1. Tämä sivusto käyttää keksejä (cookie). Jatkamalla sivuston käyttämistä hyväksyt keksien käyttämisen. Lue lisää.

Svchost.exe syö muistit ja kone hidas

Viestiketju Virukset ja haittaohjelmat - HijackThis -logit -osiossa. Ketjun avasi k0libri 09.04.2008.

  1. Hujo

    Hujo Guest

    laitas sitten hjt:n loki ennen kuin poistat.. ei sitä ainakaan lokissa näkynyt..
     
  2.  
  3. k0libri

    k0libri Guest

    Varmaan sen takia, koska asensin aviran ja comodon vasta äskö :) Mutta oliks tos SDfixin logissa jotai mätää ?
     
    Moderaattorin viimeksi muokkaama: 09.04.2008
  4. Hujo

    Hujo Guest

    eipä siinä ole mutta scannaa se uusi hjt:n loki
     
  5. k0libri

    k0libri Guest

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 18:49:12, on 9.4.2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\COMODO\Firewall\cfp.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\COMODO\Firewall\cmdagent.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O3 - Toolbar: (no name) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - (no file)
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
    O4 - HKCU\..\Run: [HistoryKill] "C:\Program Files\HistoryKill 2007\histkill.exe" /startup
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe
    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe (file missing)
    O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe (file missing)

    --
    End of file - 4734 bytes

    Minkä takia tuo Svchost.exe käyttää eniten resursseja ?
     
    Moderaattorin viimeksi muokkaama: 09.04.2008
  6. Hujo

    Hujo Guest

    No niin

    Kopioi / liitä seuraava teksti alapuolella tyhjään muistioFiluun
    Varmista että tiedoston tyyppi on ”all Files” ja tallenna se Poisto.bat. nimisenä
    työpöydällesi.

    @echo off
    sc stop LIVESRV
    sc delete LIVESRV
    sc stop VSSERV
    sc delete VSSERV
    sc stop XCOMM
    sc delete XCOMM

    Tupla-klikkaa Poisto.bat. filua työpöydälläsi , ikkuna avautuu ja Sulkeutuu tämä on normaalia.

    Poista kansio vikasiedossa.

    C:\Program Files\Common Files\BitDefender
    C:\Program Files\BitDefender

    scannaa hjt:llä merkkaa paina Fix checked

    O3 - Toolbar: (no name) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - (no file)

    ==============

    vieläkö se jyllää siellä
     
  7. k0libri

    k0libri Guest

    Tein ton poisto.bat. jutun, mutta ei se mulla sulkeutunu ittestää, ja menin vikasietoon ja yritin ettiä tota bitdefenderii sielt C:asemalta, mutta ei sitä siellä ollu. Ja joo kyllä se käyttää sen 21 000kt muistia.
     
    Moderaattorin viimeksi muokkaama: 09.04.2008
  8. Hujo

    Hujo Guest

    scannaa uusi hjt:n loki
     
  9. k0libri

    k0libri Guest

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 19:51:55, on 9.4.2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\COMODO\Firewall\cfp.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\COMODO\Firewall\cmdagent.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
    O4 - HKCU\..\Run: [HistoryKill] "C:\Program Files\HistoryKill 2007\histkill.exe" /startup
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe
    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe (file missing)
    O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe (file missing)

    --
    End of file - 4656 bytes
     
  10. Hujo

    Hujo Guest

    joo nyt sitteen eti nuo

    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe (file missing)
    O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe (file missing)
    O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe (file missing)


    Mene käynnistä -> suorita -> services.msc -> ok

    tuplaklikkaa ja laita seis ja alas vetovalikosta ei käytössä
    käytä ja ok
     
  11. k0libri

    k0libri Guest

    Juu, laitoin kaikkiin Bitdefender juttuihi ei käytössä ja niitä oli yhteensä 4.
     
  12. Hujo

    Hujo Guest

    jokos ne katosi hjt:n lokista.
     
    Moderaattorin viimeksi muokkaama: 09.04.2008
  13. k0libri

    k0libri Guest

    Jep, nyt läks.
     
  14. Hujo

    Hujo Guest

    sitten loki on ilo silmälle. ;)
     
  15. k0libri

    k0libri Guest

    Joo mutta vielläki toi Svchost.exe käyttää paljo resursseja ? Ja kone on edelleen hidas :( Huomasin myös nytte että joku Explorer.exe käyttää myös paljon resursseja?
     
