mikä mättää?

jussi

Logfile of HijackThis v1.99.0
Scan saved at 22:36:24, on 22.12.2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\NORMAN\Nvc\BIN\ZLH.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Windows ControlAd\WinCtlAd.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Windows ControlAd\WinCtlAdAlt.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
C:\winzip\WZQKPICK.EXE
C:\Norman\Nvc\BIN\Zanda.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\NORMAN\Nvc\BIN\NYMSE.EXE
C:\Windows\system32\ZoneLabs\vsmon.exe
C:\NORMAN\Nvc\BIN\NIP.EXE
C:\NORMAN\Nvc\BIN\npfmsg2.exe
C:\NORMAN\Nvc\BIN\nvcoas.exe
C:\NORMAN\Nvc\BIN\NJEEVES.EXE
C:\NORMAN\Nvc\BIN\nipsvc.exe
C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
C:\NORMAN\Nvc\BIN\cclaw.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe
C:\imutusohjelmat\dc \DCPlusPlus.exe
C:\Program Files\ht\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Markus Louhela\Local Settings\Temporary Internet Files\Content.IE5\Y4GNDSYR\HijackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\spy\SPYBOT~1\SDHelper.dll (file missing)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: (no name) - {ABD459A0-B5FD-40E6-9AB1-FD49209ABC6B} - C:\WINDOWS\System32\abohpc.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\Nvc\BIN\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [zSPGuard] c:\program files\virusohjelmat\spguard\spguard.exe /s
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Windows ControlAd] C:\Program Files\Windows ControlAd\WinCtlAd.exe
O4 - HKLM\..\Run: [Windows ServeAd] C:\Program Files\Windows ServeAd\WinServAd.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\spy\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\winzip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O10 - Broken Internet access because of LSP provider 'xfire_lsp.dll' missing
O15 - Trusted IP range: 67.19.185.246
O15 - Trusted IP range: (HKLM)
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by13fd.bay13.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5BDBD95C-1E7F-4FB1-8497-20AF879F8B68} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/fi/filesharingctrl.cab
O16 - DPF: {67B57B24-1DFE-538E-3589-0CF932FD45CA} - http://205.252.249.254/1/gdnFR1077.exe
O16 - DPF: {706F3805-27D7-478D-80E5-E25D2BB030B3} (VacPro.internazionale_ver3) - http://ocx1.advnt01.com/dialer/internazionale_ver3.CAB
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) - http://de.trendmicro-europe.com/file_downloads/common/housecall/HouseCallButton.CAB
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9E98E84C-79E1-49C3-82EB-798FCD552EFB} (VacPro.internazionale_ver4) - http://advnt01.com/dialer/internazionale_ver4.CAB
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.hostance.net/dialer/604485.exe
O18 - Filter: text/html - {0F906D41-C6F1-404E-B01E-CC16A9CB6451} - C:\WINDOWS\System32\abohpc.dll
O18 - Filter: text/plain - {0F906D41-C6F1-404E-B01E-CC16A9CB6451} - C:\WINDOWS\System32\abohpc.dll
O23 - Service: avast! iAVS4 Control Service - Unknown - C:\avant\aswUpdSv.exe (file missing)
O23 - Service: avast! Antivirus - Unknown - C:\avant\ashServ.exe (file missing)
O23 - Service: Loogisen levyn hallinnan valvontapalvelu - Unknown - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Tapahtumaloki - Unknown - C:\WINDOWS\system32\services.exe
O23 - Service: Fax - Unknown - C:\WINDOWS\system32\fxssvc.exe
O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu - Unknown - C:\WINDOWS\System32\imapi.exe
O23 - Service: InCD Helper - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod-palvelu - Unknown - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NetMeeting etätyöpöydän jakaminen - Unknown - C:\WINDOWS\System32\mnmsrvc.exe
O23 - Service: Verkon DDE - Unknown - C:\WINDOWS\system32\netdde.exe
O23 - Service: Verkon DDE DSDM - Unknown - C:\WINDOWS\system32\netdde.exe
O23 - Service: Norman API-hooking helper - Unknown - C:\NORMAN\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown - C:\NORMAN\Nvc\BIN\NJEEVES.EXE
O23 - Service: Norman Type-R - Unknown - C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
O23 - Service: Norman ZANDA - Unknown - C:\Norman\Nvc\BIN\Zanda.exe
O23 - Service: Norman Virus Control on-access component - Norman ASA - C:\NORMAN\Nvc\BIN\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler - Norman Data Defense Systems - C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
O23 - Service: Plug and Play - Unknown - C:\WINDOWS\system32\services.exe
O23 - Service: Etätyöpöydän ohjeen istunnonhallinta - Unknown - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Älykortti-apuohjelma - Unknown - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Älykortti - Unknown - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: SmartLinkService - Unknown - slserv.exe (file missing)
O23 - Service: Resurssilokit ja -hälytykset - Unknown - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\Windows\system32\ZoneLabs\vsmon.exe
O23 - Service: Aseman tilannevedos - Unknown - C:\WINDOWS\System32\vssvc.exe
O23 - Service: WMI resurssisovitin - Unknown - C:\WINDOWS\System32\wbem\wmiapsrv.exe

