User Käyttäjä Salasana  
   
maanantai 21.7.2025 / 08:35
Hae keskustelualueilta:        In English   Suomeksi   På svenska
afterdawn.com > keskustelu > yleistä keskustelua tietokoneista > virukset ja haittaohjelmat - hijackthis -logit > tarvii apua! viiruksia pääs koneelle, tsekatkaa-
Näytä aiheet
 
Keskustelualueet
Keskustelualueet
Tarvii apua! Viiruksia pääs koneelle, tsekatkaa-
  Siirry:
 
Kirjoittaja Viesti
Sivu:12>
st3f4
Suspended due to non-functional email address
_
29. marraskuuta 2006 @ 14:19 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Tässä toi HijackThis logi, onko jotain viiruksia tai mitä mun pitäs tehdä että sais koneen putsattua?

Logfile of HijackThis v1.99.1
Scan saved at 19:18:33, on 29.11.2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Prevx1\PXAgent.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Prevx1\PXConsole.exe
C:\Program Files\Common Files\{A4726140-07CD-1035-0804-040301220166}\Update.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {35F7813A-AF74-4474-B1DC-7EE6FB6C43C6} - C:\WINDOWS\System32\bnxqnqre.dll
O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: (no name) - {65077E0C-6C0F-4BCC-8EB0-6E572521BD5A} - (no file)
O2 - BHO: (no name) - {755bbd1a-aa59-456c-afeb-b4c42c4dcb6f} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdat...b?1137962249389
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: geebb - C:\WINDOWS\
O20 - Winlogon Notify: winuqw32 - C:\WINDOWS\
O21 - SSODL: expatriates - {1a01a98c-4f25-42e1-971a-185cf63569b2} - C:\WINDOWS\System32\tpedvf.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
st3f4
Suspended due to non-functional email address
_
29. marraskuuta 2006 @ 14:22 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Ja huomasin että prosesseissa oli vähän aikaa sitten sellanen kun issearch.exe...En tiiä mitä oon nyt tehny ku sitä ei enää ole.
Wezda
Member

1 tuotearvio
_
29. marraskuuta 2006 @ 15:28 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Lainaus, alkuperäisen viestin kirjoitti st3f4:
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Rohkea sälli olet kun tälläisellä surffailet, ei mitään pävityksiä.
No, ennen pöpöjen poistoa ei edes kannata yrittää päivittää.
Niin ja ohjeet siivoukseen tulee noilta HjT-guruilta...

| P4 2,66GHz | Asus P4PE-X | GeForce 7600GT 256MB | 2048MB | BenQ FP93GX |
Hujo
Suspended permanently
_
29. marraskuuta 2006 @ 15:44 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
sp1 koneelle

Linkki

Kun on koneella uusi HjT loki

Voiko tietsikka koskaan toimia?

Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 29. marraskuuta 2006 @ 15:51

st3f4
Suspended due to non-functional email address
_
29. marraskuuta 2006 @ 16:45 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
"Päivitystä ei voi suorittaa. Syynä voi olla toinen tai molemmat seuraavista: (1)Päivitys on tarkoitettu tuotteen eri kieliversiolle. (2)Tuotetta, johon päivitys on tarkoitettu, ei ole asennettu."

*iso huokaus* mitä teen?
Hujo
Suspended permanently
_
29. marraskuuta 2006 @ 17:15 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Tuosta uusi linkki

Voiko tietsikka koskaan toimia?
st3f4
Suspended due to non-functional email address
_
29. marraskuuta 2006 @ 17:35 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Mitä mä tolla uusimmalla ie:llä teen ku en edes ie:tä käytä vaan firefoxia?
Hujo
Suspended permanently
_
29. marraskuuta 2006 @ 17:40 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
no putsaa nyt tolla aluksi

Ohje AVG Anti-Spyware 7.5:n käyttöön
Huom! Tässä ohjeessa sammutetaan tuo reaaliaikasuojaus (Shield). Näin vältetään tilanteet joissa suojaus estäisi esim HijackThis työkalun toimintaa.

