afterdawn.com > keskustelu > yleistä keskustelua tietokoneista > virukset ja haittaohjelmat - hijackthis -logit > hjt-logi
Keskustelualueet
Keskustelualueet
hjt-logi
Newbie
13. heinäkuuta 2007 @ 12:18
Linkki tähän viestiin
Täs olis hjt -logi tarkistettavaks:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:15:20, on 13.7.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\program files\powerstrip\pstrip.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\MSI\Live Update 3\LMonitor.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Radeon Omega Drivers\v3.8.221\ATI Tray Tools\atitray.exe
D:\steam\steam.exe
C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
C:\Program Files\MSI\PC Alert 4\CoolerXP.exe
C:\Program Files\World of Warcraft\WoW-2.1.1.6739-to-2.1.2.6803-enUS-downloader.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\Mape\LOCALS~1\Temp\Blizzard Installer Bootstrap - 00702fd9\Installer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://messenger.msn.com/flash/?mkt=fi-fi&version=9,0,28,0
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [PowerStrip] c:\program files\powerstrip\pstrip.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AtiTrayTools] "C:\Program Files\Radeon Omega Drivers\v3.8.221\ATI Tray Tools\atitray.exe"
O4 - HKCU\..\Run: [Steam] "d:\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
O4 - HKUS\S-1-5-21-1454471165-789336058-725345543-1004\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Gaypete')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-21-1454471165-789336058-725345543-1004 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Gaypete')
O4 - S-1-5-21-1454471165-789336058-725345543-1004 User Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Gaypete')
O4 - Global Startup: PC Alert 4.lnk = C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
--
End of file - 4289 bytes
Auttaja
Suspended permanently
13. heinäkuuta 2007 @ 12:26
Linkki tähän viestiin
Lataa ATF Cleaner
http://www.atribune.org/ccount/click.php?id=1
Tupla-klikkaa ATF-Cleaner.exe käynnistääksesi ohjelman. Main:n alla valitse: Select All
Klikkaa Empty Selected valintaa.
Jos käytät FireFoxia selaimenasi Klikkaa Firefox yläpuolelta ja valitse: Select All
Klikkaa Empty Selected valintaa.
HUOMIO: Jos haluaisit pitää tallennetut salasanasi, klikkaa No kun se sitä kysyy.
Jos käytät Operaa selaimenasi Klikkaa Opera yläpuolelta ja valitse: Select All
Klikkaa Empty Selected valintaa taas.
HUOMIO: Jos haluaisit pitää tallennetut salasanasi, klikkaa No kun se sitä kysyy.
Klikkaa Exit päävalikosta sulkeaksesi ohjelman.
Teknistä tukea tulee jos tupla-klikkaat sähköpostiosoitetta joka sijaitsee jokaisen menun alapuolella kyseisessä työkalussa. (Huomatkaa että se tuki on sitten englanniksi)
===========
Lataa Deckard's System Scanner Työpöydällesi.
Huomioi : Sinulla tulee olla Järjestelmänvalvojan oikeudet ajaaksesi ohjelman.
[*]Sulje kaikki avoimet ikkunat ja ohjelmat.
[*]Tupla Klikkaa
Dss.exe tiedostoa ajaaksesi ohjelman, seuraa ohjeita.
[*]Kun Scannaus on valmis 2 textitiedostoa pitäisi avautua, Main.txt ja extra.txt
[*]Näppäile Kopioi ( CTRL+A -> CTRL + C ) ja liitä ( CTRL + V )
[*]kopioi ja liitä
Extra.txt &
Main.txt sisältö seuraavaan vastaukseesi.
