|
Keskustelualueet
Keskustelualueet
|
|
Hjt loki smartlinkservice pois!!
|
|
FIN_Kla
Suspended due to non-functional email address
|
3. lokakuuta 2006 @ 17:56 |
Linkki tähän viestiin
|
Logfile of HijackThis v1.99.1
Scan saved at 21:56:09, on 3.10.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ELISAT~1\backweb\4119343\Program\SERVIC~1.EXE
C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32st.exe
C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\program\fsbwsys.exe
C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\FSGK32.EXE
C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMA32.EXE
C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fssm32.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMB32.EXE
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Elisa Tietoturvapalvelu\Common\FCH32.EXE
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Elisa Tietoturvapalvelu\Common\FAMEH32.EXE
C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsrw.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE
C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\ispnews.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Elisa Tietoturvapalvelu\FWES\Program\fsdfwd.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\{88B8388E-0B09-1035-1225-030723200166}\Update.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsav32.exe
C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\Program\fspex.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\PROGRA~1\ELISAT~1\ANTI-S~1\fsaw.exe
C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\fsguidll.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Winamp\winamp.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\PrintView\pvmodule.exe
C:\WINDOWS\system32\rundll32.exe
C:\Kaspersky\kavupd.exe
C:\WINDOWS\system32\taskmgr.exe
C:\hijack this\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://elisa.net/
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Elisa Tietoturvapalvelu\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Elisa Tietoturvapalvelu\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [News Service] "C:\Program Files\Elisa Tietoturvapalvelu\FSGUI\ispnews.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [WinAntiVirusPro2006] "C:\Program Files\WinAntiVirus Pro 2006\WinAV.exe" /min
O4 - HKLM\..\Run: [PVModule] C:\PROGRA~1\PRINTV~1\pvmodule.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe"
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Elisa Tietoturvapalvelu.lnk = C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\Program\fspex.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &Estä tämä kohoikkuna - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: IE-suojaus - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: IE-suojaus... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Spyware\ieshield.dll
O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O14 - IERESET.INF: START_PAGE_URL=http://elisa.net/
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: Extensions - C:\WINDOWS\system32\gp20l3fm1.dll (file missing)
O20 - Winlogon Notify: RunServices - C:\WINDOWS\system32\s0rsla971d.dll
O23 - Service: Elisa Tietoturvapalvelu (BackWeb Plug-in - 4119343) - BackWeb Technologies Inc. - C:\PROGRA~1\ELISAT~1\backweb\4119343\Program\SERVIC~1.EXE
O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\Elisa Tietoturvapalvelu\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\Elisa Tietoturvapalvelu\backweb\4119343\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\FWES\Program\fsdfwd.exe
O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\Elisa Tietoturvapalvelu\Common\FSMA32.EXE
O23 - Service: Firewall service (FWSvc) - Unknown owner - C:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
Millä saan tyhjäksi koneen psksta? kiitos
|
hannu71
Member
|
4. lokakuuta 2006 @ 12:02 |
Linkki tähän viestiin
|
1. Lataa combofix.exe tiedosto työpöydällesi.
2. Tuplaklikkaa combofix.exe tiedostoa ja seuraa ohjeistuksia.
3. Kun työkalu on valmis, se tuottaa lokin. Lähetä tämä loki viesti ketjuusi.
Huom! Älä klikkaile combofixin ikkunaa käytön aikana. Tämä saattaa aiheuttaa ohjelman jumiutumisen.
Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 4. lokakuuta 2006 @ 12:26
|
FIN_Kla
Suspended due to non-functional email address
|
4. lokakuuta 2006 @ 14:35 |
Linkki tähän viestiin
|
Combofixin loki:
Jufka - 06-10-04 18:18:49.89 Service Pack 2
ComboFix 06.09.28 - Running from: "C:\Documents and Settings\Jufka\Ty?p?yt?"
