tarvisin apua..

jussi

Logfile of HijackThis v1.99.0
Scan saved at 15:05:16, on 6.1.2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
C:\Norman\Nvc\BIN\Zanda.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Windows\system32\ZoneLabs\vsmon.exe
C:\NORMAN\Nvc\BIN\NJEEVES.EXE
C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
C:\NORMAN\Nvc\BIN\nipsvc.exe
C:\NORMAN\Nvc\BIN\nvcoas.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\NORMAN\Nvc\BIN\ZLH.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Winamp\winampa.exe
C:\NORMAN\Nvc\BIN\NYMSE.EXE
C:\NORMAN\Nvc\BIN\NIP.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\NORMAN\Nvc\BIN\cclaw.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\NORMAN\Nvc\BIN\npfmsg2.exe
C:\winzip\WZQKPICK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe
C:\Program Files\ht\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
O2 - BHO: (no name) - {F81CFBA6-C191-455C-836F-8EB4BB55ED8C} - C:\WINDOWS\System32\eong.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\Nvc\BIN\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [zSPGuard] c:\program files\virusohjelmat\spguard\spguard.exe /s
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\spy\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\winzip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O10 - Broken Internet access because of LSP provider 'xfire_lsp.dll' missing
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by13fd.bay13.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) - http://de.trendmicro-europe.com/file_downloads/common/housecall/HouseCallButton.CAB
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
O16 - DPF: {C40F8F85-3FC3-4C0C-AD91-6A204FAAD59F} (UCInstall Class) - http://ultimatecleaner.com/install/UCInst.cab
O18 - Filter: text/html - {08963AB8-DC00-44B0-9F3C-5CB8EBEA7A19} - C:\WINDOWS\System32\eong.dll
O18 - Filter: text/plain - {08963AB8-DC00-44B0-9F3C-5CB8EBEA7A19} - C:\WINDOWS\System32\eong.dll
O23 - Service: avast! iAVS4 Control Service - Unknown - C:\avant\aswUpdSv.exe (file missing)
O23 - Service: avast! Antivirus - Unknown - C:\avant\ashServ.exe (file missing)
O23 - Service: Loogisen levyn hallinnan valvontapalvelu - Unknown - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Tapahtumaloki - Unknown - C:\WINDOWS\system32\services.exe
O23 - Service: Fax - Unknown - C:\WINDOWS\system32\fxssvc.exe
O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu - Unknown - C:\WINDOWS\System32\imapi.exe
O23 - Service: InCD Helper - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod-palvelu - Unknown - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NetMeeting etätyöpöydän jakaminen - Unknown - C:\WINDOWS\System32\mnmsrvc.exe
O23 - Service: Verkon DDE - Unknown - C:\WINDOWS\system32\netdde.exe
O23 - Service: Verkon DDE DSDM - Unknown - C:\WINDOWS\system32\netdde.exe
O23 - Service: Norman API-hooking helper - Unknown - C:\NORMAN\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown - C:\NORMAN\Nvc\BIN\NJEEVES.EXE
O23 - Service: Norman Type-R - Unknown - C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
O23 - Service: Norman ZANDA - Unknown - C:\Norman\Nvc\BIN\Zanda.exe
O23 - Service: Norman Virus Control on-access component - Norman ASA - C:\NORMAN\Nvc\BIN\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler - Norman Data Defense Systems - C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
O23 - Service: Plug and Play - Unknown - C:\WINDOWS\system32\services.exe
O23 - Service: Etätyöpöydän ohjeen istunnonhallinta - Unknown - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Älykortti-apuohjelma - Unknown - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Älykortti - Unknown - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: SmartLinkService - Unknown - slserv.exe (file missing)
O23 - Service: Resurssilokit ja -hälytykset - Unknown - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\Windows\system32\ZoneLabs\vsmon.exe
O23 - Service: Aseman tilannevedos - Unknown - C:\WINDOWS\System32\vssvc.exe
O23 - Service: WMI resurssisovitin - Unknown - C:\WINDOWS\System32\wbem\wmiapsrv.exe

13

1087

    Vastaukset

    Anonyymi (Kirjaudu / Rekisteröidy)
    5000
    • Juu
      • jussi

      • Juu

      • jussi
        Juu kirjoitti:

        Käytäkkö sitä kyllä ohjeiden mukaan.
        Tuleeko mitään virheilmoitusta,vai se vaan jumittuu.
        Lähetä uus logi.

        ei mitään ilmoitusta, se vaan jumittuu niin myös konekkin samalla.


