eScanin löydöt

skanneri

onko peli menetetty?
File C:\DOCUME~1\Omistaja\APPLIC~1\MAILBI~1\BONEBR~1.EXE infected by "Trojan-Downloader.Win32.Swizzor.bo" Virus. Action Taken: File to be deleted on reboot.
File C:\DOCUME~1\ALLUSE~1\APPLIC~1\TYPENU~1\MEET01~1.EXE infected by "Trojan-Downloader.Win32.Swizzor.cn" Virus. Action Taken: File Deleted.
File C:\DOCUME~1\ALLUSE~1\APPLIC~1\ANTITE~1\ACEBYT~1.EXE tagged as not-a-virus:AdWare.Lop.ad. No Action Taken.
File C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOLDVG~1\TEAMAC~1.EXE tagged as not-a-virus:AdWare.Lop.ad. No Action Taken.
File C:\WINDOWS\system32\.pif infected by "Trojan-Downloader.BAT.Ftp.z" Virus. Action Taken: File Deleted.
File C:\WINDOWS\system32\tadam.pif infected by "Trojan-Downloader.BAT.Ftp.z" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\ace byte.exe tagged as not-a-virus:AdWare.Lop.ad. No Action Taken.
File C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\bodysettings.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\BoneLies.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\Bows Web.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\film first.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\grey wave.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\joyhide.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\MeetCopy.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\NURBMAIL.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\Sendmedia.exe tagged as not-a-virus:AdWare.Lop.ad. No Action Taken.
File C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\software barb.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\style dvd.exe tagged as not-a-virus:AdWare.Lop.ad. No Action Taken.
File C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\Support cash.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\Support Chic.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\tons four.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\tooltrust.exe tagged as not-a-virus:AdWare.Lop.ad. No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Bold Vga Bows Chin\Firstproxy.exe tagged as not-a-virus:AdWare.Lop.ad. No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Bold Vga Bows Chin\Second Sign.exe tagged as not-a-virus:AdWare.Lop.ad. No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Bold Vga Bows Chin\Team Acid.exe tagged as not-a-virus:AdWare.Lop.ad. No Action Taken.
File C:\Documents and Settings\All Users\Application Data\TypeNurbRegsSect\memokind.exe infected by "Trojan-Downloader.Win32.Swizzor.cn" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Application Data\MailBinVc\bone browse.exe infected by "Trojan-Downloader.Win32.Swizzor.bo" Virus. Action Taken: File to be deleted on reboot.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\Activesetup16.exe tagged as not-a-virus:AdWare.Lop.m. No Action Taken.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\aiquxxhk.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\aycqijbw.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\bags list platform grim.exe infected by "Trojan-Downloader.Win32.Swizzor.dr" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\duycjdbz.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\egdwzskz.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\ejtdfqts.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\fldlmjpz.exe tagged as not-a-virus:AdWare.Lop.ad. No Action Taken.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\hbfezyuw.exe infected by "Trojan-Downloader.Win32.Swizzor.dh" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\iyihnyyk.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\jouxqrxc.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\Mp3 Copy Meet.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\ngzvtiro.exe tagged as not-a-virus:AdWare.Lop.ad. No Action Taken.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\ntmcwwrx.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\nvmnoyyy.exe tagged as not-a-virus:AdWare.Lop.ad. No Action Taken.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\qpmqkjjh.exe tagged as not-a-virus:AdWare.Lop.ad. No Action Taken.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\qrvizuuw.exe infected by "Trojan-Downloader.Win32.Swizzor.cn" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\rcsbnkxe.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\vqukwvim.exe infected by "Trojan-Downloader.Win32.Swizzor.cn" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\wlszzyzg.exe tagged as not-a-virus:AdWare.Lop.ad. No Action Taken.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\wudpdrku.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\zrtpvvnx.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Application Data\MOVE 1 FOUR\zsdjpwjk.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Local Settings\Temp\ac68cdf1.exe infected by "Trojan-Downloader.Win32.Swizzor.di" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Local Settings\Temp\Inside Program.exe infected by "Trojan-Downloader.Win32.Swizzor.dr" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Local Settings\Temp\rnuznjmb.exe tagged as not-a-virus:AdWare.Lop.m. No Action Taken.