    Moderaattorin viimeksi muokkaama: 10.04.2008
  16. Hujo

    Hujo Guest

    Lataa OTMoveIt
    OTMoveIt ja tallenna se työpöydällesi.

    Tuplaklikkaa OTMoveIt.exe.
    Klikkaa CleanUp!.
    Valitse Yes kun kysytään "Begin cleanup Process?".
    Jos pyydetään, että saako koneen käynnistää uudeelleen, valitse Yes.OTMoveIt poistaa itsensä kun se on valmis, jos näin ei käy poista se itse.

    HUOM: Jos palomuurisi tai joku muu tietoturvaohjelma varoittaa, että OTMoveIt yrittää päästä nettin, niin anna sen päästä sinne.

    ===========

    Lataa: RegSeeker.zip työpöydälle:

    Pura zip C:\RegSeeker\ kansioon. Sieltä käynnistät RegSeeker.exe ohjelman.
    Oikeasa yläkulmassa on Languages.... linkki, josta valitset Suomenkielen.
    Vasemmasta alakulmasta ruksit Luo vrmuuskopio ja sitten linkki Puhdista rekisteri
    Ruksit kaikkiin muihin kohtiin paitsi "Käyttökelvottomat.." sitten "OK" (odotat hetken).
    Ruutuun ilmestyy lista epäkelvoista rekisterimerkinnöistä, jotka alapalkista Valitse kohdasta
    klikkaat Valitse kaikki jolloin valitut saavat keltaisen pohjavärin.
    Alapalkin Toiminnot linkistä klikkaat Poista valitut kohteet
    Ponnahdusikkunaan "Kaikki valitut kohteet poistetaan ? vastaat "OK".
    Seuraavaan Ponnahdusikkunaan "Varmuuskopiot" vastaat "OK".
    Klikaa vasemmalta Lopeta RegSeeker ja käynnistä koneesi uudelleen.

    ===========

    Lataa Dr.Web CureIt työpöydälle:

    Tuplaklikkaa drweb-cureit.exe ja anna sen tehdä express scan
    Se skannaa käynnissä olevat ohjelmat ja jos jotain löytyy, klikkaa yes kun se kysyy haluatko poistaa sen. Tämä on vain lyhyt scan.
    Kun scan on valmis, Klikkaa Custom scan merkkaa asemat, jotka haluat scannata.
    Valitse kaikki asemat. Punainen piste osoittaa, mitkä asemat on valittu.
    Klikaa vihreää nuolta oikealla ja scan alkaa.
    Klikkaa 'Yes to all', jos kysytään haluatko poistaa/siirtää tiedoston.
    Kun scan on valmis, katso voitko klikata next-kuvaketta löytyneiden tiedostojen vieressä: [​IMG]
    Jos asia on niin, klikkaa sitä ja sitten klikkaa next-kuvaketta oikealla alhaalla ja valitse Move incurable kuten alla olevalla kuvassa:
    [​IMG]
    Tämä siirtää sen %userprofile%\DoctorWeb\quarantine-hakemistoon.
    Tämän jälkeen klikkaa Dr.Web CureIt-valikossa file ja valitse save report list
    Tallenna raportti työpöydälle. Raportin nimi on DrWeb.csv
    Sulje Dr.Web Cureit.
    Käynnistä kone uudelleen !! Tämä siksi, että käytössä olevat tiedostot poistetaan/siirretään käynnistyksen yhteydessä.
    Käynnistyksen jälkeen liitä Dr.Web-lokin, jonka tallensit aiemmin, sisältö seuraavaan vastaukseesi.
     
  17. k0libri

    k0libri Guest

    Joo eli en tiedä laitoinko oikein mutta tässä loki:

    A0001880.exe;C:\System Volume Information\_restore{B9F15D7F-8ED8-45AE-B31C-454320350ED4}\RP10;Probably DLOADER.Trojan;Incurable.Moved.;
    A0002012.exe;C:\System Volume Information\_restore{B9F15D7F-8ED8-45AE-B31C-454320350ED4}\RP12;Tool.Prockill;Incurable.Moved.;
    A0002063.EXE;C:\System Volume Information\_restore{B9F15D7F-8ED8-45AE-B31C-454320350ED4}\RP14;Program.PsExec.170;Incurable.Moved.;
    A0002071.bat;C:\System Volume Information\_restore{B9F15D7F-8ED8-45AE-B31C-454320350ED4}\RP14;Probably BATCH.Virus;Incurable.Moved.;
    A0002077.bat;C:\System Volume Information\_restore{B9F15D7F-8ED8-45AE-B31C-454320350ED4}\RP14;Probably SCRIPT.Virus;Incurable.Moved.;
    A0002293.exe;C:\System Volume Information\_restore{B9F15D7F-8ED8-45AE-B31C-454320350ED4}\RP14;Tool.Prockill;Incurable.Moved.;
    A0002296.exe;C:\System Volume Information\_restore{B9F15D7F-8ED8-45AE-B31C-454320350ED4}\RP14;Tool.ShutDown.11;Incurable.Moved.;
    A0003205.exe;C:\System Volume Information\_restore{B9F15D7F-8ED8-45AE-B31C-454320350ED4}\RP15;Tool.Prockill;Incurable.Moved.;
    PSEXESVC.EXE;C:\WINDOWS;Program.PsExec.170;Incurable.Moved.;
    Process.exe;C:\WINDOWS\system32;Tool.Prockill;Incurable.Moved.;
     
    Moderaattorin viimeksi muokkaama: 11.04.2008
  18. Hujo

    Hujo Guest

    1. Klikkaa käynnistä > Oma tietokone oikean puoleisella hiiren napilla
    2. Valitse ominaisuudet
    3. Valitse järjestelmän palauttaminen välilehti
    4. Ruksi eteen ¤ poista järjestelmän palauttaminen kaikissa asemissa
    5. Paina Käytä
    6. Paina ok
    7. Sammuta ja käynnistä
    8. Ota ruksi pois ¤ poista järjestelmän palauttaminen kaikissa asemissa
    9. Käytä ja OK
     
  19. k0libri

    k0libri Guest

    Dodiih, mitäs sitten ? =) Vielläkin tuo Svchost.exe jyllää tuolla ja samoin explorer.exe. Voisiko noille tehdä jotain?
     
  20. Hujo

    Hujo Guest

    Lataa Deckard's System Scanner
    Työpöydällesi.

    Huomioi: Sinulla tulee olla Järjestelmänvalvojan oikeudet ajaaksesi ohjelman.

    [*]Sulje kaikki avoimet ikkunat ja ohjelmat.
    [*]Tupla Klikkaa Dss.exe tiedostoa ajaaksesi ohjelman, seuraa ohjeita.
    [*]Kun Scannaus on valmis 2 textitiedostoa pitäisi avautua, Main.txt ja extra.txt
    [*]Näppäile Kopioi ( CTRL+A -> CTRL + C ) ja liitä ( CTRL + V )
    [*]kopioi ja liitä main.txt ja extra.txt sisältö seuraavaan vastaukseesi.
     
  21. k0libri

    k0libri Guest

    Tässä main.txt:

    Deckard's System Scanner v20071014.68
    Run by Jepe on 2008-04-11 17:46:39
    Computer is in Normal Mode.
    --------------------------------------------------------------------------------

    -- System Restore --------------------------------------------------------------

    Successfully created a Deckard's System Scanner Restore Point.


    -- Last 2 Restore Point(s) --
    2: 2008-04-11 14:46:42 UTC - RP2 - Deckard's System Scanner Restore Point
    1: 2008-04-11 14:28:45 UTC - RP1 - Järjestelmän tarkistuspiste


    Backed up registry hives.
    Performed disk cleanup.



    -- HijackThis (run as Jepe.exe) ------------------------------------------------

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 17:47:15, on 11.4.2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\COMODO\Firewall\cfp.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\Program Files\COMODO\Firewall\cmdagent.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Documents and Settings\Jepe\Työpöytä\dss.exe
    C:\PROGRA~1\TRENDM~1\HIJACK~1\Jepe.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKCU\..\Run: [HistoryKill] "C:\Program Files\HistoryKill 2007\histkill.exe" /startup
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    --
    End of file - 4075 bytes

    -- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------

    backup-20080409-101212-680 O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
    backup-20080409-132132-549 O20 - AppInit_DLLs:
    backup-20080409-194542-613 O3 - Toolbar: (no name) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - (no file)

    -- File Associations -----------------------------------------------------------

    .bat - batfile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,71
    .cmd - cmdfile - DefaultIcon - C:\WINDOWS\System32\shell32.dll,-153
    .hlp - hlpfile - DefaultIcon - C:\WINDOWS\System32\shell32.dll,23
    .inf - inffile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,69
    .ini - inifile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,69
    .js - JSFile - DefaultIcon - C:\WINDOWS\System32\WScript.exe,3
    .reg - regfile - DefaultIcon - C:\WINDOWS\regedit.exe,1
    .txt - txtfile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,70