7

600

    Vastaukset

    Anonyymi (Kirjaudu / Rekisteröidy)
    5000
    • juggis
      • jussi

        Logfile of HijackThis v1.99.0
        Scan saved at 13:41:21, on 25.12.2004
        Platform: Windows XP SP1 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Ahead\InCD\InCDsrv.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        C:\NORMAN\Nvc\BIN\ZLH.EXE
        C:\Norman\Nvc\BIN\Zanda.exe
        C:\Program Files\Ahead\InCD\InCD.exe
        C:\WINDOWS\system32\slserv.exe
        C:\Program Files\Winamp\winampa.exe
        C:\Program Files\Windows ControlAd\WinCtlAd.exe
        C:\Program Files\Logitech\MouseWare\system\em_exec.exe
        C:\Program Files\MSN Messenger\MsnMsgr.Exe
        C:\Program Files\Windows ControlAd\WinCtlAdAlt.exe
        C:\WINDOWS\System32\wdfmgr.exe
        C:\Windows\system32\ZoneLabs\vsmon.exe
        C:\NORMAN\Nvc\BIN\NYMSE.EXE
        C:\NORMAN\Nvc\BIN\NIP.EXE
        C:\winzip\WZQKPICK.EXE
        C:\NORMAN\Nvc\BIN\npfmsg2.exe
        C:\WINDOWS\System32\wuauclt.exe
        C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        C:\NORMAN\Nvc\BIN\nipsvc.exe
        C:\NORMAN\Nvc\BIN\nvcoas.exe
        C:\NORMAN\Nvc\BIN\cclaw.exe
        C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe
        C:\Program Files\ht\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
        R3 - Default URLSearchHook is missing
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\spy\SPYBOT~1\SDHelper.dll (file missing)
        O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
        O2 - BHO: (no name) - {ABD459A0-B5FD-40E6-9AB1-FD49209ABC6B} - C:\WINDOWS\System32\abohpc.dll
        O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\Nvc\BIN\ZLH.EXE /LOAD /SPLASH
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
        O4 - HKLM\..\Run: [zSPGuard] c:\program files\virusohjelmat\spguard\spguard.exe /s
        O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKLM\..\Run: [Windows ControlAd] C:\Program Files\Windows ControlAd\WinCtlAd.exe
        O4 - HKLM\..\Run: [Windows ServeAd] C:\Program Files\Windows ServeAd\WinServAd.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\spy\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
        O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
        O4 - Global Startup: WinZip Quick Pick.lnk = C:\winzip\WZQKPICK.EXE
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
        O10 - Broken Internet access because of LSP provider 'xfire_lsp.dll' missing
        O15 - Trusted IP range: 67.19.185.246
        O15 - Trusted IP range: (HKLM)
        O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
        O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by13fd.bay13.hotmail.msn.com/resources/MsnPUpld.cab
        O16 - DPF: {5BDBD95C-1E7F-4FB1-8497-20AF879F8B68} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/fi/filesharingctrl.cab
        O16 - DPF: {67B57B24-1DFE-538E-3589-0CF932FD45CA} - http://205.252.249.254/1/gdnFR1077.exe
        O16 - DPF: {706F3805-27D7-478D-80E5-E25D2BB030B3} (VacPro.internazionale_ver3) - http://ocx1.advnt01.com/dialer/internazionale_ver3.CAB
        O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
        O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) - http://de.trendmicro-europe.com/file_downloads/common/housecall/HouseCallButton.CAB
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
        O16 - DPF: {9E98E84C-79E1-49C3-82EB-798FCD552EFB} (VacPro.internazionale_ver4) - http://advnt01.com/dialer/internazionale_ver4.CAB
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
        O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.hostance.net/dialer/604485.exe
        O18 - Filter: text/html - {561F7DF6-1A25-4A0E-A52D-3A5048477401} - C:\WINDOWS\System32\abohpc.dll
        O18 - Filter: text/plain - {561F7DF6-1A25-4A0E-A52D-3A5048477401} - C:\WINDOWS\System32\abohpc.dll
        O23 - Service: avast! iAVS4 Control Service - Unknown - C:\avant\aswUpdSv.exe (file missing)
        O23 - Service: avast! Antivirus - Unknown - C:\avant\ashServ.exe (file missing)
        O23 - Service: Loogisen levyn hallinnan valvontapalvelu - Unknown - C:\WINDOWS\System32\dmadmin.exe
        O23 - Service: Tapahtumaloki - Unknown - C:\WINDOWS\system32\services.exe
        O23 - Service: Fax - Unknown - C:\WINDOWS\system32\fxssvc.exe
        O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu - Unknown - C:\WINDOWS\System32\imapi.exe
        O23 - Service: InCD Helper - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
        O23 - Service: iPod-palvelu - Unknown - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: NetMeeting etätyöpöydän jakaminen - Unknown - C:\WINDOWS\System32\mnmsrvc.exe
        O23 - Service: Verkon DDE - Unknown - C:\WINDOWS\system32\netdde.exe
        O23 - Service: Verkon DDE DSDM - Unknown - C:\WINDOWS\system32\netdde.exe
        O23 - Service: Norman API-hooking helper - Unknown - C:\NORMAN\Nvc\BIN\nipsvc.exe
        O23 - Service: Norman NJeeves - Unknown - C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        O23 - Service: Norman Type-R - Unknown - C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        O23 - Service: Norman ZANDA - Unknown - C:\Norman\Nvc\BIN\Zanda.exe
        O23 - Service: Norman Virus Control on-access component - Norman ASA - C:\NORMAN\Nvc\BIN\nvcoas.exe
        O23 - Service: Norman Virus Control Scheduler - Norman Data Defense Systems - C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        O23 - Service: Plug and Play - Unknown - C:\WINDOWS\system32\services.exe
        O23 - Service: Etätyöpöydän ohjeen istunnonhallinta - Unknown - C:\WINDOWS\system32\sessmgr.exe
        O23 - Service: Älykortti-apuohjelma - Unknown - C:\WINDOWS\System32\SCardSvr.exe
        O23 - Service: Älykortti - Unknown - C:\WINDOWS\System32\SCardSvr.exe
        O23 - Service: SmartLinkService - Unknown - slserv.exe (file missing)
        O23 - Service: Resurssilokit ja -hälytykset - Unknown - C:\WINDOWS\system32\smlogsvc.exe
        O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\Windows\system32\ZoneLabs\vsmon.exe
        O23 - Service: Aseman tilannevedos - Unknown - C:\WINDOWS\System32\vssvc.exe
        O23 - Service: WMI resurssisovitin - Unknown - C:\WINDOWS\System32\wbem\wmiapsrv.exe