((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))
REGISTRY ENTRIES REMOVED:
[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}]
@=""
"IDEx"="ADDR"
[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\InprocServer32]
@="C:\\WINDOWS\\system32\\wznotify.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\InprocServer32]
@="C:\\WINDOWS\\system32\\serenacm.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\InprocServer32]
@="C:\\WINDOWS\\system32\\pbrfts.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\InprocServer32]
@="C:\\WINDOWS\\system32\\migsvc.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\InprocServer32]
@="C:\\WINDOWS\\system32\\jvproxy.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\InprocServer32]
@="C:\\WINDOWS\\system32\\cefgnt.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\InprocServer32]
@="C:\\WINDOWS\\system32\\kedfi1.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\InprocServer32]
@="C:\\WINDOWS\\system32\\mztext40.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\InprocServer32]
@="C:\\windows\\system32\\khdcz1.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\InprocServer32]
@="C:\\WINDOWS\\system32\\kmdusl.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\InprocServer32]
@="C:\\WINDOWS\\system32\\oncache.dll"
"ThreadingModel"="Apartment"
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
FILES REMOVED:
C:\WINDOWS\system32\en06l1ds1.dll
C:\WINDOWS\system32\f0l00a3med.dll
C:\WINDOWS\system32\khdcz1.dll
C:\WINDOWS\system32\oue2nls.dll
Granting sedebugprivilege to Järjestelmänvalvojat ... successful
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\Inetget2
C:\Program Files\Common Files\{88B8388E-0B09-1035-1225-030723200166}
C:\Program Files\PrintView
((((((((((((((((((((((((((((((( Files Created from 2006-09-04 to 2006-10-04 ))))))))))))))))))))))))))))))))))
2006-10-03 22:03 53,248 --a------ C:\WINDOWS\system32\Process.exe
2006-10-03 22:03 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2006-10-03 22:03 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2006-10-03 22:03 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2006-09-25 17:47 51,072 --a------ C:\WINDOWS\system32\drivers\ikhlayer.sys
2006-09-25 17:47 30,592 --a------ C:\WINDOWS\system32\drivers\ikhfile.sys
2006-09-25 17:37 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2006-09-25 17:37 8,704 --a------ C:\WINDOWS\system32\SpOrder.dll
2006-09-25 17:37 6,144 --a------ C:\WINDOWS\system32\stera.exe
2006-09-24 17:30 73,796 --a------ C:\WINDOWS\system32\slserv.exe
2006-09-24 17:30 73,796 --a------ C:\WINDOWS\system32\slserv.0xe.exe
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-10-04 18:22 -------- d-------- C:\Program Files\Common Files
2006-10-04 18:03 -------- d-------- C:\Program Files\Mozilla Firefox
2006-10-04 17:49 -------- d-------- C:\Program Files\DAEMON Tools
2006-10-04 11:52 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
2006-10-03 21:24 -------- d-------- C:\Program Files\Expekt
2006-10-03 21:23 -------- d-------- C:\Program Files\GustoSoft
2006-09-28 19:10 -------- d-------- C:\Program Files\MSN Messenger
2006-09-28 19:10 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-09-25 18:51 -------- d-------- C:\Program Files\Lavasoft
2006-09-25 18:19 -------- d-------- C:\Program Files\Spyware Doctor
2006-09-21 20:24 -------- d-------- C:\Program Files\DC++
2006-08-21 15:26 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 12:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-21 12:14 128896 --------- C:\WINDOWS\system32\drivers\fltmgr.sys
2006-08-10 21:48 -------- d-------- C:\Program Files\Internet Explorer
2006-07-29 19:32 48936 --a------ C:\WINDOWS\system32\sirenacm.dll
2006-07-27 16:26 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-21 11:28 72704 --a------ C:\WINDOWS\system32\hlink.dll
2006-07-04 16:16 855 --a------ C:\Program Files\Ace DivX Player.lnk
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\windows\\system32\\ctfmon.exe"
"BitComet"="\"C:\\Program Files\\BitComet\\BitComet.exe\""
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Wizard"=hex(2):00
"SoundMan"="SOUNDMAN.EXE"
"F-Secure Manager"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\Common\\FSM32.EXE\" /splash"
"F-Secure TNB"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\TNB\\TNBUtil.exe\" /CHECKALL /WAITFORSW"
"F-Secure Startup Wizard"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\FSGUI\\FSSW.EXE\" /reboot"
"News Service"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\FSGUI\\ispnews.exe\""
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonceex]
@=""
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
Contents of the 'Scheduled Tasks' folder
C:\windows\tasks\Scheduled scanning task.job
Completion time: Wed 04.10.2006 18:25:05.89
ComboFix.txt
ComboFix2.txt
|
FIN_Kla
Suspended due to non-functional email address
|
4. lokakuuta 2006 @ 14:35 |
Linkki tähän viestiin
|
Combofixin loki:
Jufka - 06-10-04 18:18:49.89 Service Pack 2
ComboFix 06.09.28 - Running from: "C:\Documents and Settings\Jufka\Ty?p?yt?"