        Logfile of HijackThis v1.99.0
        Scan saved at 17:11:32, on 7.1.2005
        Platform: Windows XP SP1 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\NORMAN\Nvc\BIN\ZLH.EXE
        C:\Program Files\Ahead\InCD\InCD.exe
        C:\Program Files\Winamp\winampa.exe
        C:\Program Files\MSN Messenger\MsnMsgr.Exe
        C:\Program Files\Logitech\MouseWare\system\em_exec.exe
        C:\Program Files\Ahead\InCD\InCDsrv.exe
        C:\winzip\WZQKPICK.EXE
        C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        C:\Norman\Nvc\BIN\Zanda.exe
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\System32\wdfmgr.exe
        C:\Windows\system32\ZoneLabs\vsmon.exe
        C:\NORMAN\Nvc\BIN\NYMSE.EXE
        C:\NORMAN\Nvc\BIN\NIP.EXE
        C:\NORMAN\Nvc\BIN\npfmsg2.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe
        C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        C:\NORMAN\Nvc\BIN\nipsvc.exe
        C:\NORMAN\Nvc\BIN\nvcoas.exe
        C:\NORMAN\Nvc\BIN\cclaw.exe
        C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
        C:\imutusohjelmat\dc \DCPlusPlus.exe
        C:\Program Files\ht\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
        O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O2 - BHO: (no name) - {F81CFBA6-C191-455C-836F-8EB4BB55ED8C} - C:\WINDOWS\System32\eong.dll
        O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\Nvc\BIN\ZLH.EXE /LOAD /SPLASH
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
        O4 - HKLM\..\Run: [zSPGuard] c:\program files\virusohjelmat\spguard\spguard.exe /s
        O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\spy\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
        O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
        O4 - Global Startup: WinZip Quick Pick.lnk = C:\winzip\WZQKPICK.EXE
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
        O10 - Broken Internet access because of LSP provider 'xfire_lsp.dll' missing
        O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
        O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by13fd.bay13.hotmail.msn.com/resources/MsnPUpld.cab
        O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
        O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) - http://de.trendmicro-europe.com/file_downloads/common/housecall/HouseCallButton.CAB
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
        O16 - DPF: {C40F8F85-3FC3-4C0C-AD91-6A204FAAD59F} (UCInstall Class) - http://ultimatecleaner.com/install/UCInst.cab
        O18 - Filter: text/html - {08963AB8-DC00-44B0-9F3C-5CB8EBEA7A19} - C:\WINDOWS\System32\eong.dll
        O18 - Filter: text/plain - {08963AB8-DC00-44B0-9F3C-5CB8EBEA7A19} - C:\WINDOWS\System32\eong.dll
        O23 - Service: avast! iAVS4 Control Service - Unknown - C:\avant\aswUpdSv.exe (file missing)
        O23 - Service: avast! Antivirus - Unknown - C:\avant\ashServ.exe (file missing)
        O23 - Service: Loogisen levyn hallinnan valvontapalvelu - Unknown - C:\WINDOWS\System32\dmadmin.exe
        O23 - Service: Tapahtumaloki - Unknown - C:\WINDOWS\system32\services.exe
        O23 - Service: Fax - Unknown - C:\WINDOWS\system32\fxssvc.exe
        O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu - Unknown - C:\WINDOWS\System32\imapi.exe
        O23 - Service: InCD Helper - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
        O23 - Service: iPod-palvelu - Unknown - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: NetMeeting etätyöpöydän jakaminen - Unknown - C:\WINDOWS\System32\mnmsrvc.exe
        O23 - Service: Verkon DDE - Unknown - C:\WINDOWS\system32\netdde.exe
        O23 - Service: Verkon DDE DSDM - Unknown - C:\WINDOWS\system32\netdde.exe
        O23 - Service: Norman API-hooking helper - Unknown - C:\NORMAN\Nvc\BIN\nipsvc.exe
        O23 - Service: Norman NJeeves - Unknown - C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        O23 - Service: Norman Type-R - Unknown - C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        O23 - Service: Norman ZANDA - Unknown - C:\Norman\Nvc\BIN\Zanda.exe
        O23 - Service: Norman Virus Control on-access component - Norman ASA - C:\NORMAN\Nvc\BIN\nvcoas.exe
        O23 - Service: Norman Virus Control Scheduler - Norman Data Defense Systems - C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        O23 - Service: Plug and Play - Unknown - C:\WINDOWS\system32\services.exe
        O23 - Service: Etätyöpöydän ohjeen istunnonhallinta - Unknown - C:\WINDOWS\system32\sessmgr.exe
        O23 - Service: Älykortti-apuohjelma - Unknown - C:\WINDOWS\System32\SCardSvr.exe
        O23 - Service: Älykortti - Unknown - C:\WINDOWS\System32\SCardSvr.exe
        O23 - Service: SmartLinkService - Unknown - slserv.exe (file missing)
        O23 - Service: Resurssilokit ja -hälytykset - Unknown - C:\WINDOWS\system32\smlogsvc.exe
        O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\Windows\system32\ZoneLabs\vsmon.exe
        O23 - Service: Aseman tilannevedos - Unknown - C:\WINDOWS\System32\vssvc.exe
        O23 - Service: WMI resurssisovitin - Unknown - C:\WINDOWS\System32\wbem\wmiapsrv.exe


      • Juu
        jussi kirjoitti:

        ei mitään ilmoitusta, se vaan jumittuu niin myös konekkin samalla.