Newbie
13. heinäkuuta 2007 @ 13:02
Linkki tähän viestiin
Main.txt:
Deckard's System Scanner v20070711.54
Run by Mape on 2007-07-13 at 16:55:33
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
30: 2007-07-13 13:55:36 UTC - RP30 - Deckard's System Scanner Restore Point
29: 2007-07-13 12:15:40 UTC - RP29 - Järjestelmän tarkistuspiste
28: 2007-07-10 22:44:08 UTC - RP28 - Installed Adobe Photoshop CS2
27: 2007-07-10 22:40:39 UTC - RP27 - Removed Adobe Photoshop CS2
26: 2007-07-10 22:25:23 UTC - RP26 - Installed Adobe Photoshop CS2
-- First Restore Point --
1: 2007-07-04 15:19:20 UTC - RP1 - Järjestelmän tarkistuspiste
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Mape.exe) ------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:56:00, on 13.7.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\program files\powerstrip\pstrip.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\MSI\Live Update 3\LMonitor.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Radeon Omega Drivers\v3.8.221\ATI Tray Tools\atitray.exe
C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
C:\Program Files\MSI\PC Alert 4\CoolerXP.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Tiedostoja\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Mape.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://messenger.msn.com/flash/?mkt=fi-fi&version=9,0,28,0
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [PowerStrip] c:\program files\powerstrip\pstrip.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AtiTrayTools] "C:\Program Files\Radeon Omega Drivers\v3.8.221\ATI Tray Tools\atitray.exe"
O4 - HKCU\..\Run: [Steam] "d:\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
O4 - HKUS\S-1-5-21-1454471165-789336058-725345543-1004\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Gaypete')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-21-1454471165-789336058-725345543-1004 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Gaypete')
O4 - S-1-5-21-1454471165-789336058-725345543-1004 User Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Gaypete')
O4 - Global Startup: PC Alert 4.lnk = C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
--
End of file - 4105 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 giveio - c:\windows\system32\giveio.sys
R0 speedfan - c:\windows\system32\speedfan.sys
R1 atitray - c:\program files\radeon omega drivers\v3.8.221\ati tray tools\atitray.sys
R3 CoolerXPDriver - c:\program files\msi\pc alert 4\ntcooler.sys
R3 PCAlertDriver - c:\program files\msi\pc alert 4\ntglm7x.sys MSI PCAlert 4>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 AntiVirScheduler (AntiVir PersonalEdition Classic Scheduler) - c:\program files\antivir personaledition classic\sched.exe
-- Files created between 2007-06-13 and 2007-07-13 -----------------------------
2007-07-13 16:14:57 0 d-------- C:\Program Files\Trend Micro
2007-07-13 14:32:21 0 d-------- C:\Program Files\DC++
2007-07-13 00:45:51 0 d-------- C:\Documents and Settings\Gaypete\Application Data\uTorrent
2007-07-12 18:37:05 0 d-------- C:\Program Files\Common Files\Blizzard Entertainment
2007-07-12 02:48:38 0 d-------- C:\Imuja
2007-07-12 02:47:46 0 d-------- C:\Documents and Settings\Mape\Application Data\uTorrent
2007-07-11 14:37:03 0 d-------- C:\Program Files\RevConnect
2007-07-11 01:44:52 0 d-------- C:\Program Files\Common Files\Adobe Systems Shared
2007-07-11 01:39:15 0 d-------- C:\Documents and Settings\Gaypete\Application Data\Adobe
2007-07-11 01:26:13 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2007-07-11 01:25:26 0 d-------- C:\Program Files\Common Files\Adobe
2007-07-11 01:25:25 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2007-07-09 00:17:23 0 d-------- C:\Documents and Settings\Mape\Application Data\Xfire
2007-07-09 00:17:22 0 d---s---- C:\Program Files\Xfire
2007-07-08 23:14:18 0 d-------- C:\Documents and Settings\Mape\Application Data\BSplayer Pro
