User Käyttäjä Salasana  
   
perjantai 14.3.2025 / 14:52
Hae keskustelualueilta:        In English   Suomeksi   På svenska
afterdawn.com > keskustelu > yleistä keskustelua tietokoneista > virukset ja haittaohjelmat - hijackthis -logit > hjt loki smartlinkservice pois!!
Näytä aiheet
 
Keskustelualueet
Keskustelualueet
Hjt loki smartlinkservice pois!!
  Siirry:
 
Kirjoittaja Viesti
FIN_Kla
Suspended due to non-functional email address
_
3. lokakuuta 2006 @ 17:56 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Logfile of HijackThis v1.99.1
Scan saved at 21:56:09, on 3.10.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ELISAT~1\backweb\4119343\Program\SERVIC~1.EXE
C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32st.exe
C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\program\fsbwsys.exe
C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\FSGK32.EXE
C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMA32.EXE
C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fssm32.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMB32.EXE
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Elisa Tietoturvapalvelu\Common\FCH32.EXE
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Elisa Tietoturvapalvelu\Common\FAMEH32.EXE
C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsrw.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE
C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\ispnews.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Elisa Tietoturvapalvelu\FWES\Program\fsdfwd.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\{88B8388E-0B09-1035-1225-030723200166}\Update.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsav32.exe
C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\Program\fspex.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\PROGRA~1\ELISAT~1\ANTI-S~1\fsaw.exe
C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\fsguidll.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Winamp\winamp.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\PrintView\pvmodule.exe
C:\WINDOWS\system32\rundll32.exe
C:\Kaspersky\kavupd.exe
C:\WINDOWS\system32\taskmgr.exe
C:\hijack this\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://elisa.net/
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Elisa Tietoturvapalvelu\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [News Service] "C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\ispnews.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [WinAntiVirusPro2006] "C:\Program Files\WinAntiVirus Pro 2006\WinAV.exe" /min
O4 - HKLM\..\Run: [PVModule] C:\PROGRA~1\PRINTV~1\pvmodule.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe"
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Elisa Tietoturvapalvelu.lnk = C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\Program\fspex.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &Estä tämä kohoikkuna - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: IE-suojaus - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: IE-suojaus... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\ieshield.dll
O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O14 - IERESET.INF: START_PAGE_URL=http://elisa.net/
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: Extensions - C:\WINDOWS\system32\gp20l3fm1.dll (file missing)
O20 - Winlogon Notify: RunServices - C:\WINDOWS\system32\s0rsla971d.dll
O23 - Service: Elisa Tietoturvapalvelu (BackWeb Plug-in - 4119343) - BackWeb Technologies Inc. - C:\PROGRA~1\ELISAT~1\backweb\4119343\Program\SERVIC~1.EXE
O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\FWES\Program\fsdfwd.exe
O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMA32.EXE
O23 - Service: Firewall service (FWSvc) - Unknown owner - C:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe



Millä saan tyhjäksi koneen psksta? kiitos
hannu71
Member
_
4. lokakuuta 2006 @ 12:02 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
1. Lataa combofix.exe tiedosto työpöydällesi.
2. Tuplaklikkaa combofix.exe tiedostoa ja seuraa ohjeistuksia.
3. Kun työkalu on valmis, se tuottaa lokin. Lähetä tämä loki viesti ketjuusi.
Huom! Älä klikkaile combofixin ikkunaa käytön aikana. Tämä saattaa aiheuttaa ohjelman jumiutumisen.

Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 4. lokakuuta 2006 @ 12:26

FIN_Kla
Suspended due to non-functional email address
_
4. lokakuuta 2006 @ 14:35 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Combofixin loki:

Jufka - 06-10-04 18:18:49.89 Service Pack 2
ComboFix 06.09.28 - Running from: "C:\Documents and Settings\Jufka\Ty?p?yt?"