        Logfile of HijackThis v1.99.0
        Scan saved at 17:11:32, on 7.1.2005
        Platform: Windows XP SP1 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\NORMAN\Nvc\BIN\ZLH.EXE
        C:\Program Files\Ahead\InCD\InCD.exe
        C:\Program Files\Winamp\winampa.exe
        C:\Program Files\MSN Messenger\MsnMsgr.Exe
        C:\Program Files\Logitech\MouseWare\system\em_exec.exe
        C:\Program Files\Ahead\InCD\InCDsrv.exe
        C:\winzip\WZQKPICK.EXE
        C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        C:\Norman\Nvc\BIN\Zanda.exe
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\System32\wdfmgr.exe
        C:\Windows\system32\ZoneLabs\vsmon.exe
        C:\NORMAN\Nvc\BIN\NYMSE.EXE
        C:\NORMAN\Nvc\BIN\NIP.EXE
        C:\NORMAN\Nvc\BIN\npfmsg2.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe
        C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        C:\NORMAN\Nvc\BIN\nipsvc.exe
        C:\NORMAN\Nvc\BIN\nvcoas.exe
        C:\NORMAN\Nvc\BIN\cclaw.exe
        C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
        C:\imutusohjelmat\dc \DCPlusPlus.exe
        C:\Program Files\ht\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
        O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O2 - BHO: (no name) - {F81CFBA6-C191-455C-836F-8EB4BB55ED8C} - C:\WINDOWS\System32\eong.dll
        O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\Nvc\BIN\ZLH.EXE /LOAD /SPLASH
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
        O4 - HKLM\..\Run: [zSPGuard] c:\program files\virusohjelmat\spguard\spguard.exe /s
        O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\spy\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
        O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
        O4 - Global Startup: WinZip Quick Pick.lnk = C:\winzip\WZQKPICK.EXE
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
        O10 - Broken Internet access because of LSP provider 'xfire_lsp.dll' missing
        O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
        O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by13fd.bay13.hotmail.msn.com/resources/MsnPUpld.cab
        O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
        O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) - http://de.trendmicro-europe.com/file_downloads/common/housecall/HouseCallButton.CAB
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
        O16 - DPF: {C40F8F85-3FC3-4C0C-AD91-6A204FAAD59F} (UCInstall Class) - http://ultimatecleaner.com/install/UCInst.cab
        O18 - Filter: text/html - {08963AB8-DC00-44B0-9F3C-5CB8EBEA7A19} - C:\WINDOWS\System32\eong.dll
        O18 - Filter: text/plain - {08963AB8-DC00-44B0-9F3C-5CB8EBEA7A19} - C:\WINDOWS\System32\eong.dll
        O23 - Service: avast! iAVS4 Control Service - Unknown - C:\avant\aswUpdSv.exe (file missing)
        O23 - Service: avast! Antivirus - Unknown - C:\avant\ashServ.exe (file missing)
        O23 - Service: Loogisen levyn hallinnan valvontapalvelu - Unknown - C:\WINDOWS\System32\dmadmin.exe
        O23 - Service: Tapahtumaloki - Unknown - C:\WINDOWS\system32\services.exe
        O23 - Service: Fax - Unknown - C:\WINDOWS\system32\fxssvc.exe
        O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu - Unknown - C:\WINDOWS\System32\imapi.exe
        O23 - Service: InCD Helper - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
        O23 - Service: iPod-palvelu - Unknown - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: NetMeeting etätyöpöydän jakaminen - Unknown - C:\WINDOWS\System32\mnmsrvc.exe
        O23 - Service: Verkon DDE - Unknown - C:\WINDOWS\system32\netdde.exe
        O23 - Service: Verkon DDE DSDM - Unknown - C:\WINDOWS\system32\netdde.exe
        O23 - Service: Norman API-hooking helper - Unknown - C:\NORMAN\Nvc\BIN\nipsvc.exe
        O23 - Service: Norman NJeeves - Unknown - C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        O23 - Service: Norman Type-R - Unknown - C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        O23 - Service: Norman ZANDA - Unknown - C:\Norman\Nvc\BIN\Zanda.exe
        O23 - Service: Norman Virus Control on-access component - Norman ASA - C:\NORMAN\Nvc\BIN\nvcoas.exe
        O23 - Service: Norman Virus Control Scheduler - Norman Data Defense Systems - C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        O23 - Service: Plug and Play - Unknown - C:\WINDOWS\system32\services.exe
        O23 - Service: Etätyöpöydän ohjeen istunnonhallinta - Unknown - C:\WINDOWS\system32\sessmgr.exe
        O23 - Service: Älykortti-apuohjelma - Unknown - C:\WINDOWS\System32\SCardSvr.exe
        O23 - Service: Älykortti - Unknown - C:\WINDOWS\System32\SCardSvr.exe
        O23 - Service: SmartLinkService - Unknown - slserv.exe (file missing)
        O23 - Service: Resurssilokit ja -hälytykset - Unknown - C:\WINDOWS\system32\smlogsvc.exe
        O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\Windows\system32\ZoneLabs\vsmon.exe
        O23 - Service: Aseman tilannevedos - Unknown - C:\WINDOWS\System32\vssvc.exe
        O23 - Service: WMI resurssisovitin - Unknown - C:\WINDOWS\System32\wbem\wmiapsrv.exe

        Piilotiedostot näkyviin,ohje tuolla

        http://www.xtra.co.nz/help/0,,4155-1916458,00.html

        Merkkaa nuo sulje selain ja muut avoimet kkunat ja paina FIX checked

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        O2 - BHO: (no name) - {F81CFBA6-C191-455C-836F-8EB4BB55ED8C} - C:\WINDOWS\System32\eong.dll
        O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
        O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
        O18 - Filter: text/html - {08963AB8-DC00-44B0-9F3C-5CB8EBEA7A19} - C:\WINDOWS\System32\eong.dll
        O18 - Filter: text/plain - {08963AB8-DC00-44B0-9F3C-5CB8EBEA7A19} - C:\WINDOWS\System32\eong.dll


        Käynnistä sitte vikasietotilassa etsi ja poista jos löytyy

        eong.dll

        Käynnistä sitte normaalisti ja kokeile uudestaan jos se tooli toimis.


      • jussi
        Juu kirjoitti:

        Piilotiedostot näkyviin,ohje tuolla

        http://www.xtra.co.nz/help/0,,4155-1916458,00.html

        Merkkaa nuo sulje selain ja muut avoimet kkunat ja paina FIX checked

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        O2 - BHO: (no name) - {F81CFBA6-C191-455C-836F-8EB4BB55ED8C} - C:\WINDOWS\System32\eong.dll
        O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
        O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
        O18 - Filter: text/html - {08963AB8-DC00-44B0-9F3C-5CB8EBEA7A19} - C:\WINDOWS\System32\eong.dll
        O18 - Filter: text/plain - {08963AB8-DC00-44B0-9F3C-5CB8EBEA7A19} - C:\WINDOWS\System32\eong.dll


        Käynnistä sitte vikasietotilassa etsi ja poista jos löytyy

        eong.dll

        Käynnistä sitte normaalisti ja kokeile uudestaan jos se tooli toimis.

        Logfile of HijackThis v1.99.0
        Scan saved at 21:49:48, on 7.1.2005
        Platform: Windows XP SP1 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Ahead\InCD\InCDsrv.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        C:\NORMAN\Nvc\BIN\ZLH.EXE
        C:\Norman\Nvc\BIN\Zanda.exe
        C:\Program Files\Ahead\InCD\InCD.exe
        C:\Program Files\Winamp\winampa.exe
        C:\WINDOWS\system32\slserv.exe
        C:\Program Files\MSN Messenger\MsnMsgr.Exe
        C:\Program Files\Logitech\MouseWare\system\em_exec.exe
        C:\WINDOWS\System32\wdfmgr.exe
        C:\Windows\system32\ZoneLabs\vsmon.exe
        C:\NORMAN\Nvc\BIN\NYMSE.EXE
        C:\winzip\WZQKPICK.EXE
        C:\NORMAN\Nvc\BIN\NIP.EXE
        C:\NORMAN\Nvc\BIN\npfmsg2.exe
        C:\WINDOWS\System32\wuauclt.exe
        C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        C:\NORMAN\Nvc\BIN\nipsvc.exe
        C:\NORMAN\Nvc\BIN\nvcoas.exe
        C:\NORMAN\Nvc\BIN\cclaw.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe
        C:\Program Files\ht\HijackThis.exe

