| 
					Polonaisev virus vaivaa myllyä, ja siitä olis logi tarkastettavaksi
				 | 
				
				
					
				 | 
				
			
			
			
			
				
					
					
				
			
			
			
			
			
				
				
					
				
				
				
				
					
						| 
							
								 icete4 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						26. lokakuuta 2005 @ 13:43 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						
						
						
							
							Eli koneelle on kätkeytynyt polonaisev virus.
 Luin polonaisev:ia koskevan viestiketjun ja nyt olis oma logi tarkastettavaksi.
 
 Eli logi olis tässä:
 
 
 
 Logfile of HijackThis v1.99.1
 Scan saved at 17:35:24, on 26.10.2005
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\LEXBCES.EXE
 C:\WINDOWS\system32\LEXPPS.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\WINDOWS\system32\RunDll32.exe
 C:\WINDOWS\Dit.exe
 C:\WINDOWS\mHotkey.exe
 C:\WINDOWS\CNYHKey.exe
 C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
 C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
 C:\WINDOWS\system32\rundll32.exe
 C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE
 C:\Program Files\D-Tools\daemon.exe
 C:\WINDOWS\system32\rmctrl.exe
 C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
 C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
 C:\Program Files\QuickTime\qttask.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
 C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
 C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
 C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
 C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
 C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
 C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
 C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
 C:\WINDOWS\DitExp.exe
 C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
 C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
 C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
 C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
 C:\Program Files\F-Secure Internet Security\FSPC\fspc.exe
 C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
 C:\Program Files\F-Secure Internet Security\FSGUI\fsguiexe.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\Program Files\Winamp\winamp.exe
 C:\hijackthis\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://laajakaista.elisa.net/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
 O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\Ipswitch\WS_FTP Home\wsbho2k0.dll
 O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
 O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
 O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
 O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
 O4 - HKLM\..\Run: [Dit] Dit.exe
 O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
 O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
 O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
 O4 - HKLM\..\Run: [Camera Detector] C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE -autorun
 O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
 O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\system32\rmctrl.exe
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [security] C:\WINDOWS\system32\wsecure32.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
 O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
 O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
 O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [windows] C:\WINDOWS\winntlogon.exe
 O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
 O9 - Extra button: Web-suodatin - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
 O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
 O9 - Extra 'Tools' menuitem: Näytä &Web-sivuluettelo... - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
 O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
 O9 - Extra 'Tools' menuitem: &Keskeytä Web-sivujen suodatus - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
 O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
 O9 - Extra 'Tools' menuitem: &Kiellä tämä Web-sivusto - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
 O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
 O9 - Extra 'Tools' menuitem: &Salli tämä Web-sivusto - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O10 - Broken Internet access because of LSP provider 'winsflt.dll' missing
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x8... O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - file://F:\ols\cd-db\fscax.cab
 O23 - Service: Atm28ok - ATI Technologies Inc. - (no file)
 O23 - Service: F-Secure product (BackWeb Plug-in - 4476822) - Unknown owner - C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
 O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
 O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
 O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
 O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
 O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
 O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSPC\fshttps\fshttps.exe
 O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
 O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
 O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
 
 Nyt jos joku viisaampi osaisi kertoa mitä pitäis tehdä?
							
						 
						
						
						
						 | 
					
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						26. lokakuuta 2005 @ 13:52 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						
						
						
							
							Hae LSPFix tuolta (joko se zippi tai sitten exe).
 http://cexx.org/lspfix.htm 
 Tallenna se vaikka työpöydälle tai johonkin hakemistoon.
 
 Avaa LSPFix
 
 Laita rasti ruutuun, "I know what I?m doing".
 
 Klikkaa vasemmassa ruudussa olevaa winsflt.dll , siirrä se oikealla olevaan ruutuun nuolinäppäimellä, klikkaa "Remove" ja sulje LSPFix.
 
 Fixaa HjT:llä (do a system scan only, merkkaa nämä ja paina fix checked):
 
 O4 - HKLM\..\Run: [security] C:\WINDOWS\system32\wsecure32.exe
 O4 - HKCU\..\Run: [windows] C:\WINDOWS\winntlogon.exe 
 
 Laita piilotiedostot näkyviin, ohje ->http://keskustelu.afterdawn.com/thread_view.cfm/248944 
 Käynnistä vikasietotilaan (F8 käynnistyksen yhteydessä) ja poista:
 
 C:\WINDOWS\system32\==>wsecure32.exe<==
 C:\WINDOWS\==>winntlogon.exe<==
 
 Käynnistä kone uudestaan ja lähetä uusi hijackthis-loki.
							
