| 
					"Ylimääräisiä"  prosseja ja muuta vikaa?  (HjT-logi mukana)
				 | 
				
				
					
				 | 
				
			
			
			
			
				
					
					
				
			
			
			
			
			
				
				
					
				
				
				
				
					
						| 
							
								 Pezmerga 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						29. syyskuuta 2005 @ 14:33 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						
						
						
							
							Jooh elikkä oon tässä lähiaikoina huomannu koneessa aivan törkeää hidasttumista ja oon pyöritelly kaikenlaista ohjelmaa jolla siitä sais jotain tolkkua. Tuossa tehtävienhallinnassa prosessissa on myös alkanu pyöriin "ylimääräisiä" prosesseja joiden alkuperästä en juurikaan tiedä. Näistä yksi esimerkki on tuo "svchost.exe" -joka ilmeisesti siis on joku täysin normaali ohjelman osa, mutta se nyt on suht lähi päivinä tupannu ilmestymään tuohon "prosessit" -listaan vähintää 5:ssä eri muodossa.
 
 Anyway, Löysin sitten sattumalta tänne googlettamisen seurauksena ja täällä tuntuu asiantuntevaa porukkaa olevan paikalla pyörittelemässä noita HijackThis -logeja ja kun en niistä itse juurikaan ymmärrä aattelin kysyä neuvoa ennenkuin alan itse pyörittelemään noita tiedostoja.
 
 tässä ois just otettu HijackThis Logi:
 
 Logfile of HijackThis v1.99.1
 Scan saved at 18:06:52, on 29.9.2005
 Platform: Windows XP SP1 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Juzzi\Hyödyllistä\SPF\smc.exe
 C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\System32\CTSvcCDA.EXE
 C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
 C:\Program Files\Norton AntiVirus\navapsvc.exe
 C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
 C:\WINDOWS\System32\nvsvc32.exe
 C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\System32\devldr32.exe
 C:\WINDOWS\System32\wuauclt.exe
 C:\Program Files\FarStone\RestoreIT!\RestoreIT!_XP\VBPTASK.EXE
 C:\Juzzi\DTools\daemon.exe
 C:\WINDOWS\System32\RUNDLL32.exe
 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
 C:\WINDOWS\System32\ctfmon.exe
 C:\Juzzi\Hyödyllistä\GCS\GrabClipSave.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\Juzzi\Hyödyllistä\HijackThis\HijackThis.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.rqzxnzfbnakwvkydz.biz/rNMVcRxGDJySs8jM2e1oKQUmgdFC3yqS... R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soneraplaza.fi R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?new-hklm R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.google.fi/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Sonera Plaza Oy
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
 F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
 O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000000221} - C:\PROGRA~1\Lycos\IEagent\CSIE.DLL
 O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - (no file)
 O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_11_0.dll
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
 O2 - BHO: IEHlprObj Class - {09259C26-548B-4AF7-A236-EABB7A24D97C} - C:\WINDOWS\system32\mo030414s.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
 O2 - BHO: (no name) - {9AE9D42C-095F-C169-9D7F-15D4C61EF218} - C:\DOCUME~1\deejay\APPLIC~1\LOGAIM~1\Eqteam.exe (file missing)
 O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
 O2 - BHO: CWebDirObj Object - {C003C49F-53E4-4A72-B7D6-0B2B9997392F} - C:\WINDOWS\webdir.dll (file missing)
 O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_11_0.dll
 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
 O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
 O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
 O4 - HKLM\..\Run: [RestoreIT!] "C:\Program Files\FarStone\RestoreIT!\RestoreIT!_XP\VBPTASK.EXE" VBStart
 O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
 O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Juzzi\DTools\daemon.exe"  -lang 1033
 O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
 O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
 O4 - HKLM\..\Run: [SmcService] C:\Juzzi\HYDYLL~1\SPF\smc.exe -startgui
 O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
 O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
 O4 - HKLM\..\Run: [Extrahelpdeadonline] C:\Documents and Settings\All Users\Application Data\Waitgreyextrahelp\FlagHtm.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
 O4 - HKCU\..\Run: [GCS] "C:\Juzzi\Hyödyllistä\GCS\GrabClipSave.exe"
 O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
 O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
 O4 - Startup: PowerReg Scheduler V3.exe
 O4 - Startup: PowerReg Scheduler.exe
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
 O8 - Extra context menu item: &Format Offline Inbox - c:\windows\web\ie_customizations\Format Offline Inbox.html
 O8 - Extra context menu item: &Friend or Foe - c:\windows\web\ie_customizations\Friend or Foe.html
 O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
 O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind13.dll (file missing)
 O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\WINDOWS\System32\shdocvw.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
 O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
 O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi O15 - Trusted Zone: http://ad.searchsquire.com O15 - Trusted Zone: http://search.searchsquire.com O15 - Trusted Zone: http://update.searchsquire.com O15 - Trusted Zone: http://www.searchsquire.com O15 - Trusted Zone: http://*.searchsquire.com O16 - DPF: {5BDBD95C-1E7F-4FB1-8497-20AF879F8B68} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSha... O16 - DPF: {6EB5B540-1E74-4D91-A7F0-5B758D333702} - http://infinity.n-case.com/captioncitymain/resources/nCaseInstall... O16 - DPF: {907CA0E5-CE84-11D6-9508-02608CDD2846} (Squire Class) - http://update.searchsquire.com/SearchSquire33.CAB O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - https://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
 O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = mydomain.com
 O17 - HKLM\System\CCS\Services\Tcpip\..\{5700C191-4DBB-455A-AABB-3D55FEE6C671}: NameServer = 216.127.92.38
 O17 - HKLM\System\CS1\Services\VxD\MSTCP: Domain = mydomain.com
 O17 - HKLM\System\CS1\Services\VxD\MSTCP: NameServer = 216.127.92.38
 O17 - HKLM\System\CS2\Services\VxD\MSTCP: Domain = mydomain.com
 O17 - HKLM\System\CS2\Services\VxD\MSTCP: NameServer = 216.127.92.38
 O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 216.127.92.38
 O23 - Service: F-Secure BackWeb (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE (file missing)
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
 O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
 O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
 O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
 O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
 O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
 O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Juzzi\Hyödyllistä\SPF\smc.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 O23 - Service: Time Zones for PCs Installer - Unknown owner - C:\Program Files\Digital Design Ltd\Time Zones for PCs\TZPCINST.EXE" /update (file missing)
 