File C:\Documents and Settings\Omistaja\Local Settings\Temp\tnavbpni.exe tagged as not-a-virus:AdWare.Lop.m. No Action Taken.
File C:\Documents and Settings\Omistaja\Local Settings\Temp\wopfdpzv.exe tagged as not-a-virus:AdWare.Lop.m. No Action Taken.
File C:\Documents and Settings\Omistaja\Local Settings\Temporary Internet Files\Content.IE5\8317AEB1\upAYB[1].int infected by "Trojan-Downloader.Win32.Swizzor.dr" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Local Settings\Temporary Internet Files\Content.IE5\PVZZDD8E\upAYB[1].int infected by "Trojan-Downloader.Win32.Swizzor.di" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Local Settings\Temporary Internet Files\Content.IE5\PVZZDD8E\upAYB[2].int infected by "Trojan-Downloader.Win32.Swizzor.dj" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\Omistaja\Local Settings\Temporary Internet Files\Content.IE5\PVZZDD8E\upAYB[4].int infected by "Trojan-Downloader.Win32.Swizzor.dr" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP193\A0075583.exe tagged as not-a-virus:AdWare.Lop.m. No Action Taken.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP193\A0075584.exe tagged as not-a-virus:AdWare.Lop.ad. No Action Taken.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP193\A0075585.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP193\A0075611.exe tagged as not-a-virus:AdWare.Lop.m. No Action Taken.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP193\A0075612.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP193\A0075613.exe tagged as not-a-virus:AdWare.Lop.ad. No Action Taken.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP195\A0075884.exe tagged as not-a-virus:AdWare.Lop.m. No Action Taken.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP195\A0075885.exe tagged as not-a-virus:AdWare.Lop.ad. No Action Taken.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP195\A0075886.exe tagged as not-a-virus:AdWare.Lop.ad. No Action Taken.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP195\A0075887.exe infected by "Trojan-Downloader.Win32.Swizzor.bo" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP195\A0075888.exe infected by "Trojan-Downloader.Win32.Swizzor.dr" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP195\A0075889.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076301.exe infected by "Trojan-Downloader.Win32.Swizzor.cn" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076302.pif infected by "Trojan-Downloader.BAT.Ftp.z" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076303.pif infected by "Trojan-Downloader.BAT.Ftp.z" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076304.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076305.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076306.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076307.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076308.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076309.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076310.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076311.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076312.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076313.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076314.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076315.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076316.exe infected by "Trojan-Downloader.Win32.Swizzor.cn" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076317.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076318.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076319.exe infected by "Trojan-Downloader.Win32.Swizzor.dr" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076320.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076321.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076322.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076323.exe infected by "Trojan-Downloader.Win32.Swizzor.dh" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076324.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076325.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076326.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076327.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076328.exe infected by "Trojan-Downloader.Win32.Swizzor.cn" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076329.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076330.exe infected by "Trojan-Downloader.Win32.Swizzor.cn" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076331.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076332.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{0293F332-7200-4BC8-A383-89D98D0BA9E5}\RP202\A0076333.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus. Action Taken: File Deleted.
File C:\WINDOWS\system32\drivers\etc\hosts infected by "Trojan.Win32.Qhost.a" Virus. Action Taken: File Deleted.
File C:\WINDOWS\system32\drivers\etc\hosts.20050824-202858.backup infected by "Trojan.Win32.Qhost.a" Virus. Action Taken: File Deleted.
File C:\WINDOWS\system32\drivers\etc\hosts.20050910-145619.backup infected by "Trojan.Win32.Qhost.a" Virus. Action Taken: File Deleted.
File C:\WINDOWS\system32\drivers\etc\hosts.20050912-171350.backup infected by "Trojan.Win32.Qhost.a" Virus. Action Taken: File Deleted.

