ja lähetän uuden lokin Sinulle.

     

Jaa tämä sivu