 ja Jooh, siellä on aika paljon turhaa krääsää jota on ajan kuluessa tarttunu mukaan, mutta jos sieltä jotain hälyyttävää löytyis ois tosi jees jos joku ehtis sitä vilkaista ja antaa mahdollisia etenemis ohjeita. Kiitos etukäteen ^^;; 
							
						 
						
						
 ^^;; 
						
						 | 
					
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
   1 tuotearvio
								
							
							 
							 
						 | 
						29. syyskuuta 2005 @ 14:44 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						
						
						
							
							Fixaa seuraavat:
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.rqzxnzfbnakwvkydz.biz/rNMVcRxGDJySs8jM2e1oKQUmgdFC3yqS... 
 O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - (no file)
 
 R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
 
 -kemisti- saa kattoo loput, tai joku muu joka tietää enemmän tosta enemmän :-)
 
 EDIT1: vielä yks juttu unohtu, päivitä windows. 
							
						 
						
						 
						
							Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 29. syyskuuta 2005 @ 14:46 
						
						 | 
					
				
				
			
				
				
				
				
				
					
						| 
							
								 Pezmerga 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						29. syyskuuta 2005 @ 15:12 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						
						
						
							
							Kiitos nopeasta vastauksesta, päivätän widowsia samaan aikaan tuossa taustalla :)
 
 nuo listaamat kohdat fixattu, uus logi näyttää tältä, laitan viel uuden kun windows on päivitetty:
 