Tallenna nämä ohjeet tekstitiedostoon tai tulosta nämä, muuten et pääse niihin käsiksi vikasietotilasta

Lataa AVG Anti-Spyware 7.5 http://www.ewido.net/en/download/
ja tallenna ohjelma työpöydällesi.
? Kun olet ladannut ohjelman, kaksoisklikkaa asennuohjelman pikakuvaketta työpöydälläsi, asennus alkaa.
? Asennuksen jälkeen täytyy ohjelma käynnistää ja sen tunnisteet päivittää.
? Käynnistä AVG Anti-Spyware.
? Klikkaa "Update" kuvaketta päävalikossa. Sen jälkeen klikkaa "Update now" painiketta.

o Sitten klikkaa "Start Update" kuvaketta jolloin päivitys alkaa.

? Kun päivitykset on ladattu, klikkaa "Scanner" kuvaketta ikkunan ylälaidassa. Valitse sitten "Settings" välilehti.
? Kun "Settings" valikko on auennut, klikkaa "Recommended actions" ja sitten valitse "Quarantine".
? Sitten "Reports" valikon alta:

o Laita täppi kohtaan "Automatically generate report after every scan"
o Ota täppi pois kohdasta"Only if threats were found"

? Sitten klikkaa "Shield" kuvaketta ikkunan ylälaidassa
? "Resident shield is", muuta tila active:sta inactive:ksi
? Sulje ohjelma, ÄLÄ skannaa vielä.
Käynnistä koneesi vikasietotilaan,

sammuta ja käynnistä
käynnistyksen yhteydessä naputtele F8
valitse nuoli näppäimellä vikasietotila
paina enter ja enter

HUOM! Älä käytä muita ohjelmia AVG skannauksen aikana, tämä saattaa häiritä skannausta.
? Kun vikasietotilassa, käynnistä AVG Anti-Spyware.
? Klikkaa "Scanner" kuvaketta ikkunan ylälaidassa ja valitse "Scan" välilehti. Sitten klikkaa "Complete System Scan".
? Ewido aloittaa nyt tietokoneen skannaamisen, ole kärsivällinen sillä skannaus vie aikaa.

Kun skannaus on valmis:
TÄRKEÄÄ : Älä klikkaa "Save Scan Report" ennen kuin klikkaat "Apply all Actions"
? Varmistu, että Set all elements to: näyttää Quarantine (1), jos ei, klikkaa linkkiä ja valitse Quarantine popup-valikosta.
? Sinulta kysytään mitä tehdä jos infektioita löytyi, valitse silloin "Apply all actions"

? Sitten klikkaa "Reports" kuvaketta ohjelma yläosasta.
? Klikkaa "Save report as" painiketta ikkunan vasemmassa alalaidassa ja tallenna raportti työpöydälle.
? Sulje ohjelma, käynnistä kone normaalisti ja lähetä AVG:n raportti viestikejuusi.

tolla tokaksi

Escan

Ohjeet tuolla sivulla.
http://koti.mbnet.fi/pattaya1/escanmwav.htm

lataa tuosta
http://www.spywareinfo.dk/download/mwav.exe

päivitä tuosta
http://koti.mbnet.fi/pattaya1/lataus/Mwav.bat

laita täpit merkkauksien mukaan
http://koti.mbnet.fi/pattaya1/eScan6.jpg

scannaa

jos ala luukkuun tulee jotain niin kopioi se näin:

Käytä komentoa Ctrl+A.
Kopioi rivit komennolla Ctrl+C.
Liitä rivit komennolla Ctrl+V.

Laita virus log tänne.

Poista lisää poista sovelutuksesta

VSToolBar


scannaa hjt:llä merkkaa paina Fix checked

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {65077E0C-6C0F-4BCC-8EB0-6E572521BD5A} - (no file)
O2 - BHO: (no name) - {755bbd1a-aa59-456c-afeb-b4c42c4dcb6f} - (no file)
O20 - Winlogon Notify: geebb - C:\WINDOWS\
O20 - Winlogon Notify: winuqw32 - C:\WINDOWS\



Voiko tietsikka koskaan toimia?

Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 29. marraskuuta 2006 @ 17:56

st3f4
Suspended due to non-functional email address
_
29. marraskuuta 2006 @ 18:07 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Jees kiitos ohjeista, huomenna koitetaan! :)
st3f4
Suspended due to non-functional email address
_
30. marraskuuta 2006 @ 16:38 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Tässähän tämä..Meniköhän ihan oikein? Pitääkö tuo "tolla tokaksi" tehdä myös?