24

2026

    Vastaukset

    Anonyymi (Kirjaudu / Rekisteröidy)
    5000
    • tähän

      Logfile of HijackThis v1.99.1
      Scan saved at 10:37:37, on 16.9.2005
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\System32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Sygate\SPF\smc.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      C:\WINDOWS\system32\slserv.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\Real\RealPlayer\RealPlay.exe
      C:\Program Files\Winamp\winampa.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
      C:\Program Files\Microsoft Office\Office\OSA.EXE
      C:\Program Files\Internet Explorer\iexplore.exe
      c:\progra~1\intern~1\iexplore.exe
      C:\HJT\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.mytjrprsqqxaiwkrd.uk/T/MMe8s4yFxHr4u6r6vOtVxtR7JYiOKW_aM2Q7suSGLvyf7W4uikSSLZtwTO9F0z.html
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.xtatxhylvskyiuhnzg.com/T/MMe8s4yFzCPGlG7nah5fyxOWcwrcpAJvp4tkTc8ko.html
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {266E2D59-C577-42DB-4048-171642340C27} - C:\DOCUME~1\Omistaja\APPLIC~1\MAILBI~1\bone browse.exe
      O2 - BHO: (no name) - {B49968CA-5FCE-0C88-CE2A-05D7AC760A75} - C:\DOCUME~1\Omistaja\APPLIC~1\MAILBI~1\bone browse.exe
      O2 - BHO: (no name) - {EF5A9D6C-C210-08D0-9813-1E3168A392B9} - C:\DOCUME~1\Omistaja\APPLIC~1\MAILBI~1\bone browse.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
      O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
      O4 - HKLM\..\Run: [RegsSectDoesFace] C:\Documents and Settings\All Users\Application Data\TypeNurbRegsSect\meet 01.exe
      O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
      O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
      O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [corn download hide bags] C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\ace byte.exe
      O4 - HKLM\..\Run: [bowschinfivesecond] C:\Documents and Settings\All Users\Application Data\Bold Vga Bows Chin\Team Acid.exe
      O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Steam] "c:\valve\steam\steam.exe" -silent
      O4 - HKCU\..\Run: [debug poll] C:\DOCUME~1\Omistaja\APPLIC~1\MOVE1F~1\Activesetup16.exe
      O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
      O4 - Startup: PowerReg Scheduler.exe
      O4 - Global Startup: Microsoft Office Pikahaku.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
      O4 - Global Startup: Officen käynnistys.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
      O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
      O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125666863807
      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
      O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
      O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
      O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

      • Juu

        Merkkaa nuo sulje selain ja muut avoimet ikkunat ja paina Fix checked

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.mytjrprsqqxaiwkrd.uk/T/MMe8s4yFxHr4u6r6vOtVxtR7JYiOKW_aM2Q7suSGLvyf7W4uikSSLZtwTO9F0z.html
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.xtatxhylvskyiuhnzg.com/T/MMe8s4yFzCPGlG7nah5fyxOWcwrcpAJvp4tkTc8ko.html
        O2 - BHO: (no name) - {266E2D59-C577-42DB-4048-171642340C27} - C:\DOCUME~1\Omistaja\APPLIC~1\MAILBI~1\bone browse.exe
        O2 - BHO: (no name) - {B49968CA-5FCE-0C88-CE2A-05D7AC760A75} - C:\DOCUME~1\Omistaja\APPLIC~1\MAILBI~1\bone browse.exe
        O2 - BHO: (no name) - {EF5A9D6C-C210-08D0-9813-1E3168A392B9} - C:\DOCUME~1\Omistaja\APPLIC~1\MAILBI~1\bone browse.exe
        O4 - HKLM\..\Run: [RegsSectDoesFace] C:\Documents and Settings\All Users\Application Data\TypeNurbRegsSect\meet 01.exe
        O4 - HKLM\..\Run: [corn download hide bags] C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\ace byte.exe
        O4 - HKLM\..\Run: [bowschinfivesecond] C:\Documents and Settings\All Users\Application Data\Bold Vga Bows Chin\Team Acid.exe
        O4 - HKCU\..\Run: [debug poll] C:\DOCUME~1\Omistaja\APPLIC~1\MOVE1F~1\Activesetup16.exe
        O4 - Startup: PowerReg Scheduler.exe