((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))

REGISTRY ENTRIES REMOVED:

[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}]
@=""
"IDEx"="ADDR"

[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\InprocServer32]
@="C:\\WINDOWS\\system32\\wznotify.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\InprocServer32]
@="C:\\WINDOWS\\system32\\serenacm.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\InprocServer32]
@="C:\\WINDOWS\\system32\\pbrfts.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\InprocServer32]
@="C:\\WINDOWS\\system32\\migsvc.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\InprocServer32]
@="C:\\WINDOWS\\system32\\jvproxy.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\InprocServer32]
@="C:\\WINDOWS\\system32\\cefgnt.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\InprocServer32]
@="C:\\WINDOWS\\system32\\kedfi1.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\InprocServer32]
@="C:\\WINDOWS\\system32\\mztext40.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\InprocServer32]
@="C:\\windows\\system32\\khdcz1.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\InprocServer32]
@="C:\\WINDOWS\\system32\\kmdusl.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\InprocServer32]
@="C:\\WINDOWS\\system32\\oncache.dll"
"ThreadingModel"="Apartment"

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


FILES REMOVED:

C:\WINDOWS\system32\en06l1ds1.dll
C:\WINDOWS\system32\f0l00a3med.dll
C:\WINDOWS\system32\khdcz1.dll
C:\WINDOWS\system32\oue2nls.dll


Granting sedebugprivilege to Järjestelmänvalvojat ... successful


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\Inetget2
C:\Program Files\Common Files\{88B8388E-0B09-1035-1225-030723200166}
C:\Program Files\PrintView


((((((((((((((((((((((((((((((( Files Created from 2006-09-04 to 2006-10-04 ))))))))))))))))))))))))))))))))))


2006-10-03 22:03 53,248 --a------ C:\WINDOWS\system32\Process.exe
2006-10-03 22:03 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2006-10-03 22:03 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2006-10-03 22:03 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2006-09-25 17:47 51,072 --a------ C:\WINDOWS\system32\drivers\ikhlayer.sys
2006-09-25 17:47 30,592 --a------ C:\WINDOWS\system32\drivers\ikhfile.sys
2006-09-25 17:37 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2006-09-25 17:37 8,704 --a------ C:\WINDOWS\system32\SpOrder.dll
2006-09-25 17:37 6,144 --a------ C:\WINDOWS\system32\stera.exe
2006-09-24 17:30 73,796 --a------ C:\WINDOWS\system32\slserv.exe
2006-09-24 17:30 73,796 --a------ C:\WINDOWS\system32\slserv.0xe.exe


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-10-04 18:22 -------- d-------- C:\Program Files\Common Files
2006-10-04 18:03 -------- d-------- C:\Program Files\Mozilla Firefox
2006-10-04 17:49 -------- d-------- C:\Program Files\DAEMON Tools
2006-10-04 11:52 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
2006-10-03 21:24 -------- d-------- C:\Program Files\Expekt
2006-10-03 21:23 -------- d-------- C:\Program Files\GustoSoft
2006-09-28 19:10 -------- d-------- C:\Program Files\MSN Messenger
2006-09-28 19:10 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-09-25 18:51 -------- d-------- C:\Program Files\Lavasoft
2006-09-25 18:19 -------- d-------- C:\Program Files\Spyware Doctor
2006-09-21 20:24 -------- d-------- C:\Program Files\DC++
2006-08-21 15:26 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 12:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-21 12:14 128896 --------- C:\WINDOWS\system32\drivers\fltmgr.sys
2006-08-10 21:48 -------- d-------- C:\Program Files\Internet Explorer
2006-07-29 19:32 48936 --a------ C:\WINDOWS\system32\sirenacm.dll
2006-07-27 16:26 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-21 11:28 72704 --a------ C:\WINDOWS\system32\hlink.dll
2006-07-04 16:16 855 --a------ C:\Program Files\Ace DivX Player.lnk


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\windows\\system32\\ctfmon.exe"
"BitComet"="\"C:\\Program Files\\BitComet\\BitComet.exe\""
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Wizard"=hex(2):00
"SoundMan"="SOUNDMAN.EXE"
"F-Secure Manager"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\Common\\FSM32.EXE\" /splash"
"F-Secure TNB"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\TNB\\TNBUtil.exe\" /CHECKALL /WAITFORSW"
"F-Secure Startup Wizard"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\FSGUI\\FSSW.EXE\" /reboot"
"News Service"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\FSGUI\\ispnews.exe\""
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonceex]
@=""

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


Contents of the 'Scheduled Tasks' folder
C:\windows\tasks\Scheduled scanning task.job

Completion time: Wed 04.10.2006 18:25:05.89
ComboFix.txt
ComboFix2.txt
FIN_Kla
Suspended due to non-functional email address
_
4. lokakuuta 2006 @ 14:35 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Combofixin loki:

Jufka - 06-10-04 18:18:49.89 Service Pack 2
ComboFix 06.09.28 - Running from: "C:\Documents and Settings\Jufka\Ty?p?yt?"