---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 21:32:12 30.11.2006

+ Scan result:



HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winuqw32 -> Adware.Generic : Cleaned with backup (quarantined).
C:\Program Files\Hotbar -> Adware.HotBar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{69F9BDA0-3458-4032-BD36-41636F73A6A8}\RP351\A0179847.exe -> Adware.Maxifiles : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{69F9BDA0-3458-4032-BD36-41636F73A6A8}\RP352\A0180358.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\Program Files\Common Files\{A4726140-07CD-1035-0804-040301220166}\Update.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Common Files\{A4726140-07CD-1035-0804-040301220166}\system.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Virus-Bursters -> Adware.VirusBursters : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{69F9BDA0-3458-4032-BD36-41636F73A6A8}\RP351\A0179828.exe -> Dropper.Agent.azn : Cleaned with backup (quarantined).
:mozilla.829:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.830:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.831:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.832:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.494:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.495:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.496:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.497:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.498:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.499:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.500:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.501:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.502:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.595:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.596:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.718:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.962:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.214:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.215:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.216:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.897:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Petri\Cookies\petri@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.865:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Adbutler : Cleaned.
:mozilla.866:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Adbutler : Cleaned.
:mozilla.867:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Adbutler : Cleaned.
:mozilla.613:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.614:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.615:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.167:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.168:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.144:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.145:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.178:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.181:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.184:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.185:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.187:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.189:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.180:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Petri\Cookies\petri@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.578:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.188:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.190:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.194:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.512:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.513:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.514:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.515:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.516:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.517:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.518:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Petri\Cookies\petri@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.29:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.557:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Estat : Cleaned.
:mozilla.474:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.475:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.476:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.477:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.478:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.569:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.570:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.571:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.572:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.163:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.164:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.165:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.166:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.530:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.28:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.647:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.653:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.274:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned.
C:\Documents and Settings\Petri\Cookies\petri@kmpads[2].txt -> TrackingCookie.Kmpads : Cleaned.
:mozilla.204:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.205:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.206:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.361:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.161:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.537:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.538:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.539:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.226:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.227:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.774:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.775:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.776:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.777:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.778:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.779:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.723:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.724:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.725:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.726:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.727:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.728:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.729:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.730:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.731:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.732:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.733:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.734:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.735:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.736:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.737:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.738:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.739:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.740:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.741:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.742:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.743:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.744:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.745:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.746:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.747:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.748:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.749:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.750:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.751:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.752:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.753:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.754:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.755:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.756:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.757:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.758:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.759:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.760:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.761:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.762:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.763:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.764:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.765:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.766:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.767:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.768:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.769:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.770:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.771:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.772:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.773:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.273:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Spylog : Cleaned.
:mozilla.237:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.238:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.239:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.240:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.241:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.242:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.243:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.244:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.245:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.246:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.247:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.248:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.249:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.250:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.251:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.252:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.253:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.254:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.255:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.256:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.257:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.258:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.259:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.260:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.261:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.262:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.263:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.264:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.265:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.266:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.267:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.268:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.269:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.270:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.271:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.272:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.196:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.197:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.198:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Petri\Cookies\petri@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.876:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned.
:mozilla.111:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.112:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.113:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.114:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.115:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.169:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.926:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.927:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.928:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.929:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.555:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.556:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.558:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.654:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.225:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.228:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.162:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.171:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.172:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.173:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.174:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.175:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.179:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Petri\Cookies\petri@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.277:C:\Documents and Settings\Petri\Application Data\Mozilla\Firefox\Profiles\vhkvgz3a.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\System Volume Information\_restore{69F9BDA0-3458-4032-BD36-41636F73A6A8}\RP352\A0180342.dll -> Trojan.Mezzia : Cleaned with backup (quarantined).


::Report end
Hujo
Suspended permanently
_
30. marraskuuta 2006 @ 16:43 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
joo, aja se tokakin lävitse.
Kynnetään koneen pohjat.