        O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
        O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\Nvc\BIN\ZLH.EXE /LOAD /SPLASH
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
        O4 - HKLM\..\Run: [zSPGuard] c:\program files\virusohjelmat\spguard\spguard.exe /s
        O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\spy\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
        O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
        O4 - Global Startup: WinZip Quick Pick.lnk = C:\winzip\WZQKPICK.EXE
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
        O10 - Broken Internet access because of LSP provider 'xfire_lsp.dll' missing
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by13fd.bay13.hotmail.msn.com/resources/MsnPUpld.cab
        O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
        O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) - http://de.trendmicro-europe.com/file_downloads/common/housecall/HouseCallButton.CAB
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
        O16 - DPF: {C40F8F85-3FC3-4C0C-AD91-6A204FAAD59F} (UCInstall Class) - http://ultimatecleaner.com/install/UCInst.cab
        O23 - Service: avast! iAVS4 Control Service - Unknown - C:\avant\aswUpdSv.exe (file missing)
        O23 - Service: avast! Antivirus - Unknown - C:\avant\ashServ.exe (file missing)
        O23 - Service: Loogisen levyn hallinnan valvontapalvelu - Unknown - C:\WINDOWS\System32\dmadmin.exe
        O23 - Service: Tapahtumaloki - Unknown - C:\WINDOWS\system32\services.exe
        O23 - Service: Fax - Unknown - C:\WINDOWS\system32\fxssvc.exe
        O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu - Unknown - C:\WINDOWS\System32\imapi.exe
        O23 - Service: InCD Helper - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
        O23 - Service: iPod-palvelu - Unknown - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: NetMeeting etätyöpöydän jakaminen - Unknown - C:\WINDOWS\System32\mnmsrvc.exe
        O23 - Service: Verkon DDE - Unknown - C:\WINDOWS\system32\netdde.exe
        O23 - Service: Verkon DDE DSDM - Unknown - C:\WINDOWS\system32\netdde.exe
        O23 - Service: Norman API-hooking helper - Unknown - C:\NORMAN\Nvc\BIN\nipsvc.exe
        O23 - Service: Norman NJeeves - Unknown - C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        O23 - Service: Norman Type-R - Unknown - C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        O23 - Service: Norman ZANDA - Unknown - C:\Norman\Nvc\BIN\Zanda.exe
        O23 - Service: Norman Virus Control on-access component - Norman ASA - C:\NORMAN\Nvc\BIN\nvcoas.exe
        O23 - Service: Norman Virus Control Scheduler - Norman Data Defense Systems - C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        O23 - Service: Plug and Play - Unknown - C:\WINDOWS\system32\services.exe
        O23 - Service: Etätyöpöydän ohjeen istunnonhallinta - Unknown - C:\WINDOWS\system32\sessmgr.exe
        O23 - Service: Älykortti-apuohjelma - Unknown - C:\WINDOWS\System32\SCardSvr.exe
        O23 - Service: Älykortti - Unknown - C:\WINDOWS\System32\SCardSvr.exe
        O23 - Service: SmartLinkService - Unknown - slserv.exe (file missing)
        O23 - Service: Resurssilokit ja -hälytykset - Unknown - C:\WINDOWS\system32\smlogsvc.exe
        O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\Windows\system32\ZoneLabs\vsmon.exe
        O23 - Service: Aseman tilannevedos - Unknown - C:\WINDOWS\System32\vssvc.exe
        O23 - Service: WMI resurssisovitin - Unknown - C:\WINDOWS\System32\wbem\wmiapsrv.exe


        tooli jumittaa edelleen..


      • Juu
        jussi kirjoitti:

        Logfile of HijackThis v1.99.0
        Scan saved at 21:49:48, on 7.1.2005
        Platform: Windows XP SP1 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Ahead\InCD\InCDsrv.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        C:\NORMAN\Nvc\BIN\ZLH.EXE
        C:\Norman\Nvc\BIN\Zanda.exe
        C:\Program Files\Ahead\InCD\InCD.exe
        C:\Program Files\Winamp\winampa.exe
        C:\WINDOWS\system32\slserv.exe
        C:\Program Files\MSN Messenger\MsnMsgr.Exe
        C:\Program Files\Logitech\MouseWare\system\em_exec.exe
        C:\WINDOWS\System32\wdfmgr.exe
        C:\Windows\system32\ZoneLabs\vsmon.exe
        C:\NORMAN\Nvc\BIN\NYMSE.EXE
        C:\winzip\WZQKPICK.EXE
        C:\NORMAN\Nvc\BIN\NIP.EXE
        C:\NORMAN\Nvc\BIN\npfmsg2.exe
        C:\WINDOWS\System32\wuauclt.exe
        C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        C:\NORMAN\Nvc\BIN\nipsvc.exe
        C:\NORMAN\Nvc\BIN\nvcoas.exe
        C:\NORMAN\Nvc\BIN\cclaw.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe
        C:\Program Files\ht\HijackThis.exe