((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))

REGISTRY ENTRIES REMOVED:

[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}]
@=""
"IDEx"="ADDR"

[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\InprocServer32]
@="C:\\WINDOWS\\system32\\wznotify.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\InprocServer32]
@="C:\\WINDOWS\\system32\\serenacm.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\InprocServer32]
@="C:\\WINDOWS\\system32\\pbrfts.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\InprocServer32]
@="C:\\WINDOWS\\system32\\migsvc.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\InprocServer32]
@="C:\\WINDOWS\\system32\\jvproxy.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\InprocServer32]
@="C:\\WINDOWS\\system32\\cefgnt.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\InprocServer32]
@="C:\\WINDOWS\\system32\\kedfi1.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\InprocServer32]
@="C:\\WINDOWS\\system32\\mztext40.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\InprocServer32]
@="C:\\windows\\system32\\khdcz1.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\InprocServer32]
@="C:\\WINDOWS\\system32\\kmdusl.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\InprocServer32]
@="C:\\WINDOWS\\system32\\oncache.dll"
"ThreadingModel"="Apartment"

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


FILES REMOVED:

C:\WINDOWS\system32\en06l1ds1.dll
C:\WINDOWS\system32\f0l00a3med.dll
C:\WINDOWS\system32\khdcz1.dll
C:\WINDOWS\system32\oue2nls.dll


Granting sedebugprivilege to Järjestelmänvalvojat ... successful


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\Inetget2
C:\Program Files\Common Files\{88B8388E-0B09-1035-1225-030723200166}
C:\Program Files\PrintView


((((((((((((((((((((((((((((((( Files Created from 2006-09-04 to 2006-10-04 ))))))))))))))))))))))))))))))))))


2006-10-03 22:03 53,248 --a------ C:\WINDOWS\system32\Process.exe
2006-10-03 22:03 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2006-10-03 22:03 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2006-10-03 22:03 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2006-09-25 17:47 51,072 --a------ C:\WINDOWS\system32\drivers\ikhlayer.sys
2006-09-25 17:47 30,592 --a------ C:\WINDOWS\system32\drivers\ikhfile.sys
2006-09-25 17:37 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2006-09-25 17:37 8,704 --a------ C:\WINDOWS\system32\SpOrder.dll
2006-09-25 17:37 6,144 --a------ C:\WINDOWS\system32\stera.exe
2006-09-24 17:30 73,796 --a------ C:\WINDOWS\system32\slserv.exe
2006-09-24 17:30 73,796 --a------ C:\WINDOWS\system32\slserv.0xe.exe


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-10-04 18:22 -------- d-------- C:\Program Files\Common Files
2006-10-04 18:03 -------- d-------- C:\Program Files\Mozilla Firefox
2006-10-04 17:49 -------- d-------- C:\Program Files\DAEMON Tools
2006-10-04 11:52 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
2006-10-03 21:24 -------- d-------- C:\Program Files\Expekt
2006-10-03 21:23 -------- d-------- C:\Program Files\GustoSoft
2006-09-28 19:10 -------- d-------- C:\Program Files\MSN Messenger
2006-09-28 19:10 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-09-25 18:51 -------- d-------- C:\Program Files\Lavasoft
2006-09-25 18:19 -------- d-------- C:\Program Files\Spyware Doctor
2006-09-21 20:24 -------- d-------- C:\Program Files\DC++
2006-08-21 15:26 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 12:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-21 12:14 128896 --------- C:\WINDOWS\system32\drivers\fltmgr.sys
2006-08-10 21:48 -------- d-------- C:\Program Files\Internet Explorer
2006-07-29 19:32 48936 --a------ C:\WINDOWS\system32\sirenacm.dll
2006-07-27 16:26 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-21 11:28 72704 --a------ C:\WINDOWS\system32\hlink.dll
2006-07-04 16:16 855 --a------ C:\Program Files\Ace DivX Player.lnk


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\windows\\system32\\ctfmon.exe"
"BitComet"="\"C:\\Program Files\\BitComet\\BitComet.exe\""
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Wizard"=hex(2):00
"SoundMan"="SOUNDMAN.EXE"
"F-Secure Manager"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\Common\\FSM32.EXE\" /splash"
"F-Secure TNB"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\TNB\\TNBUtil.exe\" /CHECKALL /WAITFORSW"
"F-Secure Startup Wizard"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\FSGUI\\FSSW.EXE\" /reboot"
"News Service"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\FSGUI\\ispnews.exe\""
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonceex]
@=""

