| 
		
		
			
		
		
	 | 
												  
												
													
	
		| 
			 Keskustelualueet 
			Keskustelualueet 
		 | 
		
			
				
					
						
			
			
		
					
				
			 | 
		
	 
 
														
															
															
	
			
			
				| 
					Apua tarvittaisiin, HJT loki matkassa
				 | 
				
				
					
				 | 
				
			 
			
			
			
				
					
					
				 
			
			
			
			
			
				
				
					
				
				
				
				
					
						| 
							
								 Madz^ 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						25. lokakuuta 2005 @ 12:42 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					 
					
					
					
						| 
						
						 
							
							Jooh eli selain aukaisee kaiken mailman ärsyttäviä mainoksia :S 
 
 Logfile of HijackThis v1.99.1
 Scan saved at 16:42:35, on 25.10.2005
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
 C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
 C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 C:\Program Files\Norton Internet Security\ISSVC.exe
 C:\WINDOWS\system32\rundll32.exe
 C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
 C:\Program Files\D-Tools\daemon.exe
 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
 C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
 C:\Program Files\EPoX\EPTP\EPTP.EXE
 C:\Program Files\Google\Gmail Notifier\gnotify.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\Program Files\MSN Messenger\MsnMsgr.Exe
 C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
 C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
 C:\WINDOWS\system32\nvsvc32.exe
 C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 C:\Program Files\UltraVNC\winvnc.exe
 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
 C:\Program Files\mIRC\mirc.exe
 C:\Program Files\Winamp\winamp.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\Documents and Settings\Kalle Ratilainen\Työpöytä\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
 O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
 O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
 O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1035
 O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
 O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\winvnc.exe" -servicehelper
 O4 - HKLM\..\Run: [hwmdr] "C:\Program Files\EPoX\EPTP\EPTP.EXE" "5000"
 O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
 O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
 O20 - Winlogon Notify: Dynamic Directory - C:\WINDOWS\system32\h60q0gd5e60.dll
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
 O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
 O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
 O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
 O23 - Service: Norton AntiVirus Auto-Protect -palvelu (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
 O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
 O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
 O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
 O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\winvnc.exe" -service (file missing) 
							
						 
						
						
						
						 | 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						25. lokakuuta 2005 @ 12:46 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					 
					
					
					
						
						
						
							
							Hae täältä -> http://www.atribune.org/downloads/l2mfix.exe l2mfix ja tallenna työpöydälle. Tuplaklikkaa sitä ja klikkaa install. Avaa l2mfix -kansio työpöydältä ja tuplaklikkaa l2mfix.bat ja valitse #1 painamalla 1 ja enter(ÄLÄ tee vielä mitään muuta!!). Kopioi se loki ja lähetä tänne.
							
						 
						
						
						
						 | 
					 
				
				
			
				
				
				
				
				
					
						| 
							
								 Madz^ 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						25. lokakuuta 2005 @ 12:53 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					 
					
					
					
						
						
						
							
							Tässäpä tuo loki olis ->
 
 L2MFIX find log 1.04a
 These are the registry keys present
 **********************************************************************************
 Winlogon/notify:
 Windows Registry Editor Version 5.00
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
 "Asynchronous"=dword:00000000
 "Impersonate"=dword:00000000
 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
   6c,00,00,00
 "Logoff"="ChainWlxLogoffEvent"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
 "Asynchronous"=dword:00000000
 "Impersonate"=dword:00000000
 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
   6c,00,6c,00,00,00
 "Logoff"="CryptnetWlxLogoffEvent"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
 "DLLName"="cscdll.dll"
 "Logon"="WinlogonLogonEvent"
 "Logoff"="WinlogonLogoffEvent"
 "ScreenSaver"="WinlogonScreenSaverEvent"
 "Startup"="WinlogonStartupEvent"
 "Shutdown"="WinlogonShutdownEvent"
 "StartShell"="WinlogonStartShellEvent"
 "Impersonate"=dword:00000000
 "Asynchronous"=dword:00000001
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Dynamic Directory]
 "Asynchronous"=dword:00000000
 "DllName"="C:\\WINDOWS\\system32\\h60q0gd5e60.dll"
 "Impersonate"=dword:00000000
 "Logon"="WinLogon"
 "Logoff"="WinLogoff"
 "Shutdown"="WinShutdown"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
 "DLLName"="wlnotify.dll"
 "Logon"="SCardStartCertProp"
 "Logoff"="SCardStopCertProp"
 "Lock"="SCardSuspendCertProp"
 "Unlock"="SCardResumeCertProp"
 "Enabled"=dword:00000001
 "Impersonate"=dword:00000001
 "Asynchronous"=dword:00000001
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
 "Asynchronous"=dword:00000000
 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
   6c,00,6c,00,00,00
 "Impersonate"=dword:00000000
 "StartShell"="SchedStartShell"
 "Logoff"="SchedEventLogOff"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
 "Logoff"="WLEventLogoff"
 "Impersonate"=dword:00000000
 "Asynchronous"=dword:00000001
 "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
   6c,00,6c,00,00,00
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
 "DLLName"="WlNotify.dll"
 "Lock"="SensLockEvent"
 "Logon"="SensLogonEvent"
 "Logoff"="SensLogoffEvent"
 "Safe"=dword:00000001
 "MaxWait"=dword:00000258
 "StartScreenSaver"="SensStartScreenSaverEvent"
 "StopScreenSaver"="SensStopScreenSaverEvent"
 "Startup"="SensStartupEvent"
 "Shutdown"="SensShutdownEvent"
 "StartShell"="SensStartShellEvent"
 "PostShell"="SensPostShellEvent"
 "Disconnect"="SensDisconnectEvent"
 "Reconnect"="SensReconnectEvent"
 "Unlock"="SensUnlockEvent"
 "Impersonate"=dword:00000001
 "Asynchronous"=dword:00000001
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
 "Asynchronous"=dword:00000000
 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
   6c,00,6c,00,00,00
 "Impersonate"=dword:00000000
 "Logoff"="TSEventLogoff"
 "Logon"="TSEventLogon"
 "PostShell"="TSEventPostShell"
 "Shutdown"="TSEventShutdown"
 "StartShell"="TSEventStartShell"
 "Startup"="TSEventStartup"
 "MaxWait"=dword:00000258
 "Reconnect"="TSEventReconnect"
 "Disconnect"="TSEventDisconnect"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
 "DLLName"="wlnotify.dll"
 "Logon"="RegisterTicketExpiredNotificationEvent"
 "Logoff"="UnregisterTicketExpiredNotificationEvent"
 "Impersonate"=dword:00000001
 "Asynchronous"=dword:00000001
 
 
 RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
 Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
 This program is Freeware, use it on your own risk!
 
 Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
 (NI)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (IO)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (NI)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (IO)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-NI) ALLOW  Read        	BUILTIN\K?ytt?j?t
 (ID-IO) ALLOW  Read        	BUILTIN\K?ytt?j?t
 (ID-NI) ALLOW  Read        	BUILTIN\Tehok?ytt?j?t
 (ID-IO) ALLOW  Read        	BUILTIN\Tehok?ytt?j?t
 (ID-NI) ALLOW  Full access 	BUILTIN\J?rjestelm?nvalvojat
 (ID-IO) ALLOW  Full access 	BUILTIN\J?rjestelm?nvalvojat
 (ID-NI) ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-IO) ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-IO) ALLOW  Full access 	LUOJA-OMISTAJA
 
 
 **********************************************************************************
 useragent:
 Windows Registry Editor Version 5.00
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
 "{46633127-22C5-5341-1A84-6AEE99901C8E}"=""
 
 **********************************************************************************
 Shell Extension key:
 Windows Registry Editor Version 5.00
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
 "{00022613-0000-0000-C000-000000000046}"="Multimediatiedoston ominaisuusikkuna"
 "{176d6597-26d3-11d1-b350-080036a75b03}"="ICM-kuvanlukijan hallinta"
 "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS-suojaussivu"
 "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE-asiakirjatiedoston ominaisuussivu"
 "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Liittym?laajennus jakamista varten"
 "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
 "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="N?ytt?sovittimen CPL-laajennus"
 "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="N?yt?n CPL -laajennus"
 "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL -laajennus"
 "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Hakemistopalvelun suojaussivu"
 "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Yhteensopivuussivusto"
 "{56117100-C0CD-101B-81E2-00AA004AE837}"="K?ytt?liittym?n leikkeidenk?sittelytoiminto"
 "{59099400-57FF-11CE-BD94-0020AF85B590}"="Levykkeen kopiointilaajennus"
 "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Microsoft Windows -verkon objektien liittym?laajennukset"
 "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM-n?yt?n hallinta"
 "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM-tulostimen hallinta"
 "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Tiedostonpakkauksen liittym?laajennukset"
 "{77597368-7b15-11d0-a0c2-080036af3f03}"="Web-tulostimen liittym?laajennus"
 "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
 "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Salauksen pikavalikko"
 "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Salkku"
 "{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal-kuvakkeen tunniste"
 "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
 "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC-profiili"
 "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Tulostimen suojaussivu"
 "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Liittym?laajennus jakamista varten"
 "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
 "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO -laajennus"
 "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign -laajennus"
 "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Verkkoyhteydet"
 "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Verkkoyhteydet"
 "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Skannerit ja kamerat"
 "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Skannerit ja kamerat"
 "{905667aa-acd6-11d2-8080-00805f6596d2}"="Skannerit ja kamerat"
 "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Skannerit ja kamerat"
 "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Skannerit ja kamerat"
 "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
 "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Windows Script Hostin liittym?laajennukset"
 "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft-tietolinkki"
 "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
 "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
 "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Ajoitetut teht?v?t"
 "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
 "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
 "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Teht?v?palkki ja K?ynnist?-valikko"
 "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Etsi"
 "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Ohje ja tuki"
 "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Ohje ja tuki"
 "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Suorita..."
 "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
 "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="S?hk?posti"
 "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fontit"
 "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Valvontaty?kalut"
 "{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Aiempien versioiden ominaisuudet -sivu"
 "{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Edelliset versiot"
 "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
 "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
 "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
 "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
 "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
 "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
 "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet-ty?kalurivi"
 "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Lataamisen tila"
 "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
 "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
 "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
 "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
 "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Etsint?palkki"
 "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
 "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
 "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
 "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&L?hiosoite"
 "{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
 "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
 "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
 "{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
 "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
 "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
 "{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
 "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
 "{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
 "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
 "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
 "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
 "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
 "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
 "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
 "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
 "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
 "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
 "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
 "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
 "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
 "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
 "{FF393560-C2A7-11CF-BFF4-444553540000}"="Sivuhistoria"
 "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
 "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
 "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
 "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
 "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
 "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
 "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
 "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
 "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
 "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
 "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
 "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
 "{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX-v?limuistikansio"
 "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
 "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
 "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
 "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
 "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
 "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
 "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
 "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
 "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
 "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
 "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="K?ytt?liittym?n sovelluksenhallintaohjelma"
 "{0B124F8F-91F0-11D1-B8B5-006008059382}"="Sovellusluettelo asennettiin"
 "{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
 "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
 "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
 "{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}"="Autoplay for SlideShow"
 "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ -tiedoston pikkukuvan purkaja"
 "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Yhteenvetotiedot pikkukuvien k?sittelyst? (DOCFILES)"
 "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML-pikkukuvien purkuohjelma"
 "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
 "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Ohjattu Web-julkaisutoiminto"
 "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Valokuvien paperikopioiden tilaaminen Internetist?"
 "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
 "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Ohjattu Passport toiminto"
 "{7A9D77BD-5403-11d2-8785-2E0420524153}"="K?ytt?j?tilit"
 "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
 "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
 "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Kanavatiedosto"
 "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Kanavan pikakuvake"
 "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Kanavienk?sittelyobjekti"
 "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
 "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
 "{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
 "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
 "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
 "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
 "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
 "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
 "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
 "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
 "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
 "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
 "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
 "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
 "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
 "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
 "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
 "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
 "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
 "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
 "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
 "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline-tiedostot-kansio"
 "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
 "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
 "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
 "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
 "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
 "{32714800-2E5F-11d0-8B85-00AA0044F941}"="&Henkil?it?..."
 "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
 "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
 "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
 "{A70C977A-BF00-412C-90B7-034C51DA2439}"="NvCpl DesktopContext Class"
 "{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
 "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
 "{1E9B04FB-F9E5-4718-997B-B8DA88302A48}"="nView Desktop Context Menu"
 "{FFB699E0-306A-11d3-8BD1-00104B6F7516}"="Play on my TV helper"
 "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
 "{32020A01-506E-484D-A2A8-BE3CF17601C3}"="AlcoholShellEx"
 "{A057FF86-C261-4483-A1C8-EFCD4EF60EA6}"=""
 "{D20FC2A5-6998-47F2-9DD8-7EEC25FB7D23}"=""
 "{3F6DAFB4-39D7-4172-92B1-CBDD37A78DDD}"=""
 "{4389221D-C245-4CA3-98C5-5E14A908E50D}"=""
 "{15D24308-A0B9-4298-8DCD-E78B07FB628E}"=""
 "{9EE87276-AF80-4F66-AE3F-4A4629FEAD6D}"=""
 
 **********************************************************************************
 HKEY ROOT CLASSIDS:
 Windows Registry Editor Version 5.00
 
 [HKEY_CLASSES_ROOT\CLSID\{A057FF86-C261-4483-A1C8-EFCD4EF60EA6}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{A057FF86-C261-4483-A1C8-EFCD4EF60EA6}\Implemented Categories]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{A057FF86-C261-4483-A1C8-EFCD4EF60EA6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{A057FF86-C261-4483-A1C8-EFCD4EF60EA6}\InprocServer32]
 @="C:\\WINDOWS\\system32\\pagfilt.dll"
 "ThreadingModel"="Apartment"
 
