afterdawn.com  > keskustelu  > yleistä keskustelua tietokoneista  > virukset ja haittaohjelmat  > hjt-logi - katsoisiko joku?  
											 
											
												
	 
											
											
						 				 	
	
		
		
			
		
		
	 
												  
												
													
	
		
			Keskustelualueet
			Keskustelualueet
		 
		
			
				
					
						
			
			
		
					
				
			 
		
	 
														
															
															
	
			
			
				
					HJT-logi - katsoisiko joku?
				 
				
				
					
				 
				
			 
			
			
			
				
					
					
				 
			
			
			
			
			
				
				
					
				
				
				
				
					
						
							
								Tommoona
							
							
								
									Suspended due to non-functional email address
								
							
							 
							 
						 
						21. lokakuuta 2005 @ 17:16  
						 
							
								Linkki tähän viestiin 
								  
								 
								  
							
							 
						 
					 
					
					
					
						
						
						
							
							Tuossapa olisi logi, löytyykö mitään "ikävää"?
 
 
 Logfile of HijackThis v1.99.1
 Scan saved at 21:11:12, on 21.10.2005
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 C:\Program Files\Arcade\PCMService.exe
 C:\WINDOWS\system32\rundll32.exe
 C:\WINDOWS\system32\igfxtray.exe
 C:\WINDOWS\system32\hkcmd.exe
 C:\acer\epm\epm-dm.exe
 C:\Program Files\eDonkey2000\edonkey2000.exe
 C:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe
 C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe
 C:\WINDOWS\system32\LVCOMSX.EXE
 C:\Program Files\Logitech\Video\LogiTray.exe
 C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
 D:\secure\Common\FSM32.EXE
 C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
 C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
 C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
 D:\Phone\Skype.exe
 C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
 C:\Program Files\Logitech\Video\FxSvr2.exe
 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
 C:\Acer\eManager\anbmServ.exe
 C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
 D:\secure\backweb\4436233\Program\SERVIC~1.EXE
 D:\secure\backweb\4436233\Program\fspex.exe
 D:\secure\Anti-Virus\fsgk32st.exe
 D:\secure\Anti-Virus\FSGK32.EXE
 D:\secure\backweb\4436233\program\fsbwsys.exe
 D:\secure\Common\FSMA32.EXE
 D:\secure\Anti-Virus\fssm32.exe
 D:\secure\Common\FSMB32.EXE
 C:\WINDOWS\system32\svchost.exe
 D:\secure\Common\FCH32.EXE
 D:\secure\Common\FAMEH32.EXE
 D:\secure\Anti-Virus\fsav32.exe
 D:\secure\FWES\Program\fsdfwd.exe
 D:\secure\FSGUI\fsguiexe.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\WinRAR\WinRAR.exe
 C:\WINDOWS\system32\NOTEPAD.EXE
 C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
 C:\hjt\HijackThis.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://haku.soneraplaza.fi/haku/queryie5.jsp  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.webalta.com/?p1=313&p2=0&p3=787940133dd4028d26991f5196...  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soneraplaza.fi  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Sonera Internet
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi;<local>
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
 R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\4.bin\MWSSRCAS.DLL
 O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\4.bin\MWSSRCAS.DLL
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
 O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\4.bin\MWSBAR.DLL
 O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
 O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
 O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
 O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
 O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
 O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
 O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
 O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
 O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
 O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
 O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
 O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
 O4 - HKLM\..\Run: [eDonkey2000] "C:\Program Files\eDonkey2000\edonkey2000.exe" -t
 O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray
 O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
 O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay
 O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
 O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe 
 O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
 O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
 O4 - HKLM\..\Run: [F-Secure Manager] "D:\secure\Common\FSM32.EXE" /splash
 O4 - HKLM\..\Run: [F-Secure TNB] "D:\secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
 O4 - HKLM\..\Run: [News Service] "D:\secure\FSGUI\ispnews.exe"
 O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
 O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
 O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe
 O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
 O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
 O4 - HKCU\..\Run: [Skype] "D:\Phone\Skype.exe" /nosplash /minimized
 O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\4.bin\MWSOEMON.EXE
 O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\4.bin\MWSOEMON.EXE
 O4 - Global Startup: Microsoft Office.lnk = D:\Office10\OSA.EXE
 O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
 O4 - Global Startup: HP Image Zone -pikakäynnistys.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
 O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZR  O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
 O8 - Extra context menu item: Vie Microsoft E&xceliin - res://D:\Office10\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
 O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi  O18 - Protocol: bt2 - {1730B77B-F429-498F-9B15-4514D83C8294} - D:\BT2Net\BT2PLU~1.DLL (file missing)
 O18 - Filter: application/x-bt2 - {6E1DDCE8-76BC-4390-9488-806E8FB1AD77} - D:\BT2Net\BT2PLU~1.DLL
 O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
 O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
 O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: Sonera Tietoturva (BackWeb Plug-in - 4436233) - Unknown owner - D:\secure\backweb\4436233\Program\SERVIC~1.EXE
 O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - D:\secure\Anti-Virus\fsgk32st.exe
 O23 - Service: fsbwsys - F-Secure Corp. - D:\secure\backweb\4436233\program\fsbwsys.exe
 O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - D:\secure\FWES\Program\fsdfwd.exe
 O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - D:\secure\Common\FSMA32.EXE
 O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe 
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								Zipp2
							