    -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

    R1 SCDEmu - c:\windows\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>

    S1 bdftdif - c:\program files\common files\bitdefender\bitdefender firewall\bdftdif.sys (file missing)
    S3 BDSelfPr - c:\program files\bitdefender\bitdefender 2008\bdselfpr.sys (file missing)
    S3 Profos - c:\program files\common files\bitdefender\bitdefender threat scanner\profos.sys (file missing)
    S3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>
    S3 Trufos - c:\program files\common files\bitdefender\bitdefender threat scanner\trufos.sys (file missing)


    -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

    S4 LIVESRV (BitDefender Desktop Update Service) - "c:\program files\common files\bitdefender\bitdefender update service\livesrv.exe" /service (file missing)
    S4 VSSERV (BitDefender Virus Shield) - "c:\program files\bitdefender\bitdefender 2008\vsserv.exe" /service (file missing)
    S4 XCOMM (BitDefender Communicator) - "c:\program files\common files\bitdefender\bitdefender communicator\xcommsvr.exe" /service (file missing)


    -- Device Manager: Disabled ----------------------------------------------------

    No disabled devices found.


    -- Files created between 2008-03-11 and 2008-04-11 -----------------------------

    2008-04-11 17:27:20 0 dr-h----- C:\Documents and Settings\Jepe\Recent
    2008-04-11 17:14:04 0 d-------- C:\Documents and Settings\Jepe\Application Data\AVG7
    2008-04-11 17:13:58 0 d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
    2008-04-11 17:13:42 0 d-------- C:\Documents and Settings\All Users\Application Data\avg7
    2008-04-11 15:46:05 0 d-------- C:\Documents and Settings\Jepe\DoctorWeb
    2008-04-09 18:09:32 0 d-------- C:\Program Files\COMODO
    2008-04-09 16:14:26 5702 --ah----- C:\WINDOWS\nod32restoretemdono.reg
    2008-04-09 16:13:15 0 d-------- C:\Documents and Settings\All Users\Application Data\ESET
    2008-04-09 16:04:39 0 d-------- C:\WINDOWS\SxsCaPendDel
    2008-04-09 15:34:42 0 d-------- C:\WINDOWS\ERUNT
    2008-04-09 13:22:47 0 d-------- C:\Documents and Settings\Jepe\Application Data\Malwarebytes
    2008-04-09 13:22:31 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-04-09 13:22:30 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-04-09 11:06:15 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
    2008-04-09 10:54:40 0 d-------- C:\WINDOWS\system32\Adobe
    2008-04-08 23:10:17 0 d-------- C:\Program Files\Electronic Arts
    2008-04-08 20:35:42 0 d-------- C:\Program Files\PowerISO
    2008-04-08 10:19:08 0 d-------- C:\Program Files\RocketDock
    2008-04-08 10:01:53 0 d-------- C:\Documents and Settings\Jepe\.housecall6.6
    2008-04-07 21:04:04 0 d-------- C:\WINDOWS\Sun
    2008-04-06 22:46:11 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
    2008-04-06 22:46:04 0 d-------- C:\Program Files\SUPERAntiSpyware
    2008-04-06 22:46:04 0 d-------- C:\Documents and Settings\Jepe\Application Data\SUPERAntiSpyware.com
    2008-04-06 17:31:07 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
    2008-04-06 17:31:07 86528 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
    2008-04-06 17:31:07 82432 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
    2008-04-06 17:31:06 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
    2008-04-06 17:31:06 51200 --a------ C:\WINDOWS\system32\dumphive.exe
    2008-04-06 13:37:16 0 d-------- C:\Program Files\Stardock
    2008-04-06 10:51:28 0 d-------- C:\Program Files\Java
    2008-04-06 10:51:24 0 d-------- C:\Program Files\Common Files\Java
    2008-04-05 19:49:59 0 d-------- C:\Program Files\Trend Micro
    2008-04-05 13:47:16 0 d-------- C:\Program Files\MSXML 4.0
    2008-04-05 13:41:44 0 d-------- C:\Documents and Settings\Jepe\Application Data\Grisoft
    2008-04-05 13:41:33 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
    2008-04-05 13:37:47 0 d-------- C:\Program Files\GameSpy Arcade
    2008-04-05 13:36:00 0 d-------- C:\Program Files\Microsoft Games
    2008-04-05 11:42:53 0 d-------- C:\Program Files\Steam
    2008-04-04 17:52:15 0 d-------- C:\Program Files\DC++
    2008-04-04 16:39:58 164352 --a------ C:\WINDOWS\system32\unrar.dll
    2008-04-04 16:39:53 217088 --a------ C:\WINDOWS\system32\yv12vfw.dll <Not Verified; www.helixcommunity.org; Helix YV12 YUV Codec>
    2008-04-04 16:39:53 159839 --a------ C:\WINDOWS\system32\xvidvfw.dll
    2008-04-04 16:39:53 755027 --a------ C:\WINDOWS\system32\xvidcore.dll
    2008-04-04 16:39:52 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
    2008-04-04 16:39:52 81920 --a------ C:\WINDOWS\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