 Windows Registry Editor Version 5.00
 
 [HKEY_CLASSES_ROOT\CLSID\{3F6DAFB4-39D7-4172-92B1-CBDD37A78DDD}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{3F6DAFB4-39D7-4172-92B1-CBDD37A78DDD}\Implemented Categories]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{3F6DAFB4-39D7-4172-92B1-CBDD37A78DDD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{3F6DAFB4-39D7-4172-92B1-CBDD37A78DDD}\InprocServer32]
 @="C:\\WINDOWS\\system32\\pgotowiz.dll"
 "ThreadingModel"="Apartment"
 
 Windows Registry Editor Version 5.00
 
 [HKEY_CLASSES_ROOT\CLSID\{4389221D-C245-4CA3-98C5-5E14A908E50D}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{4389221D-C245-4CA3-98C5-5E14A908E50D}\Implemented Categories]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{4389221D-C245-4CA3-98C5-5E14A908E50D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{4389221D-C245-4CA3-98C5-5E14A908E50D}\InprocServer32]
 @="C:\\WINDOWS\\system32\\krdbene.dll"
 "ThreadingModel"="Apartment"
 
 Windows Registry Editor Version 5.00
 
 [HKEY_CLASSES_ROOT\CLSID\{15D24308-A0B9-4298-8DCD-E78B07FB628E}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{15D24308-A0B9-4298-8DCD-E78B07FB628E}\Implemented Categories]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{15D24308-A0B9-4298-8DCD-E78B07FB628E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{15D24308-A0B9-4298-8DCD-E78B07FB628E}\InprocServer32]
 @="C:\\WINDOWS\\system32\\muvidctl.dll"
 "ThreadingModel"="Apartment"
 
 Windows Registry Editor Version 5.00
 
 [HKEY_CLASSES_ROOT\CLSID\{9EE87276-AF80-4F66-AE3F-4A4629FEAD6D}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{9EE87276-AF80-4F66-AE3F-4A4629FEAD6D}\Implemented Categories]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{9EE87276-AF80-4F66-AE3F-4A4629FEAD6D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{9EE87276-AF80-4F66-AE3F-4A4629FEAD6D}\InprocServer32]
 @="C:\\WINDOWS\\system32\\aEaamon.dll"
 "ThreadingModel"="Apartment"
 
 **********************************************************************************
 Files Found are not all bad files:
 
 C:\WINDOWS\SYSTEM32\
    browseui.dll   Sat  3 Sep 2005   3.05.16   A....      1 019 904   996,00 K
    cdfview.dll    Sat  3 Sep 2005   3.05.16   A....        151 552   148,00 K
    cdosys.dll     Sat 10 Sep 2005   4.55.12   A....      2 067 968     1,97 M
    cmdlin~1.dll   Wed 24 Aug 2005  21.52.06   A....         98 304    96,00 K
    danim.dll      Sat  3 Sep 2005   3.05.18   A....      1 054 720     1,00 M
    dxtrans.dll    Sat  3 Sep 2005   3.05.18   A....        205 312   200,50 K
    extmgr.dll     Sat  3 Sep 2005   3.05.18   A....         55 808    54,50 K
    ff_vfw.dll     Mon 22 Aug 2005  13.55.18   A....          5 632     5,50 K
    h60q0g~1.dll   Tue 25 Oct 2005   7.20.16   ..S.R        234 272   228,78 K
    iepeers.dll    Sat  3 Sep 2005   3.05.18   A....        250 880   245,00 K
    inseng.dll     Sat  3 Sep 2005   3.05.18   A....         96 256    94,00 K
    linkinfo.dll   Thu  1 Sep 2005   4.43.22   A....         19 968    19,50 K
    lv6009~1.dll   Tue 25 Oct 2005  15.07.24   ..S.R        234 937   229,43 K
    mshtml.dll     Wed  5 Oct 2005   3.26.04   A....      3 013 120     2,87 M
    mshtmled.dll   Sat  3 Sep 2005   3.05.18   A....        448 512   438,00 K
    msrating.dll   Sat  3 Sep 2005   3.05.18   A....        146 432   143,00 K
    mstime.dll     Sat  3 Sep 2005   3.05.18   A....        530 432   518,00 K
    netman.dll     Mon 22 Aug 2005  21.35.16   A....        197 632   193,00 K
    nwwks.dll      Thu 11 Aug 2005  18.11.34   A....         65 024    63,50 K
    pngfilt.dll    Sat  3 Sep 2005   3.05.18   A....         39 424    38,50 K
    quartz.dll     Tue 30 Aug 2005   6.55.44   A....      1 287 680     1,23 M
    s32evnt1.dll   Thu 28 Jul 2005  14.52.18   A....         91 856    89,70 K
    shdocvw.dll    Sat  3 Sep 2005   3.05.18   A....      1 483 264     1,41 M
    shell32.dll    Fri 23 Sep 2005   6.07.16   A....      8 454 656     8,06 M
    shlwapi.dll    Sat  3 Sep 2005   3.05.18   A....        473 600   462,50 K
    sirenacm.dll   Sat 13 Aug 2005  21.41.12   A....        118 784   116,00 K
    umpnpmgr.dll   Tue 23 Aug 2005   6.39.36   A....        123 904   121,00 K
    urlmon.dll     Sat  3 Sep 2005   3.05.18   A....        604 160   590,00 K
    wininet.dll    Sat  3 Sep 2005   3.05.18   A....        658 432   643,00 K
    winsrv.dll     Thu  1 Sep 2005   4.43.22   A....        291 840   285,00 K
 
 30 items found:  30 files (2 H/S), 0 directories.
    Total of file sizes:  23 524 265 bytes     22,43 M
 Locate .tmp files:
 
 No matches found.
 **********************************************************************************
 Directory Listing of system files:
  Asemalla C ei ole nime?.
  Aseman sarjanumero on 6C9B-97C7
 
  Kansio C:\WINDOWS\System32
 
 25.10.2005  15:07           234˙937 lv6009jme.dll
 25.10.2005  07:20           234˙272 h60q0gd5e60.dll
 13.10.2005  03:01    <KANSIO>       dllcache
 23.08.2005  20:04    <KANSIO>       Microsoft
                2 tiedosto(a)        469˙209 tavua
                2 kansio(ta)  91˙272˙126˙464 tavua vapaana
  
							
						 
						
						
						
						 | 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						25. lokakuuta 2005 @ 12:56 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					 
					
					
					
						| 
						
						 
							
							Sulje ensin kaikki ohjelmat, koska kone käynnistyy uudelleen.
 