 Logfile of HijackThis v1.99.1
 Scan saved at 19:08:48, on 29.9.2005
 Platform: Windows XP SP1 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Juzzi\Hyödyllistä\SPF\smc.exe
 C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\System32\CTSvcCDA.EXE
 C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
 C:\Program Files\Norton AntiVirus\navapsvc.exe
 C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
 C:\WINDOWS\System32\nvsvc32.exe
 C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\System32\devldr32.exe
 C:\Program Files\FarStone\RestoreIT!\RestoreIT!_XP\VBPTASK.EXE
 C:\Juzzi\DTools\daemon.exe
 C:\WINDOWS\System32\RUNDLL32.exe
 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
 C:\WINDOWS\System32\ctfmon.exe
 C:\Juzzi\Hyödyllistä\GCS\GrabClipSave.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\WINDOWS\System32\wuauclt.exe
 C:\Juzzi\Hyödyllistä\HijackThis\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soneraplaza.fi R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?new-hklm R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.google.fi/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Sonera Plaza Oy
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
 O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000000221} - C:\PROGRA~1\Lycos\IEagent\CSIE.DLL
 O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_11_0.dll
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
 O2 - BHO: IEHlprObj Class - {09259C26-548B-4AF7-A236-EABB7A24D97C} - C:\WINDOWS\system32\mo030414s.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
 O2 - BHO: (no name) - {9AE9D42C-095F-C169-9D7F-15D4C61EF218} - C:\DOCUME~1\deejay\APPLIC~1\LOGAIM~1\Eqteam.exe (file missing)
 O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
 O2 - BHO: CWebDirObj Object - {C003C49F-53E4-4A72-B7D6-0B2B9997392F} - C:\WINDOWS\webdir.dll (file missing)
 O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_11_0.dll
 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
 O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
 O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
 O4 - HKLM\..\Run: [RestoreIT!] "C:\Program Files\FarStone\RestoreIT!\RestoreIT!_XP\VBPTASK.EXE" VBStart
 O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
 O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Juzzi\DTools\daemon.exe"  -lang 1033
 O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
 O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
 O4 - HKLM\..\Run: [SmcService] C:\Juzzi\HYDYLL~1\SPF\smc.exe -startgui
 O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
 O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
 O4 - HKLM\..\Run: [Extrahelpdeadonline] C:\Documents and Settings\All Users\Application Data\Waitgreyextrahelp\FlagHtm.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
 O4 - HKCU\..\Run: [GCS] "C:\Juzzi\Hyödyllistä\GCS\GrabClipSave.exe"
 O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
 O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
 O4 - Startup: PowerReg Scheduler V3.exe
 O4 - Startup: PowerReg Scheduler.exe
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
 O8 - Extra context menu item: &Format Offline Inbox - c:\windows\web\ie_customizations\Format Offline Inbox.html
 O8 - Extra context menu item: &Friend or Foe - c:\windows\web\ie_customizations\Friend or Foe.html
 O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
 O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind13.dll (file missing)
 O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\WINDOWS\System32\shdocvw.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
 O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
 O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi O15 - Trusted Zone: http://ad.searchsquire.com O15 - Trusted Zone: http://search.searchsquire.com O15 - Trusted Zone: http://update.searchsquire.com O15 - Trusted Zone: http://www.searchsquire.com O15 - Trusted Zone: http://*.searchsquire.com O16 - DPF: {5BDBD95C-1E7F-4FB1-8497-20AF879F8B68} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSha... O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl... O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/... O16 - DPF: {6EB5B540-1E74-4D91-A7F0-5B758D333702} - http://infinity.n-case.com/captioncitymain/resources/nCaseInstall... O16 - DPF: {907CA0E5-CE84-11D6-9508-02608CDD2846} (Squire Class) - http://update.searchsquire.com/SearchSquire33.CAB O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - https://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
 O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = mydomain.com
 O17 - HKLM\System\CCS\Services\Tcpip\..\{5700C191-4DBB-455A-AABB-3D55FEE6C671}: NameServer = 216.127.92.38
 O17 - HKLM\System\CS1\Services\VxD\MSTCP: Domain = mydomain.com
 O17 - HKLM\System\CS1\Services\VxD\MSTCP: NameServer = 216.127.92.38
 O17 - HKLM\System\CS2\Services\VxD\MSTCP: Domain = mydomain.com
 O17 - HKLM\System\CS2\Services\VxD\MSTCP: NameServer = 216.127.92.38
 O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 216.127.92.38
 O23 - Service: F-Secure BackWeb (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE (file missing)
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
 O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
 O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
 O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
 O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
 O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
 O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Juzzi\Hyödyllistä\SPF\smc.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe 
							
						 
						
						
 ^^;; 
						
							Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 29. syyskuuta 2005 @ 15:32 
						
						 | 
					
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						29. syyskuuta 2005 @ 15:33 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						
						
						
							
							Kiitos Disa-, jatketaan tästä eteenpäin :)
 
 Fixaa hijackthisillä (do a system scan, merkkaa ja paina fix checked):
 
