Logfile of Advanced WindowsCare 3 Security Analyzer
Scan saved at 11:35:09, on 17.7.2008
Platform: Windows Vista (WinNT 6.0)
MSIE: Internet Explorer v7.0 (7.0.6000.16681)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\SPYWAREfighter\spftray.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\System32\p2phost.exe
C:\Users\susse ja marko\Program Files\DNA\btdna.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\JGsoft\EditPadLite\EditPadLite.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Norton Security Scan\Nss.exe
C:\Program Files\Norton Security Scan\Nss.exe
C:\Program Files\IObit\Advanced WindowsCare 3 Beta\AWC.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Yahoo! Toolbar Helper - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Users\susse ja marko\BitComet\tools\BitCometBHO_1.1.11.30.dll
O2 - BHO: Yahoo! Toolbar Helper - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! Toolbar Helper - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Yahoo! Toolbar Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [CollaborationHost] "C:\Windows\system32\p2phost.exe" -s
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\susse ja marko\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [spywarefighterguard] C:\Program Files\SPYWAREfighter\spftray.exe
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O8 - Extra context menu item: &Search - ?p=ZN
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O9 - Extra button: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
O9 - Extra button: &Lisää tämä blogiin tuotteessa Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} -
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} -
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res:\\C:\Users\susse ja marko\BitComet\tools\BitCometBHO_1.1.11.30.dll\206
O9 - Extra button: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - http://fpdownload.macromedia.com/get/fla...t/ultrashim.cab O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: (Ati External Event Utility) - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour-palvelu (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SPYWAREfighterRP - SpamFighter APS - C:\Program Files\SPYWAREfighter\spfprc.exe
O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown - %ProgramFiles%\Windows Media Player\wmpnetwk.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
ja tälläinen
rocess Unknown System No Record
Process S smss.exe Session Manager Subsystem
Process S csrss.exe Client/Server Runtime Server Subsystem
Process Unknown wininit.exe No Record
Process S csrss.exe Client/Server Runtime Server Subsystem
Process S services.exe Windows Service Controller
Process S winlogon.exe Windows Logon Process
Process S lsass.exe Local Security Service
Process Unknown lsm.exe No Record
Process S svchost.exe Service Host Process
Process S svchost.exe Service Host Process
Process S svchost.exe Service Host Process
Process G Ati2evxx.exe ATI driver (envent agent)
Process S svchost.exe Service Host Process
Process S svchost.exe Service Host Process
Process Unknown LVPrcSrv.exe No Record
Process S svchost.exe Service Host Process
Process Unknown audiodg.exe No Record
Process Unknown SLsvc.exe No Record
Process S svchost.exe Service Host Process
Process G Ati2evxx.exe ATI driver (envent agent)
Process S svchost.exe Service Host Process
Process G vsmon.exe True Vector Internet Monitor
Process Unknown dwm.exe No Record
Process G explorer.exe Windows Explorer
Process Unknown aswUpdSv.exe No Record
Process Unknown ashServ.exe No Record
Process S spoolsv.exe Printer Spooler Service
Process S svchost.exe Service Host Process
Process Unknown taskeng.exe No Record
Process Unknown mDNSResponder.exe No Record
Process Unknown LVComSer.exe No Record
Process S svchost.exe Service Host Process
Process S svchost.exe Service Host Process
Process Unknown TestHandler.exe No Record
Process S svchost.exe Service Host Process
Process Unknown SearchIndexer.exe No Record
Process Unknown WUDFHost.exe No Record
Process Unknown LVComSer.exe No Record
Process Unknown WasherSvc.exe No Record
Process Unknown ashMaiSv.exe No Record
Process Unknown ashWebSv.exe No Record
Process Unknown taskeng.exe No Record
Process Unknown MSASCui.exe No Record
Process Unknown RtHDVCpl.exe No Record
Process Unknown Communications_Helper.exe No Record
Process Unknown ashDisp.exe No Record
Process Unknown zlclient.exe No Record
Process Unknown spftray.exe No Record
Process Unknown wpcumi.exe No Record
Process Unknown WinPatrol.exe No Record
Process Unknown sidebar.exe No Record
Process Unknown msnmsgr.exe No Record
Process Unknown NMBgMonitor.exe No Record
Process Unknown ehtray.exe No Record
Process Unknown Skype.exe No Record
Process Unknown p2phost.exe No Record
Process Unknown btdna.exe No Record
Process Unknown SUPERAntiSpyware.exe No Record
Process Unknown wmpnscfg.exe No Record
Process Unknown ehmsas.exe No Record
Process G mobsync.exe Microsoft Synchronization Manager
Process Unknown COCIManager.exe No Record
Process Unknown wmpnetwk.exe No Record
Process Unknown spfprc.exe No Record
Process Unknown skypePM.exe No Record
Process Unknown WmiPrvSE.exe No Record
Process Unknown EditPadLite.exe No Record
Process Unknown taskeng.exe No Record
Process Unknown SPYWAREfighter.exe No Record
Process Unknown VSSVC.exe No Record
Process S svchost.exe Service Host Process
Process G AWC.exe Advanced WindowsCare Process Unknown firefox.exe No Record
Services L aswUpdSv.exe Related to Avast AntiVirus
Services L Ati2evxx.exe ATI Video Card Control Panel
Services L ashServ.exe Related to Avast AntiVirus
Services L ashMaiSv.exe Related to Avast AntiVirus
Services L ashWebSv.exe Related to AWIL Software http://www.avast.com/ Services L mDNSResponder.exe Create's a network of computers and smart devices. Made by Apple Computer, Inc. For more information Click_Here File location is in the Program Files\Gizmo Project folder.