        O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
        O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\Nvc\BIN\ZLH.EXE /LOAD /SPLASH
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
        O4 - HKLM\..\Run: [zSPGuard] c:\program files\virusohjelmat\spguard\spguard.exe /s
        O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\spy\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
        O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
        O4 - Global Startup: WinZip Quick Pick.lnk = C:\winzip\WZQKPICK.EXE
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
        O10 - Broken Internet access because of LSP provider 'xfire_lsp.dll' missing
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by13fd.bay13.hotmail.msn.com/resources/MsnPUpld.cab
        O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
        O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) - http://de.trendmicro-europe.com/file_downloads/common/housecall/HouseCallButton.CAB
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
        O16 - DPF: {C40F8F85-3FC3-4C0C-AD91-6A204FAAD59F} (UCInstall Class) - http://ultimatecleaner.com/install/UCInst.cab
        O23 - Service: avast! iAVS4 Control Service - Unknown - C:\avant\aswUpdSv.exe (file missing)
        O23 - Service: avast! Antivirus - Unknown - C:\avant\ashServ.exe (file missing)
        O23 - Service: Loogisen levyn hallinnan valvontapalvelu - Unknown - C:\WINDOWS\System32\dmadmin.exe
        O23 - Service: Tapahtumaloki - Unknown - C:\WINDOWS\system32\services.exe
        O23 - Service: Fax - Unknown - C:\WINDOWS\system32\fxssvc.exe
        O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu - Unknown - C:\WINDOWS\System32\imapi.exe
        O23 - Service: InCD Helper - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
        O23 - Service: iPod-palvelu - Unknown - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: NetMeeting etätyöpöydän jakaminen - Unknown - C:\WINDOWS\System32\mnmsrvc.exe
        O23 - Service: Verkon DDE - Unknown - C:\WINDOWS\system32\netdde.exe
        O23 - Service: Verkon DDE DSDM - Unknown - C:\WINDOWS\system32\netdde.exe
        O23 - Service: Norman API-hooking helper - Unknown - C:\NORMAN\Nvc\BIN\nipsvc.exe
        O23 - Service: Norman NJeeves - Unknown - C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        O23 - Service: Norman Type-R - Unknown - C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        O23 - Service: Norman ZANDA - Unknown - C:\Norman\Nvc\BIN\Zanda.exe
        O23 - Service: Norman Virus Control on-access component - Norman ASA - C:\NORMAN\Nvc\BIN\nvcoas.exe
        O23 - Service: Norman Virus Control Scheduler - Norman Data Defense Systems - C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        O23 - Service: Plug and Play - Unknown - C:\WINDOWS\system32\services.exe
        O23 - Service: Etätyöpöydän ohjeen istunnonhallinta - Unknown - C:\WINDOWS\system32\sessmgr.exe
        O23 - Service: Älykortti-apuohjelma - Unknown - C:\WINDOWS\System32\SCardSvr.exe
        O23 - Service: Älykortti - Unknown - C:\WINDOWS\System32\SCardSvr.exe
        O23 - Service: SmartLinkService - Unknown - slserv.exe (file missing)
        O23 - Service: Resurssilokit ja -hälytykset - Unknown - C:\WINDOWS\system32\smlogsvc.exe
        O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\Windows\system32\ZoneLabs\vsmon.exe
        O23 - Service: Aseman tilannevedos - Unknown - C:\WINDOWS\System32\vssvc.exe
        O23 - Service: WMI resurssisovitin - Unknown - C:\WINDOWS\System32\wbem\wmiapsrv.exe


        tooli jumittaa edelleen..

        Ota tosta DllCompare.exe

        http://www.downloads.subratam.org/DllCompare.exe

        Aukase se ja klikkaa Run Locate.com kohtaa
        Sitte klikkaa Compare kohtaa ja ootat että se tutkii valmiiks.
        Sitte klikkaa Make Log of what was found.

        Sitte kopioi alla oleva teksti notepadiin


        Reg save "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows" windows1.hiv
        ren windows1.hiv windows.txt


        Säästä se työpöydälle nimellä Appinit.bat
        Tallennusmuotoon kaikki tiedostot.

        Sitte klikkaat sitä Appinit.bat:ia työpöydällä
        ja ulos tulee windows.txt logi

        Kopioi ja pistä tänne sitte ne molemmat logit


      • kyllä
        jussi kirjoitti:

        Logfile of HijackThis v1.99.0
        Scan saved at 21:49:48, on 7.1.2005
        Platform: Windows XP SP1 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Ahead\InCD\InCDsrv.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        C:\NORMAN\Nvc\BIN\ZLH.EXE
        C:\Norman\Nvc\BIN\Zanda.exe
        C:\Program Files\Ahead\InCD\InCD.exe
        C:\Program Files\Winamp\winampa.exe
        C:\WINDOWS\system32\slserv.exe
        C:\Program Files\MSN Messenger\MsnMsgr.Exe
        C:\Program Files\Logitech\MouseWare\system\em_exec.exe
        C:\WINDOWS\System32\wdfmgr.exe
        C:\Windows\system32\ZoneLabs\vsmon.exe
        C:\NORMAN\Nvc\BIN\NYMSE.EXE
        C:\winzip\WZQKPICK.EXE
        C:\NORMAN\Nvc\BIN\NIP.EXE
        C:\NORMAN\Nvc\BIN\npfmsg2.exe
        C:\WINDOWS\System32\wuauclt.exe
        C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        C:\NORMAN\Nvc\BIN\nipsvc.exe
        C:\NORMAN\Nvc\BIN\nvcoas.exe
        C:\NORMAN\Nvc\BIN\cclaw.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe
        C:\Program Files\ht\HijackThis.exe