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?new-hklm O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
 O2 - BHO: (no name) - {9AE9D42C-095F-C169-9D7F-15D4C61EF218} - C:\DOCUME~1\deejay\APPLIC~1\LOGAIM~1\Eqteam.exe (file missing) 
 O2 - BHO: CWebDirObj Object - {C003C49F-53E4-4A72-B7D6-0B2B9997392F} - C:\WINDOWS\webdir.dll (file missing)
 O4 - HKLM\..\Run: [Extrahelpdeadonline] C:\Documents and Settings\All Users\Application Data\Waitgreyextrahelp\FlagHtm.exe 
 O4 - Startup: PowerReg Scheduler V3.exe
 O4 - Startup: PowerReg Scheduler.exe 
 
 Oletko laittanut itse nämä luotettujen sivujen listaan? Jos et, fixaa:
 
 O15 - Trusted Zone: http://ad.searchsquire.com O15 - Trusted Zone: http://search.searchsquire.com O15 - Trusted Zone: http://update.searchsquire.com O15 - Trusted Zone: http://www.searchsquire.com O15 - Trusted Zone: http://*.searchsquire.com 
 O16 - DPF: {6EB5B540-1E74-4D91-A7F0-5B758D333702} - http://infinity.n-case.com/captioncitymain/resources/nCaseInstall... O16 - DPF: {907CA0E5-CE84-11D6-9508-02608CDD2846} (Squire Class) - http://update.searchsquire.com/SearchSquire33.CAB O17 -HKLM\System\CCS\Services\Tcpip\..\{5700C191-4DBB-455A-AABB-3D55FEE6C671}: NameServer = 216.127.92.38
 O17 - HKLM\System\CS1\Services\VxD\MSTCP: Domain = mydomain.com
 O17 - HKLM\System\CS1\Services\VxD\MSTCP: NameServer = 216.127.92.38
 O17 - HKLM\System\CS2\Services\VxD\MSTCP: Domain = mydomain.com
 O17 - HKLM\System\CS2\Services\VxD\MSTCP: NameServer = 216.127.92.38
 O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 216.127.92.38 
 
 Käynnistä vikasietotilaan (F8 käynnistyksen yhteydessä) ja poista:
 
 C:\Documents and Settings\All Users\Application Data\==>Waitgreyextrahelp<==
 C:\DOCUME~1\deejay\APPLIC~1\==>LOGAIM~1<== (jos on)
 
 Käynnistä uudestaan ja lähetä uusi HjT-loki.
							
						 
						
						
						
						 | 
					
				
				
			
				
				
				
				
				
					
						| 
							
								 Pezmerga 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						29. syyskuuta 2005 @ 16:17 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						
						
						
							
							wow, kiitti :D
 
 ok, fixasin kaikki nuo kohdat ja poistin tuon Waitgreyextrahelp´in. tässä ois uus logi:
 
 Logfile of HijackThis v1.99.1
 Scan saved at 20:13:53, on 29.9.2005
 Platform: Windows XP SP1 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Juzzi\Hyödyllistä\SPF\smc.exe
 C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\System32\CTSvcCDA.EXE
 C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
 C:\Program Files\Norton AntiVirus\navapsvc.exe
 C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
 C:\WINDOWS\System32\nvsvc32.exe
 C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\System32\devldr32.exe
 C:\Program Files\FarStone\RestoreIT!\RestoreIT!_XP\VBPTASK.EXE
 C:\Juzzi\DTools\daemon.exe
 C:\WINDOWS\System32\RUNDLL32.exe
 C:\WINDOWS\System32\wuauclt.exe
 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
 C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
 C:\WINDOWS\System32\ctfmon.exe
 C:\Juzzi\Hyödyllistä\GCS\GrabClipSave.exe
 C:\WINDOWS\System32\wuauclt.exe
 C:\Juzzi\Hyödyllistä\HijackThis\HijackThis.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soneraplaza.fi R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.google.fi/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Sonera Plaza Oy
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
 O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000000221} - C:\PROGRA~1\Lycos\IEagent\CSIE.DLL
 O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_11_0.dll
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
 O2 - BHO: IEHlprObj Class - {09259C26-548B-4AF7-A236-EABB7A24D97C} - C:\WINDOWS\system32\mo030414s.dll
 O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_11_0.dll
 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
 O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
 O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
 O4 - HKLM\..\Run: [RestoreIT!] "C:\Program Files\FarStone\RestoreIT!\RestoreIT!_XP\VBPTASK.EXE" VBStart
 O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
 O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Juzzi\DTools\daemon.exe"  -lang 1033
 O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
 O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
 O4 - HKLM\..\Run: [SmcService] C:\Juzzi\HYDYLL~1\SPF\smc.exe -startgui
 O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
 O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
 O4 - HKCU\..\Run: [GCS] "C:\Juzzi\Hyödyllistä\GCS\GrabClipSave.exe"
 O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
 O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
 O8 - Extra context menu item: &Format Offline Inbox - c:\windows\web\ie_customizations\Format Offline Inbox.html
 O8 - Extra context menu item: &Friend or Foe - c:\windows\web\ie_customizations\Friend or Foe.html
 O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
 O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind13.dll (file missing)
 O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\WINDOWS\System32\shdocvw.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
 O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
 O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi O16 - DPF: {5BDBD95C-1E7F-4FB1-8497-20AF879F8B68} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSha... O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl... O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/... O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - https://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
 O23 - Service: F-Secure BackWeb (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE (file missing)
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
 O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
 O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
 O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
 O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
 O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
 O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Juzzi\Hyödyllistä\SPF\smc.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe 
							
