| 
		
		
			
		
		
	 | 
												  
												
													
	
		| 
			 Keskustelualueet 
			Keskustelualueet 
		 | 
		
			
				
					
						
			
			
		
					
				
			 | 
		
	 
 
														
															
															
	
			
			
				| 
					Kone käynnistyy hitaasti
				 | 
				
				
					
				 | 
				
			 
			
			
			
				
					
					
				 
			
			
			
			
			
				
				
					
				
				
				
				
					
						| 
							
								 jetuomin 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						26. elokuuta 2006 @ 21:13 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					 
					
					
					
						
						
						
							
							Löytyykö logista jotakin epämääräistä?
 Kiitos.
 
 Logfile of HijackThis v1.99.1
 Scan saved at 01:06, on 06-08-27
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\Program Files\HPQ\IAM\bin\asghost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\NavNT\defwatch.exe
 C:\Program Files\NavNT\rtvscan.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE
 C:\WINDOWS\system32\dla\tfswctrl.exe
 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
 C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
 C:\WINDOWS\system32\LVCOMSX.EXE
 C:\Program Files\Logitech\Video\LogiTray.exe
 C:\Program Files\NavNT\vptray.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\Program Files\MSN Messenger\MsnMsgr.Exe
 C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
 C:\Program Files\USB Phone\USB Driver\USB Phone Driver.exe
 C:\WINDOWS\system32\MsgSys.EXE
 C:\Program Files\iPod\bin\iPodService.exe
 C:\Program Files\Logitech\Video\FxSvr2.exe
 C:\Program Files\HPQ\SHARED\HPQWMI.exe
 C:\WINDOWS\System32\svchost.exe
 C:\HijackThis\HijackThis_v1.99.1.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O2 - BHO: HP Credential Manager for ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\HPQ\IAM\Bin\ItIeAddIN.dll
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
 O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
 O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
 O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
 O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
 O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\HPQ\IAM\Bin\AsTsVcc.dll,RegisterModule
 O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
 O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
 O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
 O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe 
 O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
 O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
 O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
 O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
 O4 - Startup: USB Phone Driver Startup.lnk = ?
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
 O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
 O20 - AppInit_DLLs: ASAPHook
 O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
 O20 - Winlogon Notify: OneCard - C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
 O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
 O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
							
						 
						
						
						
						 | 
					 
				
				
			
				
				
				
				
				
					
						| 
							
								 jetuomin 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						26. elokuuta 2006 @ 21:17 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					 
					
					
					
						
						
						
							
							Tässä vielä combofixin logi
 
  - 06-08-27  0:33:26,14 
 ComboFix 06.08.26BT - Running from: C:\Program Files\Mozilla Firefox 
 
 ((((((((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
  
  
 C:\WINDOWS\system32\ati2evxx.dll
 C:\WINDOWS\system32\ati2evxx.dll	 
  
  
 (((((((((((((((((((((((((((((((   Files Created from 2006-07-27 to 2006-08-27  ))))))))))))))))))))))))))))))))))
  
 
 No new files created in this timespan 
  
 
 ((((((((((((((((((((((((((((((((((((((((((((((((   Find3M Report   )))))))))))))))))))))))))))))))))))))))))))))))))))))
 
 
 2006-08-27 00:32	--------	d--------	C:\Program Files\Mozilla Firefox
 2006-08-27 00:26	--------	d--------	C:\Program Files\Mozilla Thunderbird
 2006-08-27 00:18	--------	d--------	C:\Documents and Settings\Eila\Application Data\Skype
 2006-08-13 10:38	--------	d--------	C:\Program Files\Internet Explorer
 2006-07-27 16:26	679424	--a------	C:\WINDOWS\system32\inetcomm.dll
 2006-07-21 11:28	72704	--a------	C:\WINDOWS\system32\hlink.dll
  
 
 ((((((((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))
  
