Vapaa kuvaus

Aloituksia

2

Kommenttia

399

  1. Se on varmaan Lisää/Poista sovelluksesa myös, mutta tuosta on aika niukalti tietoa, voi hyvinkin olla örkkimörkki.
    O4 - HKCU\..\Run: [Archibald Picks] C:\WINDOWS\System32\ArchibaldPicks.exe /h
  2. OK!
  3. öitä.
  4. merkkaa nuo, sulje selain ja muut ikkunat, paina FIX--KYLLÄ

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.richfind.com/ie/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.richfind.com/ie/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.richfind.com/home/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.richfind.com/ie/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.richfind.com/ie/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.richfind.com/home/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.richfind.com/ie/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.richfind.com/ie/
    R3 - URLSearchHook: Richfind - {2E78B868-3C61-4EEF-9A1D-25961BF63A63} - C:\WINNT\system32\Q50129542.dll (file missing)
    R3 - URLSearchHook: Richfind - {184EF0AD-5C56-438B-88D6-EED588C7EAE9} - C:\WINNT\system32\Q50129542.dll (file missing)
    R3 - URLSearchHook: Richfind - {2CC79661-6C0D-47D7-B862-6AA6B768B267} - C:\WINNT\system32\Q50129542.dll (file missing)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Richfind - {999C9393-CEBB-4F2C-9ACF-58CCBDBDC45C} - C:\WINNT\system32\Q50129542.dll (file missing)
    O2 - BHO: Richfind - {A8FF3F9B-1A89-42BB-A9B9-73D563FEEA21} - C:\WINNT\system32\Q50129542.dll (file missing)
    O3 - Toolbar: Richfind - {4F6A283F-8304-4FDA-AB07-C421672B6176} - C:\WINNT\system32\Q50129542.dll (file missing)
    O3 - Toolbar: Richfind - {B77DA66F-984A-4539-B917-AE421DAB29CF} - C:\WINNT\system32\Q50129542.dll (file missing)
    O3 - Toolbar: Richfind - {456035B4-0436-4A61-B4DB-D48FCDC6AFA9} - C:\WINNT\system32\Q50129542.dll (file missing)
    O4 - HKCU\..\Run: [Ecea] C:\Documents and Settings\Järjestelmänvalvoja\Application Data\arsd.exe
    O4 - HKLM\..\Run: [websx] C:\Program Files\websx\int167078.exe -auto
    O9 - Extra button: Richfind - {456035B4-0436-4A61-B4DB-D48FCDC6AFA9} - C:\WINNT\system32\Q50129542.dll (file missing)
    O9 - Extra button: Richfind - {4F6A283F-8304-4FDA-AB07-C421672B6176} - C:\WINNT\system32\Q50129542.dll (file missing)
    O9 - Extra button: Richfind - {B77DA66F-984A-4539-B917-AE421DAB29CF} - C:\WINNT\system32\Q50129542.dll (file missing)
    O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - file://C:\install.cab
    O16 - DPF: {42F2D240-B23C-11D6-8C73-70A05DC10000} - http://63.217.31.12/dial5/058735fi.exe
    O16 - DPF: {EEECA057-AD0F-44A7-8BE5-8634CEDBDBD1} - http://akamai.downloadv3.com/binaries/IA/netpe32_EN.cab
    O16 - DPF: {F57D17AE-CE37-4BC8-B232-EA57747BE5E7} - http://real-euros.com/EPlugin_FI.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab

    Laita piilotiedostot näkyviin, tuossa ohjeet
    http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2002092715262339

    Käynnistä vikasietotilaan, näpyttele (F8) käynnistyksen aikana. Poista jos löydät
    C:\Program Files\-- Tuo kansio--websx

    Laita sitten uusi HjT logi