| 
		
		
			
		
		
	 | 
												  
												
													
	
		| 
			 Keskustelualueet 
			Keskustelualueet 
		 | 
		
			
				
					
						
			
			
		
					
				
			 | 
		
	 
 
														
															
															
	
			
			
				| 
					Pop-uppeja pukkaa!
				 | 
				
				
					
				 | 
				
			 
			
			
			
				
					
					
				 
			
			
			
			
			
				
				
					
				
				
				
				
					
						
							
								
							
							
								Junior Member
								
									
   4 tuotearviota
								
							
							 
							 
						 | 
						24. lokakuuta 2005 @ 15:05 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					 
					
					
					
						
						
						
							
							Juu eli sellanen ongelma, et parin minuutin välein aukeaa firefox itestään tällasille sivuille:
 
 http://www.mega-savings.com/normal/yyy34.html http://www.coupon-online.com/normal/yyy34.html http://www.discount-home.com/normal/yyy34.html http://www.savings-card.com/normal/yyy34.html http://www.searc-h.com/normal/yyy34.html http://www.mega-savings.com/normal/yyy34.html http://www.deal-mobile.com/normal/yyy34.html http://www.your-deal.com/normal/yyy34.html 
 Oon ajellu läpi kaikenmaailman ad-awaret, spywareblasterpopit jne...ja poistellu turhat tiedostot ja virustarkistus ei valita mitään. Mitäköhän tässä pitäis tehä? 
 
 Tässä on vielä HJT-logi et jos siitä löytyis jotain
 
 Logfile of HijackThis v1.99.1
 Scan saved at 19:04:53, on 24.10.2005
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\rundll32.exe
 C:\WINDOWS\system32\LEXBCES.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\system32\LEXPPS.EXE
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
 C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
 C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
 C:\WINDOWS\system32\PROMon.exe
 C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
 C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 C:\Program Files\AVPersonal\AVGNT.EXE
 C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
 C:\Program Files\D-Tools\daemon.exe
 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\MSN Messenger\MsnMsgr.Exe
 C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
 C:\Program Files\WinZip\WZQKPICK.EXE
 C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE
 C:\Program Files\AVPersonal\AVWUPSRV.EXE
 C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
 C:\Program Files\Compaq\Easy Access Button Support\CPQEAKSYSTEMTRAY.EXE
 C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
 C:\Compaq\EAKDRV\EAUSBKBD.EXE
 C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
 C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
 C:\WINDOWS\System32\NMSSvc.exe
 C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
 C:\WINDOWS\system32\UAService7.exe
 C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
 C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\HJT\HijackThis.exe
 
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://desktop.presario.net/scripts/redirectors/presario/deskredi... R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.presario.net/scripts/redirectors/presario/srchredir... R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.presario.net/scripts/redirectors/presario/srchredir... R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://desktop.presario.net/scripts/redirectors/presario/deskredi... R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
 O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
 O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
 O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
 O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe
 O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
 O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
 O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
 O4 - HKLM\..\Run: [ChkAdmin] C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
 O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
 O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
 O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
 O4 - Global Startup: Microsoft Works Kalenterin muistutukset.lnk = ?
 O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl... O20 - Winlogon Notify: IPConfTSP - C:\WINDOWS\system32\j0j60a1sed.dll
 O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
 O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
 O23 - Service: Compaq Local Alerter (CPQALERT) - Compaq Computer Corporation - C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
 O23 - Service: cpqdmi - Compaq Computer Corporation - C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
 O23 - Service: Compaq DMI Web Agent (cpqWebDmi) - Compaq Computer Corporation - C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
 O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
 O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
 O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
 O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
 O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 O23 - Service: Win32Sl (WIN32SL) - Intel - C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe 
							
						 
						
						
 Moi 
						
						 | 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						24. lokakuuta 2005 @ 15:49 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					 
					
					
					
						
						
						
							
							Hae täältä -> http://www.atribune.org/downloads/l2mfix.exe l2mfix ja tallenna työpöydälle. Tuplaklikkaa sitä ja klikkaa install. Avaa l2mfix -kansio työpöydältä ja tuplaklikkaa l2mfix.bat ja valitse #1 painamalla 1 ja enter(ÄLÄ tee vielä mitään muuta!!). Kopioi se loki ja lähetä tänne.
							
						 
						
						
						
						 | 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Junior Member
								
									
   4 tuotearviota
								
							
							 
							 
						 | 
						24. lokakuuta 2005 @ 16:04 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					 
					
					
					
						
						
						
							