((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))
REGISTRY ENTRIES REMOVED:
[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}]
@=""
"IDEx"="ADDR"
[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\InprocServer32]
@="C:\\WINDOWS\\system32\\wznotify.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\InprocServer32]
@="C:\\WINDOWS\\system32\\serenacm.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\InprocServer32]
@="C:\\WINDOWS\\system32\\pbrfts.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\InprocServer32]
@="C:\\WINDOWS\\system32\\migsvc.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\InprocServer32]
@="C:\\WINDOWS\\system32\\jvproxy.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\InprocServer32]
@="C:\\WINDOWS\\system32\\cefgnt.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\InprocServer32]
@="C:\\WINDOWS\\system32\\kedfi1.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\InprocServer32]
@="C:\\WINDOWS\\system32\\mztext40.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\InprocServer32]
@="C:\\windows\\system32\\khdcz1.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\InprocServer32]
@="C:\\WINDOWS\\system32\\kmdusl.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\InprocServer32]
@="C:\\WINDOWS\\system32\\oncache.dll"
"ThreadingModel"="Apartment"
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
FILES REMOVED:
C:\WINDOWS\system32\en06l1ds1.dll
C:\WINDOWS\system32\f0l00a3med.dll
C:\WINDOWS\system32\khdcz1.dll
C:\WINDOWS\system32\oue2nls.dll
Granting sedebugprivilege to Järjestelmänvalvojat ... successful
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\Inetget2
C:\Program Files\Common Files\{88B8388E-0B09-1035-1225-030723200166}
C:\Program Files\PrintView
((((((((((((((((((((((((((((((( Files Created from 2006-09-04 to 2006-10-04 ))))))))))))))))))))))))))))))))))
2006-10-03 22:03 53,248 --a------ C:\WINDOWS\system32\Process.exe
2006-10-03 22:03 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2006-10-03 22:03 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2006-10-03 22:03 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2006-09-25 17:47 51,072 --a------ C:\WINDOWS\system32\drivers\ikhlayer.sys
2006-09-25 17:47 30,592 --a------ C:\WINDOWS\system32\drivers\ikhfile.sys
2006-09-25 17:37 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2006-09-25 17:37 8,704 --a------ C:\WINDOWS\system32\SpOrder.dll
2006-09-25 17:37 6,144 --a------ C:\WINDOWS\system32\stera.exe
2006-09-24 17:30 73,796 --a------ C:\WINDOWS\system32\slserv.exe
2006-09-24 17:30 73,796 --a------ C:\WINDOWS\system32\slserv.0xe.exe
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-10-04 18:22 -------- d-------- C:\Program Files\Common Files
2006-10-04 18:03 -------- d-------- C:\Program Files\Mozilla Firefox
2006-10-04 17:49 -------- d-------- C:\Program Files\DAEMON Tools
2006-10-04 11:52 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
2006-10-03 21:24 -------- d-------- C:\Program Files\Expekt
2006-10-03 21:23 -------- d-------- C:\Program Files\GustoSoft
2006-09-28 19:10 -------- d-------- C:\Program Files\MSN Messenger
2006-09-28 19:10 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-09-25 18:51 -------- d-------- C:\Program Files\Lavasoft
2006-09-25 18:19 -------- d-------- C:\Program Files\Spyware Doctor
2006-09-21 20:24 -------- d-------- C:\Program Files\DC++
2006-08-21 15:26 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 12:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-21 12:14 128896 --------- C:\WINDOWS\system32\drivers\fltmgr.sys