      • jussi kirjoitti:

        Logfile of HijackThis v1.99.0
        Scan saved at 13:41:21, on 25.12.2004
        Platform: Windows XP SP1 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Ahead\InCD\InCDsrv.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        C:\NORMAN\Nvc\BIN\ZLH.EXE
        C:\Norman\Nvc\BIN\Zanda.exe
        C:\Program Files\Ahead\InCD\InCD.exe
        C:\WINDOWS\system32\slserv.exe
        C:\Program Files\Winamp\winampa.exe
        C:\Program Files\Windows ControlAd\WinCtlAd.exe
        C:\Program Files\Logitech\MouseWare\system\em_exec.exe
        C:\Program Files\MSN Messenger\MsnMsgr.Exe
        C:\Program Files\Windows ControlAd\WinCtlAdAlt.exe
        C:\WINDOWS\System32\wdfmgr.exe
        C:\Windows\system32\ZoneLabs\vsmon.exe
        C:\NORMAN\Nvc\BIN\NYMSE.EXE
        C:\NORMAN\Nvc\BIN\NIP.EXE
        C:\winzip\WZQKPICK.EXE
        C:\NORMAN\Nvc\BIN\npfmsg2.exe
        C:\WINDOWS\System32\wuauclt.exe
        C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        C:\NORMAN\Nvc\BIN\nipsvc.exe
        C:\NORMAN\Nvc\BIN\nvcoas.exe
        C:\NORMAN\Nvc\BIN\cclaw.exe
        C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe
        C:\Program Files\ht\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
        R3 - Default URLSearchHook is missing
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\spy\SPYBOT~1\SDHelper.dll (file missing)
        O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
        O2 - BHO: (no name) - {ABD459A0-B5FD-40E6-9AB1-FD49209ABC6B} - C:\WINDOWS\System32\abohpc.dll
        O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\Nvc\BIN\ZLH.EXE /LOAD /SPLASH
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
        O4 - HKLM\..\Run: [zSPGuard] c:\program files\virusohjelmat\spguard\spguard.exe /s
        O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKLM\..\Run: [Windows ControlAd] C:\Program Files\Windows ControlAd\WinCtlAd.exe
        O4 - HKLM\..\Run: [Windows ServeAd] C:\Program Files\Windows ServeAd\WinServAd.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\spy\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
        O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
        O4 - Global Startup: WinZip Quick Pick.lnk = C:\winzip\WZQKPICK.EXE
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
        O10 - Broken Internet access because of LSP provider 'xfire_lsp.dll' missing
        O15 - Trusted IP range: 67.19.185.246
        O15 - Trusted IP range: (HKLM)
        O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
        O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by13fd.bay13.hotmail.msn.com/resources/MsnPUpld.cab
        O16 - DPF: {5BDBD95C-1E7F-4FB1-8497-20AF879F8B68} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/fi/filesharingctrl.cab
        O16 - DPF: {67B57B24-1DFE-538E-3589-0CF932FD45CA} - http://205.252.249.254/1/gdnFR1077.exe
        O16 - DPF: {706F3805-27D7-478D-80E5-E25D2BB030B3} (VacPro.internazionale_ver3) - http://ocx1.advnt01.com/dialer/internazionale_ver3.CAB
        O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
        O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) - http://de.trendmicro-europe.com/file_downloads/common/housecall/HouseCallButton.CAB
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
        O16 - DPF: {9E98E84C-79E1-49C3-82EB-798FCD552EFB} (VacPro.internazionale_ver4) - http://advnt01.com/dialer/internazionale_ver4.CAB
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
        O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.hostance.net/dialer/604485.exe
        O18 - Filter: text/html - {561F7DF6-1A25-4A0E-A52D-3A5048477401} - C:\WINDOWS\System32\abohpc.dll
        O18 - Filter: text/plain - {561F7DF6-1A25-4A0E-A52D-3A5048477401} - C:\WINDOWS\System32\abohpc.dll
        O23 - Service: avast! iAVS4 Control Service - Unknown - C:\avant\aswUpdSv.exe (file missing)
        O23 - Service: avast! Antivirus - Unknown - C:\avant\ashServ.exe (file missing)
        O23 - Service: Loogisen levyn hallinnan valvontapalvelu - Unknown - C:\WINDOWS\System32\dmadmin.exe
        O23 - Service: Tapahtumaloki - Unknown - C:\WINDOWS\system32\services.exe
        O23 - Service: Fax - Unknown - C:\WINDOWS\system32\fxssvc.exe
        O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu - Unknown - C:\WINDOWS\System32\imapi.exe
        O23 - Service: InCD Helper - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
        O23 - Service: iPod-palvelu - Unknown - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: NetMeeting etätyöpöydän jakaminen - Unknown - C:\WINDOWS\System32\mnmsrvc.exe
        O23 - Service: Verkon DDE - Unknown - C:\WINDOWS\system32\netdde.exe
        O23 - Service: Verkon DDE DSDM - Unknown - C:\WINDOWS\system32\netdde.exe
        O23 - Service: Norman API-hooking helper - Unknown - C:\NORMAN\Nvc\BIN\nipsvc.exe
        O23 - Service: Norman NJeeves - Unknown - C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        O23 - Service: Norman Type-R - Unknown - C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        O23 - Service: Norman ZANDA - Unknown - C:\Norman\Nvc\BIN\Zanda.exe
        O23 - Service: Norman Virus Control on-access component - Norman ASA - C:\NORMAN\Nvc\BIN\nvcoas.exe
        O23 - Service: Norman Virus Control Scheduler - Norman Data Defense Systems - C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        O23 - Service: Plug and Play - Unknown - C:\WINDOWS\system32\services.exe
        O23 - Service: Etätyöpöydän ohjeen istunnonhallinta - Unknown - C:\WINDOWS\system32\sessmgr.exe
        O23 - Service: Älykortti-apuohjelma - Unknown - C:\WINDOWS\System32\SCardSvr.exe
        O23 - Service: Älykortti - Unknown - C:\WINDOWS\System32\SCardSvr.exe
        O23 - Service: SmartLinkService - Unknown - slserv.exe (file missing)
        O23 - Service: Resurssilokit ja -hälytykset - Unknown - C:\WINDOWS\system32\smlogsvc.exe
        O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\Windows\system32\ZoneLabs\vsmon.exe
        O23 - Service: Aseman tilannevedos - Unknown - C:\WINDOWS\System32\vssvc.exe
        O23 - Service: WMI resurssisovitin - Unknown - C:\WINDOWS\System32\wbem\wmiapsrv.exe