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


Contents of the 'Scheduled Tasks' folder
C:\windows\tasks\Scheduled scanning task.job

Completion time: Wed 04.10.2006 18:25:05.89
ComboFix.txt
ComboFix2.txt
FIN_Kla
Suspended due to non-functional email address
_
4. lokakuuta 2006 @ 14:35 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
Combofixin loki:

Jufka - 06-10-04 18:18:49.89 Service Pack 2
ComboFix 06.09.28 - Running from: "C:\Documents and Settings\Jufka\Ty?p?yt?"

((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))

REGISTRY ENTRIES REMOVED:

[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}]
@=""
"IDEx"="ADDR"

[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\InprocServer32]
@="C:\\WINDOWS\\system32\\wznotify.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\InprocServer32]
@="C:\\WINDOWS\\system32\\serenacm.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\InprocServer32]
@="C:\\WINDOWS\\system32\\pbrfts.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\InprocServer32]
@="C:\\WINDOWS\\system32\\migsvc.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\InprocServer32]
@="C:\\WINDOWS\\system32\\jvproxy.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\InprocServer32]
@="C:\\WINDOWS\\system32\\cefgnt.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\InprocServer32]
@="C:\\WINDOWS\\system32\\kedfi1.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\InprocServer32]
@="C:\\WINDOWS\\system32\\mztext40.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\InprocServer32]
@="C:\\windows\\system32\\khdcz1.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\InprocServer32]
@="C:\\WINDOWS\\system32\\kmdusl.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\InprocServer32]
@="C:\\WINDOWS\\system32\\oncache.dll"
"ThreadingModel"="Apartment"

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


FILES REMOVED:

C:\WINDOWS\system32\en06l1ds1.dll
C:\WINDOWS\system32\f0l00a3med.dll
C:\WINDOWS\system32\khdcz1.dll
C:\WINDOWS\system32\oue2nls.dll


Granting sedebugprivilege to Järjestelmänvalvojat ... successful


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\Inetget2
C:\Program Files\Common Files\{88B8388E-0B09-1035-1225-030723200166}
C:\Program Files\PrintView


((((((((((((((((((((((((((((((( Files Created from 2006-09-04 to 2006-10-04 ))))))))))))))))))))))))))))))))))


2006-10-03 22:03 53,248 --a------ C:\WINDOWS\system32\Process.exe
2006-10-03 22:03 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2006-10-03 22:03 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2006-10-03 22:03 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2006-09-25 17:47 51,072 --a------ C:\WINDOWS\system32\drivers\ikhlayer.sys
2006-09-25 17:47 30,592 --a------ C:\WINDOWS\system32\drivers\ikhfile.sys
2006-09-25 17:37 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2006-09-25 17:37 8,704 --a------ C:\WINDOWS\system32\SpOrder.dll
2006-09-25 17:37 6,144 --a------ C:\WINDOWS\system32\stera.exe
2006-09-24 17:30 73,796 --a------ C:\WINDOWS\system32\slserv.exe
2006-09-24 17:30 73,796 --a------ C:\WINDOWS\system32\slserv.0xe.exe


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-10-04 18:22 -------- d-------- C:\Program Files\Common Files
2006-10-04 18:03 -------- d-------- C:\Program Files\Mozilla Firefox
2006-10-04 17:49 -------- d-------- C:\Program Files\DAEMON Tools
2006-10-04 11:52 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
2006-10-03 21:24 -------- d-------- C:\Program Files\Expekt
2006-10-03 21:23 -------- d-------- C:\Program Files\GustoSoft
2006-09-28 19:10 -------- d-------- C:\Program Files\MSN Messenger
2006-09-28 19:10 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-09-25 18:51 -------- d-------- C:\Program Files\Lavasoft
2006-09-25 18:19 -------- d-------- C:\Program Files\Spyware Doctor
2006-09-21 20:24 -------- d-------- C:\Program Files\DC++
2006-08-21 15:26 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 12:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-21 12:14 128896 --------- C:\WINDOWS\system32\drivers\fltmgr.sys
2006-08-10 21:48 -------- d-------- C:\Program Files\Internet Explorer
2006-07-29 19:32 48936 --a------ C:\WINDOWS\system32\sirenacm.dll
2006-07-27 16:26 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-21 11:28 72704 --a------ C:\WINDOWS\system32\hlink.dll
2006-07-04 16:16 855 --a------ C:\Program Files\Ace DivX Player.lnk


