| 
					isnotify.exe ja issearch.exe.APUA
				 | 
				
				
					
				 | 
				
			
			
			
			
				
					
					
				
			
			
			
			
			
				
				
					
				
				
				
				
					
						| 
							
								 miryt79 
							
							
								
									Suspended due to non-functional email address
								
							
							 
							 
						 | 
						9. syyskuuta 2006 @ 09:58 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						
						
						
							
							Help! Alla HjT logi:
 ogfile of HijackThis v1.99.1
 Scan saved at 13:21:05, on 1.9.2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Common Files\STOPzilla!\SZServer.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
 C:\WINDOWS\system32\CTsvcCDA.EXE
 C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
 C:\Program Files\F-Secure\BackWeb\7681197\Program\BackWeb-7681197.exe
 C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
 C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
 C:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE
 C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
 C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
 C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
 C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 C:\Program Files\F-Secure\Common\FSMA32.EXE
 C:\Program Files\F-Secure\Common\FSMB32.EXE
 C:\Program Files\F-Secure\Common\FCH32.EXE
 C:\Program Files\F-Secure\Common\FAMEH32.EXE
 C:\Program Files\F-Secure\Common\FNRB32.EXE
 C:\Program Files\F-Secure\Common\FIH32.EXE
 C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\ishost.exe
 C:\WINDOWS\system32\issearch.exe
 C:\WINDOWS\system32\isnotify.exe
 C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
 C:\WINDOWS\system32\ismon.exe
 C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 C:\Program Files\F-Secure\Common\FSM32.EXE
 C:\PROGRA~1\PESTPA~1\PPControl.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
 C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
 C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
 C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
 C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
 C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
 C:\Program Files\WinZip\WZQKPICK.EXE
 C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
 C:\Documents and Settings\Mika\Omat tiedostot\Ajurit\hijackthis\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fi\msntb.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
 O3 - Toolbar: (no name) - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - (no file)
 O3 - Toolbar: Safety Bar - {052b12f7-86fa-4921-8482-26c42316b522} - C:\Program Files\Safety Bar\SafetyBar.dll
 O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
 O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
 O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
 O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
 O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
 O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
 O4 - HKLM\..\Run: [STOPzilla] C:\Program Files\STOPzilla!\STOPzilla.exe /autostart
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
 O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
 O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
 O4 - Global Startup: WinZIP Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
 O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
 O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
 O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - C:\WINDOWS\system32\urroxtl.dll (file missing)
 O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
 O23 - Service: F-Secure BackWeb (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
 O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
 O23 - Service: F-Secure BackWeb LAN Access - Unknown owner - C:\Program Files\F-Secure\BackWeb\7681197\Program\fsbwlan.exe
 O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
 O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
 O23 - Service: F-Secure Authentication Agent (FSAA) - F-Secure Corporation. All Rights Reserved. - C:\Program Files\F-Secure\Common\FSAA.EXE
 O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
 O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE
 O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
 O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
 O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
 O23 - Service: STOPzilla Service (szserver) - Unknown owner - C:\Program Files\Common Files\STOPzilla!\SZServer.exe
 O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 
 
 Ei lähde,ei. Onko edessä koneen alustaminen?Toivottavasti pystyypi joku auttamaan...
 
 t:miry
							
						 
						
						
						
						 | 
					
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						9. syyskuuta 2006 @ 12:21 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						
						
						
							
							Ei ole.
 
 Lataa SmitfraudFix (c) S!Ri
 http://siri.urz.free.fr/Fix/SmitfraudFix.zip
 Pura sisältö (kansio nimeltä SmitfraudFix) työpöydällesi:
 
 Avaa SmitfraudFix-kansio ja tuplaklikkaa smitfraudfix.cmd
 Valitse optio #1 - Search kirjoittamalla 1 ja painamalla "Enter"; tekstitiedosto avautuu, joka listaa tarttuneet tiedostot (jos olemassa).
 Postita tämän tekstitiedoston sisältö viestiketjuusi. 
							