        Moi

        Sammuta kone. Käynnistä VIKASIETOTILASSA.

        Poista ensimmäiseksi lisää / poista sovelluksen kautta seuraavat jos löytyy

        Windows ControlAd
        Windows ServeAd

        Paluu normaalitilaan. Sitten haet tuolta
        http://securityresponse.symantec.com/avcenter/venc/data/backdoor.agent.b.removal.tool.html

        työkalun. Lue ohjeet tarkasti !

        How to download and run the tool

        Pistä uusi logi tämän jälkeen ja ilmoitus myös siitä löysikö kyseinen työkalu mitään.
        .
        .


      • juggis
        jussi kirjoitti:

        Logfile of HijackThis v1.99.0
        Scan saved at 13:41:21, on 25.12.2004
        Platform: Windows XP SP1 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Ahead\InCD\InCDsrv.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        C:\NORMAN\Nvc\BIN\ZLH.EXE
        C:\Norman\Nvc\BIN\Zanda.exe
        C:\Program Files\Ahead\InCD\InCD.exe
        C:\WINDOWS\system32\slserv.exe
        C:\Program Files\Winamp\winampa.exe
        C:\Program Files\Windows ControlAd\WinCtlAd.exe
        C:\Program Files\Logitech\MouseWare\system\em_exec.exe
        C:\Program Files\MSN Messenger\MsnMsgr.Exe
        C:\Program Files\Windows ControlAd\WinCtlAdAlt.exe
        C:\WINDOWS\System32\wdfmgr.exe
        C:\Windows\system32\ZoneLabs\vsmon.exe
        C:\NORMAN\Nvc\BIN\NYMSE.EXE
        C:\NORMAN\Nvc\BIN\NIP.EXE
        C:\winzip\WZQKPICK.EXE
        C:\NORMAN\Nvc\BIN\npfmsg2.exe
        C:\WINDOWS\System32\wuauclt.exe
        C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        C:\NORMAN\Nvc\BIN\nipsvc.exe
        C:\NORMAN\Nvc\BIN\nvcoas.exe
        C:\NORMAN\Nvc\BIN\cclaw.exe
        C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe
        C:\Program Files\ht\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
        R3 - Default URLSearchHook is missing
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\spy\SPYBOT~1\SDHelper.dll (file missing)
        O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
        O2 - BHO: (no name) - {ABD459A0-B5FD-40E6-9AB1-FD49209ABC6B} - C:\WINDOWS\System32\abohpc.dll
        O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\Nvc\BIN\ZLH.EXE /LOAD /SPLASH
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
        O4 - HKLM\..\Run: [zSPGuard] c:\program files\virusohjelmat\spguard\spguard.exe /s
        O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKLM\..\Run: [Windows ControlAd] C:\Program Files\Windows ControlAd\WinCtlAd.exe
        O4 - HKLM\..\Run: [Windows ServeAd] C:\Program Files\Windows ServeAd\WinServAd.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\spy\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
        O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
        O4 - Global Startup: WinZip Quick Pick.lnk = C:\winzip\WZQKPICK.EXE
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
        O10 - Broken Internet access because of LSP provider 'xfire_lsp.dll' missing
        O15 - Trusted IP range: 67.19.185.246
        O15 - Trusted IP range: (HKLM)
        O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
        O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by13fd.bay13.hotmail.msn.com/resources/MsnPUpld.cab
        O16 - DPF: {5BDBD95C-1E7F-4FB1-8497-20AF879F8B68} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/fi/filesharingctrl.cab
        O16 - DPF: {67B57B24-1DFE-538E-3589-0CF932FD45CA} - http://205.252.249.254/1/gdnFR1077.exe
        O16 - DPF: {706F3805-27D7-478D-80E5-E25D2BB030B3} (VacPro.internazionale_ver3) - http://ocx1.advnt01.com/dialer/internazionale_ver3.CAB
        O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
        O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) - http://de.trendmicro-europe.com/file_downloads/common/housecall/HouseCallButton.CAB
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
        O16 - DPF: {9E98E84C-79E1-49C3-82EB-798FCD552EFB} (VacPro.internazionale_ver4) - http://advnt01.com/dialer/internazionale_ver4.CAB
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
        O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.hostance.net/dialer/604485.exe