2007-07-08 23:14:16 0 d-------- C:\Program Files\Webteh
2007-07-08 21:27:57 0 d-------- C:\Program Files\World of Warcraft
2007-07-08 21:25:57 0 d-------- C:\Documents and Settings\Mape\Application Data\Ventrilo
2007-07-08 01:14:52 0 d-------- C:\Documents and Settings\Gaypete\Application Data\WinRAR
2007-07-07 18:07:07 0 d-------- C:\Program Files\Setup Files
2007-07-07 01:21:56 0 d-------- C:\Program Files\MSN Messenger
2007-07-07 00:00:31 49152 -r------- C:\WINDOWS\system32\ChCfg.exe
2007-07-07 00:00:18 0 d-------- C:\Program Files\Realtek Sound Manager
2007-07-07 00:00:18 0 d-------- C:\Program Files\AvRack
2007-07-07 00:00:06 315392 -r------- C:\WINDOWS\alcupd.exe
2007-07-06 22:04:04 0 d-------- C:\Program Files\sisagp
2007-07-06 22:02:52 0 d-------- C:\Program Files\Realtek AC97
2007-07-06 21:53:14 18359 --a------ C:\WINDOWS\system32\Ntaccess.sys
2007-07-06 21:53:14 8704 --a------ C:\WINDOWS\system32\drivers\FlashSys.sys
2007-07-06 21:53:14 0 d-------- C:\Program Files\MSI
2007-07-06 21:53:08 327168 --a------ C:\WINDOWS\IsUninst.exe
2007-07-06 21:52:57 0 d-------- C:\Documents and Settings\Mape\Application Data\WinRAR
2007-07-06 01:30:42 0 d-------- C:\Program Files\Steam
2007-07-05 23:13:22 0 d-------- C:\WINDOWS\system32\appmgmt
2007-07-05 14:05:14 0 d-------- C:\Documents and Settings\Gaypete\Contacts
2007-07-05 14:02:44 0 d-------- C:\Documents and Settings\Gaypete\Application Data\Macromedia
2007-07-05 14:01:48 0 d-------- C:\Program Files\pIRC
2007-07-05 14:00:59 0 d-------- C:\Documents and Settings\Gaypete\Application Data\Mozilla
2007-07-05 13:59:56 0 d-------- C:\Documents and Settings\Gaypete\Application Data\Identities
2007-07-05 13:59:51 0 dr------- C:\Documents and Settings\Gaypete\Omat tiedostot
2007-07-05 13:59:48 0 d---s---- C:\Documents and Settings\Gaypete\Application Data\Microsoft
2007-07-05 13:59:47 0 d--h----- C:\Documents and Settings\Gaypete\Verkkoympäristö
2007-07-05 13:59:47 0 d-------- C:\Documents and Settings\Gaypete\Työpöytä
2007-07-05 13:59:47 0 d--h----- C:\Documents and Settings\Gaypete\Tulostinympäristö
2007-07-05 13:59:47 0 dr------- C:\Documents and Settings\Gaypete\Suosikit
2007-07-05 13:59:47 0 dr-h----- C:\Documents and Settings\Gaypete\SendTo
2007-07-05 13:59:47 0 dr-h----- C:\Documents and Settings\Gaypete\Recent
2007-07-05 13:59:47 1048576 --ah----- C:\Documents and Settings\Gaypete\NTUSER.DAT
2007-07-05 13:59:47 0 d--h----- C:\Documents and Settings\Gaypete\Mallit
2007-07-05 13:59:47 0 d--h----- C:\Documents and Settings\Gaypete\Local Settings
2007-07-05 13:59:47 0 dr------- C:\Documents and Settings\Gaypete\Käynnistä-valikko
2007-07-05 13:59:47 0 d---s---- C:\Documents and Settings\Gaypete\Cookies
2007-07-05 13:59:47 0 dr-h----- C:\Documents and Settings\Gaypete\Application Data
2007-07-05 00:16:53 0 d-------- C:\Program Files\uTorrent
2007-07-04 21:32:59 0 d-------- C:\Documents and Settings\Mape\Application Data\Macromedia
2007-07-04 21:32:31 1156 --a------ C:\WINDOWS\mozver.dat
2007-07-04 21:14:39 0 d-------- C:\Program Files\Winamp
2007-07-04 21:04:28 0 d-------- C:\WINDOWS
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\WinSxS
2007-07-04 21:04:28 0 dr------- C:\WINDOWS\Web
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\twain_32
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\wins
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\wbem
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\usmt
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\spool
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\ShellExt
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\Setup
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\ras
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\oobe
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\npp
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\mui
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\inetsrv
