|
Kone on hidas Hjt-Logi
|
|
|
NaabKilla
Junior Member
|
21. heinäkuuta 2006 @ 10:50 |
Linkki tähän viestiin
|
Kone on ihan hidas ja AntiVir ilmoittaa jostain Key.exe:stä mutta ei suostu poistamaan sitä
Logfile of HijackThis v1.99.1
Scan saved at 14:49:21, on 21.7.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Prevx1\PXConsole.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Valve\Steam\Steam.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Prevx1\PXAgent.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Winamp\winamp.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Työpöytä\HjT\HijackThis_v1.99.1.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users.WINDOWS\Application Data\Prevx\pxbho.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fi\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fi\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [!1_pgaccount] "C:\Program Files\ProcessGuard\pgaccount.exe"
O4 - HKLM\..\Run: [PrevxOne] C:\Program Files\Prevx1\PXConsole.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31... O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl... O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/... O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: geedc - C:\WINDOWS\
O23 - Service: AntiVir Scheduler (AntiVirScheduler) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: DiamondCS Process Guard Service v3.000 (DCSPGSRV) - Unknown owner - C:\Program Files\ProcessGuard\dcsuserprot.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Windows Update Manager Tool (UpdateManagerTool) - Unknown owner - C:\WINDOWS\update\updmangr.exe (file missing)
|
|
Marku2
Senior Member
|
21. heinäkuuta 2006 @ 15:13 |
Linkki tähän viestiin
|
|
Käynnistä->Suorita->Kirjoita siihen:
sc stop UpdateManagerTool ja enter
sc delete UpdateManagerTool ja enter
Fixaa HjT:llä (do a system scan only->merkkaa seuraavat ja paina fix checked)
O20 - Winlogon Notify: geedc - C:\WINDOWS\
23 - Service: Windows Update Manager Tool (UpdateManagerTool) - Unknown owner - C:\WINDOWS\update\updmangr.exe (file missing)
Poista: (jos ei lähe kokeile vikasietotilassa, F8 käynnistyksen yhteydessä ja valitset vikasietotilan)
C:\WINDOWS\==>update<--
Onko sulla vielä ProcessGuard asenettuna koneelle, vai oletko poistanu sen?
Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 21. heinäkuuta 2006 @ 15:13
|
|
NaabKilla
Junior Member
|
21. heinäkuuta 2006 @ 20:18 |
Linkki tähän viestiin
|
|
Olen poistanut sen
|
|
Marku2
Senior Member
|
22. heinäkuuta 2006 @ 06:47 |
Linkki tähän viestiin
|
Jatketaan puhdistusta...
Käynnistä->suorita->Kirjoita siihen:
sc stop DCSPGSRV ja enter
sc delete DCSPGSRV ja enter
Poista:
C:\Program Files\==>ProcessGuard<--
Hommaa ewido: http://aaxxeell.googlepages.com/ewido4
Päivitä, scannaa, poista löydöt ja lähetä raportti tänne, sekä uusi HjT-loki.
|
|
NaabKilla
Junior Member
|
22. heinäkuuta 2006 @ 10:03 |
Linkki tähän viestiin
|
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 13:58:16 22.7.2006
+ Scan result:
C:\Program Files\BitComet\Downloads\steam cd key generator\steamkeygen.exe/SERVER~1.EXE -> Backdoor.Ciadoor.13 : No action taken.
C:\Program Files\BitComet\Downloads\steam cd key generator\steamkeygen.exe/STEAMA~1.EXE -> Dropper.Small : No action taken.
C:\Program Files\EMCO Malware Destroyer\MalwareDestroyer.exe -> Logger.Delf.28 : No action taken.
:mozilla.129:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.67:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.71:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.68:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.69:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.70:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.72:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.134:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.107:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Bluestreak : No action taken.
:mozilla.124:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.125:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.126:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.117:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.118:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.119:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.120:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.121:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.122:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.123:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.101:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.127:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Euroclick : No action taken.