        O18 - Filter: text/html - {561F7DF6-1A25-4A0E-A52D-3A5048477401} - C:\WINDOWS\System32\abohpc.dll
        O18 - Filter: text/plain - {561F7DF6-1A25-4A0E-A52D-3A5048477401} - C:\WINDOWS\System32\abohpc.dll
        O23 - Service: avast! iAVS4 Control Service - Unknown - C:\avant\aswUpdSv.exe (file missing)
        O23 - Service: avast! Antivirus - Unknown - C:\avant\ashServ.exe (file missing)
        O23 - Service: Loogisen levyn hallinnan valvontapalvelu - Unknown - C:\WINDOWS\System32\dmadmin.exe
        O23 - Service: Tapahtumaloki - Unknown - C:\WINDOWS\system32\services.exe
        O23 - Service: Fax - Unknown - C:\WINDOWS\system32\fxssvc.exe
        O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu - Unknown - C:\WINDOWS\System32\imapi.exe
        O23 - Service: InCD Helper - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
        O23 - Service: iPod-palvelu - Unknown - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: NetMeeting etätyöpöydän jakaminen - Unknown - C:\WINDOWS\System32\mnmsrvc.exe
        O23 - Service: Verkon DDE - Unknown - C:\WINDOWS\system32\netdde.exe
        O23 - Service: Verkon DDE DSDM - Unknown - C:\WINDOWS\system32\netdde.exe
        O23 - Service: Norman API-hooking helper - Unknown - C:\NORMAN\Nvc\BIN\nipsvc.exe
        O23 - Service: Norman NJeeves - Unknown - C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        O23 - Service: Norman Type-R - Unknown - C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        O23 - Service: Norman ZANDA - Unknown - C:\Norman\Nvc\BIN\Zanda.exe
        O23 - Service: Norman Virus Control on-access component - Norman ASA - C:\NORMAN\Nvc\BIN\nvcoas.exe
        O23 - Service: Norman Virus Control Scheduler - Norman Data Defense Systems - C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        O23 - Service: Plug and Play - Unknown - C:\WINDOWS\system32\services.exe
        O23 - Service: Etätyöpöydän ohjeen istunnonhallinta - Unknown - C:\WINDOWS\system32\sessmgr.exe
        O23 - Service: Älykortti-apuohjelma - Unknown - C:\WINDOWS\System32\SCardSvr.exe
        O23 - Service: Älykortti - Unknown - C:\WINDOWS\System32\SCardSvr.exe
        O23 - Service: SmartLinkService - Unknown - slserv.exe (file missing)
        O23 - Service: Resurssilokit ja -hälytykset - Unknown - C:\WINDOWS\system32\smlogsvc.exe
        O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\Windows\system32\ZoneLabs\vsmon.exe
        O23 - Service: Aseman tilannevedos - Unknown - C:\WINDOWS\System32\vssvc.exe
        O23 - Service: WMI resurssisovitin - Unknown - C:\WINDOWS\System32\wbem\wmiapsrv.exe

        Scannasitko cwshredderillä?
        Kotisivu ei ainakaan parantunut.

        Poista seuraavat lisää/poista sovelluksen kautta:
        Windows ControlAd
        Windows ServeAd
        Winad

        Ruksaa HJT:ssä seuraavat:

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        R3 - Default URLSearchHook is missing
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\spy\SPYBOT~1\SDHelper.dll (file missing)
        O2 - BHO: (no name) - {ABD459A0-B5FD-40E6-9AB1-FD49209ABC6B} - C:\WINDOWS\System32\abohpc.dll
        O4 - HKLM\..\Run: [Windows ControlAd] C:\Program Files\Windows ControlAd\WinCtlAd.exe
        O4 - HKLM\..\Run: [Windows ServeAd] C:\Program Files\Windows ServeAd\WinServAd.exe
        O16 - DPF: {67B57B24-1DFE-538E-3589-0CF932FD45CA} - http://205.252.249.254/1/gdnFR1077.exe
        O16 - DPF: {706F3805-27D7-478D-80E5-E25D2BB030B3} (VacPro.internazionale_ver3) - http://ocx1.advnt01.com/dialer/internazionale_ver3.CAB
        O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.hostance.net/dialer/604485.exe
        O18 - Filter: text/html - {561F7DF6-1A25-4A0E-A52D-3A5048477401} - C:\WINDOWS\System32\abohpc.dll
        O18 - Filter: text/plain - {561F7DF6-1A25-4A0E-A52D-3A5048477401} - C:\WINDOWS\System32\abohpc.dll

        Sammuta muut ohjelmat ja paina hjt:ssä Fix checked. Käynnistä kone vikasietitilaan ja etsi ja poista seuraavat:

        C:\WINDOWS\System32\abohpc.dll


      • juggis
        Ad-Aware kirjoitti:

        Moi

        Sammuta kone. Käynnistä VIKASIETOTILASSA.