 *Note* empty entries are not shown
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
 "ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
 "PTHOSTTR"="C:\\Program Files\\HPQ\\HP ProtectTools Security Manager\\PTHOSTTR.EXE /Start"
 "UpdateManager"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
 "dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
 "SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
 "SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
 "hpWirelessAssistant"="C:\\Program Files\\hpq\\HP Wireless Assistant\\HP Wireless Assistant.exe"
 "eabconfg.cpl"="C:\\Program Files\\HPQ\\Quick Launch Buttons\\EabServr.exe /Start"
 "CognizanceTS"="rundll32.exe C:\\PROGRA~1\\HPQ\\IAM\\Bin\\AsTsVcc.dll,RegisterModule"
 "Cpqset"="C:\\Program Files\\HPQ\\Default Settings\\cpqset.exe"
 "WatchDog"="C:\\Program Files\\InterVideo\\DVD Check\\DVDCheck.exe"
 "LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
 "LogitechVideoRepair"="C:\\Program Files\\Logitech\\Video\\ISStart.exe "
 "LogitechVideoTray"="C:\\Program Files\\Logitech\\Video\\LogiTray.exe"
 "vptray"="C:\\Program Files\\NavNT\\vptray.exe"
 "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
 "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
 "Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
 "Installed"="1"
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
 "NoChange"="1"
 "Installed"="1"
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
 "Installed"="1"
 
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
 "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
 "MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
 "LDM"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\BackWeb-8876480.exe"
 "LogitechSoftwareUpdate"="\"C:\\Program Files\\Logitech\\Video\\ManifestEngine.exe\" boot"
 "updateMgr"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_7 -reboot 1"
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
 "dontdisplaylastusername"=dword:00000000
 "legalnoticecaption"=""
 "legalnoticetext"=""
 "shutdownwithoutlogon"=dword:00000001
 "undockwithoutlogon"=dword:00000001
 
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
 "NoDriveTypeAutoRun"=dword:00000091
 
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
 
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
 "DeskHtmlVersion"=dword:00000110
 "DeskHtmlMinorVersion"=dword:00000005
 "Settings"=dword:00000001
 "GeneralFlags"=dword:00000001
 
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
 "Source"="About:Home"
 "SubscribedURL"="About:Home"
 "FriendlyName"="Nykyinen kotisivu"
 "Flags"=dword:00000002
 "Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
   00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
 "CurrentState"=hex:04,00,00,40
 "OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
   ff,ff,04,00,00,00
 "RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
   00,00,01,00,00,00
 
 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
 
 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
 "NoDriveTypeAutoRun"=dword:00000091
 
 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
 
 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
 "NoDriveTypeAutoRun"=dword:00000091
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\sharedtaskscheduler]
 "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
 "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
 "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
   
 HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard
  
  
 Completion time: Sun 27.08.2006  0:35:35.55 
 ComboFix.txt
							
						 
						
						
						
						 | 
					 
				
				
			
				
				
				
				
				
					
						| 
							
								 sasesi 
							
							
								Junior Member
								
									
								
							
							 
							 
						 | 
						27. elokuuta 2006 @ 05:39 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					 
					
					
					
						
						
						
							
							Eivät ole viruksia/spywarea, mutta turhia mitkä hidastavat tietokoneen avautumista: 
 
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe 
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime 
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe 
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe 
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" 
 O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r 
 O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
 O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1 
 
 Sinulla on vanha versio Javasta joten asennamme uuden:
 
 Ensin poistamme vanhan version.
 Paina ??Käynnistä-valikkoa?? Sieltä ??Ohjauspaneeli?? ja ??Lisää tai poista sovellus??.
 Etsi listasta kaikki ??J2SE Runtime Enviroment?? alkuiset sovellukset ja poista ne.
 Lataa sitten uusi versio tuosta: http://jdl.sun.com/webapps/download/AutoDL?BundleId=10695 ja asenna se. (Pidä Internet-selaimet suljettuna asennuksen aikana)
 Nyt sinulla on uusin versio Javasta.
 
 Mitään vakavaa silmiini e logista osu
							
						 
						
						
						
						 | 
					 
				
				
			
				
				
				
					
						| 
							 Mainos 
							 
						 | 
						   | 
					 
					
						
							
							  
								
							
						 | 
					 
				
				
				
					
						| 
							
								 jetuomin 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						27. elokuuta 2006 @ 11:55 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					 
					
					
					
						| 
						
						 
							
							Kiitos nopeasta vastauksesta.
 Tein ohjeiden mukaisesti.
							
						 
						
						
						
						 | 
					 
				
				
			
			
			
				
				
					
				 
				
			
			
			
		 
		
	
			
			
		
	 |