2006-08-10 21:48 -------- d-------- C:\Program Files\Internet Explorer
2006-07-29 19:32 48936 --a------ C:\WINDOWS\system32\sirenacm.dll
2006-07-27 16:26 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-21 11:28 72704 --a------ C:\WINDOWS\system32\hlink.dll
2006-07-04 16:16 855 --a------ C:\Program Files\Ace DivX Player.lnk
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\windows\\system32\\ctfmon.exe"
"BitComet"="\"C:\\Program Files\\BitComet\\BitComet.exe\""
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Wizard"=hex(2):00
"SoundMan"="SOUNDMAN.EXE"
"F-Secure Manager"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\Common\\FSM32.EXE\" /splash"
"F-Secure TNB"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\TNB\\TNBUtil.exe\" /CHECKALL /WAITFORSW"
"F-Secure Startup Wizard"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\FSGUI\\FSSW.EXE\" /reboot"
"News Service"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\FSGUI\\ispnews.exe\""
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonceex]
@=""
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
Contents of the 'Scheduled Tasks' folder
C:\windows\tasks\Scheduled scanning task.job
Completion time: Wed 04.10.2006 18:25:05.89
ComboFix.txt
ComboFix2.txt
|
FIN_Kla
Suspended due to non-functional email address
|
4. lokakuuta 2006 @ 14:35 |
Linkki tähän viestiin
|
Combofixin loki:
Jufka - 06-10-04 18:18:49.89 Service Pack 2
ComboFix 06.09.28 - Running from: "C:\Documents and Settings\Jufka\Ty?p?yt?"
((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))
REGISTRY ENTRIES REMOVED:
[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}]
@=""
"IDEx"="ADDR"
[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{0889F06E-8B2C-4A5B-A93D-7F2BAD1DEA62}\InprocServer32]
@="C:\\WINDOWS\\system32\\wznotify.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{16C00AEA-A8ED-43AF-859B-93C458303F2B}\InprocServer32]
@="C:\\WINDOWS\\system32\\serenacm.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{7C4A142F-0B80-46CF-9579-0B03F46C3133}\InprocServer32]
@="C:\\WINDOWS\\system32\\pbrfts.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{23892F19-E760-4D03-9884-4D79D53AD7AD}\InprocServer32]
@="C:\\WINDOWS\\system32\\migsvc.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DA3D8F1A-9568-4AD0-83D2-B5D21D36EB63}\InprocServer32]
@="C:\\WINDOWS\\system32\\jvproxy.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F20A5F53-5F8D-4E14-85D2-A81310F2A3B7}\InprocServer32]
@="C:\\WINDOWS\\system32\\cefgnt.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{B48544AD-6982-4EF6-95D9-BF99DCE6FFDA}\InprocServer32]
@="C:\\WINDOWS\\system32\\kedfi1.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1055BAAE-01E7-4602-9E39-450F1E8FA9C2}\InprocServer32]
@="C:\\WINDOWS\\system32\\mztext40.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{8755756D-9295-4041-B84D-22654B234BD1}\InprocServer32]
@="C:\\windows\\system32\\khdcz1.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{45EB9152-BCB5-4891-8B9F-DCBA8A9E2449}\InprocServer32]
@="C:\\WINDOWS\\system32\\kmdusl.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{DEC8D61D-BF9D-4DBD-B996-95B91E33B423}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{C9E8954B-4D9D-44D8-927C-751FB3612E8A}\InprocServer32]
@="C:\\WINDOWS\\system32\\oncache.dll"
"ThreadingModel"="Apartment"
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
FILES REMOVED:
C:\WINDOWS\system32\en06l1ds1.dll
C:\WINDOWS\system32\f0l00a3med.dll
C:\WINDOWS\system32\khdcz1.dll
C:\WINDOWS\system32\oue2nls.dll
Granting sedebugprivilege to Järjestelmänvalvojat ... successful