 Avaa l2mfix-kansio työpöydältä, tuplaklikkaa l2mfix.bat ja valitse valinta #2 (Run Fix) painamalla 2 ja enter ,  paina sitten mitä tahansa näppäintä, jolloin kone käynnistyy uudelleen. Käynnistyksen jälkeen työpöytä ja kuvakkeet häipyvät hetkeksi näkyvistä,se on normaalia. L2mfix jatkaa scannia ja kun se on valmia, loki avautuu muistioon. Kopioi se ja liitä tänne uuden hijackthis-lokin kanssa.
 
 Jos käynnistyksen jälkeen kuvakkeet eivät häviä tai loki ei avaudu muistioon, tuplaklikkaa l2mfix-kansiossa olevaa second.bat, jotta fixi jatkuu.
							
						 
						
						
						
						 | 
					 
				
				
			
				
				
				
				
				
					
						| 
							
								 Madz^ 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						25. lokakuuta 2005 @ 13:03 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					 
					
					
					
						
						
						
							
							Se ei kyllä jatkanut fixausta.. ja eivät pikakuvakkeet hävinneet ?.. mutta silti tässä uusitut logit 
 
 L2MFIX find log 1.04a
 These are the registry keys present
 **********************************************************************************
 Winlogon/notify:
 Windows Registry Editor Version 5.00
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
 "Asynchronous"=dword:00000000
 "Impersonate"=dword:00000000
 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
   6c,00,00,00
 "Logoff"="ChainWlxLogoffEvent"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
 "Asynchronous"=dword:00000000
 "Impersonate"=dword:00000000
 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
   6c,00,6c,00,00,00
 "Logoff"="CryptnetWlxLogoffEvent"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
 "DLLName"="cscdll.dll"
 "Logon"="WinlogonLogonEvent"
 "Logoff"="WinlogonLogoffEvent"
 "ScreenSaver"="WinlogonScreenSaverEvent"
 "Startup"="WinlogonStartupEvent"
 "Shutdown"="WinlogonShutdownEvent"
 "StartShell"="WinlogonStartShellEvent"
 "Impersonate"=dword:00000000
 "Asynchronous"=dword:00000001
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
 "DLLName"="wlnotify.dll"
 "Logon"="SCardStartCertProp"
 "Logoff"="SCardStopCertProp"
 "Lock"="SCardSuspendCertProp"
 "Unlock"="SCardResumeCertProp"
 "Enabled"=dword:00000001
 "Impersonate"=dword:00000001
 "Asynchronous"=dword:00000001
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
 "Asynchronous"=dword:00000000
 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
   6c,00,6c,00,00,00
 "Impersonate"=dword:00000000
 "StartShell"="SchedStartShell"
 "Logoff"="SchedEventLogOff"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
 "Logoff"="WLEventLogoff"
 "Impersonate"=dword:00000000
 "Asynchronous"=dword:00000001
 "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
   6c,00,6c,00,00,00
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
 "DLLName"="WlNotify.dll"
 "Lock"="SensLockEvent"
 "Logon"="SensLogonEvent"
 "Logoff"="SensLogoffEvent"
 "Safe"=dword:00000001
 "MaxWait"=dword:00000258
 "StartScreenSaver"="SensStartScreenSaverEvent"
 "StopScreenSaver"="SensStopScreenSaverEvent"
 "Startup"="SensStartupEvent"
 "Shutdown"="SensShutdownEvent"
 "StartShell"="SensStartShellEvent"
 "PostShell"="SensPostShellEvent"
 "Disconnect"="SensDisconnectEvent"
 "Reconnect"="SensReconnectEvent"
 "Unlock"="SensUnlockEvent"
 "Impersonate"=dword:00000001
 "Asynchronous"=dword:00000001
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
 "Asynchronous"=dword:00000000
 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
   6c,00,6c,00,00,00
 "Impersonate"=dword:00000000
 "Logoff"="TSEventLogoff"
 "Logon"="TSEventLogon"
 "PostShell"="TSEventPostShell"
 "Shutdown"="TSEventShutdown"
 "StartShell"="TSEventStartShell"
 "Startup"="TSEventStartup"
 "MaxWait"=dword:00000258
 "Reconnect"="TSEventReconnect"
 "Disconnect"="TSEventDisconnect"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
 "DLLName"="wlnotify.dll"
 "Logon"="RegisterTicketExpiredNotificationEvent"
 "Logoff"="UnregisterTicketExpiredNotificationEvent"
 "Impersonate"=dword:00000001
 "Asynchronous"=dword:00000001
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
 "DLLName"="wzcdlg.dll"
 "Logon"="WZCEventLogon"
 "Logoff"="WZCEventLogoff"
 "Impersonate"=dword:00000000
 "Asynchronous"=dword:00000000
 
 
 RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
 Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
 This program is Freeware, use it on your own risk!
 
 Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
 (CI)    DENY   --C-------   	BUILTIN\J?rjestelm?nvalvojat
 (NI)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (IO)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (NI)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (IO)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-NI) ALLOW  Read        	BUILTIN\K?ytt?j?t
 (ID-IO) ALLOW  Read        	BUILTIN\K?ytt?j?t
 (ID-NI) ALLOW  Read        	BUILTIN\Tehok?ytt?j?t
 (ID-IO) ALLOW  Read        	BUILTIN\Tehok?ytt?j?t
 (ID-NI) ALLOW  Full access 	BUILTIN\J?rjestelm?nvalvojat
 (ID-IO) ALLOW  Full access 	BUILTIN\J?rjestelm?nvalvojat
 (ID-NI) ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-IO) ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-IO) ALLOW  Full access 	LUOJA-OMISTAJA
 
 
 **********************************************************************************
 useragent:
 Windows Registry Editor Version 5.00
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
 "{46633127-22C5-5341-1A84-6AEE99901C8E}"=""
 