        Käynnistä sitte vikasietotilassa ja poista

        C:\DOCUME~1\Omistaja\APPLIC~1\MAILBI~1\ < kansio

        C:\Documents and Settings\All Users\Application Data\TypeNurbRegsSect\ < kansio

        C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\ < kansio

        C:\Documents and Settings\All Users\Application Data\Bold Vga Bows Chin\ < kansio

        C:\DOCUME~1\Omistaja\APPLIC~1\MOVE1F~1\ < kansio

        C:\DOCUME~1\ALLUSE~1\APPLIC~1\ANTITE~1\ < kansio

        C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOLDVG~1\ < kansio


        Käynnistä sitte normaalisti ja uus Hijack logi.
        Pistä myös StartupList logi Hijackistä.

        Config... > MiscTools > sieltä löytyy

        Pistä ensin täpit niihin kahteen pikkuruutuun ja sitte vasta scannaa.


      • hei
        Juu kirjoitti:

        Merkkaa nuo sulje selain ja muut avoimet ikkunat ja paina Fix checked

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.mytjrprsqqxaiwkrd.uk/T/MMe8s4yFxHr4u6r6vOtVxtR7JYiOKW_aM2Q7suSGLvyf7W4uikSSLZtwTO9F0z.html
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.xtatxhylvskyiuhnzg.com/T/MMe8s4yFzCPGlG7nah5fyxOWcwrcpAJvp4tkTc8ko.html
        O2 - BHO: (no name) - {266E2D59-C577-42DB-4048-171642340C27} - C:\DOCUME~1\Omistaja\APPLIC~1\MAILBI~1\bone browse.exe
        O2 - BHO: (no name) - {B49968CA-5FCE-0C88-CE2A-05D7AC760A75} - C:\DOCUME~1\Omistaja\APPLIC~1\MAILBI~1\bone browse.exe
        O2 - BHO: (no name) - {EF5A9D6C-C210-08D0-9813-1E3168A392B9} - C:\DOCUME~1\Omistaja\APPLIC~1\MAILBI~1\bone browse.exe
        O4 - HKLM\..\Run: [RegsSectDoesFace] C:\Documents and Settings\All Users\Application Data\TypeNurbRegsSect\meet 01.exe
        O4 - HKLM\..\Run: [corn download hide bags] C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\ace byte.exe
        O4 - HKLM\..\Run: [bowschinfivesecond] C:\Documents and Settings\All Users\Application Data\Bold Vga Bows Chin\Team Acid.exe
        O4 - HKCU\..\Run: [debug poll] C:\DOCUME~1\Omistaja\APPLIC~1\MOVE1F~1\Activesetup16.exe
        O4 - Startup: PowerReg Scheduler.exe


        Käynnistä sitte vikasietotilassa ja poista

        C:\DOCUME~1\Omistaja\APPLIC~1\MAILBI~1\ < kansio

        C:\Documents and Settings\All Users\Application Data\TypeNurbRegsSect\ < kansio

        C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\ < kansio

        C:\Documents and Settings\All Users\Application Data\Bold Vga Bows Chin\ < kansio

        C:\DOCUME~1\Omistaja\APPLIC~1\MOVE1F~1\ < kansio

        C:\DOCUME~1\ALLUSE~1\APPLIC~1\ANTITE~1\ < kansio

        C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOLDVG~1\ < kansio


        Käynnistä sitte normaalisti ja uus Hijack logi.
        Pistä myös StartupList logi Hijackistä.

        Config... > MiscTools > sieltä löytyy

        Pistä ensin täpit niihin kahteen pikkuruutuun ja sitte vasta scannaa.