    2008-04-04 16:39:51 682496 --a------ C:\WINDOWS\system32\divx.dll <Not Verified; DivX, Inc.; DivX®>
    2008-04-04 16:39:50 7680 --a------ C:\WINDOWS\system32\ff_vfw.dll
    2008-04-04 16:39:49 0 d-------- C:\Program Files\K-Lite Codec Pack
    2008-04-04 16:37:15 0 d-------- C:\Program Files\Ganymede
    2008-04-04 15:43:11 0 d-------- C:\WINDOWS\HistoryKill
    2008-04-04 15:43:11 0 d-------- C:\Program Files\HistoryKill 2007
    2008-04-04 15:31:46 0 d-------- C:\Program Files\CCleaner
    2008-04-04 14:46:07 0 d-------- C:\Documents and Settings\Jepe\Application Data\WinRAR
    2008-04-04 14:44:29 0 d-------- C:\Documents and Settings\All Users\Application Data\GRETECH
    2008-04-04 14:44:03 0 d-------- C:\Documents and Settings\Jepe\Application Data\GRETECH
    2008-04-04 14:43:51 0 d-------- C:\Program Files\GRETECH
    2008-04-04 14:22:28 0 d-------- C:\Program Files\Windows Media Connect 2
    2008-04-04 14:21:09 0 d-------- C:\WINDOWS\system32\LogFiles
    2008-04-04 14:21:09 0 d-------- C:\WINDOWS\system32\drivers\UMDF
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\WinSxS
    2008-04-03 22:28:44 0 dr------- C:\WINDOWS\Web
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\twain_32
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\wins
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\wbem
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\usmt
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\spool
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\ShellExt
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\Setup
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\ras
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\oobe
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\npp
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\mui
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\inetsrv
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\IME
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\icsxml
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\ias
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\export
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\drivers
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\drivers\etc
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\drivers\disdn
    2008-04-03 22:28:44 0 dr-hs--c- C:\WINDOWS\system32\dllcache
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\dhcp
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\config
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\3com_dmi
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\3076
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\2052
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\1054
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\1042
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\1041
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\1037
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\1035
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\1033
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\1031
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\1028
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system32\1025
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\system
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\security
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\Resources
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\repair
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\mui
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\msapps
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\msagent
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\Media
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\java
    2008-04-03 22:28:44 0 d--h----- C:\WINDOWS\inf
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\ime
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\Help
    2008-04-03 22:28:44 0 dr--s---- C:\WINDOWS\Fonts
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\Driver Cache
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\Debug
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\Cursors
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\Connection Wizard
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\Config
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\AppPatch
    2008-04-03 22:28:44 0 d-------- C:\WINDOWS\addins
    2008-04-03 22:11:47 0 d-------- C:\Documents and Settings\Jepe\Application Data\BitDefender
    2008-04-03 22:10:44 0 d-------- C:\Documents and Settings\All Users\Application Data\BitDefender
    2008-04-03 22:06:19 0 d-------- C:\Documents and Settings\Jepe\Application Data\Sun
    2008-04-03 21:58:46 0 d-------- C:\Program Files\uTorrent