						 
						
						
 ^^;; 
						
						 | 
					
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						29. syyskuuta 2005 @ 16:25 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						| 
						
						 
							
							Loki näyttää muuten hyvältä, mutta unohdin äsken yhden kohdan :(
 
 Fixaa tämä:
 
 O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - https://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab 
 
 Käynnistä uudestaan ja lähetä uusi hjt-loki. Auttoiko hidastumiseen?
							
						 
						
						
						
						 | 
					
				
				
			
				
				
				
				
				
					
						| 
							
								 Pezmerga 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						29. syyskuuta 2005 @ 16:46 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						
						
						
							
							ok nyt on sekin poistettu, tässä ois tää seuraava logi:
 
 Logfile of HijackThis v1.99.1
 Scan saved at 20:38:57, on 29.9.2005
 Platform: Windows XP SP1 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Juzzi\Hyödyllistä\SPF\smc.exe
 C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\System32\CTSvcCDA.EXE
 C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
 C:\Program Files\Norton AntiVirus\navapsvc.exe
 C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
 C:\WINDOWS\System32\nvsvc32.exe
 C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 C:\WINDOWS\System32\devldr32.exe
 C:\Program Files\FarStone\RestoreIT!\RestoreIT!_XP\VBPTASK.EXE
 C:\Juzzi\DTools\daemon.exe
 C:\WINDOWS\System32\RUNDLL32.exe
 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
 C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
 C:\WINDOWS\System32\wuauclt.exe
 C:\WINDOWS\System32\ctfmon.exe
 C:\Juzzi\Hyödyllistä\GCS\GrabClipSave.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\Juzzi\Hyödyllistä\HijackThis\HijackThis.exe
 C:\WINDOWS\System32\wuauclt.exe
 C:\WINDOWS\System32\taskmgr.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soneraplaza.fi R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.google.fi/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Sonera Plaza Oy
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
 O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000000221} - C:\PROGRA~1\Lycos\IEagent\CSIE.DLL
 O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_11_0.dll
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
 O2 - BHO: IEHlprObj Class - {09259C26-548B-4AF7-A236-EABB7A24D97C} - C:\WINDOWS\system32\mo030414s.dll
 O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_11_0.dll
 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
 O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
 O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
 O4 - HKLM\..\Run: [RestoreIT!] "C:\Program Files\FarStone\RestoreIT!\RestoreIT!_XP\VBPTASK.EXE" VBStart
 O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
 O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Juzzi\DTools\daemon.exe"  -lang 1033
 O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
 O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
 O4 - HKLM\..\Run: [SmcService] C:\Juzzi\HYDYLL~1\SPF\smc.exe -startgui
 O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
 O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
 O4 - HKCU\..\Run: [GCS] "C:\Juzzi\Hyödyllistä\GCS\GrabClipSave.exe"
 O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
 O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
 O8 - Extra context menu item: &Format Offline Inbox - c:\windows\web\ie_customizations\Format Offline Inbox.html
 O8 - Extra context menu item: &Friend or Foe - c:\windows\web\ie_customizations\Friend or Foe.html
 O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
 O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind13.dll (file missing)
 O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\WINDOWS\System32\shdocvw.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
 O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
 O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi O16 - DPF: {5BDBD95C-1E7F-4FB1-8497-20AF879F8B68} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSha... O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl... O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/... O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab O23 - Service: F-Secure BackWeb (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE (file missing)
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
 O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
 O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
 O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
 O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
 O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
 O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Juzzi\Hyödyllistä\SPF\smc.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 
 Ei varmaankaan näihin HjT logeihin liity hirveesti, mut viel tuota svchost.exeä tässä kummastelen, sitä löytyy 5 kappaletta sovellusluettelosta, onko tuo ihan normaalia? Löysin aika ristiriitasta tietoa siitä
 