        mitähän tein kun nyt tämä näyttää tältä vaikka en ole vielä ohjeitasi käyttänyt?
        Logfile of HijackThis v1.99.1
        Scan saved at 14:42:18, on 16.9.2005
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\System32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Sygate\SPF\smc.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\Real\RealPlayer\RealPlay.exe
        C:\Program Files\Winamp\winampa.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
        C:\Program Files\Microsoft Office\Office\OSA.EXE
        C:\Program Files\Internet Explorer\iexplore.exe
        c:\progra~1\intern~1\iexplore.exe
        C:\Program Files\Opera2\Opera.exe
        C:\HJT\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.jmmcnusnoytgmcchbd.com/T/MMe8s4yFxHr4u6r6vOtVxtR7JYiOKW_aM2Q7suSGIXCa9IjekVDSLZtwTO9F0z.asp
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
        O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
        O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [corn download hide bags] C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\ace byte.exe
        O4 - HKLM\..\Run: [bowschinfivesecond] C:\Documents and Settings\All Users\Application Data\Bold Vga Bows Chin\Team Acid.exe
        O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [debug poll] C:\DOCUME~1\Omistaja\APPLIC~1\MOVE1F~1\Activesetup16.exe
        O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
        O4 - Startup: PowerReg Scheduler.exe
        O4 - Global Startup: Microsoft Office Pikahaku.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
        O4 - Global Startup: Officen käynnistys.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
        O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125666863807
        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
        O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
        O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
        O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
        O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
        O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe


      • haa
        Juu kirjoitti:

        Merkkaa nuo sulje selain ja muut avoimet ikkunat ja paina Fix checked

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.mytjrprsqqxaiwkrd.uk/T/MMe8s4yFxHr4u6r6vOtVxtR7JYiOKW_aM2Q7suSGLvyf7W4uikSSLZtwTO9F0z.html
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.xtatxhylvskyiuhnzg.com/T/MMe8s4yFzCPGlG7nah5fyxOWcwrcpAJvp4tkTc8ko.html
        O2 - BHO: (no name) - {266E2D59-C577-42DB-4048-171642340C27} - C:\DOCUME~1\Omistaja\APPLIC~1\MAILBI~1\bone browse.exe
        O2 - BHO: (no name) - {B49968CA-5FCE-0C88-CE2A-05D7AC760A75} - C:\DOCUME~1\Omistaja\APPLIC~1\MAILBI~1\bone browse.exe
        O2 - BHO: (no name) - {EF5A9D6C-C210-08D0-9813-1E3168A392B9} - C:\DOCUME~1\Omistaja\APPLIC~1\MAILBI~1\bone browse.exe
        O4 - HKLM\..\Run: [RegsSectDoesFace] C:\Documents and Settings\All Users\Application Data\TypeNurbRegsSect\meet 01.exe
        O4 - HKLM\..\Run: [corn download hide bags] C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\ace byte.exe
        O4 - HKLM\..\Run: [bowschinfivesecond] C:\Documents and Settings\All Users\Application Data\Bold Vga Bows Chin\Team Acid.exe
        O4 - HKCU\..\Run: [debug poll] C:\DOCUME~1\Omistaja\APPLIC~1\MOVE1F~1\Activesetup16.exe
        O4 - Startup: PowerReg Scheduler.exe


        Käynnistä sitte vikasietotilassa ja poista

        C:\DOCUME~1\Omistaja\APPLIC~1\MAILBI~1\ < kansio

        C:\Documents and Settings\All Users\Application Data\TypeNurbRegsSect\ < kansio

        C:\Documents and Settings\All Users\Application Data\AntiTeamCornDownload\ < kansio

        C:\Documents and Settings\All Users\Application Data\Bold Vga Bows Chin\ < kansio

        C:\DOCUME~1\Omistaja\APPLIC~1\MOVE1F~1\ < kansio

        C:\DOCUME~1\ALLUSE~1\APPLIC~1\ANTITE~1\ < kansio

        C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOLDVG~1\ < kansio


        Käynnistä sitte normaalisti ja uus Hijack logi.
        Pistä myös StartupList logi Hijackistä.