Voiko tietsikka koskaan toimia?
st3f4
Suspended due to non-functional email address
_
30. marraskuuta 2006 @ 17:03 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Tässä siitä "files scanned" kohdasta:



Thu Nov 30 21:59:11 2006 => ***** Scanning Memory Files *****
Thu Nov 30 21:59:11 2006 => Scanning File C:\WINDOWS\system32\services.exe
Thu Nov 30 21:59:11 2006 => Scanning File C:\WINDOWS\system32\lsass.exe
Thu Nov 30 21:59:11 2006 => Scanning File C:\WINDOWS\System32\Ati2evxx.exe
Thu Nov 30 21:59:11 2006 => Scanning File C:\WINDOWS\system32\svchost.exe
Thu Nov 30 21:59:11 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Nov 30 21:59:11 2006 => Scanning File C:\PROGRA~1\COMMON~1\SYMANT~1\ccSetMgr.exe
Thu Nov 30 21:59:11 2006 => Scanning File C:\PROGRA~1\COMMON~1\SYMANT~1\SNDSrvc.exe
Thu Nov 30 21:59:11 2006 => Scanning File C:\PROGRA~1\COMMON~1\SYMANT~1\SPBBC\SPBBCSvc.exe
Thu Nov 30 21:59:11 2006 => Scanning File C:\PROGRA~1\COMMON~1\SYMANT~1\ccEvtMgr.exe
Thu Nov 30 21:59:12 2006 => Scanning File C:\WINDOWS\system32\spoolsv.exe
Thu Nov 30 21:59:12 2006 => Scanning File C:\WINDOWS\system32\Ati2evxx.exe
Thu Nov 30 21:59:12 2006 => Scanning File C:\WINDOWS\Explorer.EXE
Thu Nov 30 21:59:12 2006 => Scanning File C:\PROGRA~1\COMMON~1\SYMANT~1\ccApp.exe
Thu Nov 30 21:59:12 2006 => Scanning File C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
Thu Nov 30 21:59:12 2006 => Scanning File C:\PROGRA~1\iTunes\ITUNES~1.EXE
Thu Nov 30 21:59:12 2006 => Scanning File C:\PROGRA~1\NVIDIA~1\NvMixer\NVMIXE~1.EXE
Thu Nov 30 21:59:12 2006 => Scanning File C:\PROGRA~1\DAEMON~1\daemon.exe
Thu Nov 30 21:59:12 2006 => Scanning File C:\PROGRA~1\Java\JRE15~1.0_0\bin\jusched.exe
Thu Nov 30 21:59:12 2006 => Scanning File C:\PROGRA~1\QUICKT~1\qttask.exe
Thu Nov 30 21:59:12 2006 => Scanning File C:\PROGRA~1\Prevx1\PXCONS~1.EXE
Thu Nov 30 21:59:12 2006 => Scanning File C:\PROGRA~1\Grisoft\AVGANT~1.5\avgas.exe
Thu Nov 30 21:59:12 2006 => Scanning File C:\WINDOWS\System32\ctfmon.exe
Thu Nov 30 21:59:12 2006 => Scanning File C:\PROGRA~1\MSNMES~1\msnmsgr.exe
Thu Nov 30 21:59:13 2006 => Scanning File C:\PROGRA~1\Symantec\LIVEUP~1\ALUSCH~1.EXE
Thu Nov 30 21:59:13 2006 => Scanning File C:\PROGRA~1\Grisoft\AVGANT~1.5\guard.exe
Thu Nov 30 21:59:13 2006 => Scanning File C:\PROGRA~1\NORTON~2\navapsvc.exe
Thu Nov 30 21:59:13 2006 => Scanning File C:\PROGRA~1\NORTON~2\IWP\NPFMntor.exe
Thu Nov 30 21:59:13 2006 => Scanning File C:\PROGRA~1\Prevx1\PXAgent.exe
Thu Nov 30 21:59:13 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Nov 30 21:59:13 2006 => Scanning File C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
Thu Nov 30 21:59:13 2006 => Scanning File C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Thu Nov 30 21:59:13 2006 => Scanning File C:\PROGRA~1\iPod\bin\IPODSE~1.EXE
Thu Nov 30 21:59:13 2006 => Scanning File C:\WINDOWS\System32\svchost.exe
Thu Nov 30 21:59:13 2006 => Scanning File C:\PROGRA~1\MOZILL~1\firefox.exe
Thu Nov 30 21:59:13 2006 => Scanning File C:\Kaspersky\mwavscan.com
Thu Nov 30 21:59:14 2006 => Scanning File C:\Kaspersky\kavss.exe