						 
						
						
 Ei HjT-lokeja tms. yksityisviestillä! 
						
						 | 
					
				
				
			
				
				
				
				
				
					
						| 
							
								 miryt79 
							
							
								
									Suspended due to non-functional email address
								
							
							 
							 
						 | 
						9. syyskuuta 2006 @ 12:49 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						| 
						
						 
							
							SmitFraudFix v2.84
 
 Scan done at 16:43:12,01, pe 01.09.2006
 Run from C:\Documents and Settings\Mika\Ty?p?yt?\smitfraud\SmitfraudFix
 OS: Microsoft Windows XP [versio 5.1.2600] - Windows_NT
 Fix ran in normal mode
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
 
 C:\WINDOWS\system32\ishost.exe FOUND !
 C:\WINDOWS\system32\ismon.exe FOUND !
 C:\WINDOWS\system32\isnotify.exe FOUND !
 C:\WINDOWS\system32\issearch.exe FOUND !
 C:\WINDOWS\system32\ixt?.dll FOUND !
 C:\WINDOWS\system32\ixt??.dll FOUND !
 C:\WINDOWS\system32\ot.ico FOUND !
 C:\WINDOWS\system32\ts.ico FOUND !
 C:\WINDOWS\system32\components\flx?.dll FOUND !
 C:\WINDOWS\system32\components\flx??.dll FOUND !
 C:\WINDOWS\system32\components\flx???.dll FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Mika\Application Data
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
 
 C:\DOCUME~1\ALLUSE~1\KYNNIS~1\Online Security Guide.url FOUND !
 C:\DOCUME~1\ALLUSE~1\KYNNIS~1\Security Troubleshooting.url FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Mika\Suosikit
 
 C:\DOCUME~1\Mika\Suosikit\Antivirus Test Online.url FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop
 
 C:\DOCUME~1\ALLUSE~1\TYPYT~1\Online Security Guide.url FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files 
 
 C:\Program Files\Safety Bar\ FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
  
 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
 "Source"="About:Home"
 "SubscribedURL"="About:Home"
 "FriendlyName"="Nykyinen kotisivu"
  
 
 »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
 "incestuously"="{03413bf7-e34c-445b-bfc0-a2b127255871}"
 
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
 !!!Attention, following keys are not inevitably infected!!!
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
 "AppInit_DLLs"=""
 
 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
							
						 
						
						
						
						 | 
					
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						9. syyskuuta 2006 @ 13:16 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						
						
						
							
							Printtaa ohjeet ulos.
 
 Käynnistä koneesi vikasietotilaan ja valitse tavallinen käyttäjätilisi.
 
 Kun vikasietotilassa, avaa SmitfraudFix-kansio ja tuplaklikkaa smitfraudfix.cmd
 Valitse optio #2 - Clean kirjoittamalla 2 ja painamalla "Enter" poistaaksesi tarttuneet tiedostot.
 
 Sinulta kysytään: "Registry cleaning - Do you want to clean the registry ?"; vastaa "Yes" kirjoittamalla Y ja paina "Enter" poistaaksesi työpöydän  taustakuvan ja puhdistaaksesi tarttuneet rekisteriavaimet.
 
 Työkalu tarkistaa jos wininet.dll on tarttunut. Sinua saatetaan pyytää korvaamaan tarttunut .dll (jos löytyy); vastaa "Yes" kirjoittamalla Y ja painamalla "Enter".
 
 Työkalun saattaa tarvita käynnistää kone uudelleen; jos ei tee niin, käynnistä normaaliin Windowsiin.
 Tekstitiedosto ilmestyy, puhdistusprosessin jäljiltä; kopioi & liitä tämän raportin tulokset vastaukseesi.
 Raportti löytyy paikalliselta levyltäsi, useimmiten C:\rapport.txt.
 
 Lähetä sen sisältö ja uusi HjT-loki tänne. 
							
						 
						
						
 Ei HjT-lokeja tms. yksityisviestillä! 
						
						 | 
					
				
				
			
				
				
				
				
				
					
						| 
							
								 miryt79 
							
							
								
									Suspended due to non-functional email address
								
							
							 
							 
						 | 
						10. syyskuuta 2006 @ 12:35 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						
						
						
							
							Moikka
 Kiitokset nyt jo avusta...Alla smitfraudin logi ja sen jälkeen hjt:n logi
 
 ________________
 SmitFraudFix v2.84
 
 Scan done at 16:17:06,93, la 02.09.2006
 Run from C:\Documents and Settings\Mika\Ty?p?yt?\smitfraud\SmitfraudFix
 OS: Microsoft Windows XP [versio 5.1.2600] - Windows_NT
 Fix ran in safe mode
 