        Config... > MiscTools > sieltä löytyy

        Pistä ensin täpit niihin kahteen pikkuruutuun ja sitte vasta scannaa.

        tässä ohjeittesi mukaan tehty versio.
        näyttääkö vielä pahalta?Logfile of HijackThis v1.99.1
        Scan saved at 15:50:48, on 16.9.2005
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\System32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Sygate\SPF\smc.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\Real\RealPlayer\RealPlay.exe
        C:\Program Files\Winamp\winampa.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
        C:\Program Files\Microsoft Office\Office\OSA.EXE
        C:\HJT\HijackThis.exe
        C:\WINDOWS\system32\wuauclt.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.dieayyvhyurlildjpgiraqhw.uk/T/MMe8s4yFxHr4u6r6vOtVxtR7JYiOKW_aM2Q7suSGLlNtlZI/UHRiLZtwTO9F0z.jpg
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
        O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
        O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
        O4 - Global Startup: Microsoft Office Pikahaku.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
        O4 - Global Startup: Officen käynnistys.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
        O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125666863807
        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
        O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
        O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
        O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
        O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
        O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe


      • ei muuta kun menoksi
        haa kirjoitti:

        tässä ohjeittesi mukaan tehty versio.
        näyttääkö vielä pahalta?Logfile of HijackThis v1.99.1
        Scan saved at 15:50:48, on 16.9.2005
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\System32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Sygate\SPF\smc.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\Real\RealPlayer\RealPlay.exe
        C:\Program Files\Winamp\winampa.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
        C:\Program Files\Microsoft Office\Office\OSA.EXE
        C:\HJT\HijackThis.exe
        C:\WINDOWS\system32\wuauclt.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.dieayyvhyurlildjpgiraqhw.uk/T/MMe8s4yFxHr4u6r6vOtVxtR7JYiOKW_aM2Q7suSGLlNtlZI/UHRiLZtwTO9F0z.jpg
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
        O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
        O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
        O4 - Global Startup: Microsoft Office Pikahaku.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
        O4 - Global Startup: Officen käynnistys.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
        O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125666863807
        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
        O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
        O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
        O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
        O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
        O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

        hyvä tuli


      • Juu
        haa kirjoitti:

        tässä ohjeittesi mukaan tehty versio.
        näyttääkö vielä pahalta?Logfile of HijackThis v1.99.1
        Scan saved at 15:50:48, on 16.9.2005
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\System32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Sygate\SPF\smc.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\Real\RealPlayer\RealPlay.exe
        C:\Program Files\Winamp\winampa.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
        C:\Program Files\Microsoft Office\Office\OSA.EXE
        C:\HJT\HijackThis.exe
        C:\WINDOWS\system32\wuauclt.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.dieayyvhyurlildjpgiraqhw.uk/T/MMe8s4yFxHr4u6r6vOtVxtR7JYiOKW_aM2Q7suSGLlNtlZI/UHRiLZtwTO9F0z.jpg
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
        O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
        O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
        O4 - Global Startup: Microsoft Office Pikahaku.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
        O4 - Global Startup: Officen käynnistys.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
        O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125666863807
        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
        O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
        O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
        O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
        O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
        O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

        Merkkaa ja Fix:saa

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.dieayyvhyurlildjpgiraqhw.uk/T/MMe8s4yFxHr4u6r6vOtVxtR7JYiOKW_aM2Q7suSGLlNtlZI/UHRiLZtwTO9F0z.jpg

        ja sitte pistä se StartupList logi jota jo aikasemmin pyysin.


      • mutta

      • nyt
        Juu kirjoitti:

        Merkkaa ja Fix:saa

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.dieayyvhyurlildjpgiraqhw.uk/T/MMe8s4yFxHr4u6r6vOtVxtR7JYiOKW_aM2Q7suSGLlNtlZI/UHRiLZtwTO9F0z.jpg

        ja sitte pistä se StartupList logi jota jo aikasemmin pyysin.

        StartupList report, 16.9.2005, 18:59:58
        StartupList version: 1.52.2
        Started from : C:\HJT\HijackThis.EXE
        Detected: Windows XP SP2 (WinNT 5.01.2600)
        Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        * Using default options
        * Including empty and uninteresting sections
        * Showing rarely important sections
        ==================================================

        Running processes:

        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\System32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Sygate\SPF\smc.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\Real\RealPlayer\RealPlay.exe
        C:\Program Files\Winamp\winampa.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
        C:\Program Files\Microsoft Office\Office\OSA.EXE
        C:\Program Files\Opera2\Opera.exe
        C:\HJT\HijackThis.exe
        C:\WINDOWS\system32\NOTEPAD.EXE