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\Inetget2
C:\Program Files\Common Files\{88B8388E-0B09-1035-1225-030723200166}
C:\Program Files\PrintView
((((((((((((((((((((((((((((((( Files Created from 2006-09-04 to 2006-10-04 ))))))))))))))))))))))))))))))))))
2006-10-03 22:03 53,248 --a------ C:\WINDOWS\system32\Process.exe
2006-10-03 22:03 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2006-10-03 22:03 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2006-10-03 22:03 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2006-09-25 17:47 51,072 --a------ C:\WINDOWS\system32\drivers\ikhlayer.sys
2006-09-25 17:47 30,592 --a------ C:\WINDOWS\system32\drivers\ikhfile.sys
2006-09-25 17:37 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2006-09-25 17:37 8,704 --a------ C:\WINDOWS\system32\SpOrder.dll
2006-09-25 17:37 6,144 --a------ C:\WINDOWS\system32\stera.exe
2006-09-24 17:30 73,796 --a------ C:\WINDOWS\system32\slserv.exe
2006-09-24 17:30 73,796 --a------ C:\WINDOWS\system32\slserv.0xe.exe
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-10-04 18:22 -------- d-------- C:\Program Files\Common Files
2006-10-04 18:03 -------- d-------- C:\Program Files\Mozilla Firefox
2006-10-04 17:49 -------- d-------- C:\Program Files\DAEMON Tools
2006-10-04 11:52 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
2006-10-03 21:24 -------- d-------- C:\Program Files\Expekt
2006-10-03 21:23 -------- d-------- C:\Program Files\GustoSoft
2006-09-28 19:10 -------- d-------- C:\Program Files\MSN Messenger
2006-09-28 19:10 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-09-25 18:51 -------- d-------- C:\Program Files\Lavasoft
2006-09-25 18:19 -------- d-------- C:\Program Files\Spyware Doctor
2006-09-21 20:24 -------- d-------- C:\Program Files\DC++
2006-08-21 15:26 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 12:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-21 12:14 128896 --------- C:\WINDOWS\system32\drivers\fltmgr.sys
2006-08-10 21:48 -------- d-------- C:\Program Files\Internet Explorer
2006-07-29 19:32 48936 --a------ C:\WINDOWS\system32\sirenacm.dll
2006-07-27 16:26 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-21 11:28 72704 --a------ C:\WINDOWS\system32\hlink.dll
2006-07-04 16:16 855 --a------ C:\Program Files\Ace DivX Player.lnk
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\windows\\system32\\ctfmon.exe"
"BitComet"="\"C:\\Program Files\\BitComet\\BitComet.exe\""
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Wizard"=hex(2):00
"SoundMan"="SOUNDMAN.EXE"
"F-Secure Manager"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\Common\\FSM32.EXE\" /splash"
"F-Secure TNB"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\TNB\\TNBUtil.exe\" /CHECKALL /WAITFORSW"
"F-Secure Startup Wizard"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\FSGUI\\FSSW.EXE\" /reboot"
"News Service"="\"C:\\Program Files\\Elisa Tietoturvapalvelu\\FSGUI\\ispnews.exe\""
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonceex]
@=""
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
Contents of the 'Scheduled Tasks' folder
C:\windows\tasks\Scheduled scanning task.job
Completion time: Wed 04.10.2006 18:25:05.89
ComboFix.txt
ComboFix2.txt
|
Mainos
|
  |
|
hannu71
Member
|
4. lokakuuta 2006 @ 16:26 |
Linkki tähän viestiin
|
lopeta tehtävien hallinnasta (ctrl+alt+delete) seuraavat:
pvmodule.exe
Poista ohjauspaneelista seuraavat:
WinAntiVirus Pro 2006
Save tai whenUsave tai vastaava
Avaa HijackThis, klikkaa do a system scan only, merkkaa nämä rivit. Sitten sulje kaikki muut ikkunat ja paina fix checked.