Thu Nov 30 21:59:14 2006 => ***** Scanning Registry Files *****
Thu Nov 30 21:59:14 2006 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
Thu Nov 30 21:59:14 2006 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects
Thu Nov 30 21:59:14 2006 => Scanning HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Thu Nov 30 21:59:14 2006 => Scanning HKCU\Control Panel\Desktop
Thu Nov 30 21:59:14 2006 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Thu Nov 30 21:59:15 2006 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Thu Nov 30 21:59:15 2006 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
Thu Nov 30 21:59:15 2006 => Scanning HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Thu Nov 30 21:59:15 2006 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Thu Nov 30 21:59:15 2006 => ERROR!!! Invalid Entry OM_Monitor = C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart. Removing it.
Thu Nov 30 21:59:26 2006 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Thu Nov 30 21:59:26 2006 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
Thu Nov 30 21:59:26 2006 => Scanning HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Thu Nov 30 21:59:26 2006 => Scanning HKCR\txtfile\shell\open\command
Thu Nov 30 21:59:26 2006 => Scanning HKCR\comfile\shell\open\command
Thu Nov 30 21:59:26 2006 => Scanning HKCR\exefile\shell\open\command
Thu Nov 30 21:59:26 2006 => Scanning HKCR\dllfile\shell\open\command
Thu Nov 30 21:59:26 2006 => Scanning HKCR\batfile\shell\open\command
Thu Nov 30 21:59:26 2006 => Scanning HKCR\piffile\shell\open\command
Thu Nov 30 21:59:26 2006 => Scanning HKCR\scrfile\shell\open\command
Thu Nov 30 21:59:26 2006 => Scanning HKCR\scrfile\shell\config\command
Thu Nov 30 21:59:26 2006 => Scanning HKCR\regfile\shell\open\command

Thu Nov 30 21:59:26 2006 => ***** Scanning StartUp Folders *****

Thu Nov 30 21:59:26 2006 => ***** Scanning C:\Documents and Settings\Petri\Käynnistä-valikko\Ohjelmat\Käynnistys Folder *****
Thu Nov 30 21:59:26 2006 => Scanning Folder: C:\Documents and Settings\Petri\Käynnistä-valikko\Ohjelmat\Käynnistys\*.*

Thu Nov 30 21:59:26 2006 => ***** Scanning C:\Documents and Settings\All Users\Käynnistä-valikko\Ohjelmat\Käynnistys Folder *****
Thu Nov 30 21:59:26 2006 => Scanning Folder: C:\Documents and Settings\All Users\Käynnistä-valikko\Ohjelmat\Käynnistys\*.*

Thu Nov 30 21:59:26 2006 => ***** Scanning Service Files *****
Thu Nov 30 21:59:26 2006 => Scanning HKLM\SYSTEM\CurrentControlSet\Services
Thu Nov 30 21:59:28 2006 => ERROR!!! ScanFile Fails...
Thu Nov 30 21:59:35 2006 => ERROR!!! ScanFile Fails...
Thu Nov 30 21:59:36 2006 => ERROR!!! Invalid Entry System32\Drivers\ulink.sys in SYSTEM\CurrentControlSet\Services\Usblink...

Thu Nov 30 21:59:37 2006 => ***** Scanning System32 Folders *****
Thu Nov 30 21:59:37 2006 => Scanning C:\WINDOWS Directory
Thu Nov 30 21:59:37 2006 => Scanning Folder: C:\WINDOWS\*.*
Thu Nov 30 21:59:47 2006 => Scanning C:\WINDOWS\System32 Directory
Thu Nov 30 21:59:47 2006 => Scanning Folder: C:\WINDOWS\System32\*.
st3f4
Suspended due to non-functional email address
_
30. marraskuuta 2006 @ 17:09 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Ja viruslogissa ei ollu mitään. Kopsaanko kaiken siitä "view log"? Avautuu tekstitiedostoon jotain..
Hujo
Suspended permanently
_
30. marraskuuta 2006 @ 17:10 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
tää ei ollut siintä.

alimmasta luukusta, tulikos siihen mitään?