 Mut jooh, tuntui ainakin hieman auttavan tuohon hitauteen, ja ihan muutenkin ihan hyvä päästä tuosta sälästä eroon, kiitos :D 
							
						 
						
						
 ^^;; 
						
						 | 
					
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						29. syyskuuta 2005 @ 16:54 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						| 
						
						 
							
							Niitä svchosteja voi olla auki 1-6 kpl, eli ihan normaalia.
 
 EDIT: Ja taas unohtui yks. Aletaan huolellisemmaksi :( Fixaa vielä:
 
 O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000000221} - C:\PROGRA~1\Lycos\IEagent\CSIE.DLL
 
 Ja poista hakemisto C:\PROGRA~1\==>Lycos<== vikasiedossa
 
 Käynnistys ja uusi HjT-loki.
 
 @Disa-: On, sen voi myös fixata.
							
						 
						
						
						
							Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 29. syyskuuta 2005 @ 17:03 
						
						 | 
					
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
   1 tuotearvio
								
							
							 
							 
						 | 
						29. syyskuuta 2005 @ 16:55 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						| 
						
						 
							
							Onko seuraava rivi turha?
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
							
						 
						
						 
						
						 | 
					
				
				
			
				
				
				
				
				
					
						| 
							
								 Toymaatti 
							
							
								Senior Member
								
									
								
							
							 
							 
						 | 
						29. syyskuuta 2005 @ 17:41 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						| 
						
						 
							
							Näyttäis ongelmien tulleen osittain MessengerPlussan mukana :(
 
 Mites nuo virustorjunta- ja palomuuriohjelmat kun siellä näyttäis pyörivän Nortonilta molemmat, Pandan antivirus, Sygaten muuri? 
							
						 
						
						
 Se parhaiten nauraa joka toiselle kuoppaa kaivaa. 
						
						 | 
					
				
				
			
				
				
				
				
				
					
						| 
							
								 Pezmerga 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						29. syyskuuta 2005 @ 20:49 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						
						
						
							
							jooh F-Secure oli jossain vaihees, mutta sen kans alko tuleen kaikkea häsmää ja neuvvottiin ihansuosiolla dumppaan sen (joku prosessi söi suoritinmuistia ihan törkeesti ja se oli osa F-securea ja täten ei poistettavissa). Tuo Sygaten muuri on ihan näppärästi toiminu ja ei näyttäs olevan mitään ongelmia sen ja Nortonin välillä, mut Pandan asennus jäi kesken koska se ihan suoraan pyytää Nortonin poistamista toimiakseen, jostain syystä unohtu poistaa se mitä siitä asennuksesta jäi jäljelle. Pandan online scan tosin tulee pyöritettyä vähän väliä.
 Sit viel easy cleaner, Spybot, F-Prot ja spywareblaster pienemmän roskan siivoamiseen mutta vielä sitä tuntuu pukkaavan. =/ 
							
						 
						
						
 ^^;; 
						
						 | 
					
				
				
			
				
				
				
				
				
					
						| 
							
								 Toymaatti 
							
							
								Senior Member
								
									
								
							
							 
							 
						 | 
						30. syyskuuta 2005 @ 08:25 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						
						
						
							
							OK, ja Nortonissako ei ole muuria?
 