        O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
        O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\Nvc\BIN\ZLH.EXE /LOAD /SPLASH
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
        O4 - HKLM\..\Run: [zSPGuard] c:\program files\virusohjelmat\spguard\spguard.exe /s
        O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\spy\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
        O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
        O4 - Global Startup: WinZip Quick Pick.lnk = C:\winzip\WZQKPICK.EXE
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
        O10 - Broken Internet access because of LSP provider 'xfire_lsp.dll' missing
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by13fd.bay13.hotmail.msn.com/resources/MsnPUpld.cab
        O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
        O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) - http://de.trendmicro-europe.com/file_downloads/common/housecall/HouseCallButton.CAB
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
        O16 - DPF: {C40F8F85-3FC3-4C0C-AD91-6A204FAAD59F} (UCInstall Class) - http://ultimatecleaner.com/install/UCInst.cab
        O23 - Service: avast! iAVS4 Control Service - Unknown - C:\avant\aswUpdSv.exe (file missing)
        O23 - Service: avast! Antivirus - Unknown - C:\avant\ashServ.exe (file missing)
        O23 - Service: Loogisen levyn hallinnan valvontapalvelu - Unknown - C:\WINDOWS\System32\dmadmin.exe
        O23 - Service: Tapahtumaloki - Unknown - C:\WINDOWS\system32\services.exe
        O23 - Service: Fax - Unknown - C:\WINDOWS\system32\fxssvc.exe
        O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu - Unknown - C:\WINDOWS\System32\imapi.exe
        O23 - Service: InCD Helper - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
        O23 - Service: iPod-palvelu - Unknown - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: NetMeeting etätyöpöydän jakaminen - Unknown - C:\WINDOWS\System32\mnmsrvc.exe
        O23 - Service: Verkon DDE - Unknown - C:\WINDOWS\system32\netdde.exe
        O23 - Service: Verkon DDE DSDM - Unknown - C:\WINDOWS\system32\netdde.exe
        O23 - Service: Norman API-hooking helper - Unknown - C:\NORMAN\Nvc\BIN\nipsvc.exe
        O23 - Service: Norman NJeeves - Unknown - C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        O23 - Service: Norman Type-R - Unknown - C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        O23 - Service: Norman ZANDA - Unknown - C:\Norman\Nvc\BIN\Zanda.exe
        O23 - Service: Norman Virus Control on-access component - Norman ASA - C:\NORMAN\Nvc\BIN\nvcoas.exe
        O23 - Service: Norman Virus Control Scheduler - Norman Data Defense Systems - C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        O23 - Service: Plug and Play - Unknown - C:\WINDOWS\system32\services.exe
        O23 - Service: Etätyöpöydän ohjeen istunnonhallinta - Unknown - C:\WINDOWS\system32\sessmgr.exe
        O23 - Service: Älykortti-apuohjelma - Unknown - C:\WINDOWS\System32\SCardSvr.exe
        O23 - Service: Älykortti - Unknown - C:\WINDOWS\System32\SCardSvr.exe
        O23 - Service: SmartLinkService - Unknown - slserv.exe (file missing)
        O23 - Service: Resurssilokit ja -hälytykset - Unknown - C:\WINDOWS\system32\smlogsvc.exe
        O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\Windows\system32\ZoneLabs\vsmon.exe
        O23 - Service: Aseman tilannevedos - Unknown - C:\WINDOWS\System32\vssvc.exe
        O23 - Service: WMI resurssisovitin - Unknown - C:\WINDOWS\System32\wbem\wmiapsrv.exe


        tooli jumittaa edelleen..

        nämä
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe eli realplayer
        C:\Program Files\QuickTime\qttask.exe ja quicktime

        ja lataisin

        täältä nuo
        http://fin.afterdawn.com/ohjelmat/video_ohjelmat/dvd_soittimet/quicktime_alternative.cfm
        http://fin.afterdawn.com/ohjelmat/video_ohjelmat/dvd_soittimet/real_alternative.cfm

        onko nämä tarpeellisia

        O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
        sillä tämä puuttuu
        O10 - Broken Internet access because of LSP provider 'xfire_lsp.dll' missing

        C:\WINDOWS\system32\slserv.exe
        O23 - Service: SmartLinkService - Unknown - slserv.exe (file missing)

        sori jos sotken mukaa, sillä " juu " osaa kyllä hommansa.

        Mesen laittaisin kyllä suosiolla mäkeen !!!


      • jussi
        Juu kirjoitti:

        Ota tosta DllCompare.exe

        http://www.downloads.subratam.org/DllCompare.exe

        Aukase se ja klikkaa Run Locate.com kohtaa
        Sitte klikkaa Compare kohtaa ja ootat että se tutkii valmiiks.
        Sitte klikkaa Make Log of what was found.

        Sitte kopioi alla oleva teksti notepadiin


        Reg save "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows" windows1.hiv
        ren windows1.hiv windows.txt


        Säästä se työpöydälle nimellä Appinit.bat
        Tallennusmuotoon kaikki tiedostot.

        Sitte klikkaat sitä Appinit.bat:ia työpöydällä
        ja ulos tulee windows.txt logi

        Kopioi ja pistä tänne sitte ne molemmat logit

        * DLLCompare Log version()
        Files Found that Windows does not See or cannot Access
        *Not everything listed here means you are infected!
        ________________________________________________

        C:\WINDOWS\SYSTEM32\mskig.dll Mon 27 Sep 2004 0.06.16 A...R 57 344 56,00 K
        ________________________________________________

        1 241 items found: 1 241 files, 0 directories.
        Total of file sizes: 261 148 725 bytes 249,05 M

        Administrator Account = True

        --------------------End log---------------------


        ja windows.txt tuli tälläinen..
        regf       ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô{9 ó}

        hbin  ¨ÿÿÿnk, d


      • Juu
        jussi kirjoitti:

        * DLLCompare Log version()
        Files Found that Windows does not See or cannot Access
        *Not everything listed here means you are infected!
        ________________________________________________

        C:\WINDOWS\SYSTEM32\mskig.dll Mon 27 Sep 2004 0.06.16 A...R 57 344 56,00 K
        ________________________________________________

        1 241 items found: 1 241 files, 0 directories.
        Total of file sizes: 261 148 725 bytes 249,05 M

        Administrator Account = True

        --------------------End log---------------------


        ja windows.txt tuli tälläinen..
        regf       ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô€9 ô{9 ó}

        hbin  ¨ÿÿÿnk, d

        Joo tossa on se paholainen

        C:\WINDOWS\SYSTEM32\mskig.dll

        Sitte näköjään nuo FINDnFIX linkit ei toimi,joten joutuu kokeileen tälläviisiin sen poistoo.

        Piilotiedostot näkyviin ohje tuolla

        http://www.xtra.co.nz/help/0,,4155-1916458,00.html

        Ota tosta Hiving 154.zip

        http://computercops.biz/modules.php?name=Forums&file=download&id=1183

        Kun oot sen ladannu,niin ota kone pois netistä. (verkkopiuha irti)Se on tärkeetä

        Säästä se työpöydälle ja sitte purat sen työpöydälle.
        Tuplaklikkaa sitä hiving.bat:ia ja jos tulee jotain varotuksia,niin hyväksy sen käyttö .