1. Klikkaa käynnistä > Oma tietokone oikean puoleisella nappi
2. Valitse ominaisuudet
3. Valitse järjestelmän palauttaminen välilehti
4. Ruksi eteen ¤ poista järjestelmän palauttaminen kaikissa asemissa
5. Paina Käytä
6. Paina ok
7. Sammuta ja käynnistä
8. Ota ruksi pois ¤ poista järjestelmän palauttaminen kaikissa asemissa
9. Käytä ja OK


lataa tuolta http://www.ccleaner.com/download/builds.aspx
CCleaner v1.34.407 - Basic, joka EI sisällä Yahoo toolbaria !

laita asetukset näin:
Valinnat --> Lisäasetukset --> Ota ruksi pois kohdasta Poista vain yli 48 tuntia vanhat tilapäistiedostot.

aja puhistaja > tutki > putsaa oikea alakulma
aja virheet > etsi rekisteri virheitä > Korjaa rekisteri virheet.


Lähetä sitten uusi HjT loki

Voiko tietsikka koskaan toimia?
st3f4
Suspended due to non-functional email address
_
30. marraskuuta 2006 @ 17:54 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Kaikki nuo on nyt tehty...


Logfile of HijackThis v1.99.1
Scan saved at 22:54:29, on 30.11.2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Prevx1\PXConsole.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Prevx1\PXAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
D:\Microsoft Office XP Pro\Office10\WINWORD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {35F7813A-AF74-4474-B1DC-7EE6FB6C43C6} - C:\WINDOWS\System32\bnxqnqre.dll
O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - (no file)
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: (no name) - {65077E0C-6C0F-4BCC-8EB0-6E572521BD5A} - (no file)
O2 - BHO: (no name) - {755bbd1a-aa59-456c-afeb-b4c42c4dcb6f} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - (no file)
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdat...b?1137962249389
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: geebb - C:\WINDOWS\
O21 - SSODL: expatriates - {1a01a98c-4f25-42e1-971a-185cf63569b2} - C:\WINDOWS\System32\tpedvf.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Hujo
Suspended permanently
_
30. marraskuuta 2006 @ 18:18 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
scannaa hjt:llä merkkaa paina fix checked

O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - (no file)
O2 - BHO: (no name) - {65077E0C-6C0F-4BCC-8EB0-6E572521BD5A} - (no file)
O2 - BHO: (no name) - {755bbd1a-aa59-456c-afeb-b4c42c4dcb6f} - (no file)
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - (no file)


Lataa VundoFix.exe
http://www.atribune.org/ccount/click.php?id=4 työpöydällesi.

? Tupla-klikkaa VundoFix.exe ajaaksesi sen.
? Klikkaa Scan for Vundo valintaa.
? Kun skannaus on valmis, klikkaa Remove Vundo valintaa.
? Sinulta kysytään haluatko poistaa filut - klikkaa YES.
? Kun olet klikannut yes, työpöytäsi tyhjenee kun se alkaa poistamaan Vundoa.
? Kun se on valmis, fiksi ilmoittaa käynnistäväsi koneesi uudelleen, klikkaa OK.
? Postita C:\vundofix.txt lokin sekä tuoreen HijackThis lokin sisältö.


Huomaa: Se on mahdollista että VundoFix löysi tiedoston jota se ei pystynyt poistamaan.
Tässä tilanteessa, VundoFix ajaa itsensä rebootissa, seuraa vain yläpuolelle olevia ohjeita alkaen kohdasta "Klikkaa Scan for Vundo valintaa." kun VundoFix ilmaantuu uudelleenkäynnistyksen yhteydessä.




Voiko tietsikka koskaan toimia?
st3f4
Suspended due to non-functional email address
_
1. joulukuuta 2006 @ 08:53 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Eilen nukahdin kesken kaiken...


VundoFix V6.2.13

Checking Java version...

Java version is 1.5.0.6

Scan started at 12:58:02 1.12.2006

Listing files found while scanning....

No infected files were found.


Beginning removal...