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\IME
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\icsxml
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\ias
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\export
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\drivers
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\drivers\etc
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\drivers\disdn
2007-07-04 21:04:28 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\dhcp
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\config
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\3com_dmi
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\3076
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\2052
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\1054
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\1042
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\1041
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\1037
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\1035
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\1033
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\1031
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\1028
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system32\1025
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\system
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\security
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\Resources
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\repair
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\mui
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\msapps
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\msagent
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\Media
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\java
2007-07-04 21:04:28 0 d--h----- C:\WINDOWS\inf
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\ime
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\Help
2007-07-04 21:04:28 0 dr--s---- C:\WINDOWS\Fonts
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\Driver Cache
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\Debug
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\Cursors
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\Connection Wizard
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\Config
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\AppPatch
2007-07-04 21:04:28 0 d-------- C:\WINDOWS\addins
2007-07-04 19:21:27 0 d-------- C:\Documents and Settings\Mape\Contacts
2007-07-04 19:21:08 0 d------c- C:\WINDOWS\system32\DRVSTORE
2007-07-04 19:21:07 0 d-------- C:\Program Files\mIRC
2007-07-04 19:08:23 0 d-------- C:\Program Files\Common Files\ODBC
2007-07-04 19:08:21 0 dr------- C:\Program Files
2007-07-04 19:08:21 0 d-------- C:\Program Files\Common Files\SpeechEngines
2007-07-04 19:08:03 0 d--h----- C:\Documents and Settings\Default User\Verkkoympäristö
2007-07-04 19:08:03 0 d-------- C:\Documents and Settings\Default User\Työpöytä
2007-07-04 19:08:03 0 d--h----- C:\Documents and Settings\Default User\Tulostinympäristö
2007-07-04 19:08:03 0 d-------- C:\Documents and Settings\Default User\Suosikit
2007-07-04 19:08:03 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2007-07-04 19:08:03 0 d--h----- C:\Documents and Settings\Default User\Recent
2007-07-04 19:08:03 0 d--h----- C:\Documents and Settings\Default User\Mallit
2007-07-04 19:08:03 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2007-07-04 19:08:03 0 dr------- C:\Documents and Settings\Default User\Käynnistä-valikko
2007-07-04 19:08:03 0 d---s---- C:\Documents and Settings\Default User\Cookies
2007-07-04 19:08:03 0 d-------- C:\Documents and Settings\All Users\Työpöytä
2007-07-04 19:08:03 0 dr------- C:\Documents and Settings\All Users\Tiedostot
2007-07-04 19:08:03 0 d-------- C:\Documents and Settings\All Users\Suosikit