							L2MFIX find log 1.04a
 These are the registry keys present
 **********************************************************************************
 Winlogon/notify:
 Windows Registry Editor Version 5.00
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
 "DLLName"="Ati2evxx.dll"
 "Asynchronous"=dword:00000000
 "Impersonate"=dword:00000001
 "Lock"="AtiLockEvent"
 "Logoff"="AtiLogoffEvent"
 "Logon"="AtiLogonEvent"
 "Disconnect"="AtiDisConnectEvent"
 "Reconnect"="AtiReConnectEvent"
 "Safe"=dword:00000000
 "Shutdown"="AtiShutdownEvent"
 "StartScreenSaver"="AtiStartScreenSaverEvent"
 "StartShell"="AtiStartShellEvent"
 "Startup"="AtiStartupEvent"
 "StopScreenSaver"="AtiStopScreenSaverEvent"
 "Unlock"="AtiUnLockEvent"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
 "Asynchronous"=dword:00000000
 "Impersonate"=dword:00000000
 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
   6c,00,00,00
 "Logoff"="ChainWlxLogoffEvent"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
 "Asynchronous"=dword:00000000
 "Impersonate"=dword:00000000
 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
   6c,00,6c,00,00,00
 "Logoff"="CryptnetWlxLogoffEvent"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
 "DLLName"="cscdll.dll"
 "Logon"="WinlogonLogonEvent"
 "Logoff"="WinlogonLogoffEvent"
 "ScreenSaver"="WinlogonScreenSaverEvent"
 "Startup"="WinlogonStartupEvent"
 "Shutdown"="WinlogonShutdownEvent"
 "StartShell"="WinlogonStartShellEvent"
 "Impersonate"=dword:00000000
 "Asynchronous"=dword:00000001
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
 "DLLName"="wlnotify.dll"
 "Logon"="SCardStartCertProp"
 "Logoff"="SCardStopCertProp"
 "Lock"="SCardSuspendCertProp"
 "Unlock"="SCardResumeCertProp"
 "Enabled"=dword:00000001
 "Impersonate"=dword:00000001
 "Asynchronous"=dword:00000001
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
 "Asynchronous"=dword:00000000
 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
   6c,00,6c,00,00,00
 "Impersonate"=dword:00000000
 "StartShell"="SchedStartShell"
 "Logoff"="SchedEventLogOff"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
 "Logoff"="WLEventLogoff"
 "Impersonate"=dword:00000000
 "Asynchronous"=dword:00000001
 "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
   6c,00,6c,00,00,00
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
 "DLLName"="WlNotify.dll"
 "Lock"="SensLockEvent"
 "Logon"="SensLogonEvent"
 "Logoff"="SensLogoffEvent"
 "Safe"=dword:00000001
 "MaxWait"=dword:00000258
 "StartScreenSaver"="SensStartScreenSaverEvent"
 "StopScreenSaver"="SensStopScreenSaverEvent"
 "Startup"="SensStartupEvent"
 "Shutdown"="SensShutdownEvent"
 "StartShell"="SensStartShellEvent"
 "PostShell"="SensPostShellEvent"
 "Disconnect"="SensDisconnectEvent"
 "Reconnect"="SensReconnectEvent"
 "Unlock"="SensUnlockEvent"
 "Impersonate"=dword:00000001
 "Asynchronous"=dword:00000001
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
 "Asynchronous"=dword:00000000
 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
   6c,00,6c,00,00,00
 "Impersonate"=dword:00000000
 "Logoff"="TSEventLogoff"
 "Logon"="TSEventLogon"
 "PostShell"="TSEventPostShell"
 "Shutdown"="TSEventShutdown"
 "StartShell"="TSEventStartShell"
 "Startup"="TSEventStartup"
 "MaxWait"=dword:00000258
 "Reconnect"="TSEventReconnect"
 "Disconnect"="TSEventDisconnect"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WindowsUpdate]
 "Asynchronous"=dword:00000000
 "DllName"="C:\\WINDOWS\\system32\\gpjol3131.dll"
 "Impersonate"=dword:00000000
 "Logon"="WinLogon"
 "Logoff"="WinLogoff"
 "Shutdown"="WinShutdown"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
 "DLLName"="wlnotify.dll"
 "Logon"="RegisterTicketExpiredNotificationEvent"
 "Logoff"="UnregisterTicketExpiredNotificationEvent"
 "Impersonate"=dword:00000001
 "Asynchronous"=dword:00000001
 
 
 RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
 Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
 This program is Freeware, use it on your own risk!
 
 Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
 (NI)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (IO)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (NI)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (IO)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-NI) ALLOW  Read        	BUILTIN\K?ytt?j?t
 (ID-IO) ALLOW  Read        	BUILTIN\K?ytt?j?t
 (ID-NI) ALLOW  Full access 	BUILTIN\J?rjestelm?nvalvojat
 (ID-IO) ALLOW  Full access 	BUILTIN\J?rjestelm?nvalvojat
 (ID-NI) ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-IO) ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-IO) ALLOW  Full access 	LUOJA-OMISTAJA
 
 
 **********************************************************************************
 useragent:
 Windows Registry Editor Version 5.00
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
 "{9DF4FDF3-81BB-1662-19BA-5465F2851774}"=""
 