HijackThis lokin sisältö:



Logfile of HijackThis v1.99.1
Scan saved at 13:54:06, on 1.12.2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Prevx1\PXAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Prevx1\PXConsole.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {35F7813A-AF74-4474-B1DC-7EE6FB6C43C6} - C:\WINDOWS\System32\bnxqnqre.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdat...b?1137962249389
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: geebb - C:\WINDOWS\
O21 - SSODL: expatriates - {1a01a98c-4f25-42e1-971a-185cf63569b2} - C:\WINDOWS\System32\tpedvf.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Hujo
Suspended permanently
_
1. joulukuuta 2006 @ 10:44 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Lataa SmitfraudFix (c) S!Ri http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Pura sisältö (kansio nimeltä SmitfraudFix) työpöydällesi:

Avaa SmitfraudFix kansio ja tupla-klikkaa smitfraudfix.cmd
Valitse optio #1 - Search kirjoittamalla 1 ja painamalla "Enter"; tekstitiedosto avautuu, joka listaa tarttuneet tiedostot (jos olemassa).
Postita tämän tekstitiedoston sisältö viestiketjuusi.

Huomaa : process.exe filun tunnistaa jotkut Anti-virus ohjelmat (AntiVir, Dr.Web, Kaspersky) "Haittakaluna"; se ei ole virus, vaan ohjelma joka pysäyttää prosesseja. A/V ohjelmat eivät pysty tunnistamaan hyvän ja pahan käytön tälläisten ohjelmian väliltä, silloin ne saattavat varoittaa käyttäjää.



Voiko tietsikka koskaan toimia?
st3f4
Suspended due to non-functional email address
_
1. joulukuuta 2006 @ 11:00 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Milloinkohan tämä scannaus on ohi? Melko monella ohjelmalla jo scannattu..

Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 1. joulukuuta 2006 @ 11:13

st3f4
Suspended due to non-functional email address
_
1. joulukuuta 2006 @ 11:11 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
SmitFraudFix v2.126

Scan done at 16:02:59,85, pe 01.12.2006
Run from C:\Documents and Settings\Petri\Ty?p?yt?\SmitfraudFix
OS: Microsoft Windows XP [versio 5.1.2600] - Windows_NT
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

C:\WINDOWS\system32\ot.ico FOUND !
C:\WINDOWS\system32\tpedvf.dll FOUND !
C:\WINDOWS\system32\ts.ico FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Petri


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Petri\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»»


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Nykyinen kotisivu"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{1a01a98c-4f25-42e1-971a-185cf63569b2}"="expatriates"

[HKEY_CLASSES_ROOT\CLSID\{1a01a98c-4f25-42e1-971a-185cf63569b2}\InProcServer32]
@="C:\WINDOWS\System32\tpedvf.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{1a01a98c-4f25-42e1-971a-185cf63569b2}\InProcServer32]
@="C:\WINDOWS\System32\tpedvf.dll"



»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!



»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!



»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

pe386 detected, use a Rootkit scanner

»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End
Hujo
Suspended permanently
_
1. joulukuuta 2006 @ 11:14 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
scannaa hjt:llä merkkaa paina fix checked

O20 - Winlogon Notify: geebb - C:\WINDOWS\


Niin tuo latailu on pelkän xp:n käyttäjän yksin oikeus.
Uutta tulee sitä mukaan kun puhdistusta suoritetaan.

Voiko tietsikka koskaan toimia?

Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 1. joulukuuta 2006 @ 11:19

Hujo
Suspended permanently
_
1. joulukuuta 2006 @ 11:15 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Printtaa ohjeet ulos.

Käynnistä koneesi vikasietotilaan ja valitse tavallinen käyttäjätilisi.

Kun vikasietotilassa, avaa SmitfraudFix kansio ja tupla-klikkaa smitfraudfix.cmd
Valitse optio #2 - Clean kirjoittamalla 2 ja painamalla "Enter" poistaaksesi tarttuneet tiedostot.

Sinulta kysytään: "Registry cleaning - Do you want to clean the registry ?"; vastaa "Yes" kirjoittamalla Y ja paina "Enter" poistaaksesi työpöydän taustakuvan ja puhdistaaksesi tarttuneet rekisteriavaimet.

Työkalu tarkistaa jos wininet.dll on tarttunut. Sinua saatetaan pyytää korvaamaan tarttunut .dll (jos löytyy); vastaa "Yes" kirjoittamalla Y ja painamalla "Enter".

