afterdawn.com  > keskustelu  > yleistä keskustelua tietokoneista  > virukset ja haittaohjelmat  > loki tarkistettavaksi  
											 
											
												
	 
											
											
						 				 	
	
		
		
			
		
		
	 
												  
												
													
	
		
			Keskustelualueet
			Keskustelualueet
		 
		
			
				
					
						
			
			
		
					
				
			 
		
	 
														
															
															
	
			
			
				
					Loki tarkistettavaksi
				 
				
				
					
				 
				
			 
			
			
			
				
					
					
				 
			
			
			
			
			
				
				
					
				
				
				
				
					
						
							
								
							
							
								Senior Member
								
									  5 tuotearviota 
								
							
							 
							 
						 
						22. elokuuta 2005 @ 13:39  
						 
							
								Linkki tähän viestiin 
								  
								 
								  
							
							 
						 
					 
					
					
					
						
						
						
							
							Voisiko joku tarkistaa tämän lokin (ei kemisti, koska hän tarkisti jo ja ei ollut varma)
 
 
 
 
 
 
 Logfile of HijackThis v1.99.1
 Scan saved at 16:17:58, on 21.8.2005
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\PROGRA~1\DNANET~1\backweb\4653381\Program\SERVIC~1.EXE
 C:\Program Files\dna Nettiturva\Anti-Virus\fsgk32st.exe
 C:\Program Files\dna Nettiturva\backweb\4653381\program\fsbwsys.exe
 C:\Program Files\dna Nettiturva\Anti-Virus\FSGK32.EXE
 C:\WINDOWS\System32\nvsvc32.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\dna Nettiturva\Anti-Virus\fssm32.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
 C:\Program Files\dna Nettiturva\Common\FSMA32.EXE
 C:\Program Files\dna Nettiturva\Common\FSMB32.EXE
 C:\Program Files\dna Nettiturva\Common\FCH32.EXE
 C:\Program Files\dna Nettiturva\backweb\4653381\Program\BackWeb-4653381.exe
 C:\Program Files\dna Nettiturva\Common\FAMEH32.EXE
 C:\Program Files\dna Nettiturva\Anti-Virus\fsav32.exe
 C:\Program Files\dna Nettiturva\DFW\Program\fsdfwd.exe
 C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe
 C:\WINDOWS\System32\flcss.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE
 C:\Program Files\Winamp\winampa.exe
 C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
 C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe
 C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
 C:\Program Files\dna Nettiturva\Common\FSM32.EXE
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\WinZip\WZQKPICK.EXE
 C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
 C:\HJT\HijackThis.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fi/0SEFIFI/SAOS01  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dnainternet.fi/  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dnainternet.fi  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = dna Internet Explorer
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://paivitys.dnainternet.fi/yhteys/proxy.pac  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = info.tampere.fi:8080
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;localhost;<local>
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
 O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
 O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
 O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
 O4 - HKLM\..\Run: [F-Secure Anti-FunLove] C:\WINDOWS\System32\flcss.exe
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [EPSON Stylus C66 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE /P23 "EPSON Stylus C66 Series" /O6 "USB001" /M "Stylus C66"
 O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
 O4 - HKLM\..\Run: [CleanEasyImg] c:\apps\easydvd\cleanall.exe
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray
 O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
 O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\dna Nettiturva\Common\FSM32.EXE" /splash
 O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\dna Nettiturva\TNB\TNBUtil.exe" /CHECKALL
 O4 - HKCU\..\Run: [Update Service] C:\PROGRA~1\COMMON~1\TEKNUM~1\update.exe /startup
 O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
 O4 - HKCU\..\Run: [EPSON Stylus C66 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE /P23 "EPSON Stylus C66 Series" /M "Stylus C66" /EF "HKCU"
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
 O4 - Global Startup: WinZIP Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O14 - IERESET.INF: START_PAGE_URL=http://www.dnainternet.fi  O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab  O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab  O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab  O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31...  O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab  O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab  O16 - DPF: {5BDBD95C-1E7F-4FB1-8497-20AF879F8B68} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSha...  O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab  O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicr...  O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab  O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - http://support.f-secure.com/ols/fscax.cab  O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab  O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab  O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab  O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab  O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab  O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab  O23 - Service: dna Nettiturva (BackWeb Client - 4653381) - Unknown owner - C:\PROGRA~1\DNANET~1\backweb\4653381\Program\SERVIC~1.EXE
 O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\dna Nettiturva\Anti-Virus\fsgk32st.exe
 O23 - Service: F-Secure Authentication Agent (FSAA) - Unknown owner - C:\Program Files\dna Nettiturva\Common\FSAA.EXE (file missing)
 O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\dna Nettiturva\backweb\4653381\program\fsbwsys.exe
 O23 - Service: F-Secure Distributed Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\dna Nettiturva\DFW\Program\fsdfwd.exe
 O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\dna Nettiturva\Common\FSMA32.EXE
 O23 - Service: F-Secure Windows Security Center Legacy Detection Service (Fswsclds) - Unknown owner - C:\Program Files\F-Secure Anti-Virus\fswsclds.exe (file missing)
 O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\NORMAN\Nvc\BIN\nipsvc.exe (file missing)
 O23 - Service: Creative NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe 
							