 **********************************************************************************
 Shell Extension key:
 Windows Registry Editor Version 5.00
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
 "{00022613-0000-0000-C000-000000000046}"="Multimediatiedoston ominaisuusikkuna"
 "{176d6597-26d3-11d1-b350-080036a75b03}"="ICM-kuvanlukijan hallinta"
 "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS-suojaussivu"
 "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE-asiakirjatiedoston ominaisuussivu"
 "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Liittym?laajennus jakamista varten"
 "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
 "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="N?ytt?sovittimen CPL-laajennus"
 "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL -laajennus"
 "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL -laajennus"
 "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Hakemistopalvelun suojaussivu"
 "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Yhteensopivuussivusto"
 "{56117100-C0CD-101B-81E2-00AA004AE837}"="K?ytt?liittym?n leikkeidenk?sittelytoiminto"
 "{59099400-57FF-11CE-BD94-0020AF85B590}"="Levykkeen kopiointilaajennus"
 "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Microsoft Windows -verkon objektien liittym?laajennukset"
 "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM-n?yt?n hallinta"
 "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM-tulostimen hallinta"
 "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Tiedostonpakkauksen liittym?laajennukset"
 "{77597368-7b15-11d0-a0c2-080036af3f03}"="Web-tulostimen liittym?laajennus"
 "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
 "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Salauksen pikavalikko"
 "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Salkku"
 "{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal-kuvakkeen tunniste"
 "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
 "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC-profiili"
 "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Tulostimen suojaussivu"
 "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Liittym?laajennus jakamista varten"
 "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
 "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO -laajennus"
 "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign -laajennus"
 "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Verkkoyhteydet"
 "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Verkkoyhteydet"
 "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Skannerit ja kamerat"
 "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Skannerit ja kamerat"
 "{905667aa-acd6-11d2-8080-00805f6596d2}"="Skannerit ja kamerat"
 "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Skannerit ja kamerat"
 "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Skannerit ja kamerat"
 "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
 "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
 "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Windows Script Hostin liittym?laajennukset"
 "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft-tietolinkki"
 "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
 "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
 "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Ajoitetut teht?v?t"
 "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Teht?v?palkki ja K?ynnist?-valikko"
 "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Etsi"
 "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Ohje ja tuki"
 "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Ohje ja tuki"
 "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Suorita..."
 "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
 "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="S?hk?posti"
 "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fontit"
 "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Valvontaty?kalut"
 "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
 "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
 "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
 "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
 "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
 "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
 "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet-ty?kalurivi"
 "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Lataamisen tila"
 "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
 "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
 "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
 "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
 "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Etsint?palkki"
 "{32683183-48a0-441b-a342-7c2a440a9478}"="Media-palkki"
 "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
 "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
 "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
 "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&L?hiosoite"
 "{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
 "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
 "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
 "{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
 "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
 "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
 "{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
 "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Osoitepalkin j?sent?j?"
 "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
 "{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
 "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
 "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
 "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
 "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
 "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
 "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
 "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
 "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
 "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
 "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
 "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
 "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
 "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
 "{FF393560-C2A7-11CF-BFF4-444553540000}"="Sivuhistoria"
 "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
 "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
 "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
 "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
 "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
 "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
 "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
 "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
 "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
 "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
 "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
 "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
 "{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX-v?limuistikansio"
 "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
 "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
 "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
 "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
 "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
 "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
 "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
 "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
 "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
 "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
 "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="K?ytt?liittym?n sovelluksenhallintaohjelma"
 "{0B124F8F-91F0-11D1-B8B5-006008059382}"="Sovellusluettelo asennettiin"
 "{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
 "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
 "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
 "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ -tiedoston pikkukuvan purkaja"
 "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Yhteenvetotiedot pikkukuvien k?sittelyst? (DOCFILES)"
 "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML-pikkukuvien purkuohjelma"
 "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
 "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Ohjattu Web-julkaisutoiminto"
 "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Valokuvien paperikopioiden tilaaminen Internetist?"
 "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
 "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Ohjattu Passport toiminto"
 "{7A9D77BD-5403-11d2-8785-2E0420524153}"="K?ytt?j?tilit"
 "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
 "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
 "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Kanavatiedosto"
 "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Kanavan pikakuvake"
 "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Kanavienk?sittelyobjekti"
 "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
 "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
 "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
 "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
 "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
 "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
 "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
 "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
 "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
 "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
 "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
 "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
 "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
 "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
 "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
 "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
 "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
 "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
 "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
 "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
 "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline-tiedostot-kansio"
 "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
 "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
 "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
 "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
 "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
 "{32714800-2E5F-11d0-8B85-00AA0044F941}"="&Henkil?it?..."
 "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
 "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
 "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
 "{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders"
 "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
 "{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
 "{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
 "{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
 "{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
 "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
 "{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
 "{E0D79304-84BE-11CE-9641-444553540000}"="WinZip"
 "{E0D79305-84BE-11CE-9641-444553540000}"="WinZip"
 "{E0D79306-84BE-11CE-9641-444553540000}"="WinZip"
 "{E0D79307-84BE-11CE-9641-444553540000}"="WinZip"
 "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
 "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
 "{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
 "{CA6C600E-C7AB-4876-9D2A-97B202B2C2A7}"=""
 "{3E7BED48-C8CA-4E71-AF84-8D2C12A844CA}"=""
 "{F13E16D3-E8BD-461C-97DF-CDB3EF4611D2}"=""
 
 **********************************************************************************
 HKEY ROOT CLASSIDS:
 Windows Registry Editor Version 5.00
 
 [HKEY_CLASSES_ROOT\CLSID\{3E7BED48-C8CA-4E71-AF84-8D2C12A844CA}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{3E7BED48-C8CA-4E71-AF84-8D2C12A844CA}\Implemented Categories]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{3E7BED48-C8CA-4E71-AF84-8D2C12A844CA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{3E7BED48-C8CA-4E71-AF84-8D2C12A844CA}\InprocServer32]
 @="C:\\WINDOWS\\system32\\guard.tmp"
 "ThreadingModel"="Apartment"
 