        Poista ensimmäiseksi lisää / poista sovelluksen kautta seuraavat jos löytyy

        Windows ControlAd
        Windows ServeAd

        Paluu normaalitilaan. Sitten haet tuolta
        http://securityresponse.symantec.com/avcenter/venc/data/backdoor.agent.b.removal.tool.html

        työkalun. Lue ohjeet tarkasti !

        How to download and run the tool

        Pistä uusi logi tämän jälkeen ja ilmoitus myös siitä löysikö kyseinen työkalu mitään.
        .
        .

        Olit nopeampi.


      • jussi
        juggis kirjoitti:

        Scannasitko cwshredderillä?
        Kotisivu ei ainakaan parantunut.

        Poista seuraavat lisää/poista sovelluksen kautta:
        Windows ControlAd
        Windows ServeAd
        Winad

        Ruksaa HJT:ssä seuraavat:

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        R3 - Default URLSearchHook is missing
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\spy\SPYBOT~1\SDHelper.dll (file missing)
        O2 - BHO: (no name) - {ABD459A0-B5FD-40E6-9AB1-FD49209ABC6B} - C:\WINDOWS\System32\abohpc.dll
        O4 - HKLM\..\Run: [Windows ControlAd] C:\Program Files\Windows ControlAd\WinCtlAd.exe
        O4 - HKLM\..\Run: [Windows ServeAd] C:\Program Files\Windows ServeAd\WinServAd.exe
        O16 - DPF: {67B57B24-1DFE-538E-3589-0CF932FD45CA} - http://205.252.249.254/1/gdnFR1077.exe
        O16 - DPF: {706F3805-27D7-478D-80E5-E25D2BB030B3} (VacPro.internazionale_ver3) - http://ocx1.advnt01.com/dialer/internazionale_ver3.CAB
        O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.hostance.net/dialer/604485.exe
        O18 - Filter: text/html - {561F7DF6-1A25-4A0E-A52D-3A5048477401} - C:\WINDOWS\System32\abohpc.dll
        O18 - Filter: text/plain - {561F7DF6-1A25-4A0E-A52D-3A5048477401} - C:\WINDOWS\System32\abohpc.dll

        Sammuta muut ohjelmat ja paina hjt:ssä Fix checked. Käynnistä kone vikasietitilaan ja etsi ja poista seuraavat:

        C:\WINDOWS\System32\abohpc.dll

        Logfile of HijackThis v1.99.0
        Scan saved at 15:31:21, on 25.12.2004
        Platform: Windows XP SP1 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\Ahead\InCD\InCDsrv.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\NORMAN\Nvc\BIN\ZLH.EXE
        C:\Program Files\Ahead\InCD\InCD.exe
        C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        C:\Norman\Nvc\BIN\Zanda.exe
        C:\Program Files\Winamp\winampa.exe
        C:\Program Files\MSN Messenger\MsnMsgr.Exe
        C:\WINDOWS\system32\slserv.exe
        C:\Program Files\Logitech\MouseWare\system\em_exec.exe
        C:\WINDOWS\System32\wdfmgr.exe
        C:\Windows\system32\ZoneLabs\vsmon.exe
        C:\NORMAN\Nvc\BIN\NYMSE.EXE
        C:\winzip\WZQKPICK.EXE
        C:\NORMAN\Nvc\BIN\NIP.EXE
        C:\NORMAN\Nvc\BIN\npfmsg2.exe
        C:\WINDOWS\System32\wuauclt.exe
        C:\NORMAN\Nvc\BIN\nvcoas.exe
        C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        C:\NORMAN\Nvc\BIN\nipsvc.exe
        C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        C:\NORMAN\Nvc\BIN\cclaw.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe
        C:\Program Files\ht\HijackThis.exe