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\windows\\system32\\ctfmon.exe"
"BitComet"="\"C:\\Program Files\\BitComet\\BitComet.exe\""
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Wizard"=hex(2):00
"SoundMan"="SOUNDMAN.EXE"
"F-Secure Manager"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\Common\\FSM32.EXE\" /splash"
"F-Secure TNB"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\TNB\\TNBUtil.exe\" /CHECKALL /WAITFORSW"
"F-Secure Startup Wizard"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\FSGUI\\FSSW.EXE\" /reboot"
"News Service"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\FSGUI\\ispnews.exe\""
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonceex]
@=""

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


Contents of the 'Scheduled Tasks' folder
C:\windows\tasks\Scheduled scanning task.job

Completion time: Wed 04.10.2006 18:25:05.89
ComboFix.txt
ComboFix2.txt
Mainos
_
__
 
_
hannu71
Member
_
4. lokakuuta 2006 @ 16:26 _ Linkki tähän viestiin    Lähetä käyttäjälle yksityisviesti   
lopeta tehtävien hallinnasta (ctrl+alt+delete) seuraavat:
pvmodule.exe

Poista ohjauspaneelista seuraavat:
WinAntiVirus Pro 2006
Save tai whenUsave tai vastaava

Avaa HijackThis, klikkaa do a system scan only, merkkaa nämä rivit. Sitten sulje kaikki muut ikkunat ja paina fix checked.
O4 - HKLM\..\Run: [WinAntiVirusPro2006] "C:\Program Files\WinAntiVirus Pro 2006\WinAV.exe" /min
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe
O23 - Service: Firewall service (FWSvc) - Unknown owner - C:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe (file missing)

Kopioi/liitä seuraava teksti lainausboksista alapuolella tyhjään
muistiofiluun. Varmista että tiedostotyyppi on "All Files" ja
tallenna se Poisto.bat. nimisenä työpöydällesi.

Lainaus
------------------
@echo off
sc stop FWSvc
sc delete FWSvc
------------------

Sitten aja työpöydällä oleva Poisto.bat-tiedosto.

laita tarvittaessa piilotiedostot näkyviin. ohje==> http://keskustelu.afterdawn.com/thread_view.cfm/248944
mene vikasietotilaan. ohje==>
http://service1.symantec.com/SUPPORT/tsg...001052409420406

poista seuraavat:
C:\Program Files\==>WinAntiVirus Pro 2006<==
C:\Program Files\==>Save<==

käynnistä kone normaali tilaan ja laita piilotiedostot takaisin piiloon.

Javan päivitys ja välimuistin tyhjennys
1. Klikkaa Käynnistä > Ohjauspaneeli ja tupla-klikkaa Lisää tai poista sovellus Ohjauspaneelissa.
2. Etsi listasta kaikki entiset Java versiosi. (J2SE Runtime Environment.... )
Niissä pitäisi olla seuraava kuva vieressä:
3. Valitse kaikki entiset Java versiosi ja valitse Poista.
4. Asenna uusin Java päivitys seuraavasta linkistä..
5. Käynnistä kone uudelleen asennuksen jälkeen:

http://java.sun.com/javase/downloads/index.jsp

6. Käynnistyksen jälkeen, mene takaisin Ohjauspaneeliin ja avaa Java asetuksesi (Muita Ohjauspaneelin asetuksia -> Java kahvikuppi).
7. Temporary Internet Files -osion alla, klikkaa Delete Files nappia.
8. Varmista että kaikki kolme valintaa ovat rastitettuja:

Downloaded Applets
Downloaded Applications
Other Files

9. Klikkaa OK "Delete Temporary Internet Files" -ikkunassasi.
Huomaa: Tämä poistaa kaikki ladatut sovellukset ja appletit VÄLIMUISTISTA.
10. Klikkaa OK jättääksesi Java asetusikkunasi.


Lataa Killbox http://www.downloads.subratam.org/KillBox.zip
Huomaa: Jos sinulla on jo Killbox, tämä on uusi versio joka sinun tulee asentaa. Poista aikaisempi.