 Windows Registry Editor Version 5.00
 
 [HKEY_CLASSES_ROOT\CLSID\{F13E16D3-E8BD-461C-97DF-CDB3EF4611D2}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{F13E16D3-E8BD-461C-97DF-CDB3EF4611D2}\Implemented Categories]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{F13E16D3-E8BD-461C-97DF-CDB3EF4611D2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{F13E16D3-E8BD-461C-97DF-CDB3EF4611D2}\InprocServer32]
 @="C:\\WINDOWS\\system32\\mnc42u.dll"
 "ThreadingModel"="Apartment"
 
 **********************************************************************************
 Files Found are not all bad files:
 
 C:\WINDOWS\SYSTEM32\
    ati2cqag.dll   Wed 31 Aug 2005   4.42.50   A....        233 472   228,00 K
    ati2dvag.dll   Wed 31 Aug 2005   5.42.54   A....        238 592   233,00 K
    ati2edxx.dll   Wed 31 Aug 2005   5.37.22   A....         39 936    39,00 K
    ati2evxx.dll   Wed 31 Aug 2005   5.37.12   A....         46 080    45,00 K
    ati3duag.dll   Wed 31 Aug 2005   5.28.36   A....      2 429 824     2,32 M
    atiddc.dll     Wed 31 Aug 2005   4.35.46   A....         53 248    52,00 K
    atidemgr.dll   Wed 31 Aug 2005   6.33.32   A....        258 048   252,00 K
    atiiiexx.dll   Wed 31 Aug 2005   7.08.36   A....        307 200   300,00 K
    atikvmag.dll   Wed 31 Aug 2005   5.10.36   A....        147 456   144,00 K
    atioglx1.dll   Wed 31 Aug 2005   5.57.50   A....      6 684 672     6,38 M
    atioglxx.dll   Wed 31 Aug 2005   4.57.00   A....      4 718 592     4,50 M
    atipdlxx.dll   Wed 31 Aug 2005   4.37.44   A....        106 496   104,00 K
    atitvo32.dll   Wed 31 Aug 2005   3.47.46   A....         17 408    17,00 K
    ativvaxx.dll   Wed 31 Aug 2005   5.23.04   A....        600 672   586,59 K
    browseui.dll   Sat  3 Sep 2005   3.05.16   A....      1 019 904   996,00 K
    catsrv.dll     Tue 26 Jul 2005   7.40.30   A....        225 792   220,50 K
    catsrvut.dll   Tue 26 Jul 2005   7.40.30   A....        625 152   610,50 K
    cdfview.dll    Sat  3 Sep 2005   3.05.16   A....        151 552   148,00 K
    cdosys.dll     Sat 10 Sep 2005   4.55.12   A....      2 067 968     1,97 M
    clbcatex.dll   Tue 26 Jul 2005   7.40.30   A....        110 080   107,50 K
    clbcatq.dll    Tue 26 Jul 2005   7.40.30   A....        498 688   487,00 K
    cmdlin~1.dll   Sat 22 Oct 2005  21.15.10   A....         43 520    42,50 K
    cmdlin~2.dll   Sun 23 Oct 2005   8.32.22   A....         90 112    88,00 K
    colbact.dll    Tue 26 Jul 2005   7.40.30   A....         60 416    59,00 K
    comrepl.dll    Tue 26 Jul 2005   7.40.30   A....         97 792    95,50 K
    comsvcs.dll    Tue 26 Jul 2005   7.40.30   A....      1 267 200     1,21 M
    comuid.dll     Tue 26 Jul 2005   7.40.30   A....        540 160   527,50 K
    danim.dll      Sat  3 Sep 2005   3.05.18   A....      1 054 720     1,00 M
    dxtrans.dll    Sat  3 Sep 2005   3.05.18   A....        205 312   200,50 K
    es.dll         Tue 26 Jul 2005   7.40.30   A....        243 200   237,50 K
    extmgr.dll     Sat  3 Sep 2005   3.05.18   .....         55 808    54,50 K
    gpj8l3~1.dll   Mon 24 Oct 2005  19.57.06   ..S.R        234 154   228,66 K
    gpjol3~1.dll   Mon 24 Oct 2005  19.45.26   ..S.R        236 258   230,72 K
    iepeers.dll    Sat  3 Sep 2005   3.05.18   A....        250 880   245,00 K
    inseng.dll     Sat  3 Sep 2005   3.05.18   A....         96 256    94,00 K
    legitc~1.dll   Mon 29 Aug 2005  13.27.12   A....        520 968   508,76 K
    linkinfo.dll   Thu  1 Sep 2005   4.43.22   A....         19 968    19,50 K
    mnc42u.dll     Mon 24 Oct 2005  18.15.12   ..S.R        236 258   230,72 K
    msdtcprx.dll   Tue 26 Jul 2005   7.40.30   A....        425 472   415,50 K
    msdtctm.dll    Tue 26 Jul 2005   7.40.32   A....        945 152   923,00 K
    msdtcuiu.dll   Tue 26 Jul 2005   7.40.32   A....        161 280   157,50 K
    mshtml.dll     Wed  5 Oct 2005   3.26.04   A....      3 013 120     2,87 M
    mshtmled.dll   Sat  3 Sep 2005   3.05.18   A....        448 512   438,00 K
    msrating.dll   Sat  3 Sep 2005   3.05.18   A....        146 432   143,00 K
    msssc.dll      Sat  8 Oct 2005  14.36.32   A....             44     0,04 K
    mstime.dll     Sat  3 Sep 2005   3.05.18   A....        530 432   518,00 K
    mtxclu.dll     Tue 26 Jul 2005   7.40.32   A....         66 560    65,00 K
    mtxoci.dll     Tue 26 Jul 2005   7.40.32   A....         91 136    89,00 K
    netman.dll     Mon 22 Aug 2005  21.35.16   A....        197 632   193,00 K
    oemdspif.dll   Wed 31 Aug 2005   4.37.34   A....         73 728    72,00 K
    ole32.dll      Tue 26 Jul 2005   7.40.34   A....      1 284 608     1,22 M
    olecli32.dll   Tue 26 Jul 2005   7.40.34   A....         74 752    73,00 K
    olecnv32.dll   Tue 26 Jul 2005   7.40.34   A....         37 888    37,00 K
    pncrt.dll      Thu 20 Oct 2005  22.45.12   A....        278 528   272,00 K
    pndx5016.dll   Thu 20 Oct 2005  22.45.14   A....          6 656     6,50 K
    pndx5032.dll   Thu 20 Oct 2005  22.45.14   A....          5 632     5,50 K
    pngfilt.dll    Sat  3 Sep 2005   3.05.18   A....         39 424    38,50 K
    quartz.dll     Tue 30 Aug 2005   6.55.44   A....      1 287 680     1,23 M
    rmoc3260.dll   Thu 20 Oct 2005  22.45.26   A....        176 167   172,04 K
    rpcss.dll      Tue 26 Jul 2005   7.40.34   A....        397 824   388,50 K
    shdocvw.dll    Sat  3 Sep 2005   3.05.18   A....      1 483 264     1,41 M
    shell32.dll    Fri 23 Sep 2005   6.07.16   A....      8 454 656     8,06 M
    shlwapi.dll    Sat  3 Sep 2005   3.05.18   A....        473 600   462,50 K
    sirenacm.dll   Mon 19 Sep 2005   7.00.34   A....        119 856   117,05 K
    txflog.dll     Tue 26 Jul 2005   7.40.34   A....        101 376    99,00 K
    umpnpmgr.dll   Tue 23 Aug 2005   6.39.36   A....        123 904   121,00 K
    urlmon.dll     Sat  3 Sep 2005   3.05.18   A....        604 160   590,00 K
    vsdata.dll     Mon 29 Aug 2005  19.08.34   A....         83 712    81,75 K
    vsinit.dll     Mon 29 Aug 2005  19.08.46   A....        141 056   137,75 K
    vsmonapi.dll   Mon 29 Aug 2005  19.08.54   A....        104 192   101,75 K
    vspubapi.dll   Mon 29 Aug 2005  19.08.58   A....        227 072   221,75 K
    vsregexp.dll   Mon 29 Aug 2005  19.09.02   A....         71 424    69,75 K
    vsutil.dll     Mon 29 Aug 2005  19.09.14   A....        382 720   373,75 K
    vsxml.dll      Mon 29 Aug 2005  19.09.22   A....        100 096    97,75 K
    wininet.dll    Sat  3 Sep 2005   3.05.18   A....        658 432   643,00 K
    winsrv.dll     Thu  1 Sep 2005   4.43.22   A....        291 840   285,00 K
    xolehlp.dll    Tue 26 Jul 2005   7.40.34   A....         11 776    11,50 K
    zlcomm.dll     Mon 29 Aug 2005  19.09.42   A....         79 616    77,75 K
    zlcommdb.dll   Mon 29 Aug 2005  19.09.46   A....         71 424    69,75 K
 
