Mun HijackThis -logi, onko puhdas?

Niin, ja voisinko sulkea jotain noista Running Programs:sta kun koneessa on 233 mHz eikä se kestä enää noin montaa.


Logfile of HijackThis v1.98.2
Scan saved at 19:07:34, on 19.10.2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\OHJELM~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
C:\Ohjelmatiedostot\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
C:\Ohjelmatiedostot\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
C:\Ohjelmatiedostot\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
C:\Ohjelmatiedostot\F-Secure Internet Security\Anti-Virus\fssm32.exe
C:\Ohjelmatiedostot\F-Secure Internet Security\Common\FSMA32.EXE
C:\Ohjelmatiedostot\F-Secure Internet Security\fswsclds.exe
C:\Ohjelmatiedostot\F-Secure Internet Security\Common\FSMB32.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Ohjelmatiedostot\F-Secure Internet Security\Common\FCH32.EXE
C:\Ohjelmatiedostot\WZCBDL Service\WZCBDLS.exe
C:\Ohjelmatiedostot\F-Secure Internet Security\backweb\4476822\Program\BackWeb-4476822.exe
C:\Ohjelmatiedostot\F-Secure Internet Security\Common\FAMEH32.EXE
C:\Ohjelmatiedostot\F-Secure Internet Security\Anti-Virus\fsav32.exe
C:\Ohjelmatiedostot\F-Secure Internet Security\FWES\Program\fsdfwd.exe
C:\Ohjelmatiedostot\D-Link\Air USB Utility\AirCFG.exe
C:\Ohjelmatiedostot\F-Secure Internet Security\Common\FSM32.EXE
C:\Ohjelmatiedostot\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe
C:\Ohjelmatiedostot\Yhteiset tiedostot\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Ohjelmatiedostot\Microsoft Office\Office\FINDFAST.EXE
F:\Ohjelmia\Process Explorer\procexp.exe
C:\HjT\HijackThis.exe
C:\HjT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fi/0SEFIFI/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mbnet.fi/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Sonera Plaza Oy
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://127.0.0.1:8080/proxyconf
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.inet.fi:800
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi;;localhost;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Ohjelmia\SPYBOT~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Ohjelmatiedostot\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\ohjelmatiedostot\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Ohjelmatiedostot\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\ohjelmatiedostot\google\googletoolbar1.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Ohjelmatiedostot\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [D-Link Air USB Utility] C:\Ohjelmatiedostot\D-Link\Air USB Utility\AirCFG.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Ohjelmatiedostot\F-Secure Internet Security\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Ohjelmatiedostot\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [msnappau] "C:\Ohjelmatiedostot\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Ohjelmatiedostot\Yhteiset tiedostot\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Microsoft Office Pikahaku.lnk = C:\Ohjelmatiedostot\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Ohjelmatiedostot\Yhteiset tiedostot\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Google Search - res://C:\Ohjelmatiedostot\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Ohjelmatiedostot\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Ohjelmatiedostot\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Ohjelmatiedostot\Google\GoogleToolbar1.dll/cmsimilar.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Ohjelmatiedostot\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Ohjelmatiedostot\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Ohjelmatiedostot\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab28578.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab
2214
Äänestä

Muut lukivat myös

Vastaukset 2

Vanhimmat

tuolla pahiksia minun silmään sattunut. Ota linkistä EasyCleaner, sillä saat poistettua käynnistyviä sekä myös palautettua jos tulee tarvis.
http://koti.mbnet.fi/pattaya1/muut_ilmaisohjelmat.htm

Kun laitat .exe päätteisen (esim. NeroCheck.exe)Googleen niin saat tietoa ohjelmasta.

Äänestä

vähennettäviksi käynnistyvistä ohjelmista:

Mutta teetkö sen Hijackthisillä vai noiden ohjelmien asetuksia muuttamalla, saat päättää itse.

O4 - HKLM\..\Run: [TkBellExe] "C:\Ohjelmatiedostot\Yhteiset tiedostot\Real\Update_OB\realsched.exe" -osboot

O4 - Startup: Microsoft Office Pikahaku.lnk = C:\Ohjelmatiedostot\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Ohjelmatiedostot\Yhteiset tiedostot\Adobe\Calibration\Adobe Gamma Loader.exe

Tarvitseeko tämä päivitysten kyttääjäkään olla käynnissä? En varmaksi tiedä, kun en käytä.
O4 - HKLM\..\Run: [msnappau] "C:\Ohjelmatiedostot\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe"

Äänestä

Kommentoi aloitusta


Kraak kirjoitti:

Niin, ja voisinko sulkea jotain noista Running Programs:sta kun koneessa on 233 mHz eikä se kestä enää noin montaa.