 **********************************************************************************
 Shell Extension key:
 Windows Registry Editor Version 5.00
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
 "{00022613-0000-0000-C000-000000000046}"="Multimediatiedoston ominaisuusikkuna"
 "{176d6597-26d3-11d1-b350-080036a75b03}"="ICM-kuvanlukijan hallinta"
 "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS-suojaussivu"
 "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE-asiakirjatiedoston ominaisuussivu"
 "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Liittym?laajennus jakamista varten"
 "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
 "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="N?ytt?sovittimen CPL-laajennus"
 "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="N?yt?n CPL -laajennus"
 "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL -laajennus"
 "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Hakemistopalvelun suojaussivu"
 "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Yhteensopivuussivusto"
 "{56117100-C0CD-101B-81E2-00AA004AE837}"="K?ytt?liittym?n leikkeidenk?sittelytoiminto"
 "{59099400-57FF-11CE-BD94-0020AF85B590}"="Levykkeen kopiointilaajennus"
 "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Microsoft Windows -verkon objektien liittym?laajennukset"
 "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM-n?yt?n hallinta"
 "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM-tulostimen hallinta"
 "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Tiedostonpakkauksen liittym?laajennukset"
 "{77597368-7b15-11d0-a0c2-080036af3f03}"="Web-tulostimen liittym?laajennus"
 "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
 "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Salauksen pikavalikko"
 "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Salkku"
 "{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal-kuvakkeen tunniste"
 "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
 "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC-profiili"
 "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Tulostimen suojaussivu"
 "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Liittym?laajennus jakamista varten"
 "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
 "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO -laajennus"
 "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign -laajennus"
 "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Verkkoyhteydet"
 "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Verkkoyhteydet"
 "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Skannerit ja kamerat"
 "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Skannerit ja kamerat"
 "{905667aa-acd6-11d2-8080-00805f6596d2}"="Skannerit ja kamerat"
 "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Skannerit ja kamerat"
 "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Skannerit ja kamerat"
 "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
 "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Windows Script Hostin liittym?laajennukset"
 "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft-tietolinkki"
 "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
 "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
 "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Ajoitetut teht?v?t"
 "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
 "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
 "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Teht?v?palkki ja K?ynnist?-valikko"
 "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Etsi"
 "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Ohje ja tuki"
 "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Ohje ja tuki"
 "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Suorita..."
 "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
 "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="S?hk?posti"
 "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fontit"
 "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Valvontaty?kalut"
 "{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Aiempien versioiden ominaisuudet -sivu"
 "{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Edelliset versiot"
 "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
 "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
 "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
 "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
 "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
 "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
 "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet-ty?kalurivi"
 "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Lataamisen tila"
 "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
 "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
 "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
 "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
 "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Etsint?palkki"
 "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
 "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
 "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
 "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&L?hiosoite"
 "{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
 "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
 "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
 "{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
 "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
 "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
 "{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
 "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
 "{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
 "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
 "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
 "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
 "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
 "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
 "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
 "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
 "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
 "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
 "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
 "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
 "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
 "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
 "{FF393560-C2A7-11CF-BFF4-444553540000}"="Sivuhistoria"
 "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
 "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
 "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
 "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
 "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
 "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
 "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
 "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
 "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
 "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
 "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
 "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
 "{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX-v?limuistikansio"
 "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
 "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
 "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
 "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
 "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
 "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
 "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
 "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
 "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
 "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
 "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="K?ytt?liittym?n sovelluksenhallintaohjelma"
 "{0B124F8F-91F0-11D1-B8B5-006008059382}"="Sovellusluettelo asennettiin"
 "{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
 "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
 "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
 "{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}"="Autoplay for SlideShow"
 "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ -tiedoston pikkukuvan purkaja"
 "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Yhteenvetotiedot pikkukuvien k?sittelyst? (DOCFILES)"
 "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML-pikkukuvien purkuohjelma"
 "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
 "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Ohjattu Web-julkaisutoiminto"
 "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Valokuvien paperikopioiden tilaaminen Internetist?"
 "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
 "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Ohjattu Passport toiminto"
 "{7A9D77BD-5403-11d2-8785-2E0420524153}"="K?ytt?j?tilit"
 "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
 "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
 "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Kanavatiedosto"
 "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Kanavan pikakuvake"
 "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Kanavienk?sittelyobjekti"
 "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
 "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
 "{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
 "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
 "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
 "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
 "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
 "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
 "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
 "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
 "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
 "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
 "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
 "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
 "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
 "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
 "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
 "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
 "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
 "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
 "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
 "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline-tiedostot-kansio"
 "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
 "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
 "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
 "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
 "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
 "{32714800-2E5F-11d0-8B85-00AA0044F941}"="&Henkil?it?..."
 "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
 "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
 "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
 "{A70C977A-BF00-412C-90B7-034C51DA2439}"="NvCpl DesktopContext Class"
 "{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
 "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
 "{1E9B04FB-F9E5-4718-997B-B8DA88302A48}"="nView Desktop Context Menu"
 "{FFB699E0-306A-11d3-8BD1-00104B6F7516}"="Play on my TV helper"
 "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
 "{32020A01-506E-484D-A2A8-BE3CF17601C3}"="AlcoholShellEx"
 "{A057FF86-C261-4483-A1C8-EFCD4EF60EA6}"=""
 "{D20FC2A5-6998-47F2-9DD8-7EEC25FB7D23}"=""
 "{3F6DAFB4-39D7-4172-92B1-CBDD37A78DDD}"=""
 "{4389221D-C245-4CA3-98C5-5E14A908E50D}"=""
 "{15D24308-A0B9-4298-8DCD-E78B07FB628E}"=""
 "{9EE87276-AF80-4F66-AE3F-4A4629FEAD6D}"=""
 
 **********************************************************************************
 HKEY ROOT CLASSIDS:
 Windows Registry Editor Version 5.00
 
 [HKEY_CLASSES_ROOT\CLSID\{A057FF86-C261-4483-A1C8-EFCD4EF60EA6}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{A057FF86-C261-4483-A1C8-EFCD4EF60EA6}\Implemented Categories]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{A057FF86-C261-4483-A1C8-EFCD4EF60EA6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{A057FF86-C261-4483-A1C8-EFCD4EF60EA6}\InprocServer32]
 @="C:\\WINDOWS\\system32\\pagfilt.dll"
 "ThreadingModel"="Apartment"
 
 Windows Registry Editor Version 5.00
 
 [HKEY_CLASSES_ROOT\CLSID\{3F6DAFB4-39D7-4172-92B1-CBDD37A78DDD}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{3F6DAFB4-39D7-4172-92B1-CBDD37A78DDD}\Implemented Categories]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{3F6DAFB4-39D7-4172-92B1-CBDD37A78DDD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{3F6DAFB4-39D7-4172-92B1-CBDD37A78DDD}\InprocServer32]
 @="C:\\WINDOWS\\system32\\pgotowiz.dll"
 "ThreadingModel"="Apartment"
 
 Windows Registry Editor Version 5.00
 
 [HKEY_CLASSES_ROOT\CLSID\{4389221D-C245-4CA3-98C5-5E14A908E50D}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{4389221D-C245-4CA3-98C5-5E14A908E50D}\Implemented Categories]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{4389221D-C245-4CA3-98C5-5E14A908E50D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{4389221D-C245-4CA3-98C5-5E14A908E50D}\InprocServer32]
 @="C:\\WINDOWS\\system32\\krdbene.dll"
 "ThreadingModel"="Apartment"
 
 Windows Registry Editor Version 5.00
 
 [HKEY_CLASSES_ROOT\CLSID\{15D24308-A0B9-4298-8DCD-E78B07FB628E}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{15D24308-A0B9-4298-8DCD-E78B07FB628E}\Implemented Categories]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{15D24308-A0B9-4298-8DCD-E78B07FB628E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{15D24308-A0B9-4298-8DCD-E78B07FB628E}\InprocServer32]
 @="C:\\WINDOWS\\system32\\muvidctl.dll"
 "ThreadingModel"="Apartment"
 
 Windows Registry Editor Version 5.00
 
 [HKEY_CLASSES_ROOT\CLSID\{9EE87276-AF80-4F66-AE3F-4A4629FEAD6D}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{9EE87276-AF80-4F66-AE3F-4A4629FEAD6D}\Implemented Categories]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{9EE87276-AF80-4F66-AE3F-4A4629FEAD6D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
 @=""
 