 79 items found:  79 files (3 H/S), 0 directories.
    Total of file sizes:  49 106 649 bytes     46,83 M
 Locate .tmp files:
 
 C:\WINDOWS\SYSTEM32\
    __dele~1.tmp   Mon 24 Oct 2005  19.58.08   A....        236 258   230,72 K
 
 1 item found:  1 file, 0 directories.
    Total of file sizes:  236 258 bytes    230,72 K
 **********************************************************************************
 Directory Listing of system files:
  Asemalla C ei ole nime?.
  Aseman sarjanumero on 0C16-3390
 
  Kansio C:\WINDOWS\System32
 
 24.10.2005  19:57           234˙154 gpj8l31u1.dll
 24.10.2005  19:45           236˙258 gpjol3131.dll
 24.10.2005  18:15           236˙258 mnc42u.dll
 09.10.2005  09:31    <KANSIO>       dllcache
 08.10.2005  18:18                56 D01A6EBF52.sys
 08.10.2005  18:18             1˙890 KGyGaAvL.sys
 08.10.2005  15:03    <KANSIO>       Microsoft
                5 tiedosto(a)        708˙616 tavua
                2 kansio(ta)   5˙674˙840˙064 tavua vapaana
  
							
						 
						
						
 Moi 
						
						 | 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						24. lokakuuta 2005 @ 16:20 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					 
					
					
					
						| 
						
						 
							
							Jep, sulla on look2me.
 