Logfile of HijackThis v1.98.2
Scan saved at 19:07:34, on 19.10.2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\OHJELM~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
C:\Ohjelmatiedostot\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
C:\Ohjelmatiedostot\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
C:\Ohjelmatiedostot\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
C:\Ohjelmatiedostot\F-Secure Internet Security\Anti-Virus\fssm32.exe
C:\Ohjelmatiedostot\F-Secure Internet Security\Common\FSMA32.EXE
C:\Ohjelmatiedostot\F-Secure Internet Security\fswsclds.exe
C:\Ohjelmatiedostot\F-Secure Internet Security\Common\FSMB32.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Ohjelmatiedostot\F-Secure Internet Security\Common\FCH32.EXE
C:\Ohjelmatiedostot\WZCBDL Service\WZCBDLS.exe
C:\Ohjelmatiedostot\F-Secure Internet Security\backweb\4476822\Program\BackWeb-4476822.exe
C:\Ohjelmatiedostot\F-Secure Internet Security\Common\FAMEH32.EXE
C:\Ohjelmatiedostot\F-Secure Internet Security\Anti-Virus\fsav32.exe
C:\Ohjelmatiedostot\F-Secure Internet Security\FWES\Program\fsdfwd.exe
C:\Ohjelmatiedostot\D-Link\Air USB Utility\AirCFG.exe
C:\Ohjelmatiedostot\F-Secure Internet Security\Common\FSM32.EXE
C:\Ohjelmatiedostot\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe
C:\Ohjelmatiedostot\Yhteiset tiedostot\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Ohjelmatiedostot\Microsoft Office\Office\FINDFAST.EXE
F:\Ohjelmia\Process Explorer\procexp.exe
C:\HjT\HijackThis.exe
C:\HjT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fi/0SEFIFI/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mbnet.fi/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Sonera Plaza Oy
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://127.0.0.1:8080/proxyconf
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.inet.fi:800
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi;;localhost;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Ohjelmia\SPYBOT~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Ohjelmatiedostot\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\ohjelmatiedostot\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Ohjelmatiedostot\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\ohjelmatiedostot\google\googletoolbar1.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Ohjelmatiedostot\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [D-Link Air USB Utility] C:\Ohjelmatiedostot\D-Link\Air USB Utility\AirCFG.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Ohjelmatiedostot\F-Secure Internet Security\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Ohjelmatiedostot\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [msnappau] "C:\Ohjelmatiedostot\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Ohjelmatiedostot\Yhteiset tiedostot\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Microsoft Office Pikahaku.lnk = C:\Ohjelmatiedostot\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Ohjelmatiedostot\Yhteiset tiedostot\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Google Search - res://C:\Ohjelmatiedostot\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Ohjelmatiedostot\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Ohjelmatiedostot\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Ohjelmatiedostot\Google\GoogleToolbar1.dll/cmsimilar.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Ohjelmatiedostot\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Ohjelmatiedostot\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Ohjelmatiedostot\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab28578.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab

Anonyymi
5000

Ilmoita asiaton sisältö

  • Sisältää materiaalia, joka on loukkaavaa, herjaavaa, rasistista, uhkailevaa tai ahdistelevaa.

  • Materiaali sisältää nimiä, yhteystietoja tai muita henkilökohtaisia tietoja. Julkisuuden henkilöistä, julkisissa viroissa toimivista ihmisistä sekä yritysten vastuuhenkilöistä saa keskustella työhön liittyen. Myös yksityiselämään liittyvistä asioista voi keskustella siltä osin, kuin niistä on julkisesti kerrottu.

  • Sisältää lapsille haitallista tai heiltä kiellettyä materiaalia. Seksuaalinen sisältö on sallittua aiheeseen tarkoitetuilla palstoilla, joiden ikäraja on 18 vuotta.

  • Lainvastaista sisältöä voi olla mm. yksityiselämää loukkaavan tiedon levitys, kiihottaminen kansanryhmää vastaan, laiton uhkaaminen, alaikäisiin liittyvä seksuaalinen sisältö/grooming, petokset, identiteettivarkaudet, kunnianloukkaukset ja tekijänoikeusrikkomukset.

  • Sisältö ei liity palstan tai keskusteluketjun aiheeseen.

  • Viesti ei ole suomea tai ruotsia (pl. International Forums), se sisältää mainontaa, se sisältää tekijänoikeuksin suojattua materiaalia, se on massapostitus tai jokin muu syy.

Jaa keskustelu