        Sitte käynnistä kone vikasietotilassa ja etsi tuo

        C:\WINDOWS\SYSTEM32\mskig.dll


        klikkaa fiilua ja sitte sun pitää otta se omistukseen

        Sun pitää otta täydet oikeudet järjestemänvalvojana itelles

        Kato tuolta miten se tehään,että tiedät koska sää et voi tuolta samalla katsoo,koska kone ei saa olla netissä.

        http://support.microsoft.com/default.aspx?scid=kb;fi;308421

        Sitte kun sulla on täydet oikeudet järjestelmän valvojana,niin koitat poistaa sen fiilun,jos ei onnistu niin koita vaihtaa nimee sille
        Esim

        mskig.dll = bad.txt
        bad.txt = badfile.111

        Siis vaihat nimee mutaman kerran ja sitte koitat poistaa .


      • jussi
        Juu kirjoitti:

        Joo tossa on se paholainen

        C:\WINDOWS\SYSTEM32\mskig.dll

        Sitte näköjään nuo FINDnFIX linkit ei toimi,joten joutuu kokeileen tälläviisiin sen poistoo.

        Piilotiedostot näkyviin ohje tuolla

        http://www.xtra.co.nz/help/0,,4155-1916458,00.html

        Ota tosta Hiving 154.zip

        http://computercops.biz/modules.php?name=Forums&file=download&id=1183

        Kun oot sen ladannu,niin ota kone pois netistä. (verkkopiuha irti)Se on tärkeetä

        Säästä se työpöydälle ja sitte purat sen työpöydälle.
        Tuplaklikkaa sitä hiving.bat:ia ja jos tulee jotain varotuksia,niin hyväksy sen käyttö .

        Sitte käynnistä kone vikasietotilassa ja etsi tuo

        C:\WINDOWS\SYSTEM32\mskig.dll


        klikkaa fiilua ja sitte sun pitää otta se omistukseen

        Sun pitää otta täydet oikeudet järjestemänvalvojana itelles

        Kato tuolta miten se tehään,että tiedät koska sää et voi tuolta samalla katsoo,koska kone ei saa olla netissä.

        http://support.microsoft.com/default.aspx?scid=kb;fi;308421

        Sitte kun sulla on täydet oikeudet järjestelmän valvojana,niin koitat poistaa sen fiilun,jos ei onnistu niin koita vaihtaa nimee sille
        Esim

        mskig.dll = bad.txt
        bad.txt = badfile.111

        Siis vaihat nimee mutaman kerran ja sitte koitat poistaa .

        Logfile of HijackThis v1.98.2
        Scan saved at 14:16:44, on 8.1.2005
        Platform: Windows XP SP1 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Ahead\InCD\InCDsrv.exe
        C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        C:\Norman\Nvc\BIN\Zanda.exe
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\System32\wdfmgr.exe
        C:\Windows\system32\ZoneLabs\vsmon.exe
        C:\WINDOWS\Explorer.EXE
        C:\NORMAN\Nvc\BIN\ZLH.EXE
        C:\Program Files\Ahead\InCD\InCD.exe
        C:\Program Files\Logitech\MouseWare\system\em_exec.exe
        C:\NORMAN\Nvc\BIN\NYMSE.EXE
        C:\NORMAN\Nvc\BIN\NIP.EXE
        C:\Program Files\Winamp\winampa.exe
        C:\Program Files\MSN Messenger\MsnMsgr.Exe
        C:\NORMAN\Nvc\BIN\npfmsg2.exe
        C:\winzip\WZQKPICK.EXE
        C:\WINDOWS\System32\wuauclt.exe
        C:\NORMAN\Nvc\BIN\nvcoas.exe
        C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        C:\NORMAN\Nvc\BIN\nipsvc.exe
        C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        C:\NORMAN\Nvc\BIN\cclaw.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe
        C:\Program Files\hijack\hijackthis\HijackThis.exe

        O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
        O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\Nvc\BIN\ZLH.EXE /LOAD /SPLASH
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
        O4 - HKLM\..\Run: [zSPGuard] c:\program files\virusohjelmat\spguard\spguard.exe /s
        O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\spy\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
        O4 - Global Startup: WinZip Quick Pick.lnk = C:\winzip\WZQKPICK.EXE
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
        O10 - Broken Internet access because of LSP provider 'xfire_lsp.dll' missing
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by13fd.bay13.hotmail.msn.com/resources/MsnPUpld.cab
        O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
        O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) - http://de.trendmicro-europe.com/file_downloads/common/housecall/HouseCallButton.CAB
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
        O16 - DPF: {C40F8F85-3FC3-4C0C-AD91-6A204FAAD59F} (UCInstall Class) - http://ultimatecleaner.com/install/UCInst.cab


        onko nyt puhdas??


      • Juu
        jussi kirjoitti:

        Logfile of HijackThis v1.98.2
        Scan saved at 14:16:44, on 8.1.2005
        Platform: Windows XP SP1 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Ahead\InCD\InCDsrv.exe
        C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        C:\Norman\Nvc\BIN\Zanda.exe
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\System32\wdfmgr.exe
        C:\Windows\system32\ZoneLabs\vsmon.exe
        C:\WINDOWS\Explorer.EXE
        C:\NORMAN\Nvc\BIN\ZLH.EXE
        C:\Program Files\Ahead\InCD\InCD.exe
        C:\Program Files\Logitech\MouseWare\system\em_exec.exe
        C:\NORMAN\Nvc\BIN\NYMSE.EXE
        C:\NORMAN\Nvc\BIN\NIP.EXE
        C:\Program Files\Winamp\winampa.exe
        C:\Program Files\MSN Messenger\MsnMsgr.Exe
        C:\NORMAN\Nvc\BIN\npfmsg2.exe
        C:\winzip\WZQKPICK.EXE
        C:\WINDOWS\System32\wuauclt.exe
        C:\NORMAN\Nvc\BIN\nvcoas.exe
        C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        C:\NORMAN\Nvc\BIN\nipsvc.exe
        C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        C:\NORMAN\Nvc\BIN\cclaw.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe
        C:\Program Files\hijack\hijackthis\HijackThis.exe