:mozilla.128:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Euroclick : No action taken.
:mozilla.110:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.140:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Overture : No action taken.
:mozilla.141:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Overture : No action taken.
:mozilla.111:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Qksrv : No action taken.
:mozilla.114:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Qksrv : No action taken.
:mozilla.96:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Sitestat : No action taken.
:mozilla.97:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Sitestat : No action taken.
:mozilla.17:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
:mozilla.18:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
:mozilla.65:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.66:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.81:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.82:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.83:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.84:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.85:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.86:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.87:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.16:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.19:C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Application Data\Mozilla\Firefox\Profiles\6ihoj5xf.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
::Report end
ja
Logfile of HijackThis v1.99.1
Scan saved at 14:03:29, on 22.7.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Prevx1\PXConsole.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\a-squared Anti-Malware\a2guard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Valve\Steam\Steam.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Prevx1\PXAgent.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Winamp\winamp.exe
C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Työpöytä\HjT\HijackThis_v1.99.1.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: SuperAdBlockerBHO Class - {00000000-6C30-11D8-9363-000AE6309654} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABBHO.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users.WINDOWS\Application Data\Prevx\pxbho.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fi\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fi\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Super Ad Blocker Toolbar - {B4B3001E-0F56-4E51-8250-BDE11547EC55} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\sabtb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [PrevxOne] C:\Program Files\Prevx1\PXConsole.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [SuperAdBlocker] C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SAdBlock.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31... O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl... O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/... O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: SABWinLogon - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL
O23 - Service: Avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: Avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: Avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: Super Ad Blocker Service (SABSVC) - SuperAdBlocker.com - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
|
|
Marku2
Senior Member
|
22. heinäkuuta 2006 @ 15:04 |
Linkki tähän viestiin
|
Poista:
C:\Program Files\==>EMCO Malware Destroyer<--
C:\Program Files\BitComet\Downloads\==>steam cd key generator<--
Avaa Lisää/Poista Sovellus -> Poista kaikki javat ja lataa uusin täältä-> http://www.java.com/en/download/manual.jsp
Lähetä uusi HjT-loki.
Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 22. heinäkuuta 2006 @ 15:04
|
|
NaabKilla
Junior Member
|
22. heinäkuuta 2006 @ 15:54 |
Linkki tähän viestiin
|
Logfile of HijackThis v1.99.1
Scan saved at 19:53:27, on 22.7.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Prevx1\PXConsole.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Valve\Steam\Steam.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Prevx1\PXAgent.exe
C:\Program Files\Winamp\winamp.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\msiexec.exe
C:\Documents and Settings\Atte.ATTE-2EVB5BJBD5\Työpöytä\HjT\HijackThis_v1.99.1.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: SuperAdBlockerBHO Class - {00000000-6C30-11D8-9363-000AE6309654} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABBHO.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users.WINDOWS\Application Data\Prevx\pxbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fi\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fi\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Super Ad Blocker Toolbar - {B4B3001E-0F56-4E51-8250-BDE11547EC55} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\sabtb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [PrevxOne] C:\Program Files\Prevx1\PXConsole.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [SuperAdBlocker] C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SAdBlock.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31... O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl... O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/... O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: SABWinLogon - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL
O23 - Service: Avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: Avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: Avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: Super Ad Blocker Service (SABSVC) - SuperAdBlocker.com - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
|
|
Marku2
Senior Member
|
23. heinäkuuta 2006 @ 06:59 |
Linkki tähän viestiin
|
|
Loki on puhdas. Vieläkö ongelmia?
|
|
NaabKilla
Junior Member
|
23. heinäkuuta 2006 @ 17:54 |
Linkki tähän viestiin
|
|
Ei ole ongelmia. Kiitos sulle!
|
|
Mainos
|
  |
|
|
Marku2
Senior Member
|
24. heinäkuuta 2006 @ 05:51 |
Linkki tähän viestiin
|
|
Oleppa hyvä. :)
|