 [HKEY_CLASSES_ROOT\CLSID\{9EE87276-AF80-4F66-AE3F-4A4629FEAD6D}\InprocServer32]
 @="C:\\WINDOWS\\system32\\aEaamon.dll"
 "ThreadingModel"="Apartment"
 
 **********************************************************************************
 Files Found are not all bad files:
 
 C:\WINDOWS\SYSTEM32\
    browseui.dll   Sat  3 Sep 2005   3.05.16   A....      1 019 904   996,00 K
    cdfview.dll    Sat  3 Sep 2005   3.05.16   A....        151 552   148,00 K
    cdosys.dll     Sat 10 Sep 2005   4.55.12   A....      2 067 968     1,97 M
    cmdlin~1.dll   Wed 24 Aug 2005  21.52.06   A....         98 304    96,00 K
    danim.dll      Sat  3 Sep 2005   3.05.18   A....      1 054 720     1,00 M
    dxtrans.dll    Sat  3 Sep 2005   3.05.18   A....        205 312   200,50 K
    extmgr.dll     Sat  3 Sep 2005   3.05.18   A....         55 808    54,50 K
    ff_vfw.dll     Mon 22 Aug 2005  13.55.18   A....          5 632     5,50 K
    iepeers.dll    Sat  3 Sep 2005   3.05.18   A....        250 880   245,00 K
    inseng.dll     Sat  3 Sep 2005   3.05.18   A....         96 256    94,00 K
    linkinfo.dll   Thu  1 Sep 2005   4.43.22   A....         19 968    19,50 K
    lv6009~1.dll   Tue 25 Oct 2005  15.07.24   ..S.R        234 937   229,43 K
    mshtml.dll     Wed  5 Oct 2005   3.26.04   A....      3 013 120     2,87 M
    mshtmled.dll   Sat  3 Sep 2005   3.05.18   A....        448 512   438,00 K
    msrating.dll   Sat  3 Sep 2005   3.05.18   A....        146 432   143,00 K
    mstime.dll     Sat  3 Sep 2005   3.05.18   A....        530 432   518,00 K
    netman.dll     Mon 22 Aug 2005  21.35.16   A....        197 632   193,00 K
    nwwks.dll      Thu 11 Aug 2005  18.11.34   A....         65 024    63,50 K
    pngfilt.dll    Sat  3 Sep 2005   3.05.18   A....         39 424    38,50 K
    quartz.dll     Tue 30 Aug 2005   6.55.44   A....      1 287 680     1,23 M
    s32evnt1.dll   Thu 28 Jul 2005  14.52.18   A....         91 856    89,70 K
    shdocvw.dll    Sat  3 Sep 2005   3.05.18   A....      1 483 264     1,41 M
    shell32.dll    Fri 23 Sep 2005   6.07.16   A....      8 454 656     8,06 M
    shlwapi.dll    Sat  3 Sep 2005   3.05.18   A....        473 600   462,50 K
    sirenacm.dll   Sat 13 Aug 2005  21.41.12   A....        118 784   116,00 K
    umpnpmgr.dll   Tue 23 Aug 2005   6.39.36   A....        123 904   121,00 K
    urlmon.dll     Sat  3 Sep 2005   3.05.18   A....        604 160   590,00 K
    wininet.dll    Sat  3 Sep 2005   3.05.18   A....        658 432   643,00 K
    winsrv.dll     Thu  1 Sep 2005   4.43.22   A....        291 840   285,00 K
 
 29 items found:  29 files (1 H/S), 0 directories.
    Total of file sizes:  23 289 993 bytes     22,21 M
 Locate .tmp files:
 
 No matches found.
 **********************************************************************************
 Directory Listing of system files:
  Asemalla C ei ole nime?.
  Aseman sarjanumero on 6C9B-97C7
 
  Kansio C:\WINDOWS\System32
 
 25.10.2005  15:07           234˙937 lv6009jme.dll
 13.10.2005  03:01    <KANSIO>       dllcache
 23.08.2005  20:04    <KANSIO>       Microsoft
                1 tiedosto(a)        234˙937 tavua
                2 kansio(ta)  91˙309˙109˙248 tavua vapaana
 
 
 Ja toinen.
 
 
 Logfile of HijackThis v1.99.1
 Scan saved at 17:03:29, on 25.10.2005
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
 C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
 C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 C:\Program Files\Norton Internet Security\ISSVC.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
 C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
 C:\WINDOWS\system32\nvsvc32.exe
 C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 C:\Program Files\UltraVNC\winvnc.exe
 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
 C:\Program Files\D-Tools\daemon.exe
 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
 C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
 C:\Program Files\EPoX\EPTP\EPTP.EXE
 C:\Program Files\Google\Gmail Notifier\gnotify.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\Program Files\MSN Messenger\MsnMsgr.Exe
 C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
 C:\Documents and Settings\Kalle Ratilainen\Työpöytä\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
 O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
 O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
 O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1035
 O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
 O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\winvnc.exe" -servicehelper
 O4 - HKLM\..\Run: [hwmdr] "C:\Program Files\EPoX\EPTP\EPTP.EXE" "5000"
 O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
 O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
 O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
 O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
 O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
 O23 - Service: Norton AntiVirus Auto-Protect -palvelu (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
 O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
 O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
 O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
 O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\winvnc.exe" -service (file missing)
 
  
							
						 
						
						
						
						 | 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						25. lokakuuta 2005 @ 13:08 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					 
					
					
					
						| 
						
						 
							
							Toi on "väärä" l2m-loki (sama ku se ensimmäinen). HjT-loki on kyllä ok.
 Tee näin:
 
 Jos käynnistyksen jälkeen kuvakkeet eivät häviä tai loki ei avaudu muistioon, tuplaklikkaa työpöydällä olevassa l2mfix-kansiossa olevaa second.bat, jotta fixi jatkuu. Ja lähetä sitten uusi hijackthis-loki ja se uusi l2m-loki.
							
						 
						
						
						
						 | 
					 
				
				
			
				
				
				
				
				
					
						| 
							
								 Madz^ 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						25. lokakuuta 2005 @ 13:14 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					 
					
					
					
						
						
						
							
							L2Mfix 1.04a
  
 Running From:
 C:\Documents and Settings\Kalle Ratilainen\Ty?p?yt?\l2mfix
  
  
 
 RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
 Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
 This program is Freeware, use it on your own risk!
 
 Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
 (CI)    DENY   --C-------   	BUILTIN\J?rjestelm?nvalvojat
 (NI)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (IO)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (NI)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (IO)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-NI) ALLOW  Read        	BUILTIN\K?ytt?j?t
 (ID-IO) ALLOW  Read        	BUILTIN\K?ytt?j?t
 (ID-NI) ALLOW  Read        	BUILTIN\Tehok?ytt?j?t
 (ID-IO) ALLOW  Read        	BUILTIN\Tehok?ytt?j?t
 (ID-NI) ALLOW  Full access 	BUILTIN\J?rjestelm?nvalvojat
 (ID-IO) ALLOW  Full access 	BUILTIN\J?rjestelm?nvalvojat
 (ID-NI) ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-IO) ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-IO) ALLOW  Full access 	LUOJA-OMISTAJA
 
 
  
 Setting registry permissions:
  
 
 RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
 Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
 This program is Freeware, use it on your own risk!
 
 
 Denying C(CI) access for predefined group "Administrators"
  - adding new ACCESS DENY entry
  - removing existing ACCESS DENY entry
 
  
 Registry Permissions set too:
 
 RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
 Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
 This program is Freeware, use it on your own risk!
 
 Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
 (CI)    DENY   --C-------   	BUILTIN\J?rjestelm?nvalvojat
 (NI)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (IO)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (NI)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (IO)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-NI) ALLOW  Read        	BUILTIN\K?ytt?j?t
 (ID-IO) ALLOW  Read        	BUILTIN\K?ytt?j?t
 (ID-NI) ALLOW  Read        	BUILTIN\Tehok?ytt?j?t
 (ID-IO) ALLOW  Read        	BUILTIN\Tehok?ytt?j?t
 (ID-NI) ALLOW  Full access 	BUILTIN\J?rjestelm?nvalvojat
 (ID-IO) ALLOW  Full access 	BUILTIN\J?rjestelm?nvalvojat
 (ID-NI) ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-IO) ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-IO) ALLOW  Full access 	LUOJA-OMISTAJA
 
 
  
 Setting up for Reboot
  
  
 Starting Reboot!
  
 Setting Directory
 C:\Documents and Settings\Kalle Ratilainen\Ty?p?yt?\l2mfix 
 System Rebooted! 
  
 Running From:
 C:\Documents and Settings\Kalle Ratilainen\Ty?p?yt?\l2mfix
  
 killing explorer and rundll32.exe 
 
 Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
 Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
 Killing PID 1564 'explorer.exe'
 
 Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
 Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
 Error, Cannot find a process with an image name of rundll32.exe
  
 Scanning First Pass. Please Wait!
  
 First Pass Completed 
  
 Second Pass Scanning 
  
 Second pass Completed!
 Backing Up: C:\WINDOWS\system32\lv6009jme.dll
         1 tiedosto(a) on kopioitu.
 deleting: C:\WINDOWS\system32\lv6009jme.dll  
 Successfully Deleted: C:\WINDOWS\system32\lv6009jme.dll
  
  
 Zipping up files for submission:
   adding: lv6009jme.dll (164 bytes security) (deflated 5%)
   adding: clear.reg (164 bytes security) (deflated 58%)
   adding: echo.reg (164 bytes security) (deflated 10%)
   adding: direct.txt (164 bytes security) (stored 0%)
   adding: lo2.txt (164 bytes security) (deflated 73%)
   adding: readme.txt (164 bytes security) (deflated 52%)
   adding: report.txt (164 bytes security) (deflated 66%)
   adding: test.txt (164 bytes security) (stored 0%)
   adding: test2.txt (164 bytes security) (deflated 39%)
   adding: test3.txt (164 bytes security) (deflated 39%)
   adding: test5.txt (164 bytes security) (deflated 39%)
   adding: xfind.txt (164 bytes security) (stored 0%)
   adding: backregs/15D24308-A0B9-4298-8DCD-E78B07FB628E.reg (164 bytes security) (deflated 70%)
   adding: backregs/3F6DAFB4-39D7-4172-92B1-CBDD37A78DDD.reg (164 bytes security) (deflated 70%)
   adding: backregs/4389221D-C245-4CA3-98C5-5E14A908E50D.reg (164 bytes security) (deflated 70%)
   adding: backregs/9EE87276-AF80-4F66-AE3F-4A4629FEAD6D.reg (164 bytes security) (deflated 70%)
   adding: backregs/A057FF86-C261-4483-A1C8-EFCD4EF60EA6.reg (164 bytes security) (deflated 70%)
   adding: backregs/notibac.reg (164 bytes security) (deflated 87%)
   adding: backregs/shell.reg (164 bytes security) (deflated 72%)
  
 Restoring Registry Permissions: 
  
 
 RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
 Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
 This program is Freeware, use it on your own risk!
 
 
 Revoking access for predefined group "Administrators"
 Inherited ACE can not be revoked here!
 Inherited ACE can not be revoked here!
 
  
 Registry permissions set too:
 
 RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
 Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
 This program is Freeware, use it on your own risk!
 
 Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
 (NI)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (IO)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (NI)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (IO)    ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-NI) ALLOW  Read        	BUILTIN\K?ytt?j?t
 (ID-IO) ALLOW  Read        	BUILTIN\K?ytt?j?t
 (ID-NI) ALLOW  Read        	BUILTIN\Tehok?ytt?j?t
 (ID-IO) ALLOW  Read        	BUILTIN\Tehok?ytt?j?t
 (ID-NI) ALLOW  Full access 	BUILTIN\J?rjestelm?nvalvojat
 (ID-IO) ALLOW  Full access 	BUILTIN\J?rjestelm?nvalvojat
 (ID-NI) ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-IO) ALLOW  Full access 	NT-HALLINTA\SYSTEM
 (ID-IO) ALLOW  Full access 	LUOJA-OMISTAJA
 
 
 Restoring Sedebugprivilege:
  
  Granting SeDebugPrivilege to Administrators   ... failed (GetAccountSid(Administrators)=1332 
  
 Restoring Windows Update Certificates.:
  