Services L FNPLicensingService.exe Related to FLEXnet_Publisher from Macrovision. Note: Located in C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\
Services L LVComSer.exe Related to LVCOMSer from Logitech. Note: Located in \%Program Files%\Common Files\LogiShrd\LVCOMSER\
Services L LVPrcSrv.exe Related to Logitech QuickCam Provides additional configuration options for these devices.
Services L SrvLnch.exe Related to Logitech products
Services Unknown SDWinSec.exe No Record
Services Unknown spfprc.exe No Record
Services Unknown TestHandler.exe No Record
Services L vsmon.exe Zone Alarm Firewall
Services L wmpnetwk.exe Related to Windows_Media_Player Network Sharing Service. Note: Located in %ProgramFiles%\Windows Media Player\
Services Unknown WasherSvc.exe No Record
Start UP Unknown autoRun No Record
Start UP Unknown background No Record
Start UP U NMBgMonitor.exe Associated with Nero Scout, added by version 7 of the Nero digital media suite (CD & DVD burning, authoring, etc). Thanks to Help2Go.com, if you feel this is draining more resources that necessary you can disable it by clicking here
Start UP U ehTray.exe Enables the user to access Windows Messenger from within Windows Media Center Edition
Start UP Unknown minimized No Record
Start UP Unknown p2phost.exe -s No Record
Start UP Unknown btdna.exe No Record
Start UP U SUPERAntiSpyware.exe "SUPERAntiSpyware is the most thorough scanner on the market. Our Multi-Dimensional Scanning and Process Interrogation Technology will detect spyware that other products miss! SUPERAntiSpyware will remove ALL the Spyware, NOT just the easy ones!"
Start UP U WMPNSCFG.exe "Microsoft Windows uses wmpnscfg.exe to alert users when media rendering devices are found on the network. Wmpnscfg starts the Windows Media Player Network Sharing Service (NSS) and then waits for notifications from the service. When wmpnscfg is notified that a new media device is available on the network, it displays a popup in the system tray that informs the user about the availability of the new device. If the user clicks the popup, wmpnscfg launches Windows Media Player, which displays a dialog box tha
Start UP Unknown MSASCui.exe -hide No Record
Start UP U RtHDVCpl.exe High definition audio codec driver from Realtek Semiconductor
Start UP N jusched.exe Checks with Sun's Java updates site to see if newer Java versions are available. Visit http://java.sun.com or just run the Java Plug-In Control Panel
Start UP Unknown hide No Record
Start UP Y Communications_Helper.exe Installed with a Logitech Quickcam Messenger and if disabled the camera will not work - at least not in the quick capture mode
Start UP Y ashDisp.exe Part of Avast! anti-virus software
Start UP Y zlclient.exe Firewall program from Zonelabs. Pro version inlcudes other online security options
Start UP Unknown spftray.exe No Record
Start UP Y WpcUmi.exe Windows Vista Parental Control Notifications from Microsoft Corporation
Start UP Unknown winpatrol.exe -expressboot No Record
Start UP X NeroCheck.exe Added by the PROXY-X TROJAN! Note - this is not related to "Nero Burning Rom" CD writing software
BHO L 02478D38-C3F9-4EFB-9B51-7695ECA05670 Ycomp*_*_*_*.dll, Ycomp*,*,*,*.dll, yt.dll - Yahoo Companion, http://companion.yahoo.com/ BHO L 22BF413B-C6D2-4d91-82A9-A0F997BA588C SkypeIEPlugin.dll, SKYPE_~1.DLL, SKYPEI~1.DLL, toolbar.dll - Skype, http://www.skypejournal.com/blog/archive...e_for_inter.php toolbar for Internet Explorer
BHO L 39F7E362-828A-4B5A-BCAF-5B79BFDFEA60 BitCometBHO.dll, BitCometBHO_*.*.*.*.dll, BitCometBHO_*.*.*.**.dll (* = digit) - BitComet, http://www.bitcomet.com/ toolbar