    2008-04-03 21:58:42 0 d-------- C:\Documents and Settings\Jepe\Application Data\uTorrent
    2008-04-03 21:53:19 0 d-------- C:\WINDOWS\pss
    2008-04-03 21:49:24 0 d-------- C:\Documents and Settings\Jepe\Contacts
    2008-04-03 21:48:32 0 d------c- C:\WINDOWS\system32\DRVSTORE
    2008-04-03 21:45:06 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
    2008-04-03 21:44:52 0 d-------- C:\Program Files\Windows Live
    2008-04-03 21:44:36 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
    2008-04-03 21:39:48 0 d-------- C:\Documents and Settings\TINO\Application Data\Comodo
    2008-04-03 21:39:46 0 d-------- C:\Documents and Settings\All Users\Application Data\comodo
    2008-04-03 21:36:54 0 d-------- C:\Documents and Settings\All Users\Application Data\Avira
    2008-04-03 21:23:32 0 d-------- C:\Documents and Settings\Jepe\Application Data\Macromedia
    2008-04-03 21:23:32 0 d-------- C:\Documents and Settings\Jepe\Application Data\Adobe
    2008-04-03 21:23:28 1407 --a------ C:\WINDOWS\mozver.dat
    2008-04-03 21:22:44 0 --a------ C:\WINDOWS\nsreg.dat
    2008-04-03 21:22:41 0 d-------- C:\Documents and Settings\Jepe\Application Data\Mozilla
    2008-04-03 21:02:36 139536 --a------ C:\WINDOWS\system32\javaee.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
    2008-04-03 21:02:36 46352 --a------ C:\WINDOWS\setdebug.exe <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
    2008-04-03 21:02:36 6550 --a------ C:\WINDOWS\jautoexp.dat
    2008-04-03 21:02:33 113 --a------ C:\WINDOWS\system32\zonedon.reg
    2008-04-03 21:02:33 113 --a------ C:\WINDOWS\system32\zonedoff.reg
    2008-04-03 20:33:50 0 d-------- C:\Program Files\Common Files\ODBC
    2008-04-03 20:33:48 0 d-------- C:\Program Files\Common Files\SpeechEngines
    2008-04-03 20:33:47 0 dr------- C:\Program Files
    2008-04-03 20:33:47 0 d-------- C:\Program Files\Common Files
    2008-04-03 20:33:31 0 d--h----- C:\Documents and Settings\Default User\Verkkoympäristö
    2008-04-03 20:33:31 0 d-------- C:\Documents and Settings\Default User\Työpöytä
    2008-04-03 20:33:31 0 d--h----- C:\Documents and Settings\Default User\Tulostinympäristö
    2008-04-03 20:33:31 0 d-------- C:\Documents and Settings\Default User\Suosikit
    2008-04-03 20:33:31 0 dr-h----- C:\Documents and Settings\Default User\SendTo
    2008-04-03 20:33:31 0 d--h----- C:\Documents and Settings\Default User\Recent
    2008-04-03 20:33:31 0 d--h----- C:\Documents and Settings\Default User\Mallit
    2008-04-03 20:33:31 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
    2008-04-03 20:33:31 0 dr------- C:\Documents and Settings\Default User\Käynnistä-valikko
    2008-04-03 20:33:31 0 d---s---- C:\Documents and Settings\Default User\Cookies
    2008-04-03 20:33:31 0 d-------- C:\Documents and Settings\All Users\Työpöytä
    2008-04-03 20:33:31 0 dr------- C:\Documents and Settings\All Users\Tiedostot
    2008-04-03 20:33:31 0 d-------- C:\Documents and Settings\All Users\Suosikit
    2008-04-03 20:33:31 0 d--h----- C:\Documents and Settings\All Users\Mallit
    2008-04-03 20:33:31 0 dr------- C:\Documents and Settings\All Users\Käynnistä-valikko
    2008-04-03 20:33:21 0 d-------- C:\WINDOWS\system32\CatRoot2
    2008-04-03 20:33:21 0 d-------- C:\WINDOWS\system32\CatRoot
    2008-04-03 20:33:16 0 dr-h----- C:\Documents and Settings\Default User\Application Data
    2008-04-03 20:33:16 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
    2008-04-03 20:33:15 0 dr-h----- C:\Documents and Settings\All Users\Application Data
    2008-04-03 20:33:15 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
    2008-04-03 20:33:01 0 d-------- C:\Documents and Settings
    2008-04-03 20:31:28 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
    2008-04-03 20:25:47 0 d-------- C:\WINDOWS\system32\PreInstall
    2008-04-03 20:25:10 0 d---s---- C:\Documents and Settings\Jepe\UserData
    2008-04-03 20:23:50 0 d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
    2008-04-03 20:21:41 0 d-------- C:\WINDOWS\nview
    2008-04-03 20:21:08 0 d-------- C:\NVIDIA
    2008-04-03 20:14:34 49152 -r------- C:\WINDOWS\system32\ChCfg.exe
    2008-04-03 20:13:55 0 d-------- C:\Program Files\Realtek Sound Manager
    2008-04-03 20:13:53 0 d-------- C:\Program Files\AvRack
    2008-04-03 20:13:43 0 d-------- C:\Program Files\Realtek AC97
    2008-04-03 20:13:32 315392 -r------- C:\WINDOWS\alcupd.exe <Not Verified; Realtek Semiconductor Corp.; Realtek AC'97 Update driver Tool>
    2008-04-03 20:10:51 0 d--h----- C:\WINDOWS\$hf_mig$
    2008-04-03 20:10:25 45056 --a------ C:\WINDOWS\system32\vusetup.dll
    2008-04-03 20:10:20 306688 --a------ C:\WINDOWS\IsUninst.exe <Not Verified; InstallShield Software Corporation; InstallShield® unInstaller>