Työkalun saattaa tarvita käynnistää kone uudelleen; jos ei tee niin, käynnistä normaaliin Windowsiin.
Tekstitiedosto ilmestyy, puhdistusprosessin jäljiltä; kopioi & liitä tämän raportin tulokset vastaukseesi.
Raportti löytyy paikalliselta levyltäsi, useimmiten C:\rapport.txt.

Varoitus : Ajamalla optio 2:n EI-tarttuneessa tietokoneessa, poistaa sinun työpöytäsi taustakuvan.




Voiko tietsikka koskaan toimia?
st3f4
Suspended due to non-functional email address
_
1. joulukuuta 2006 @ 11:50 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Noniin tuosta kellon vierestä semmonen "security" hommeli on nyt hävinny. Se varotti koko ajan jostain viiruksista ja ku sitä klikkas niin meni jonnekki viruksentorjuntasivuille tms.. Mutta sitä ei nyt ole ja taustakuvakin hävis.
"Ajamalla optio 2:n EI-tarttuneessa tietokoneessa, poistaa sinun työpöytäsi taustakuvan." Eli nyt ei enää ole mitään viruksia? :)




SmitFraudFix v2.126

Scan done at 16:43:02,07, pe 01.12.2006
Run from C:\Documents and Settings\Petri\Ty?p?yt?\SmitfraudFix
OS: Microsoft Windows XP [versio 5.1.2600] - Windows_NT
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{1a01a98c-4f25-42e1-971a-185cf63569b2}"="expatriates"

[HKEY_CLASSES_ROOT\CLSID\{1a01a98c-4f25-42e1-971a-185cf63569b2}\InProcServer32]
@="C:\WINDOWS\System32\tpedvf.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{1a01a98c-4f25-42e1-971a-185cf63569b2}\InProcServer32]
@="C:\WINDOWS\System32\tpedvf.dll"


»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri

C:\WINDOWS\System32\tpedvf.dll -> Hoax.Win32.Renos.gen.i
C:\WINDOWS\System32\tpedvf.dll -> Deleted


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\system32\ot.ico Deleted
C:\WINDOWS\system32\ts.ico Deleted

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End
Hujo
Suspended permanently
_
1. joulukuuta 2006 @ 12:06 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Lähetä HjT loki uusi.

työpöydän tausta kuvan saat takasin.
klikkaamalla työpöydällä hiiren oikean puoleisella napilla ja valitset ominaisuudet > Työpöytä > valitse taustakuva > käytä > ok




Voiko tietsikka koskaan toimia?
Mainos
_
__
 
_
st3f4
Suspended due to non-functional email address
_
1. joulukuuta 2006 @ 12:11 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Logfile of HijackThis v1.99.1
Scan saved at 17:12:05, on 1.12.2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Prevx1\PXConsole.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Prevx1\PXAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {35F7813A-AF74-4474-B1DC-7EE6FB6C43C6} - C:\WINDOWS\System32\bnxqnqre.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdat...b?1137962249389
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Viestiketju on suljettu. Uusien viestien lähettäminen ei ole mahdollista.
 
Sivu:12>
afterdawn.com > keskustelu > yleistä keskustelua tietokoneista > virukset ja haittaohjelmat - hijackthis -logit > tarvii apua! viiruksia pääs koneelle, tsekatkaa-
 

Apua ongelmiin: AfterDawnin keskustelualueet | AfterDawnin Vastaukset
Uutiset: IT-alan uutiset | Uutisia puhelimista
Musiikkia: MP3Lizard.com
Tuotearviot: Laitevertailu | Vertaa puhelimia | Vertaa kännykkäliittymiä
Pelit: Pelitiedostot, pelidemot ja trailerit
Ohjelmat: download.fi | AfterDawnin ohjelma-alueet
International: AfterDawn in English | Software downloads | Free, legal MP3s | AfterDawn på svenska
RSS -syötteet: AfterDawnin uutiset | Uusimmat ohjelmapäivitykset | Keskustelualueiden viestit
Tietoja: Tietoa AfterDawn Oy:stä | Mainosta sivuillamme | Sivuston käyttöehdot ja tietoja yksityisyydensuojasta
Ota yhteyttä: Lähetä palautetta | Ota yhteyttä mainosmyyntiimme
 
  © 1999-2025 AfterDawn Oy