						 
						
						
						
						 | 
					
				
				
			
				
				
				
				
				
					
						| 
							
								 icete4 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						26. lokakuuta 2005 @ 14:18 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						
						
						
							
							Logfile of HijackThis v1.99.1
 Scan saved at 18:17:37, on 26.10.2005
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\LEXBCES.EXE
 C:\WINDOWS\system32\LEXPPS.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
 C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
 C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
 C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
 C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
 C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
 C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
 C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
 C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
 C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
 C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\WINDOWS\system32\RunDll32.exe
 C:\WINDOWS\Dit.exe
 C:\WINDOWS\mHotkey.exe
 C:\WINDOWS\CNYHKey.exe
 C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
 C:\WINDOWS\system32\rundll32.exe
 C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE
 C:\Program Files\D-Tools\daemon.exe
 C:\WINDOWS\system32\rmctrl.exe
 C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
 C:\Program Files\QuickTime\qttask.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
 C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
 C:\WINDOWS\DitExp.exe
 C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
 C:\Program Files\MSN Messenger\MsnMsgr.Exe
 C:\Program Files\F-Secure Internet Security\FSPC\fspc.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
 C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
 C:\Program Files\F-Secure Internet Security\FSGUI\fsguiexe.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\hijackthis\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://laajakaista.elisa.net/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
 O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\Ipswitch\WS_FTP Home\wsbho2k0.dll
 O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
 O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
 O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
 O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
 O4 - HKLM\..\Run: [Dit] Dit.exe
 O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
 O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
 O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
 O4 - HKLM\..\Run: [Camera Detector] C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE -autorun
 O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
 O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\system32\rmctrl.exe
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
 O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
 O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
 O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
 O9 - Extra button: Web-suodatin - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
 O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
 O9 - Extra 'Tools' menuitem: Näytä &Web-sivuluettelo... - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
 O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
 O9 - Extra 'Tools' menuitem: &Keskeytä Web-sivujen suodatus - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
 O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
 O9 - Extra 'Tools' menuitem: &Kiellä tämä Web-sivusto - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
 O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
 O9 - Extra 'Tools' menuitem: &Salli tämä Web-sivusto - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x8... O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - file://F:\ols\cd-db\fscax.cab
 O23 - Service: Atm28ok - ATI Technologies Inc. - (no file)
 O23 - Service: F-Secure product (BackWeb Plug-in - 4476822) - Unknown owner - C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
 O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
 O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
 O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
 O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
 O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
 O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSPC\fshttps\fshttps.exe
 O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
 O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
 O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
							
						 
						
						
						
						 | 
					
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						26. lokakuuta 2005 @ 14:20 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						| 
						
						 
							
							Loki on ok. Onko vielä ongelmia?
							
						 
						
						
						
						 | 
					
				
				
			
				
				
				
				
				
					
						| 
							
								 icete4 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						26. lokakuuta 2005 @ 14:28 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						| 
						
						 
							
							ei mitään, muuta ku kone aina välil jumittaa ja sammuu sitten....
 Mut se kai johtuu paskasta koneesta?
 Kiitoksia tuhannesti avusta viruksen poistosta, oli meinaan harvinaisen vittumainen virus...! :)
							
						 
						
						
						
						 | 
					
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
   1 tuotearvio
								
							
							 
							 
						 | 
						26. lokakuuta 2005 @ 14:35 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						| 
						
						 
							
							Minkälainen kone? F-secure voi jumittaa konetta välillä, niinkuin minulla :P 
							
						 
						
						 
						
						 | 
					
				
				
			
				
				
				
				
				
					
						| 
							
								 icete4 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						26. lokakuuta 2005 @ 14:38 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						| 
						
						 
							
							melkeen samanlainen kone ku sulla, eri näytön ohjain vaan. ja f-secure löytyy.
							
						 
						
						
						
						 | 
					
				
				
			
				
				
				
				
				
					
						| 
							
								 Hakkeri* 
							
							
								
									
									
										Suspended permanently
									
								
							
							 
							 
						 | 
						26. lokakuuta 2005 @ 14:41 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						| 
						
						 
							
							f-secure on paska.. miks maksaa tollasesta paskasta ku ilmasetkin on parempia..
							
						 
						
						
						
						 | 
					
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
   1 tuotearvio
								
							
							 
							 
						 | 
						26. lokakuuta 2005 @ 16:19 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						| 
						
						 
							
							@Hakkeri*:
 
 Mitä sä meet paskasta puhumaan? Sun tiedot on aika vähissä jos meet f-securea haukkumaan.. 
							
						 
						
						 
						
						 | 
					
				
				
			
				
				
				
					
						| 
							 Mainos 
							 
						 | 
						   | 
					
					
						
							
							  
								
							
						 | 
					
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						26. lokakuuta 2005 @ 16:25 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						| 
						
						
						
						
						
						 |