2007-07-04 19:08:03 0 d--h----- C:\Documents and Settings\All Users\Mallit
2007-07-04 19:08:03 0 dr------- C:\Documents and Settings\All Users\Käynnistä-valikko
2007-07-04 19:07:53 0 d-------- C:\WINDOWS\system32\CatRoot2
2007-07-04 19:07:53 0 d-------- C:\WINDOWS\system32\CatRoot
2007-07-04 19:07:48 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2007-07-04 19:07:48 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2007-07-04 19:07:48 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2007-07-04 19:07:48 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2007-07-04 19:07:35 0 d-------- C:\Documents and Settings
2007-07-04 18:53:55 0 d-------- C:\Documents and Settings\Mape\Application Data\atitray
2007-07-04 18:53:04 0 --a------ C:\WINDOWS\nsreg.dat
2007-07-04 18:53:02 0 d-------- C:\Documents and Settings\Mape\Application Data\Mozilla
2007-07-04 18:51:09 0 d-------- C:\Program Files\SpeedFan
2007-07-04 18:49:36 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-07-04 18:46:58 0 d-------- C:\Program Files\PowerStrip
2007-07-04 18:41:13 516096 -----n--- C:\WINDOWS\system32\ati2sgag.exe
2007-07-04 18:40:47 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-07-04 18:40:41 0 d-------- C:\Program Files\Common Files\InstallShield
2007-07-04 18:40:32 0 d-------- C:\Program Files\MultiRes
2007-07-04 18:40:06 0 d-------- C:\Program Files\Radeon Omega Drivers
2007-07-04 18:38:38 0 d-------- C:\Program Files\Lavalys
2007-07-04 18:37:15 0 d-------- C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Classic
2007-07-04 18:35:30 0 d-------- C:\Documents and Settings\LocalService\Käynnistä-valikko
2007-07-04 18:34:45 0 d-------- C:\WINDOWS\SoftwareDistribution
2007-07-04 18:34:42 0 d-------- C:\WINDOWS\Prefetch
2007-07-04 18:34:41 0 d---s---- C:\WINDOWS\system32\Microsoft
2007-07-04 18:29:57 1478656 --a------ C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-07-04 18:29:56 860192 --a------ C:\WINDOWS\system32\ativvaxx.dll
2007-07-04 18:29:56 2604128 --a------ C:\WINDOWS\system32\ati3duag.dll
2007-07-04 18:29:56 255488 --a------ C:\WINDOWS\system32\ati2dvag.dll
2007-07-04 18:29:56 258048 --a------ C:\WINDOWS\system32\ati2cqag.dll
2007-07-04 18:29:52 0 d-------- C:\WINDOWS\peernet
2007-07-04 18:29:51 0 d-------- C:\WINDOWS\provisioning
2007-07-04 18:28:51 0 d-------- C:\WINDOWS\ServicePackFiles
2007-07-04 18:26:46 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2007-07-04 18:25:21 0 d-------- C:\WINDOWS\EHome
2007-07-04 18:19:12 0 d--hs---- C:\WINDOWS\Installer
2007-07-04 18:19:10 0 d-------- C:\Documents and Settings\Mape\Application Data\Identities
2007-07-04 18:19:04 0 dr------- C:\Documents and Settings\Mape\Omat tiedostot
2007-07-04 18:19:01 0 d--h----- C:\Documents and Settings\Mape\Verkkoympäristö
2007-07-04 18:19:01 0 d-------- C:\Documents and Settings\Mape\Työpöytä
2007-07-04 18:19:01 0 d--h----- C:\Documents and Settings\Mape\Tulostinympäristö
2007-07-04 18:19:01 0 dr------- C:\Documents and Settings\Mape\Suosikit
2007-07-04 18:19:01 0 dr-h----- C:\Documents and Settings\Mape\SendTo
2007-07-04 18:19:01 0 dr-h----- C:\Documents and Settings\Mape\Recent
2007-07-04 18:19:01 2097152 --ah----- C:\Documents and Settings\Mape\NTUSER.DAT
2007-07-04 18:19:01 0 d--h----- C:\Documents and Settings\Mape\Mallit
2007-07-04 18:19:01 0 d--h----- C:\Documents and Settings\Mape\Local Settings
2007-07-04 18:19:01 0 dr------- C:\Documents and Settings\Mape\Käynnistä-valikko
2007-07-04 18:19:01 0 d---s---- C:\Documents and Settings\Mape\Cookies
2007-07-04 18:19:01 0 dr-h----- C:\Documents and Settings\Mape\Application Data
2007-07-04 18:18:22 0 d--hs---- C:\System Volume Information
2007-07-04 18:18:20 262144 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
2007-07-04 18:18:20 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2007-07-04 18:18:20 0 d---s---- C:\Documents and Settings\NetworkService\Cookies