 Laita piilotiedostot näkyviin
 http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/20020927... 
 Poista Lisää/Poista sovelluksesta 
 -F-Secureen ja Pandaan liittyvät
 -WildTangent
 -SideFind
 
 Kirjoita SUORITA riville SERVICES.MSC > OK, tuplaklikkaa riviä
 F-Secure BackWeb (BackWeb Client - 7681197)
 PALVELUNTILA kohdassa klikkaa SEIS > KÄYNNISTYSTAPA kohdassa valitse EI KÄYTÖSSÄ
 
 Tee sama homma Pandan palvelulle
 Panda Process Protection Service (PavPrSrv)
 
 Merkkaa nuo HjT:ssä, sulje selain ja muut ikkunat, klikkaa FIX
 O2 - BHO: IEHlprObj Class - {09259C26-548B-4AF7-A236-EABB7A24D97C} - C:\WINDOWS\system32\mo030414s.dll 
 O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
 O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind13.dll (file missing) 
 O23 - Service: F-Secure BackWeb (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE (file missing)
 O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
 
 Käynnistä vikasietotilaan ja poista nuo
 C:\WINDOWS\system32\mo030414s.dll
 C:\Program Files\WildTangent
 C:\Program Files\SideFind
 C:\Program Files\F-Secure
 C:\Program Files\Common Files\Panda Software
 Sekä jos muita F-Secure/Panda kansioita löytyy
 
 Käynnistä normaalisti, hae RegSeeker rekisterin puhdistaja ja aja se(Elä säikähä, se löytää varmaan satoja poistettavia, anna poistaa vaan kaikki se tekee niistä varmuuskopion)
 http://www.hoverdesk.net/freeware.htm 
 Putsaa EasyCleanerilla TURHAT pois ja laita uusi HjT loki 
							
						 
						
						
 Se parhaiten nauraa joka toiselle kuoppaa kaivaa. 
						
						 | 
					
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						30. syyskuuta 2005 @ 09:09 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						| 
						
						 
							
							Jaaha, jos noin paljon jäi huomaamatta, niin mun kannattaa varmaan jäädä eläkkeelle tai sitten eilen oli vaan huono päivä ;) Ollaan jatkossa paljon tarkempi.
							
						 
						
						
						
						 | 
					
				
				
			
				
				
				
				
				
					
						| 
							
								 Pezmerga 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						30. syyskuuta 2005 @ 11:07 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						
						
						
							
							ok, kaikki kohdat käyty läpi ja tässä tulos:
 
 Logfile of HijackThis v1.99.1
 Scan saved at 14:56:02, on 30.9.2005
 Platform: Windows XP SP1 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Juzzi\Hyödyllistä\SPF\smc.exe
 C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\System32\CTSvcCDA.EXE
 C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
 C:\Program Files\Norton AntiVirus\navapsvc.exe
 C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
 C:\WINDOWS\System32\nvsvc32.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 C:\WINDOWS\System32\devldr32.exe
 C:\Program Files\FarStone\RestoreIT!\RestoreIT!_XP\VBPTASK.EXE
 C:\Juzzi\DTools\daemon.exe
 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
 C:\WINDOWS\System32\ctfmon.exe
 C:\Juzzi\Hyödyllistä\GCS\GrabClipSave.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\Program Files\Symantec\LiveUpdate\AUpdate.exe
 C:\Juzzi\Hyödyllistä\HijackThis\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soneraplaza.fi R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.google.fi/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Sonera Plaza Oy
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
 O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000000221} - C:\PROGRA~1\Lycos\IEagent\CSIE.DLL
 O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_11_0.dll
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
 O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_11_0.dll
 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
 O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
 O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
 O4 - HKLM\..\Run: [RestoreIT!] "C:\Program Files\FarStone\RestoreIT!\RestoreIT!_XP\VBPTASK.EXE" VBStart
 O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Juzzi\DTools\daemon.exe"  -lang 1033
 O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
 O4 - HKLM\..\Run: [SmcService] C:\Juzzi\HYDYLL~1\SPF\smc.exe -startgui
 O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
 O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
 O4 - HKCU\..\Run: [GCS] "C:\Juzzi\Hyödyllistä\GCS\GrabClipSave.exe"
 O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
 O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
 O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi O16 - DPF: {5BDBD95C-1E7F-4FB1-8497-20AF879F8B68} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSha... O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl... O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/... O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
 O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
 O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
 O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
 O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
 O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Juzzi\Hyödyllistä\SPF\smc.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 
 ainaki logi lyhentyny jos ei muuta :D 
							
						 
						
						
 ^^;; 
						
						 | 
					
				
				
			
				
				
				
				
				
					
						| 
							
								 Toymaatti 
							
							
								Senior Member
								
									
								
							
							 
							 
						 | 
						30. syyskuuta 2005 @ 11:26 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						| 
						
						 
							
							-kemisti- Heh heh heee nuorimies, just hommat aloittanut ja meinaa että eläkkeelle ;)
 Noita sattuu ja joskus ne silmät vaan on x x :D
 
 
 Pezmerga, et vastannut siihen että onko Nortonissa palomuuri? 
 