							
								Member
								
									
								
							
							 
							 
						 
						21. lokakuuta 2005 @ 17:40  
						 
							
								Linkki tähän viestiin 
								  
								 
								  
							
							 
						 
					 
					
					
					
						
						
						
							
							Poista Lisää/Poista paneelista jos näkyy
 
 MyWebSearch
 
 Merkkaa nuo sulje selain ja paina Fix checked
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.webalta.com/?p1=313&p2=0&p3=787940133dd4028d26991f5196...  R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file) 
 R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\4.bin\MWSSRCAS.DLL 
 O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\4.bin\MWSSRCAS.DLL 
 O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\4.bin\MWSBAR.DLL 
 O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
 O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe 
 O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe 
 O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\4.bin\MWSOEMON.EXE 
 O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\4.bin\MWSOEMON.EXE 
 O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZR  
 
 Käynnistä sitte vikasietotilassa ja poista jos löytyy
 
 C:\Program Files\MyWebSearch\ < kansio
 
 Käynnistä normaalisti ja uus logi. 
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Senior Member
								
									  1 tuotearvio 
								
							
							 
							 
						 
						21. lokakuuta 2005 @ 17:49  
						 
							
								Linkki tähän viestiin 
								  
								 
								  
							
							 
						 
					 
					
					
					
						
						
						
							
							Onhan toss ikävää 8(
 
 Lisää/poista -sovellus kohdasta: My Web Search, eDonkey2000 joku tollanen :P, New.net, Wintools ja Webhancer (jos on).
 
 Sitten fixaukseen: 
 
 R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file) 
 
 R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\4.bin\MWSSRCAS.DLL 
 
 O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\4.bin\MWSSRCAS.DLL
 
 O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\4.bin\MWSBAR.DLL 
 
 O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
 
 O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe
 
 O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
 
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot 
 
 O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
 
 O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe
 
 O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\4.bin\MWSOEMON.EXE
 
 O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\4.bin\MWSOEMON.EXE
 
 O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZR  
 Sitten vikasietotilaan (F8 käynnistyksen yhteydessä)
 
 Poistat seuraavat:
 
 C:\Program Files\eDonkey2000 <- kansio (Ota waret talteen. Asensi  New.Net, Webhancer, WebSearch Toolbar, ja WinTools:n)
 
 C:\Program Files\MyWebSearch <- kansio (Spywaree, laittaa toolbarin 
 
 
							
						 
						
						 
						
							Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 21. lokakuuta 2005 @ 17:51 
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								Tommoona
							
							
								
									Suspended due to non-functional email address
								
							
							 
							 
						 
						22. lokakuuta 2005 @ 11:10  
						 
							
								Linkki tähän viestiin 
								  
								 
								  
							
							 
						 
					 
					
					
					
						
						
						
							
							Uusi logi. Vieläkö löytyy ikäviä yllätyksiä?
 