						 
						
						
						
							Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 22. elokuuta 2005 @ 13:40 
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								age007ti
							
							
								
									
									
										Suspended permanently
									
								
							
							 
							 
						 
						23. elokuuta 2005 @ 17:10  
						 
							
								Linkki tähän viestiin 
								  
								 
								  
							
							 
						 
					 
					
					
					
						
						
						
							
							suht hyvä, muutama turha päivitys on käynnissä, ilman niitäkin tulee toimeen.
 
 kannattaa kokeilla itse joittenkin ohjelmien poistamista käynnistymisen yhteydestä ottamalla yhden kerrallaan pois ja jos kone toimii niin hyvä, jos ei niin laittaa takaisin
 
 jätä kaikki f-secure rivit kuitenkin rauhaan 
							
						
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Member
								
									
								
							
							 
							 
						 
						23. elokuuta 2005 @ 18:19  
						 
							
								Linkki tähän viestiin 
								  
								 
								  
							
							 
						 
					 
					
					
					
						
						
						
							
							Mitä ongelmia sulla on koneen kanssa? 
							
						
						
						
						
							Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 23. elokuuta 2005 @ 18:21 
						
						 
					 
				
				
			
				
				
				
					
						
							Mainos
							 
						 
						 
					 
					
						
							
							  
								
							
						 
					 
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 
						24. elokuuta 2005 @ 05:29  
						 
							
								Linkki tähän viestiin 
								  
								 
								  
							
							 
						 
					 
					
					
					
						
						
						
							
							Kommentoidaan silti tähän tämän verran, vaikka "kiellettiin" ;) :
 
 Olin varma kaikista muista poistettavista riveistä, paitsi tästä ->
 
 O4 - HKCU\..\Run: [Update Service] C:\PROGRA~1\COMMON~1\TEKNUM~1\update.exe /startup
 
 Enkä vieläkään tiedä, mikä se on.
 
 Ja kaikki muut F-Securen rivit voi jättää paikoilleen, mutta ei tätä
 -> O4 - HKLM\..\Run: [F-Secure Anti-FunLove] C:\WINDOWS\System32\flcss.exe
 
 Tämä on W32.FunLove.4099-virus, infoa täällä ->
http://securityresponse.symantec.com/avcenter/venc/data/w32.funlo...   
							
						 
						
						
						
						 
					 
				
				
			
			
			
			
			
		
		
	
			
			
		
	 
 
					
						
							afterdawn.com  > keskustelu  > yleistä keskustelua tietokoneista  > virukset ja haittaohjelmat  > loki tarkistettavaksi