BHO L 53707962-6F74-2D53-2644-206D7942484F SDhelper.dll - SpyBot Search&Destroy, http://www.safer-networking.org/index.php BHO L 602ADB0E-4AFF-4217-8AA1-95DAC4DFA408 coIEPlg.dll - Browser plugin related with Norton_Confidential, http://www.symantec.com/en/me/home_homeo...cid=ts&pvid=nco BHO L 761497BB-D6F0-462C-B6EB-D4DAF1D92D43 ssv.dll - Related to Sun_Java_software, http://java.com/en/download/index.jsp BHO L 9030D464-4C02-4ABF-8ECC-5164760863C6 WindowsLiveLogin.dll - Microsoft Windows_Live, http://ideas.live.com/ BHO L BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0 msntb.dll - Windows Live Toolbar, http://ideas.live.com/programPage.aspx?v...6d-a4749e827cc5 Tool Bar L BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0 msntb.dll - Windows Live Toolbar, //ideas.live.com/programPage.aspx?versionId=f53eeee8-de38-45c8-bc6d-a4749e827cc5
Tool Bar L 7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA CoIEPlg.dll - Browser plugin related with Norton_Confidential, //www.symantec.com/en/me/home_homeoffice/products/sysreq.jsp?pcid=ts&pvid=nco
Tool Bar L EF99BD32-C1FB-11D2-892F-0090271D4F88 Ycomp*_*_*_*.dll, yt.dll - Yahoo Companion!, //companion.yahoo.com/
Button Unknown {08B0E5C0-4FCB-11CF-AAA5-00401C608501} No Database
Button Unknown {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} No Database
Button Unknown {77BF5300-1474-4EC7-9980-D32B190E9B07} No Database
Button Unknown {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} No Database
Button Unknown {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} No Database
ActiveX L 166B1BCA-3F9C-11CF-8075-444553540000 http://www.macromedia.com/software ActiveX Unknown 233C1507-6A77-46A4-9443-F871F945D258 No Record
ActiveX L 30528230-99f7-4bb4-88d8-fa1d4f56a2ab http://www.yahoo.com ActiveX L 56762DEC-6B0D-4AB4-A8AD-989993B5D08B OnlineScanner.cab NOD32 online scanner
ActiveX Unknown 8FFBE65D-2C9C-4669-84BD-5829DC0B603C No Record
ActiveX Unknown BDBDE413-7B1C-4C68-A8FF-C5B2B4090876 No Record
tossahan se sanoo tosta nerosta että se on jonkun troijalaisen juttu,mutta millä prkllä saan sen pois?
ja miks spybotti löytää spyhunterista 7 haitallista kohdetta mutta ei anna korjata niitä, koska ei ole "järjestelmänvalvojan oikeuksia"useasti sanoo niin.miksi?mitä se tarkoittaa?kiiits etukäteen.terv.susse
* Tuplaklikkaa mbam-setup.exe ja seuraa ohjeita asentaaksesi ohjelman.
* Lopuksi varmistu, että seuraavat on valittu: Päivitä Malwarebytes' Anti-Malware ja Käynnistä Malwarebytes' Anti-Malware ja sen jälkeen klikkaa Lopeta.
* Jos päivitys löytyy. ohjelma lataa ja asentaa uusimman version.
* Kun ohjelma on latautunut, valitse Suorita täysi tarkistus ja klikkaa Tarkista.
* Kun skanni on valmis, klikkaa OK ja sitten Näytä tulokset nähdäksesi tulokset.
* Varmistu, että kaikki on merkitty ja klikkaa Poista valitut.
* Tämän jälkeen loki avautuu muistioon. Tallenna se paikkaan, josta löydät sen helposti. Loki löytyy myös
täältä: C:\Documents and Settings\Käyttäjänimi\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-päiväys.txt * Lähetä lokin sisältö seuraavassa viestissäsi + uusi hjt-loki.
mulla on toi malware bytes jo!mutta se ei löytänyt mitään.olen sillä käynyt joka päivä koko koneen läpi.viimeksikään ei löytänyt, mutta spybotti löysi haittaohjelmia(spyhunterista!!5kpl) ja toi windowscare löys vaikka mitä minkä eilen latasin.olen aivan pihalla näitten juttujen kanssa ,kun yks löytää ja toinen ei.alkaa tulla wäinöharha..nerot(nero check.exe) poistin kun toi windowscaren loki sanoi että se jonkun proxy troijalaisen juttuja...prkl.katon nyt sen mlw bytesin lokin,jotta mitä se sanoo.kiits.