        O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
        O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\Nvc\BIN\ZLH.EXE /LOAD /SPLASH
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
        O4 - HKLM\..\Run: [zSPGuard] c:\program files\virusohjelmat\spguard\spguard.exe /s
        O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\spy\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
        O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
        O4 - Global Startup: WinZip Quick Pick.lnk = C:\winzip\WZQKPICK.EXE
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
        O10 - Broken Internet access because of LSP provider 'xfire_lsp.dll' missing
        O15 - Trusted IP range: 67.19.185.246
        O15 - Trusted IP range: (HKLM)
        O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
        O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by13fd.bay13.hotmail.msn.com/resources/MsnPUpld.cab
        O16 - DPF: {5BDBD95C-1E7F-4FB1-8497-20AF879F8B68} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/fi/filesharingctrl.cab
        O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
        O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) - http://de.trendmicro-europe.com/file_downloads/common/housecall/HouseCallButton.CAB
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
        O16 - DPF: {9E98E84C-79E1-49C3-82EB-798FCD552EFB} (VacPro.internazionale_ver4) - http://advnt01.com/dialer/internazionale_ver4.CAB
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
        O23 - Service: avast! iAVS4 Control Service - Unknown - C:\avant\aswUpdSv.exe (file missing)
        O23 - Service: avast! Antivirus - Unknown - C:\avant\ashServ.exe (file missing)
        O23 - Service: Loogisen levyn hallinnan valvontapalvelu - Unknown - C:\WINDOWS\System32\dmadmin.exe
        O23 - Service: Tapahtumaloki - Unknown - C:\WINDOWS\system32\services.exe
        O23 - Service: Fax - Unknown - C:\WINDOWS\system32\fxssvc.exe
        O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu - Unknown - C:\WINDOWS\System32\imapi.exe
        O23 - Service: InCD Helper - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
        O23 - Service: iPod-palvelu - Unknown - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: NetMeeting etätyöpöydän jakaminen - Unknown - C:\WINDOWS\System32\mnmsrvc.exe
        O23 - Service: Verkon DDE - Unknown - C:\WINDOWS\system32\netdde.exe
        O23 - Service: Verkon DDE DSDM - Unknown - C:\WINDOWS\system32\netdde.exe
        O23 - Service: Norman API-hooking helper - Unknown - C:\NORMAN\Nvc\BIN\nipsvc.exe
        O23 - Service: Norman NJeeves - Unknown - C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        O23 - Service: Norman Type-R - Unknown - C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        O23 - Service: Norman ZANDA - Unknown - C:\Norman\Nvc\BIN\Zanda.exe
        O23 - Service: Norman Virus Control on-access component - Norman ASA - C:\NORMAN\Nvc\BIN\nvcoas.exe
        O23 - Service: Norman Virus Control Scheduler - Norman Data Defense Systems - C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        O23 - Service: Plug and Play - Unknown - C:\WINDOWS\system32\services.exe
        O23 - Service: Etätyöpöydän ohjeen istunnonhallinta - Unknown - C:\WINDOWS\system32\sessmgr.exe
        O23 - Service: Älykortti-apuohjelma - Unknown - C:\WINDOWS\System32\SCardSvr.exe
        O23 - Service: Älykortti - Unknown - C:\WINDOWS\System32\SCardSvr.exe
        O23 - Service: SmartLinkService - Unknown - slserv.exe (file missing)
        O23 - Service: Resurssilokit ja -hälytykset - Unknown - C:\WINDOWS\system32\smlogsvc.exe
        O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\Windows\system32\ZoneLabs\vsmon.exe
        O23 - Service: Aseman tilannevedos - Unknown - C:\WINDOWS\System32\vssvc.exe
        O23 - Service: WMI resurssisovitin - Unknown - C:\WINDOWS\System32\wbem\wmiapsrv.exe


      • jussi kirjoitti:

        Logfile of HijackThis v1.99.0
        Scan saved at 15:31:21, on 25.12.2004
        Platform: Windows XP SP1 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\Ahead\InCD\InCDsrv.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\NORMAN\Nvc\BIN\ZLH.EXE
        C:\Program Files\Ahead\InCD\InCD.exe
        C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        C:\Norman\Nvc\BIN\Zanda.exe
        C:\Program Files\Winamp\winampa.exe
        C:\Program Files\MSN Messenger\MsnMsgr.Exe
        C:\WINDOWS\system32\slserv.exe
        C:\Program Files\Logitech\MouseWare\system\em_exec.exe
        C:\WINDOWS\System32\wdfmgr.exe
        C:\Windows\system32\ZoneLabs\vsmon.exe
        C:\NORMAN\Nvc\BIN\NYMSE.EXE
        C:\winzip\WZQKPICK.EXE
        C:\NORMAN\Nvc\BIN\NIP.EXE
        C:\NORMAN\Nvc\BIN\npfmsg2.exe
        C:\WINDOWS\System32\wuauclt.exe
        C:\NORMAN\Nvc\BIN\nvcoas.exe
        C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        C:\NORMAN\Nvc\BIN\nipsvc.exe
        C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        C:\NORMAN\Nvc\BIN\cclaw.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe
        C:\Program Files\ht\HijackThis.exe