 »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
 "incestuously"="{03413bf7-e34c-445b-bfc0-a2b127255871}"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Killing process
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
 
 GenericRenosFix by S!Ri
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
 
 C:\WINDOWS\system32\ishost.exe Deleted
 C:\WINDOWS\system32\ismon.exe Deleted
 C:\WINDOWS\system32\isnotify.exe Deleted
 C:\WINDOWS\system32\issearch.exe Deleted
 C:\WINDOWS\system32\ixt?.dll Deleted
 C:\WINDOWS\system32\ixt??.dll Deleted
 C:\WINDOWS\system32\ot.ico Deleted
 C:\WINDOWS\system32\ts.ico Deleted
 C:\WINDOWS\system32\components\flx?.dll Deleted
 C:\WINDOWS\system32\components\flx??.dll Deleted
 C:\WINDOWS\system32\components\flx???.dll Deleted
 C:\DOCUME~1\ALLUSE~1\TYPYT~1\Online Security Guide.url Deleted
 C:\DOCUME~1\Mika\Suosikit\Antivirus Test Online.url Deleted
 C:\DOCUME~1\ALLUSE~1\KYNNIS~1\Online Security Guide.url Deleted
 C:\DOCUME~1\ALLUSE~1\KYNNIS~1\Security Troubleshooting.url Deleted
 C:\Program Files\Safety Bar\ Deleted
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
  
 Registry Cleaning done. 
  
 »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 
 
 HJT________
 
 Logfile of HijackThis v1.99.1
 Scan saved at 16:29:16, on 2.9.2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
 C:\WINDOWS\system32\CTsvcCDA.EXE
 C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
 C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
 C:\Program Files\F-Secure\BackWeb\7681197\Program\BackWeb-7681197.exe
 C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
 C:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE
 C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
 C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
 C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
 C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 C:\Program Files\F-Secure\Common\FSMA32.EXE
 C:\Program Files\F-Secure\Common\FSMB32.EXE
 C:\Program Files\F-Secure\Common\FCH32.EXE
 C:\Program Files\F-Secure\Common\FAMEH32.EXE
 C:\Program Files\F-Secure\Common\FNRB32.EXE
 C:\Program Files\F-Secure\Common\FIH32.EXE
 C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
 C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 C:\Program Files\F-Secure\Common\FSM32.EXE
 C:\PROGRA~1\PESTPA~1\PPControl.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
 C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
 C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
 C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
 C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
 C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
 C:\Program Files\WinZip\WZQKPICK.EXE
 C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
 C:\WINDOWS\system32\msiexec.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\Documents and Settings\Mika\Omat tiedostot\Ajurit\hijackthis\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fi\msntb.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
 O3 - Toolbar: (no name) - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - (no file)
 O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
 O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
 O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
 O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
 O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
 O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
 O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
 O4 - Global Startup: WinZIP Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
 O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
 O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
 O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
 O23 - Service: F-Secure BackWeb (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
 O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
 O23 - Service: F-Secure BackWeb LAN Access - Unknown owner - C:\Program Files\F-Secure\BackWeb\7681197\Program\fsbwlan.exe
 O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
 O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
 O23 - Service: F-Secure Authentication Agent (FSAA) - F-Secure Corporation. All Rights Reserved. - C:\Program Files\F-Secure\Common\FSAA.EXE
 O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
 O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE
 O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
 O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
 O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
 O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 
 t:miryt
							
						 
						
						
						
						 | 
					
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						10. syyskuuta 2006 @ 12:37 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						
						
						
							
							Tuo fixiin:
 
 O3 - Toolbar: (no name) - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - (no file)
 
 Java päivitykseen:
 
 Javan päivitys ja välimuistin tyhjennys
 
 [*]Klikkaa Käynnistä > Ohjauspaneeli ja tupla-klikkaa Java kuvaketta (kahvikuppi) Ohjauspaneelissa.
 [*]Mene "Update" -välilehteen Java asetusikkunassasi. Päivitä Javasi klikkaamalla "Update Now" ja sitten käynnistä uudelleen.
 [*]Jos et pysty päivittämään automaattisesti, hae manuaalisesti täältä:
 
 http://www.java.com/en/download/manual.jsp
 [/list]
 [*]Käynnistyksen jälkeen, mene takaisin Ohjauspaneeliin ja siitä Java asetuksiisi.
 [*]Temporary Internet Files -osion alla, klikkaa Delete Files nappia.
 [*]Varmista että kaikki kolme valintaa ovat rastitettuja:
 