2007-07-04 18:18:20 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2007-07-04 18:18:20 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2007-07-04 18:18:20 233472 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2007-07-04 18:18:20 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2007-07-04 18:18:20 0 d---s---- C:\Documents and Settings\LocalService\Cookies
2007-07-04 18:18:20 0 d-------- C:\Documents and Settings\LocalService\Application Data
2007-07-04 18:18:20 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2007-07-04 18:15:55 0 d-------- C:\WINDOWS\system32\xircom
2007-07-04 18:15:55 0 d-------- C:\Program Files\microsoft frontpage
2007-07-04 18:15:40 233472 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
2007-07-04 18:15:36 0 -rahs---- C:\MSDOS.SYS
2007-07-04 18:15:36 0 -rahs---- C:\IO.SYS
2007-07-04 18:15:36 0 --a------ C:\CONFIG.SYS
2007-07-04 18:15:36 0 --a------ C:\AUTOEXEC.BAT
2007-07-04 18:14:54 0 d--hs---- C:\Documents and Settings\All Users\DRM
2007-07-04 18:14:47 0 dr------- C:\WINDOWS\Offline Web Pages
2007-07-04 18:14:47 0 d---s---- C:\WINDOWS\Downloaded Program Files
2007-07-04 18:14:30 0 d-------- C:\WINDOWS\srchasst
2007-07-04 18:14:25 0 d-------- C:\WINDOWS\system32\Macromed
2007-07-04 18:14:25 0 d-------- C:\WINDOWS\system32\DirectX
2007-07-04 18:14:16 0 d-------- C:\Program Files\Movie Maker
2007-07-04 18:13:57 0 d-------- C:\WINDOWS\system32\Restore
2007-07-04 18:13:53 0 d-------- C:\WINDOWS\PCHEALTH
2007-07-04 18:13:48 0 d---s---- C:\WINDOWS\Tasks
2007-07-04 18:13:46 0 d-------- C:\Program Files\Common Files\MSSoap
2007-07-04 18:13:22 21672 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-07-04 18:13:09 0 d-------- C:\WINDOWS\Registration
2007-07-04 18:13:02 0 d--h----- C:\Program Files\WindowsUpdate
2007-07-04 18:13:02 0 d-------- C:\Program Files\Online Services
2007-07-04 18:12:57 0 d-------- C:\Program Files\Messenger
2007-07-04 18:12:51 0 d-------- C:\Program Files\MSN Gaming Zone
2007-07-04 18:12:44 0 d-------- C:\Program Files\Windows NT
2007-07-04 18:12:36 0 d-------- C:\WINDOWS\system32\MsDtc
2007-07-04 18:12:34 0 d-------- C:\WINDOWS\system32\Com
-- Find3M Report ---------------------------------------------------------------
2007-07-04 19:08:03 62 --ahs---- C:\Documents and Settings\Mape\Application Data\desktop.ini
2007-07-04 18:43:55 283024 --a------ C:\WINDOWS\system32\perfh00B.dat
2007-07-04 18:43:55 48448 --a------ C:\WINDOWS\system32\perfc00B.dat
-- Registry Dump ---------------------------------------------------------------
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"avgnt"="\"C:\\Program Files\\AntiVir PersonalEdition Classic\\avgnt.exe\" /min"
"AtiPTA"="atiptaxx.exe"
"PowerStrip "="c:\\program files\\powerstrip\\pstrip.exe"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"LiveMonitor"="C:\\Program Files\\MSI\\Live Update 3\\LMonitor.exe"
"SoundMan"="SOUNDMAN.EXE"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"AtiTrayTools"="\"C:\\Program Files\\Radeon Omega Drivers\\v3.8.221\\ATI Tray Tools\\atitray.exe\""
"Steam"="\"d:\\steam\\steam.exe\" -silent"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_PCALERTDRIVER
-- End of Deckard's System Scanner: finished at 2007-07-13 at 16:57:42 ---------
extra.txt
Deckard's System Scanner v20070711.54
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professional (build 2600 ) SP 2.0
Architecture: X86; Language: Other (040B) - see http://preview.tinyurl.com/mhhp6
CPU 0: AMD Athlon(tm) XP 2800+
Percentage of Memory in Use: 30%
Physical Memory (total/avail): 1023.48 MiB / 712.08 MiB
Pagefile Memory (total/avail): 2462.18 MiB / 2154.96 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1959.3 MiB
C: is Fixed (NTFS) - 111.8 GiB total, 94.97 GiB free.
D: is Fixed (NTFS) - 74.52 GiB total, 20.05 GiB free.
E: is CDROM (No Media)
-- Security Center -------------------------------------------------------------
AUOptions is disabled.
Windows Internal Firewall is enabled.