 deleting local copy: lv6009jme.dll   
  
 The following Is the Current Export of the Winlogon notify key:
 ****************************************************************************
 Windows Registry Editor Version 5.00
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
 "Asynchronous"=dword:00000000
 "Impersonate"=dword:00000000
 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
   6c,00,00,00
 "Logoff"="ChainWlxLogoffEvent"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
 "Asynchronous"=dword:00000000
 "Impersonate"=dword:00000000
 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
   6c,00,6c,00,00,00
 "Logoff"="CryptnetWlxLogoffEvent"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
 "DLLName"="cscdll.dll"
 "Logon"="WinlogonLogonEvent"
 "Logoff"="WinlogonLogoffEvent"
 "ScreenSaver"="WinlogonScreenSaverEvent"
 "Startup"="WinlogonStartupEvent"
 "Shutdown"="WinlogonShutdownEvent"
 "StartShell"="WinlogonStartShellEvent"
 "Impersonate"=dword:00000000
 "Asynchronous"=dword:00000001
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
 "DLLName"="wlnotify.dll"
 "Logon"="SCardStartCertProp"
 "Logoff"="SCardStopCertProp"
 "Lock"="SCardSuspendCertProp"
 "Unlock"="SCardResumeCertProp"
 "Enabled"=dword:00000001
 "Impersonate"=dword:00000001
 "Asynchronous"=dword:00000001
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
 "Asynchronous"=dword:00000000
 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
   6c,00,6c,00,00,00
 "Impersonate"=dword:00000000
 "StartShell"="SchedStartShell"
 "Logoff"="SchedEventLogOff"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
 "Logoff"="WLEventLogoff"
 "Impersonate"=dword:00000000
 "Asynchronous"=dword:00000001
 "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
   6c,00,6c,00,00,00
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
 "DLLName"="WlNotify.dll"
 "Lock"="SensLockEvent"
 "Logon"="SensLogonEvent"
 "Logoff"="SensLogoffEvent"
 "Safe"=dword:00000001
 "MaxWait"=dword:00000258
 "StartScreenSaver"="SensStartScreenSaverEvent"
 "StopScreenSaver"="SensStopScreenSaverEvent"
 "Startup"="SensStartupEvent"
 "Shutdown"="SensShutdownEvent"
 "StartShell"="SensStartShellEvent"
 "PostShell"="SensPostShellEvent"
 "Disconnect"="SensDisconnectEvent"
 "Reconnect"="SensReconnectEvent"
 "Unlock"="SensUnlockEvent"
 "Impersonate"=dword:00000001
 "Asynchronous"=dword:00000001
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
 "Asynchronous"=dword:00000000
 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
   6c,00,6c,00,00,00
 "Impersonate"=dword:00000000
 "Logoff"="TSEventLogoff"
 "Logon"="TSEventLogon"
 "PostShell"="TSEventPostShell"
 "Shutdown"="TSEventShutdown"
 "StartShell"="TSEventStartShell"
 "Startup"="TSEventStartup"
 "MaxWait"=dword:00000258
 "Reconnect"="TSEventReconnect"
 "Disconnect"="TSEventDisconnect"
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
 "DLLName"="wlnotify.dll"
 "Logon"="RegisterTicketExpiredNotificationEvent"
 "Logoff"="UnregisterTicketExpiredNotificationEvent"
 "Impersonate"=dword:00000001
 "Asynchronous"=dword:00000001
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
 "DLLName"="wzcdlg.dll"
 "Logon"="WZCEventLogon"
 "Logoff"="WZCEventLogoff"
 "Impersonate"=dword:00000000
 "Asynchronous"=dword:00000000
 
  
 The following are the files found: 
 ****************************************************************************
 C:\WINDOWS\system32\lv6009jme.dll 
  
 Registry Entries that were Deleted: 
 Please verify that the listing looks ok.  
 If there was something deleted wrongly there are backups in the backreg folder. 
 ****************************************************************************
 REGEDIT4
 
 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
 "{A057FF86-C261-4483-A1C8-EFCD4EF60EA6}"=-
 "{D20FC2A5-6998-47F2-9DD8-7EEC25FB7D23}"=-
 "{3F6DAFB4-39D7-4172-92B1-CBDD37A78DDD}"=-
 "{4389221D-C245-4CA3-98C5-5E14A908E50D}"=-
 "{15D24308-A0B9-4298-8DCD-E78B07FB628E}"=-
 "{9EE87276-AF80-4F66-AE3F-4A4629FEAD6D}"=-
 [-HKEY_CLASSES_ROOT\CLSID\{A057FF86-C261-4483-A1C8-EFCD4EF60EA6}]
 [-HKEY_CLASSES_ROOT\CLSID\{D20FC2A5-6998-47F2-9DD8-7EEC25FB7D23}]
 [-HKEY_CLASSES_ROOT\CLSID\{3F6DAFB4-39D7-4172-92B1-CBDD37A78DDD}]
 [-HKEY_CLASSES_ROOT\CLSID\{4389221D-C245-4CA3-98C5-5E14A908E50D}]
 [-HKEY_CLASSES_ROOT\CLSID\{15D24308-A0B9-4298-8DCD-E78B07FB628E}]
 [-HKEY_CLASSES_ROOT\CLSID\{9EE87276-AF80-4F66-AE3F-4A4629FEAD6D}]
 REGEDIT4
 
 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
 "SV1"=""
 ****************************************************************************
 Desktop.ini Contents: 
 ****************************************************************************
 ****************************************************************************
 
 
 
 
 Ja Hijack 
 
 Logfile of HijackThis v1.99.1
 Scan saved at 17:14:41, on 25.10.2005
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
 C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
 C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 C:\Program Files\Norton Internet Security\ISSVC.exe
 C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
 C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
 C:\WINDOWS\system32\nvsvc32.exe
 C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 C:\Program Files\UltraVNC\winvnc.exe
 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
 C:\Program Files\D-Tools\daemon.exe
 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
 C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
 C:\Program Files\EPoX\EPTP\EPTP.EXE
 C:\Program Files\Google\Gmail Notifier\gnotify.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\Program Files\MSN Messenger\MsnMsgr.Exe
 C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\WINDOWS\explorer.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\Documents and Settings\Kalle Ratilainen\Työpöytä\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
 O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
 O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
 O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1035
 O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
 O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\winvnc.exe" -servicehelper
 O4 - HKLM\..\Run: [hwmdr] "C:\Program Files\EPoX\EPTP\EPTP.EXE" "5000"
 O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
 O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
 O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
 O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
 O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
 O23 - Service: Norton AntiVirus Auto-Protect -palvelu (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
 O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
 O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
 O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
 O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\winvnc.exe" -service (file missing)
 
 
 
 Siinäpä nuo.. Kiitoksia muuten paljon vaan tästäkin avusta jo :)  
							
						 
						
						
						
						 | 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						25. lokakuuta 2005 @ 13:22 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					 
					
					
					
						| 
						
						 
							
							Ole hyvä, kummatkin lokit on kunnossa, joten mainoksia ei varmaan enää tule? :)
							
						 
						
						
						
						 | 
					 
				
				
			
				
				
				
				
				
					
						| 
							
								 Madz^ 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						25. lokakuuta 2005 @ 13:25 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					 
					
					
					
						| 
						
						 
							
							Mainoksia ei ole tullut nyt :) .. Kiitoksia paljon -kemisti- ! :) .. pitää vielä noita turhia hidastavia ohjelmia tuolla hijackilla :) .. mutta osaan lukea niitä nyt itsekkin jo  
							
						 
						
						
						
						 | 
					 
				
				
			
				
				
				
					
						| 
							 Mainos 
							 
						 | 
						   | 
					 
					
						
							
							  
								
							
						 | 
					 
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						25. lokakuuta 2005 @ 13:38 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					 
					
					
					
						| 
						
						 
							
							Ole hyvä :) Katso kuitenkin, että et poista mitään tärkeää :)
 
 Nämä voit ottaa pois (eli fixata HjT:llä, kaks viimeistä, jos ei messengerien tarvitse käynnistyä, kun kone käynnistyy):
 
 O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
							
						 
						
						
						
							Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 25. lokakuuta 2005 @ 13:38 
						
						 | 
					 
				
				
			
			
			
			
			
		 
		
	
			
			
		
	 |