 Sulje ensin kaikki ohjelmat, koska kone käynnistyy uudelleen.
 
 Avaa l2mfix-kansio työpöydältä, tuplaklikkaa l2mfix.bat ja valitse valinta #2 (Run Fix) painamalla 2 ja enter ,  paina sitten mitä tahansa näppäintä, jolloin kone käynnistyy uudelleen. Käynnistyksen jälkeen työpöytä ja kuvakkeet häipyvät hetkeksi näkyvistä,se on normaalia. L2mfix jatkaa scannia ja kun se on valmia, loki avautuu muistioon. Kopioi se ja liitä tänne uuden hijackthis-lokin kanssa.
 
 Jos käynnistyksen jälkeen kuvakkeet eivät häviä tai loki ei avaudu muistioon, tuplaklikkaa l2mfix-kansiossa olevaa second.bat, jotta fixi jatkuu.
							
						 
						
						
						
						 | 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Junior Member
								
									
   4 tuotearviota
								
							
							 
							 
						 | 
						24. lokakuuta 2005 @ 16:33 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					 
					
					
					
						
						
						
							
							Juu tässä ois:
 
 L2Mfix 1.04a
  
 Running From:
 C:\Documents and Settings\Jenra\Ty?p?yt?\l2mfix
  
  
 
 RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
 Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
 This program is Freeware, use it on your own risk!
 
 Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
 (NI)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (IO)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (NI)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (IO)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-NI) ALLOW  Read        	BUILTIN\K?ytt?j?t
 (ID-IO) ALLOW  Read        	BUILTIN\K?ytt?j?t
 (ID-NI) ALLOW  Full access 	BUILTIN\J?rjestelm?nvalvojat
 (ID-IO) ALLOW  Full access 	BUILTIN\J?rjestelm?nvalvojat
 (ID-NI) ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-IO) ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-IO) ALLOW  Full access 	LUOJA-OMISTAJA
 
 
  
 Setting registry permissions:
  
 
 RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
 Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
 This program is Freeware, use it on your own risk!
 
 
 Denying C(CI) access for predefined group "Administrators"
  - adding new ACCESS DENY entry
 
  
 Registry Permissions set too:
 
 RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
 Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
 This program is Freeware, use it on your own risk!
 
 Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
 (CI)    DENY   --C-------   	BUILTIN\J?rjestelm?nvalvojat
 (NI)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (IO)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (NI)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (IO)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-NI) ALLOW  Read        	BUILTIN\K?ytt?j?t
 (ID-IO) ALLOW  Read        	BUILTIN\K?ytt?j?t
 (ID-NI) ALLOW  Full access 	BUILTIN\J?rjestelm?nvalvojat
 (ID-IO) ALLOW  Full access 	BUILTIN\J?rjestelm?nvalvojat
 (ID-NI) ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-IO) ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-IO) ALLOW  Full access 	LUOJA-OMISTAJA
 
 
  
 Setting up for Reboot
  
  
 Starting Reboot!
  
 Setting Directory
 C:\Documents and Settings\Jenra\Ty?p?yt?\l2mfix 
 System Rebooted! 
  
 Running From:
 C:\Documents and Settings\Jenra\Ty?p?yt?\l2mfix
  
 killing explorer and rundll32.exe 
 
 Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
 Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
 Killing PID 1540 'explorer.exe'
 
 Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
 Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
 Error, Cannot find a process with an image name of rundll32.exe
  
 Scanning First Pass. Please Wait!
  
 First Pass Completed 
  
 Second Pass Scanning 
  
 Second pass Completed!
 Backing Up: C:\WINDOWS\system32\gpj8l31u1.dll
         1 tiedosto(a) on kopioitu.
 Backing Up: C:\WINDOWS\system32\mnc42u.dll
         1 tiedosto(a) on kopioitu.
 deleting: C:\WINDOWS\system32\gpj8l31u1.dll  
 Successfully Deleted: C:\WINDOWS\system32\gpj8l31u1.dll
 deleting: C:\WINDOWS\system32\mnc42u.dll  
 Successfully Deleted: C:\WINDOWS\system32\mnc42u.dll
  
  
 Zipping up files for submission:
   adding: gpj8l31u1.dll (164 bytes security) (deflated 4%)
   adding: mnc42u.dll (164 bytes security) (deflated 5%)
   adding: clear.reg (164 bytes security) (deflated 46%)
   adding: echo.reg (164 bytes security) (deflated 9%)
   adding: direct.txt (164 bytes security) (stored 0%)
   adding: lo2.txt (164 bytes security) (deflated 73%)
   adding: readme.txt (164 bytes security) (deflated 52%)
   adding: report.txt (164 bytes security) (deflated 66%)
   adding: test.txt (164 bytes security) (deflated 34%)
   adding: test2.txt (164 bytes security) (deflated 27%)
   adding: test3.txt (164 bytes security) (deflated 27%)
   adding: test5.txt (164 bytes security) (deflated 27%)
   adding: xfind.txt (164 bytes security) (deflated 29%)
   adding: backregs/3E7BED48-C8CA-4E71-AF84-8D2C12A844CA.reg (164 bytes security) (deflated 70%)
   adding: backregs/F13E16D3-E8BD-461C-97DF-CDB3EF4611D2.reg (164 bytes security) (deflated 70%)
   adding: backregs/notibac.reg (164 bytes security) (deflated 87%)
   adding: backregs/shell.reg (164 bytes security) (deflated 73%)
  
 Restoring Registry Permissions: 
  
 
 RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
 Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
 This program is Freeware, use it on your own risk!
 