* Tallenna työpöydällesi.
* Tupla-klikkaa Killbox.exe ajaaksesi ohjelman.
* Valitse:
o Delete on Reboot
o sitten klikkaa All Files valintaa.

* Kopioi ja liitä alapuolella olevat tiedostopolut leikepöydälle mustaamalla KAIKKI ne ja painamalla CTRL + C (tai, mustaamisen jälkeen, oikea klikki hiirellä ja valitse kopioi):

C:\WINDOWS\system32\stera.exe
C:\WINDOWS\system32\slserv.0xe.exe

* Palaa Killboxiin, mene File valikkoon, ja valitse Paste from Clipboard.

* Klikkaa puna-valkoista Delete File valintaa. Klikkaa Yes "Delete on Reboot" pyyntöön. Klikkaa OK mihin vain PendingFileRenameOperations pyyntöön (ja anna fixaajan tietää jos jokin tälläinen tulee!).


Käynnistä koneesi itse jos se ei sitä automaattisesti tee.

Jos saat tälläisen viestin: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." Kun yrität ajaa KillBoxia, klikkaa http://www.eudaemonia.me.uk/downloads/Files/missingfilesetup.exe ladataksesi ja ajaaksesi Missingfilessetup.exe;n. Sitten koita KillBoxia uudestaan.

lähetä uusi HjT-loki
Viestiketju on suljettu. Uusien viestien lähettäminen ei ole mahdollista.
Aiheeseen liittyviä linkkejä
Lataa uusin versio HijackThis-ohjelmasta täältä!
 
Aiheeseen liittyviä viestiketjuja Viestejä Viimeisin viesti Keskustelualue
HJT Logi 2 3. kesäkuuta 2014 Virukset ja haittaohjelmat - HijackThis -logit
HJT-logi ja vale-firefox ongelmia....virus koneella ? 4 6. toukokuuta 2014 Virukset ja haittaohjelmat - HijackThis -logit
HJT logi, kone jumittaa 1 3. huhtikuuta 2014 Virukset ja haittaohjelmat - HijackThis -logit
Näppäimistö sekoilee hjt log 1 2. huhtikuuta 2014 Virukset ja haittaohjelmat - HijackThis -logit
HJT-log ja Malwarebytes- log, Troijalainen? Apu tarpeen! 2 10. maaliskuuta 2014 Virukset ja haittaohjelmat - HijackThis -logit
HJT-loki, kone valtavan hidas ja perusskannereiden läpi ajamisella ei vaikutusta 1 19. helmikuuta 2014 Virukset ja haittaohjelmat - HijackThis -logit
probook 445 hjt-logit 1 19. tammikuuta 2014 Virukset ja haittaohjelmat - HijackThis -logit
HJT loki tarkastukseen 1 19. tammikuuta 2014 Virukset ja haittaohjelmat - HijackThis -logit
Win7 + HJT ongelma ja kummitteleva Mass effect 2 1 11. tammikuuta 2014 Windows -ongelmat
HJT-logia.. 1 9. tammikuuta 2014 Virukset ja haittaohjelmat - HijackThis -logit

 
afterdawn.com > keskustelu > yleistä keskustelua tietokoneista > virukset ja haittaohjelmat - hijackthis -logit > hjt loki smartlinkservice pois!!
 

Apua ongelmiin: AfterDawnin keskustelualueet | AfterDawnin Vastaukset
Uutiset: IT-alan uutiset | Uutisia puhelimista
Musiikkia: MP3Lizard.com
Tuotearviot: Laitevertailu | Vertaa puhelimia | Vertaa kännykkäliittymiä
Pelit: Pelitiedostot, pelidemot ja trailerit
Ohjelmat: download.fi | AfterDawnin ohjelma-alueet
International: AfterDawn in English | Software downloads | Free, legal MP3s | AfterDawn på svenska
RSS -syötteet: AfterDawnin uutiset | Uusimmat ohjelmapäivitykset | Keskustelualueiden viestit
Tietoja: Tietoa AfterDawn Oy:stä | Mainosta sivuillamme | Sivuston käyttöehdot ja tietoja yksityisyydensuojasta
Ota yhteyttä: Lähetä palautetta | Ota yhteyttä mainosmyyntiimme
 
  © 1999-2025 AfterDawn Oy