        O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
        O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\Nvc\BIN\ZLH.EXE /LOAD /SPLASH
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
        O4 - HKLM\..\Run: [zSPGuard] c:\program files\virusohjelmat\spguard\spguard.exe /s
        O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\spy\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
        O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
        O4 - Global Startup: WinZip Quick Pick.lnk = C:\winzip\WZQKPICK.EXE
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
        O10 - Broken Internet access because of LSP provider 'xfire_lsp.dll' missing
        O15 - Trusted IP range: 67.19.185.246
        O15 - Trusted IP range: (HKLM)
        O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
        O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by13fd.bay13.hotmail.msn.com/resources/MsnPUpld.cab
        O16 - DPF: {5BDBD95C-1E7F-4FB1-8497-20AF879F8B68} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/fi/filesharingctrl.cab
        O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
        O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) - http://de.trendmicro-europe.com/file_downloads/common/housecall/HouseCallButton.CAB
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
        O16 - DPF: {9E98E84C-79E1-49C3-82EB-798FCD552EFB} (VacPro.internazionale_ver4) - http://advnt01.com/dialer/internazionale_ver4.CAB
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
        O23 - Service: avast! iAVS4 Control Service - Unknown - C:\avant\aswUpdSv.exe (file missing)
        O23 - Service: avast! Antivirus - Unknown - C:\avant\ashServ.exe (file missing)
        O23 - Service: Loogisen levyn hallinnan valvontapalvelu - Unknown - C:\WINDOWS\System32\dmadmin.exe
        O23 - Service: Tapahtumaloki - Unknown - C:\WINDOWS\system32\services.exe
        O23 - Service: Fax - Unknown - C:\WINDOWS\system32\fxssvc.exe
        O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu - Unknown - C:\WINDOWS\System32\imapi.exe
        O23 - Service: InCD Helper - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
        O23 - Service: iPod-palvelu - Unknown - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: NetMeeting etätyöpöydän jakaminen - Unknown - C:\WINDOWS\System32\mnmsrvc.exe
        O23 - Service: Verkon DDE - Unknown - C:\WINDOWS\system32\netdde.exe
        O23 - Service: Verkon DDE DSDM - Unknown - C:\WINDOWS\system32\netdde.exe
        O23 - Service: Norman API-hooking helper - Unknown - C:\NORMAN\Nvc\BIN\nipsvc.exe
        O23 - Service: Norman NJeeves - Unknown - C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        O23 - Service: Norman Type-R - Unknown - C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        O23 - Service: Norman ZANDA - Unknown - C:\Norman\Nvc\BIN\Zanda.exe
        O23 - Service: Norman Virus Control on-access component - Norman ASA - C:\NORMAN\Nvc\BIN\nvcoas.exe
        O23 - Service: Norman Virus Control Scheduler - Norman Data Defense Systems - C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        O23 - Service: Plug and Play - Unknown - C:\WINDOWS\system32\services.exe
        O23 - Service: Etätyöpöydän ohjeen istunnonhallinta - Unknown - C:\WINDOWS\system32\sessmgr.exe
        O23 - Service: Älykortti-apuohjelma - Unknown - C:\WINDOWS\System32\SCardSvr.exe
        O23 - Service: Älykortti - Unknown - C:\WINDOWS\System32\SCardSvr.exe
        O23 - Service: SmartLinkService - Unknown - slserv.exe (file missing)
        O23 - Service: Resurssilokit ja -hälytykset - Unknown - C:\WINDOWS\system32\smlogsvc.exe
        O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\Windows\system32\ZoneLabs\vsmon.exe
        O23 - Service: Aseman tilannevedos - Unknown - C:\WINDOWS\System32\vssvc.exe
        O23 - Service: WMI resurssisovitin - Unknown - C:\WINDOWS\System32\wbem\wmiapsrv.exe

        Käytitkö sitä työkalua ja löysikö se

        Backdoor.Agent.B Removal Tool

        mitään ?

        FIXaa vielä nämä rivit logista.

        O15 - Trusted IP range: 67.19.185.246
        O15 - Trusted IP range: (HKLM)

        O16 - DPF: {5BDBD95C-1E7F-4FB1-8497-20AF879F8B68} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/fi/filesharingctrl.cab
        O16 - DPF: {9E98E84C-79E1-49C3-82EB-798FCD552EFB} (VacPro.internazionale_ver4) - http://advnt01.com/dialer/internazionale_ver4.CAB

        .
        .


    Ketjusta on poistettu 0 sääntöjenvastaista viestiä.

    Luetuimmat keskustelut

    1. Taitaa jäädä kotimaiset mansikat ostamatta

      Kotimainen mansikka on niin kallista, että en ole vielä ainuttakana maistanut. Jos hinta pysyy näin korkealla niin tästä
      Ruoka ja juoma
      79
      2392
    2. Sinkkumiehet hukkaavat tärkeän ässän hihastaan kun

      ...eivät suostu kavereiksi naisten kanssa. Mikä voi olla heillä syynä? Hyväksyvät vain naisen, joka suorastaan anelee sa
      Ikävä
      142
      1538
    3. Mikä on loppuelämäsi suunnitelma

      Kaivattuasi kohtaan? Olet päättänyt jotain?
      Ikävä
      133
      1462
    4. Uskaltaisitko vielä

      Lähestyä vai et kaivattuasi?
      Ikävä
      158
      1234
    5. Keitä täällä on??

      Kertokaa nimenne!! 🤔
      Ikävä
      109
      1033
    6. "Kaikkien miesten asia" - kampanja on alkanut

      Miehillä on naisiin kohdistuvan väkivallan lopettamisessa merkittävä rooli. Ei riitä, ettei itse tee väkivaltaa. Miesten
      Maailman menoa
      386
      965
    7. Tiedät, että en voi enää laittaa viestiä

      Aikaa kulunut. Eikä se näyttäisi enää luontevalta vastata näin pitkän ajan jälkeen. Tiedän myös, että sinä et enää lait
      Ikävä
      82
      774
    8. Lautakunta käsittelee Iisalmen kulttuuri- ja vapaa-aikajohtajan virkasuhteen purkua koeajalla:

      Lautakunta käsittelee Iisalmen kulttuuri- ja vapaa-aikajohtajan virkasuhteen purkua koeajalla: "Aina valinta ei mene nap
      Iisalmi
      55
      724
    9. Lienee aika luopua siitä kaikesta

      mitä meillä ikinä olikaan. Hassua, koska juuri mitään ei ole edes ollutkaan. En vaan jaksa tätä mahdotonta juttua enää j
      Ikävä
      67
      694
    10. Kun kohtaatte rakkauden, tarttukaa siihen

      Toimisinko jälkiviisaana toisin? Varmasti. Vaikka silloin kuvittelin tekeväni, niin kuin on oikein. Mahdollisimman siist
      Ikävä
      50
      683
    Aihe