 
 Revoking access for predefined group "Administrators"
 Inherited ACE can not be revoked here!
 Inherited ACE can not be revoked here!
 
  
 Registry permissions set too:
 
 RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
 Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
 This program is Freeware, use it on your own risk!
 
 Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
 (NI)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (IO)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (NI)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (IO)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-NI) ALLOW  Read        	BUILTIN\K?ytt?j?t
 (ID-IO) ALLOW  Read        	BUILTIN\K?ytt?j?t
 (ID-NI) ALLOW  Full access 	BUILTIN\J?rjestelm?nvalvojat
 (ID-IO) ALLOW  Full access 	BUILTIN\J?rjestelm?nvalvojat
 (ID-NI) ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-IO) ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-IO) ALLOW  Full access 	LUOJA-OMISTAJA
 
 
 Restoring Sedebugprivilege:
  
  Granting SeDebugPrivilege to Administrators   ... failed (GetAccountSid(Administrators)=1332 
  
 Restoring Windows Update Certificates.:
  
 deleting local copy: gpj8l31u1.dll   
 deleting local copy: mnc42u.dll   
  
 The following Is the Current Export of the Winlogon notify key:
 ****************************************************************************
 Windows Registry Editor Version 5.00
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
 "DLLName"="Ati2evxx.dll"
 "Asynchronous"=dword:00000000
 "Impersonate"=dword:00000001
 "Lock"="AtiLockEvent"
 "Logoff"="AtiLogoffEvent"
 "Logon"="AtiLogonEvent"
 "Disconnect"="AtiDisConnectEvent"
 "Reconnect"="AtiReConnectEvent"
 "Safe"=dword:00000000
 "Shutdown"="AtiShutdownEvent"
 "StartScreenSaver"="AtiStartScreenSaverEvent"
 "StartShell"="AtiStartShellEvent"
 "Startup"="AtiStartupEvent"
 "StopScreenSaver"="AtiStopScreenSaverEvent"
 "Unlock"="AtiUnLockEvent"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
 "Asynchronous"=dword:00000000
 "Impersonate"=dword:00000000
 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
   6c,00,00,00
 "Logoff"="ChainWlxLogoffEvent"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
 "Asynchronous"=dword:00000000
 "Impersonate"=dword:00000000
 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
   6c,00,6c,00,00,00
 "Logoff"="CryptnetWlxLogoffEvent"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
 "DLLName"="cscdll.dll"
 "Logon"="WinlogonLogonEvent"
 "Logoff"="WinlogonLogoffEvent"
 "ScreenSaver"="WinlogonScreenSaverEvent"
 "Startup"="WinlogonStartupEvent"
 "Shutdown"="WinlogonShutdownEvent"
 "StartShell"="WinlogonStartShellEvent"
 "Impersonate"=dword:00000000
 "Asynchronous"=dword:00000001
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
 "DLLName"="wlnotify.dll"
 "Logon"="SCardStartCertProp"
 "Logoff"="SCardStopCertProp"
 "Lock"="SCardSuspendCertProp"
 "Unlock"="SCardResumeCertProp"
 "Enabled"=dword:00000001
 "Impersonate"=dword:00000001
 "Asynchronous"=dword:00000001
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
 "Asynchronous"=dword:00000000
 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
   6c,00,6c,00,00,00
 "Impersonate"=dword:00000000
 "StartShell"="SchedStartShell"
 "Logoff"="SchedEventLogOff"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
 "Logoff"="WLEventLogoff"
 "Impersonate"=dword:00000000
 "Asynchronous"=dword:00000001
 "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
   6c,00,6c,00,00,00
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
 "DLLName"="WlNotify.dll"
 "Lock"="SensLockEvent"
 "Logon"="SensLogonEvent"
 "Logoff"="SensLogoffEvent"
 "Safe"=dword:00000001
 "MaxWait"=dword:00000258
 "StartScreenSaver"="SensStartScreenSaverEvent"
 "StopScreenSaver"="SensStopScreenSaverEvent"
 "Startup"="SensStartupEvent"
 "Shutdown"="SensShutdownEvent"
 "StartShell"="SensStartShellEvent"
 "PostShell"="SensPostShellEvent"
 "Disconnect"="SensDisconnectEvent"
 "Reconnect"="SensReconnectEvent"
 "Unlock"="SensUnlockEvent"
 "Impersonate"=dword:00000001
 "Asynchronous"=dword:00000001
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
 "Asynchronous"=dword:00000000
 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
   6c,00,6c,00,00,00
 "Impersonate"=dword:00000000
 "Logoff"="TSEventLogoff"
 "Logon"="TSEventLogon"
 "PostShell"="TSEventPostShell"
 "Shutdown"="TSEventShutdown"
 "StartShell"="TSEventStartShell"
 "Startup"="TSEventStartup"
 "MaxWait"=dword:00000258
 "Reconnect"="TSEventReconnect"
 "Disconnect"="TSEventDisconnect"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
 "DLLName"="wlnotify.dll"
 "Logon"="RegisterTicketExpiredNotificationEvent"
 "Logoff"="UnregisterTicketExpiredNotificationEvent"
 "Impersonate"=dword:00000001
 "Asynchronous"=dword:00000001
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
 "DLLName"="wzcdlg.dll"
 "Logon"="WZCEventLogon"
 "Logoff"="WZCEventLogoff"
 "Impersonate"=dword:00000000
 "Asynchronous"=dword:00000000
 