 Downloaded Applets
 Downloaded Applications
 Other Files
 
 [*]Klikkaa OK "Delete Temporary Internet Files" -ikkunassasi.
 Huomaa: Tämä poistaa kaikki ladatut sovellukset ja appletit VÄLIMUISTISTA.
 [*]Klikkaa OK jättääksesi Java asetusikkunasi.
 
 Käynnistä uudelleen ja lähetä uusi HjT-loki. Vielä ongelmia? 
							
						 
						
						
 Ei HjT-lokeja tms. yksityisviestillä! 
						
						 | 
					
				
				
			
				
				
				
				
				
					
						| 
							
								 miryt79 
							
							
								
									Suspended due to non-functional email address
								
							
							 
							 
						 | 
						10. syyskuuta 2006 @ 12:56 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						
						
						
							
							Moikka
 Suuri kiitos.
 Ei enään hidastele avatessa eikä myöskään töki:)
 
 Logfile of HijackThis v1.99.1
 Scan saved at 16:49:10, on 2.9.2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
 C:\WINDOWS\system32\CTsvcCDA.EXE
 C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
 C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
 C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
 C:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE
 C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
 C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
 C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
 C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 C:\Program Files\F-Secure\Common\FSMA32.EXE
 C:\Program Files\F-Secure\Common\FSMB32.EXE
 C:\Program Files\F-Secure\Common\FCH32.EXE
 C:\Program Files\F-Secure\Common\FAMEH32.EXE
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\F-Secure\Common\FNRB32.EXE
 C:\Program Files\F-Secure\Common\FIH32.EXE
 C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
 C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 C:\Program Files\F-Secure\Common\FSM32.EXE
 C:\PROGRA~1\PESTPA~1\PPControl.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
 C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
 C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
 C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
 C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
 C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
 C:\Program Files\WinZip\WZQKPICK.EXE
 C:\WINDOWS\system32\wuauclt.exe
 C:\Program Files\F-Secure\BackWeb\7681197\Program\BackWeb-7681197.exe
 C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
 C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
 C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\WINDOWS\system32\rundll32.exe
 C:\Documents and Settings\Mika\Omat tiedostot\Ajurit\hijackthis\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
 O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fi\msntb.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
 O3 - Toolbar: (no name) - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - (no file)
 O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
 O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
 O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
 O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
 O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
 O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
 O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
 O4 - Global Startup: WinZIP Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
 O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
 O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
 O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
 O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
 O23 - Service: F-Secure BackWeb (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
 O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
 O23 - Service: F-Secure BackWeb LAN Access - Unknown owner - C:\Program Files\F-Secure\BackWeb\7681197\Program\fsbwlan.exe
 O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
 O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
 O23 - Service: F-Secure Authentication Agent (FSAA) - F-Secure Corporation. All Rights Reserved. - C:\Program Files\F-Secure\Common\FSAA.EXE
 O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
 O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE
 O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
 O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
 O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
 O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 
 t:miryt
							
						 
						
						
						
						 | 
					
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						10. syyskuuta 2006 @ 13:04 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						
						
						
							
							Tuo fixiin (avaa HijackThis, klikkaa do a system scan only, merkkaa ja paina fix checked).
 
 O3 - Toolbar: (no name) - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - (no file) 
 
 Muuten ok. 
							
						 
						
						
 Ei HjT-lokeja tms. yksityisviestillä! 
						
						 | 
					
				
				
			
				
				
				
					
						| 
							 Mainos 
							 
						 | 
						   | 
					
					
						
							
							  
								
							
						 | 
					
				
				
				
					
						| 
							
								 miryt79 
							
							
								
									Suspended due to non-functional email address
								
							
							 
							 
						 | 
						10. syyskuuta 2006 @ 13:51 | 
						 
							
								Linkki tähän viestiin
								  
								 
								  
							
							
						 | 
					
					
					
					
						| 
						
						 
							
							Kiitos!
							
						 
						
						
						
						 |