O4 - HKLM\..\Run: [WinAntiVirusPro2006] "C:\Program Files\WinAntiVirus Pro 2006\WinAV.exe" /min
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe
O23 - Service: Firewall service (FWSvc) - Unknown owner - C:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe (file missing)
Kopioi/liitä seuraava teksti lainausboksista alapuolella tyhjään
muistiofiluun. Varmista että tiedostotyyppi on "All Files" ja
tallenna se Poisto.bat. nimisenä työpöydällesi.
Lainaus
------------------
@echo off
sc stop FWSvc
sc delete FWSvc
------------------
Sitten aja työpöydällä oleva Poisto.bat-tiedosto.
laita tarvittaessa piilotiedostot näkyviin. ohje==> http://keskustelu.afterdawn.com/thread_view.cfm/248944
mene vikasietotilaan. ohje==>
http://service1.symantec.com/SUPPORT/tsg...001052409420406
poista seuraavat:
C:\Program Files\==>WinAntiVirus Pro 2006<==
C:\Program Files\==>Save<==
käynnistä kone normaali tilaan ja laita piilotiedostot takaisin piiloon.
Javan päivitys ja välimuistin tyhjennys
1. Klikkaa Käynnistä > Ohjauspaneeli ja tupla-klikkaa Lisää tai poista sovellus Ohjauspaneelissa.
2. Etsi listasta kaikki entiset Java versiosi. (J2SE Runtime Environment.... )
Niissä pitäisi olla seuraava kuva vieressä:
3. Valitse kaikki entiset Java versiosi ja valitse Poista.
4. Asenna uusin Java päivitys seuraavasta linkistä..
5. Käynnistä kone uudelleen asennuksen jälkeen:
http://java.sun.com/javase/downloads/index.jsp
6. Käynnistyksen jälkeen, mene takaisin Ohjauspaneeliin ja avaa Java asetuksesi (Muita Ohjauspaneelin asetuksia -> Java kahvikuppi).
7. Temporary Internet Files -osion alla, klikkaa Delete Files nappia.
8. Varmista että kaikki kolme valintaa ovat rastitettuja:
Downloaded Applets
Downloaded Applications
Other Files
9. Klikkaa OK "Delete Temporary Internet Files" -ikkunassasi.
Huomaa: Tämä poistaa kaikki ladatut sovellukset ja appletit VÄLIMUISTISTA.
10. Klikkaa OK jättääksesi Java asetusikkunasi.
Lataa Killbox http://www.downloads.subratam.org/KillBox.zip
Huomaa: Jos sinulla on jo Killbox, tämä on uusi versio joka sinun tulee asentaa. Poista aikaisempi.
* Tallenna työpöydällesi.
* Tupla-klikkaa Killbox.exe ajaaksesi ohjelman.
* Valitse:
o Delete on Reboot
o sitten klikkaa All Files valintaa.
* Kopioi ja liitä alapuolella olevat tiedostopolut leikepöydälle mustaamalla KAIKKI ne ja painamalla CTRL + C (tai, mustaamisen jälkeen, oikea klikki hiirellä ja valitse kopioi):
C:\WINDOWS\system32\stera.exe
C:\WINDOWS\system32\slserv.0xe.exe
* Palaa Killboxiin, mene File valikkoon, ja valitse Paste from Clipboard.
* Klikkaa puna-valkoista Delete File valintaa. Klikkaa Yes "Delete on Reboot" pyyntöön. Klikkaa OK mihin vain PendingFileRenameOperations pyyntöön (ja anna fixaajan tietää jos jokin tälläinen tulee!).
Käynnistä koneesi itse jos se ei sitä automaattisesti tee.
Jos saat tälläisen viestin: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." Kun yrität ajaa KillBoxia, klikkaa http://www.eudaemonia.me.uk/downloads/Files/missingfilesetup.exe ladataksesi ja ajaaksesi Missingfilessetup.exe;n. Sitten koita KillBoxia uudestaan.
lähetä uusi HjT-loki
|
|