  
 The following are the files found: 
 ****************************************************************************
 C:\WINDOWS\system32\gpj8l31u1.dll 
 C:\WINDOWS\system32\mnc42u.dll 
  
 Registry Entries that were Deleted: 
 Please verify that the listing looks ok.  
 If there was something deleted wrongly there are backups in the backreg folder. 
 ****************************************************************************
 REGEDIT4
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
 "{CA6C600E-C7AB-4876-9D2A-97B202B2C2A7}"=-
 "{3E7BED48-C8CA-4E71-AF84-8D2C12A844CA}"=-
 "{F13E16D3-E8BD-461C-97DF-CDB3EF4611D2}"=-
 [-HKEY_CLASSES_ROOT\CLSID\{CA6C600E-C7AB-4876-9D2A-97B202B2C2A7}]
 [-HKEY_CLASSES_ROOT\CLSID\{3E7BED48-C8CA-4E71-AF84-8D2C12A844CA}]
 [-HKEY_CLASSES_ROOT\CLSID\{F13E16D3-E8BD-461C-97DF-CDB3EF4611D2}]
 REGEDIT4
 
 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
 "SV1"=""
 ****************************************************************************
 Desktop.ini Contents: 
 ****************************************************************************
 ****************************************************************************
  
							
						 
						
						
 Moi 
						
						 | 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Junior Member
								
									
   4 tuotearviota
								
							
							 
							 
						 | 
						24. lokakuuta 2005 @ 17:23 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					 
					
					
					
						
						
						
							
							ja tässä tää:
 
 Logfile of HijackThis v1.99.1
 Scan saved at 21:23:19, on 24.10.2005
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\LEXBCES.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\system32\LEXPPS.EXE
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
 C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
 C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
 C:\WINDOWS\system32\PROMon.exe
 C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
 C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 C:\Program Files\AVPersonal\AVGNT.EXE
 C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
 C:\Program Files\D-Tools\daemon.exe
 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\MSN Messenger\MsnMsgr.Exe
 C:\Program Files\AVPersonal\AVWUPSRV.EXE
 C:\Program Files\Compaq\Easy Access Button Support\CPQEAKSYSTEMTRAY.EXE
 C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
 C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
 C:\Compaq\EAKDRV\EAUSBKBD.EXE
 C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
 C:\Program Files\WinZip\WZQKPICK.EXE
 C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
 C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
 C:\Program Files\ewido\security suite\ewidoctrl.exe
 C:\Program Files\ewido\security suite\ewidoguard.exe
 C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
 C:\WINDOWS\system32\UAService7.exe
 C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
 C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\WINDOWS\explorer.exe
 C:\HJT\HijackThis.exe
 
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://desktop.presario.net/scripts/redirectors/presario/deskredi... R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.presario.net/scripts/redirectors/presario/srchredir... R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.presario.net/scripts/redirectors/presario/srchredir... R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://desktop.presario.net/scripts/redirectors/presario/deskredi... R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
 O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
 O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
 O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
 O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe
 O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
 O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
 O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
 O4 - HKLM\..\Run: [ChkAdmin] C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
 O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
 O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
 O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
 O4 - Global Startup: Microsoft Works Kalenterin muistutukset.lnk = ?
 O4 - Global Startup: WinZIP Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl... O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
 O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
 O23 - Service: Compaq Local Alerter (CPQALERT) - Compaq Computer Corporation - C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
 O23 - Service: cpqdmi - Compaq Computer Corporation - C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
 O23 - Service: Compaq DMI Web Agent (cpqWebDmi) - Compaq Computer Corporation - C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
 O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
 O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
 O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
 O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
 O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
 O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
 O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 O23 - Service: Win32Sl (WIN32SL) - Intel - C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
 
  
							
						 
						
						
 Moi 
						
						 | 
					 
				
				
			
				
				
				
					
						| 
							 Mainos 
							 
						 | 
						   | 
					 
					
						
							
							  
								
							
						 | 
					 
				
				
				
					
						| 
							
								 Toymaatti 
							
							
								Senior Member
								
									
								
							
							 
							 
						 | 
						24. lokakuuta 2005 @ 19:26 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					 
					
					
					
						| 
						
						 
							
							Jep L2M hävisi ja kunnossa tuo minusta on muutenkin. 
							
						 
						
						
 Se parhaiten nauraa joka toiselle kuoppaa kaivaa. 
						
						 | 
					 
				
				
			
			
			
			
			
		 
		
	
			
			
		
	 |