        O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
        O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\Nvc\BIN\ZLH.EXE /LOAD /SPLASH
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
        O4 - HKLM\..\Run: [zSPGuard] c:\program files\virusohjelmat\spguard\spguard.exe /s
        O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\spy\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
        O4 - Global Startup: WinZip Quick Pick.lnk = C:\winzip\WZQKPICK.EXE
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
        O10 - Broken Internet access because of LSP provider 'xfire_lsp.dll' missing
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by13fd.bay13.hotmail.msn.com/resources/MsnPUpld.cab
        O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
        O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) - http://de.trendmicro-europe.com/file_downloads/common/housecall/HouseCallButton.CAB
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
        O16 - DPF: {C40F8F85-3FC3-4C0C-AD91-6A204FAAD59F} (UCInstall Class) - http://ultimatecleaner.com/install/UCInst.cab


        onko nyt puhdas??

        No hyvä,jos sait sen poistettua ja logi on puhas,mutta pari juttua.

        Jos sulla on koneella tuo XFire Messenger,niin mun mielestä tuo rivi saa olla.

        O10 - Broken Internet access because of LSP provider 'xfire_lsp.dll' missing

        Sitte tuo rivi

        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

        Jos ite tai joku muu on sen määritelly,niin anna olla,muuten merkkaa ja FIX:saa se.


      • jussi kirjoitti:

        Logfile of HijackThis v1.98.2
        Scan saved at 14:16:44, on 8.1.2005
        Platform: Windows XP SP1 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Ahead\InCD\InCDsrv.exe
        C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
        C:\Norman\Nvc\BIN\Zanda.exe
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\System32\wdfmgr.exe
        C:\Windows\system32\ZoneLabs\vsmon.exe
        C:\WINDOWS\Explorer.EXE
        C:\NORMAN\Nvc\BIN\ZLH.EXE
        C:\Program Files\Ahead\InCD\InCD.exe
        C:\Program Files\Logitech\MouseWare\system\em_exec.exe
        C:\NORMAN\Nvc\BIN\NYMSE.EXE
        C:\NORMAN\Nvc\BIN\NIP.EXE
        C:\Program Files\Winamp\winampa.exe
        C:\Program Files\MSN Messenger\MsnMsgr.Exe
        C:\NORMAN\Nvc\BIN\npfmsg2.exe
        C:\winzip\WZQKPICK.EXE
        C:\WINDOWS\System32\wuauclt.exe
        C:\NORMAN\Nvc\BIN\nvcoas.exe
        C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
        C:\NORMAN\Nvc\BIN\nipsvc.exe
        C:\NORMAN\Nvc\BIN\NJEEVES.EXE
        C:\NORMAN\Nvc\BIN\cclaw.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe
        C:\Program Files\hijack\hijackthis\HijackThis.exe

        O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
        O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\Nvc\BIN\ZLH.EXE /LOAD /SPLASH
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
        O4 - HKLM\..\Run: [zSPGuard] c:\program files\virusohjelmat\spguard\spguard.exe /s
        O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\spy\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
        O4 - Global Startup: WinZip Quick Pick.lnk = C:\winzip\WZQKPICK.EXE
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
        O10 - Broken Internet access because of LSP provider 'xfire_lsp.dll' missing
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by13fd.bay13.hotmail.msn.com/resources/MsnPUpld.cab
        O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
        O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) - http://de.trendmicro-europe.com/file_downloads/common/housecall/HouseCallButton.CAB
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
        O16 - DPF: {C40F8F85-3FC3-4C0C-AD91-6A204FAAD59F} (UCInstall Class) - http://ultimatecleaner.com/install/UCInst.cab


        onko nyt puhdas??

        Eiköhän poisteta tämä rivi.

        O16 - DPF: {C40F8F85-3FC3-4C0C-AD91-6A204FAAD59F} (UCInstall Class) - http://ultimatecleaner.com/install/UCInst.cab

        .
        .


    Ketjusta on poistettu 0 sääntöjenvastaista viestiä.

    Luetuimmat keskustelut

    1. Haluaisin rakastaa sinua

      Ja olla sinulle se oikea... Rakastan sinua 💗💗💗
      Ikävä
      42
      4300
    2. Vain vasemmistolaiset rakennemuutokset pelastavat Suomen

      Kansaa on ankeutettu viimeiset 30+ vuotta porvarillisella minäminä-talouspolitiikalla, jossa tavalliselta kansalta on ot
      Maailman menoa
      135
      4069
    3. Tiedätkö mihin

      Ominaisuuksiin rakastuin sinussa?
      Ikävä
      64
      3716
    4. onko kaivattusi

      vaarallinen? :D
      Ikävä
      87
      3551
    5. Purra on kantanut vastuuta täyden kympin arvoisesti

      Luottoluokituksen lasku, ennätysvelat ja ennätystyöttömyys siitä muutamana esimerkkinä. Jatkakoon hän hyvin aloittamaans
      Maailman menoa
      33
      3537
    6. Persut huutaa taas: "kato! muslimi!"

      Persut on lyhyessä ajassa ajaneet läpi kaksi työntekijöiden oikeuksien heikennystä, joita se on aiemmin vastustanut. Pe
      Maailman menoa
      64
      3341
    7. Pieni galluppi

      Mitäs lahjaa odotat joulupukilta.
      Ikävä
      86
      2921
    8. Olisiko sinulla

      Jonossa vaihtoehtoja, ehkä
      Ikävä
      54
      2835
    9. Mitä tuntemuksia

      Rakkaasi ääni herättää?
      Ikävä
      25
      2626
    10. Korjaamo suositus

      Vahva suositus Kumpulaisen korjaamolle vanhan 5-tien varrelta! Homma pelaa ja palvelu ykköslaatuista. Mukavaa kun tuli p
      Hyrynsalmi
      14
      2334
    Aihe