 Logfile of HijackThis v1.99.1
 Scan saved at 22:56:46, on 21.10.2005
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 C:\Program Files\Arcade\PCMService.exe
 C:\WINDOWS\system32\rundll32.exe
 C:\WINDOWS\system32\igfxtray.exe
 C:\WINDOWS\system32\hkcmd.exe
 C:\acer\epm\epm-dm.exe
 C:\Program Files\eDonkey2000\edonkey2000.exe
 C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe
 C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
 C:\WINDOWS\system32\LVCOMSX.EXE
 C:\Program Files\Logitech\Video\LogiTray.exe
 C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
 D:\secure\Common\FSM32.EXE
 C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
 C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\MSN Messenger\MsnMsgr.Exe
 C:\Program Files\Logitech\Video\FxSvr2.exe
 C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
 D:\Phone\Skype.exe
 C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
 C:\Acer\eManager\anbmServ.exe
 C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
 D:\secure\backweb\4436233\Program\SERVIC~1.EXE
 D:\secure\backweb\4436233\Program\fspex.exe
 D:\secure\Anti-Virus\fsgk32st.exe
 D:\secure\Anti-Virus\FSGK32.EXE
 D:\secure\backweb\4436233\program\fsbwsys.exe
 D:\secure\Common\FSMA32.EXE
 D:\secure\Common\FSMB32.EXE
 D:\secure\Anti-Virus\fssm32.exe
 C:\WINDOWS\system32\svchost.exe
 D:\secure\Common\FCH32.EXE
 D:\secure\Common\FAMEH32.EXE
 C:\WINDOWS\system32\HPZipm12.exe
 D:\secure\FWES\Program\fsdfwd.exe
 D:\secure\Anti-Virus\fsav32.exe
 D:\secure\FSGUI\fsguiexe.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Program Files\Real\RealPlayer\RealPlay.exe
 C:\hjt\HijackThis.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://haku.soneraplaza.fi/haku/queryie5.jsp  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soneraplaza.fi  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Sonera Internet
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi;<local>
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
 O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
 O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
 O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
 O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
 O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
 O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
 O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
 O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
 O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
 O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
 O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
 O4 - HKLM\..\Run: [eDonkey2000] "C:\Program Files\eDonkey2000\edonkey2000.exe" -t
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray
 O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
 O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay
 O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
 O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe 
 O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
 O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
 O4 - HKLM\..\Run: [F-Secure Manager] "D:\secure\Common\FSM32.EXE" /splash
 O4 - HKLM\..\Run: [F-Secure TNB] "D:\secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
 O4 - HKLM\..\Run: [News Service] "D:\secure\FSGUI\ispnews.exe"
 O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
 O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
 O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
 O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
 O4 - HKCU\..\Run: [Skype] "D:\Phone\Skype.exe" /nosplash /minimized
 O4 - Global Startup: Microsoft Office.lnk = D:\Office10\OSA.EXE
 O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
 O4 - Global Startup: HP Image Zone -pikakäynnistys.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
 O8 - Extra context menu item: Vie Microsoft E&xceliin - res://D:\Office10\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
 O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi  O18 - Protocol: bt2 - {1730B77B-F429-498F-9B15-4514D83C8294} - D:\BT2Net\BT2PLU~1.DLL (file missing)
 O18 - Filter: application/x-bt2 - {6E1DDCE8-76BC-4390-9488-806E8FB1AD77} - D:\BT2Net\BT2PLU~1.DLL
 O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
 O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
 O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: Sonera Tietoturva (BackWeb Plug-in - 4436233) - Unknown owner - D:\secure\backweb\4436233\Program\SERVIC~1.EXE
 O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - D:\secure\Anti-Virus\fsgk32st.exe
 O23 - Service: fsbwsys - F-Secure Corp. - D:\secure\backweb\4436233\program\fsbwsys.exe
 O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - D:\secure\FWES\Program\fsdfwd.exe
 O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - D:\secure\Common\FSMA32.EXE
 O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe 
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 
						22. lokakuuta 2005 @ 11:17  
						 
							
								Linkki tähän viestiin 
								  
								 
								  
							
							 
						 
					 
					
					
					
						
						
						
							
							Hyvä on. Käynnistyviä ohjelmia voi karsia, jos haluaa, eli esim. fixata nämä:
 
 O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 
 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
 O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName 
 O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe 
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
 O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k 
 O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot 
 
 Mutta siis ei tarvitse :) 
							
						
						
						
						
						 
					 
				
				
			
				
				
				
					
						
							Mainos
							 
						 
						 
					 
					
						
							
							  
								
							
						 
					 
				
				
				
					
						
							
								Tommoona
							
							
								
									Suspended due to non-functional email address
								
							
							 
							 
						 
						22. lokakuuta 2005 @ 11:39  
						 
							
								Linkki tähän viestiin 
								  
								 
								  
							
							 
						 
					 
					
					
					
						
						
						
							
							Jep. Enoni kiittää ja korjaa vielä nuo. 
							
						
						
						
						
						 
					 
				
				
			
			
			
			
			
		
		
	
			
			
		
	 
 
					
						
							afterdawn.com  > keskustelu  > yleistä keskustelua tietokoneista  > virukset ja haittaohjelmat  > hjt-logi - katsoisiko joku?