    2008-04-03 20:09:12 0 d-------- C:\WINDOWS\OPTIONS
    2008-04-03 20:06:55 0 d--h----- C:\Program Files\InstallShield Installation Information
    2008-04-03 20:06:25 0 d-------- C:\Program Files\VIA
    2008-04-03 20:06:19 0 d-------- C:\Program Files\Common Files\InstallShield
    2008-04-03 20:01:15 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
    2008-04-03 19:59:56 0 d-------- C:\Documents and Settings\LocalService\Käynnistä-valikko
    2008-04-03 19:59:31 0 d-------- C:\WINDOWS\SoftwareDistribution
    2008-04-03 19:59:27 0 d-------- C:\WINDOWS\Prefetch
    2008-04-03 19:58:15 0 d---s---- C:\WINDOWS\system32\Microsoft
    2008-04-03 19:54:55 0 d-------- C:\WINDOWS\peernet
    2008-04-03 19:54:54 0 d-------- C:\WINDOWS\provisioning
    2008-04-03 19:53:44 0 d-------- C:\WINDOWS\ServicePackFiles
    2008-04-03 19:51:57 0 d-------- C:\WINDOWS\system32\ReinstallBackups
    2008-04-03 19:50:42 0 d-------- C:\WINDOWS\EHome
    2008-04-03 19:44:02 0 d--hs---- C:\WINDOWS\Installer
    2008-04-03 19:44:00 0 d-------- C:\Documents and Settings\Jepe\Application Data\Identities
    2008-04-03 19:43:52 0 dr------- C:\Documents and Settings\Jepe\Omat tiedostot
    2008-04-03 19:43:51 0 d--h----- C:\Documents and Settings\Jepe\Tulostinympäristö
    2008-04-03 19:43:51 0 d---s---- C:\Documents and Settings\Jepe\Suosikit
    2008-04-03 19:43:51 0 dr-h----- C:\Documents and Settings\Jepe\SendTo
    2008-04-03 19:43:51 0 d--h----- C:\Documents and Settings\Jepe\Mallit
    2008-04-03 19:43:51 0 d--h----- C:\Documents and Settings\Jepe\Local Settings
    2008-04-03 19:43:51 0 dr------- C:\Documents and Settings\Jepe\Käynnistä-valikko
    2008-04-03 19:43:51 0 d---s---- C:\Documents and Settings\Jepe\Cookies
    2008-04-03 19:43:51 0 dr-h----- C:\Documents and Settings\Jepe\Application Data
    2008-04-03 19:43:50 0 d--h----- C:\Documents and Settings\Jepe\Verkkoympäristö
    2008-04-03 19:43:50 0 d-------- C:\Documents and Settings\Jepe\Työpöytä
    2008-04-03 19:43:50 2097152 --ah----- C:\Documents and Settings\Jepe\NTUSER.DAT
    2008-04-03 19:43:26 0 d--hs---- C:\System Volume Information
    2008-04-03 19:43:25 229376 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
    2008-04-03 19:43:25 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
    2008-04-03 19:43:25 0 d---s---- C:\Documents and Settings\LocalService\Cookies
    2008-04-03 19:43:25 0 d-------- C:\Documents and Settings\LocalService\Application Data
    2008-04-03 19:43:25 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
    2008-04-03 19:43:24 229376 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
    2008-04-03 19:43:24 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
    2008-04-03 19:43:24 0 d---s---- C:\Documents and Settings\NetworkService\Cookies
    2008-04-03 19:43:24 0 d-------- C:\Documents and Settings\NetworkService\Application Data
    2008-04-03 19:43:24 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
    2008-04-03 19:40:49 0 d-------- C:\WINDOWS\system32\xircom
    2008-04-03 19:40:49 0 d-------- C:\Program Files\microsoft frontpage
    2008-04-03 19:40:48 229376 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
    2008-04-03 19:40:47 0 -rahs---- C:\MSDOS.SYS
    2008-04-03 19:40:47 0 -rahs---- C:\IO.SYS
    2008-04-03 19:40:47 0 --a------ C:\CONFIG.SYS
    2008-04-03 19:40:47 0 -----n--- C:\AUTOEXEC.BAT
    2008-04-03 19:40:09 0 d--hs---- C:\Documents and Settings\All Users\DRM
    2008-04-03 19:40:01 0 dr------- C:\WINDOWS\Offline Web Pages
    2008-04-03 19:40:01 0 d---s---- C:\WINDOWS\Downloaded Program Files
    2008-04-03 19:39:41 0 d-------- C:\WINDOWS\system32\DirectX
    2008-04-03 19:39:05 0 d---s---- C:\WINDOWS\Tasks
    2008-04-03 19:39:02 0 d-------- C:\Program Files\Common Files\MSSoap
    2008-04-03 19:38:58 0 d-------- C:\WINDOWS\system32\Macromed
    2008-04-03 19:38:58 0 d-------- C:\WINDOWS\srchasst
    2008-04-03 19:38:57 0 d-------- C:\Program Files\Movie Maker
    2008-04-03 19:38:54 0 d-------- C:\WINDOWS\PCHealth
    2008-04-03 19:38:53 0 d-------- C:\WINDOWS\system32\Restore
    2008-04-03 19:38:39 21672 --a------ C:\WINDOWS\system32\emptyregdb.dat
    2008-04-03 19:38:35 0 d-------- C:\WINDOWS\Registration
    2008-04-03 19:38:18 0 d--h----- C:\Program Files\WindowsUpdate
    2008-04-03 19:38:17 0 d-------- C:\Program Files\Online Services
    2008-04-03 19:38:15 0 d-------- C:\Program Files\Messenger
    2008-04-03 19:38:12 0 d-------- C:\Program Files\MSN Gaming Zone
    2008-04-03 19:37:43 0 d-------- C:\Program Files\Windows NT
    2008-04-03 19:37:41 0 d-------- C:\WINDOWS\system32\MsDtc
    2008-04-03 19:37:40 0 d-------- C:\WINDOWS\system32\Com