AV: Avira AntiVir PersonalEdition v 6.39.0.131
(Avira GmbH)
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\\Steam\\SteamApps\\mapezo\\counter-strike\\hl.exe"="D:\\Steam\\SteamApps\\mapezo\\counter-strike\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\Program Files\\pIRC\\mirc.exe"="C:\\Program Files\\pIRC\\mirc.exe:*:Enabled:mIRC"
"C:\\Program Files\\mIRC\\mirc.exe"="C:\\Program Files\\mIRC\\mirc.exe:*:Enabled:mIRC"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\MSI\\i-Speeder\\i-Speeder.exe"="C:\\Program Files\\MSI\\i-Speeder\\i-Speeder.exe:*:Enabled:i-Speeder"
"C:\\Program Files\\Xfire\\xfire.exe"="C:\\Program Files\\Xfire\\xfire.exe:*:Enabled:Xfire"
"C:\\Program Files\\RevConnect\\DCPlusPlus.exe"="C:\\Program Files\\RevConnect\\DCPlusPlus.exe:*:Enabled:DC++"
"C:\\Program Files\\uTorrent\\utorrent.exe"="C:\\Program Files\\uTorrent\\utorrent.exe:*:Enabled:µTorrent"
"C:\\Program Files\\DC++\\DCPlusPlus.exe"="C:\\Program Files\\DC++\\DCPlusPlus.exe:*:Disabled:DC++"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Mape\Application Data
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=PETSKU
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Mape
LOGONSERVER=\\PETSKU
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\Program Files\Mozilla Firefox;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Common Files\Adobe\AGL
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 10 Stepping 0, AuthenticAMD
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0a00
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Mape\LOCALS~1\Temp
TMP=C:\DOCUME~1\Mape\LOCALS~1\Temp
USERDOMAIN=PETSKU
USERNAME=Mape
USERPROFILE=C:\Documents and Settings\Mape
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
Mape (admin)
Gaypete (admin)
-- Add/Remove Programs ---------------------------------------------------------
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Bridge 1.0 --> MsiExec.exe /I{B74D4E10-1033-0000-0000-000000000001}
Adobe Common File Installer --> MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5B39}
Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9c.exe -uninstallUnlock
Adobe Help Center 1.0 --> MsiExec.exe /I{E9787678-1033-0000-8E67-000000000001}
Adobe Photoshop CS2 --> msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D}
Adobe Stock Photos 1.0 --> MsiExec.exe /I{786C5747-1033-0000-B58E-000000000001}
ATI Display Driver (Omega 3.8.221) --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
µTorrent --> "C:\Program Files\uTorrent\uninstall.exe"
Avira AntiVir PersonalEdition Classic --> C:\Program Files\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
BSPlayer --> "C:\Program Files\Webteh\BSplayerPro\uninstall.exe"
DC++ 0.699 --> "C:\Program Files\DC++\uninstall.exe"
EVEREST Home Edition v2.20 --> "C:\Program Files\Lavalys\EVEREST Home Edition\unins000.exe"
FuzzyLogic4 --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\MSI\FuzzyLogic4\Uninst.isu"
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
i-Speeder --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\MSI\i-Speeder\Uninst.isu"
mIRC --> "C:\Program Files\mIRC\mirc.exe" -uninstall
Mozilla Firefox (2.0.0.4) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSI Live Update 3 --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\MSI\Live Update 3\Uninst.isu"
MultiRes (remove only) --> C:\Program Files\MultiRes\uninstal.exe
PC Alert 4 --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\MSI\PC Alert 4\Uninst.isu"
PowerStrip 3 (remove only) --> C:\Program Files\PowerStrip\uninstal.exe
Radeon Omega Drivers v3.8.221 Setup Files and Tools --> "C:\WINDOWS\Radeon Omega Drivers v3.8.221 Uninstall.exe" "/U:C:\Program Files\Radeon Omega Drivers\v3.8.221\Omega Uninstall.xml"
Realtek AC'97 Audio --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0xb -removeonly
RevConnect --> "C:\Program Files\RevConnect\uninstall.exe"
SiSAGP driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DC226AC9-0314-496C-BE6A-B6A132628466}\setup.exe" -l0xb
SpeedFan (remove only) --> "C:\Program Files\SpeedFan\uninstall.exe"
Steam --> C:\PROGRA~1\Steam\UNWISE.EXE C:\PROGRA~1\Steam\INSTALL.LOG
Winamp (remove only) --> "C:\Program Files\Winamp\UninstWA.exe"
Windows Live Messenger --> MsiExec.exe /I{DF6FEB75-A0D1-44E5-A754-0072D4967734}
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
Xfire (remove only) --> "C:\Program Files\Xfire\uninst.exe"
-- End of Deckard's System Scanner: finished at 2007-07-13 at 16:57:42 ---------
afterdawn.com > keskustelu > yleistä keskustelua tietokoneista > virukset ja haittaohjelmat - hijackthis -logit > hjt-logi