 Sulta on varmaan mennyt-kemisti-:n neuvo ohi kun Lycos on vielä siellä, eli poista Lisää/Poista sovelluksesta Lycos
 
 Fixaa tuo HjT:llä
 O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000000221} - C:\PROGRA~1\Lycos\IEagent\CSIE.DLL
 
 Poista tuo
 C:\Program Files\==>Lycos<==
 
 Mites kone toimii nyt?? 
							
						 
						
						
 Se parhaiten nauraa joka toiselle kuoppaa kaivaa. 
						
						 | 
					
				
				
			
				
				
				
				
				
					
						| 
							
								 Pezmerga 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						30. syyskuuta 2005 @ 21:49 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						
						
						
							
							Nortonilla on tarjolla palomuuri, mutta itellä ei ole kuin se antivirus ja siksi toi Sygaten muuri.
 
 tais nyt se viiminenki lähteä:
 Logfile of HijackThis v1.99.1
 Scan saved at 1:42:50, on 1.10.2005
 Platform: Windows XP SP1 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Juzzi\Hyödyllistä\SPF\smc.exe
 C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\System32\CTSvcCDA.EXE
 C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
 C:\Program Files\Norton AntiVirus\navapsvc.exe
 C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
 C:\WINDOWS\System32\nvsvc32.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\System32\wuauclt.exe
 C:\WINDOWS\System32\devldr32.exe
 C:\Program Files\FarStone\RestoreIT!\RestoreIT!_XP\VBPTASK.EXE
 C:\Juzzi\DTools\daemon.exe
 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
 C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
 C:\WINDOWS\System32\ctfmon.exe
 C:\Juzzi\Hyödyllistä\GCS\GrabClipSave.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\WINDOWS\System32\wuauclt.exe
 C:\Juzzi\Hyödyllistä\HijackThis\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soneraplaza.fi R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.google.fi/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Sonera Plaza Oy
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
 O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_11_0.dll
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
 O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_11_0.dll
 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
 O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
 O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
 O4 - HKLM\..\Run: [RestoreIT!] "C:\Program Files\FarStone\RestoreIT!\RestoreIT!_XP\VBPTASK.EXE" VBStart
 O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Juzzi\DTools\daemon.exe"  -lang 1033
 O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
 O4 - HKLM\..\Run: [SmcService] C:\Juzzi\HYDYLL~1\SPF\smc.exe -startgui
 O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
 O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
 O4 - HKCU\..\Run: [GCS] "C:\Juzzi\Hyödyllistä\GCS\GrabClipSave.exe"
 O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
 O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
 O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi O16 - DPF: {5BDBD95C-1E7F-4FB1-8497-20AF879F8B68} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSha... O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl... O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/... O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
 O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
 O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
 O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
 O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
 O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Juzzi\Hyödyllistä\SPF\smc.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 
 ja jooh kiitos, kone kehrää ku kissa verrattuna niihin pahimpiin hetkiin.
 Btw, vaikuttaako levyn eheytys jotenki merkittävästi koneen toimintaan? vaatii 15% tyhjää tilaa toimiakseen kunnolla jota tällä hetkellä ei ole tarjolla, mut jos se ei ole kauheen välttämätön en yritä järkätä ylimäärästä tilaa sille. ^^ 
							
						 
						
						
 ^^;; 
						
						 | 
					
				
				
			
				
				
				
					
						| 
							 Mainos 
							 
						 | 
						   | 
					
					
						
							
							  
								
							
						 | 
					
				
				
				
					
						| 
							
								 Toymaatti 
							
							
								Senior Member
								
									
								
							
							 
							 
						 | 
						1. lokakuuta 2005 @ 09:06 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						
						
						
						
						
 Se parhaiten nauraa joka toiselle kuoppaa kaivaa. 
						
						 |