    -- Find3M Report ---------------------------------------------------------------

    2008-04-03 21:15:00 283024 --a------ C:\WINDOWS\system32\perfh00B.dat
    2008-04-03 21:15:00 48448 --a------ C:\WINDOWS\system32\perfc00B.dat
    2008-04-03 20:33:31 62 --ahs---- C:\Documents and Settings\Jepe\Application Data\desktop.ini


    -- Registry Dump ---------------------------------------------------------------

    *Note* empty entries & legit default entries are not shown


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [11.06.2007 12:25]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [05.12.2007 01:41]
    "COMODO Firewall Pro"="C:\Program Files\COMODO\Firewall\cfp.exe" [09.04.2008 18:09]
    "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [11.04.2008 17:13]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "HistoryKill"="C:\Program Files\HistoryKill 2007\histkill.exe" [29.03.2007 06:01]
    "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [18.10.2007 11:34]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "HideLegacyLogonScripts"=0 (0x0)
    "HideLogoffScripts"=0 (0x0)
    "RunLogonScriptSync"=1 (0x1)
    "RunStartupScriptSync"=1 (0x1)
    "HideStartupScripts"=0 (0x0)
    "DisableRegistryTools"=0 (0x0)

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "HideLegacyLogonScripts"=0 (0x0)
    "HideLogoffScripts"=0 (0x0)
    "RunLogonScriptSync"=1 (0x1)
    "RunStartupScriptSync"=1 (0x1)
    "HideStartupScripts"=0 (0x0)
    "DisableRegistryTools"=0 (0x0)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [20.12.2006 12:55 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 19.04.2007 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "appinit_dlls"= C:\WINDOWS\system32\guard32.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
    @="Volume shadow copy"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
    "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
    RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
    RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
    nwiz.exe /install

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartDefrag]
    "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
    "C:\Program Files\Steam\Steam.exe" -silent

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    bdx scan




    -- End of Deckard's System Scanner: finished at 2008-04-11 17:48:50 ------------

     

Jaa tämä sivu