        --------------------------------------------------

        Listing of startup folders:

        Shell folders Startup:
        [C:\Documents and Settings\Omistaja\Käynnistä-valikko\Ohjelmat\Käynnistys]
        *No files*

        Shell folders AltStartup:
        *Folder not found*

        User shell folders Startup:
        *Folder not found*

        User shell folders AltStartup:
        *Folder not found*

        Shell folders Common Startup:
        [C:\Documents and Settings\All Users\Käynnistä-valikko\Ohjelmat\Käynnistys]
        Microsoft Office Pikahaku.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
        Officen käynnistys.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE

        Shell folders Common AltStartup:
        *Folder not found*

        User shell folders Common Startup:
        *Folder not found*

        User shell folders Alternate Common Startup:
        *Folder not found*

        --------------------------------------------------

        Checking Windows NT UserInit:

        [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
        UserInit = C:\WINDOWS\system32\userinit.exe,

        [HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
        *Registry key not found*

        [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
        *Registry value not found*

        [HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKLM\Software\Microsoft\Windows\CurrentVersion\Run

        SunJavaUpdateSched = C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        SiSUSBRG = C:\WINDOWS\SiSUSBrg.exe
        ATIModeChange = Ati2mdxx.exe
        ATIPTA = C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        SoundMan = SOUNDMAN.EXE
        RealTray = C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
        NeroFilterCheck = C:\WINDOWS\system32\NeroCheck.exe
        PinnacleDriverCheck = C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
        WinampAgent = C:\Program Files\Winamp\winampa.exe
        AVG7_CC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
        AVG7_EMC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
        QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
        SmcService = C:\PROGRA~1\Sygate\SPF\smc.exe -startgui

        --------------------------------------------------

        Autorun entries from Registry:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

        *No values found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

        *No values found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKCU\Software\Microsoft\Windows\CurrentVersion\Run

        CTFMON.EXE = C:\WINDOWS\system32\ctfmon.exe
        H/PC Connection Agent = "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"

        --------------------------------------------------

        Autorun entries from Registry:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

        *No values found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

        *Registry key not found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKLM\Software\Microsoft\Windows\CurrentVersion\Run
        *No subkeys found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
        *No subkeys found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
        *No subkeys found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
        *Registry key not found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
        *Registry key not found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKCU\Software\Microsoft\Windows\CurrentVersion\Run
        *No subkeys found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
        *No subkeys found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
        *Registry key not found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
        *Registry key not found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
        *Registry key not found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
        *Registry key not found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
        *Registry key not found*

        --------------------------------------------------

        File association entry for .EXE:
        HKEY_CLASSES_ROOT\exefile\shell\open\command

        (Default) = "%1" %*

        --------------------------------------------------

        File association entry for .COM:
        HKEY_CLASSES_ROOT\comfile\shell\open\command

        (Default) = "%1" %*

        --------------------------------------------------

        File association entry for .BAT:
        HKEY_CLASSES_ROOT\batfile\shell\open\command

        (Default) = "%1" %*

        --------------------------------------------------

        File association entry for .PIF:
        HKEY_CLASSES_ROOT\piffile\shell\open\command

        (Default) = "%1" %*

        --------------------------------------------------

        File association entry for .SCR:
        HKEY_CLASSES_ROOT\scrfile\shell\open\command

        (Default) = "%1" /S

        --------------------------------------------------

        File association entry for .HTA:
        HKEY_CLASSES_ROOT\htafile\shell\open\command

        (Default) = C:\WINDOWS\System32\mshta.exe "%1" %*

        --------------------------------------------------

        File association entry for .TXT:
        HKEY_CLASSES_ROOT\txtfile\shell\open\command

        (Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

        --------------------------------------------------

        Enumerating Active Setup stub paths:
        HKLM\Software\Microsoft\Active Setup\Installed Components
        (* = disabled by HKCU twin)

        [>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
        StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

        [>{26923b43-4d38-484f-9b9e-de460746276c}] *
        StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE

        [>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
        StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

        [>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
        StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

        [{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
        StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

        [{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
        StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

        [{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
        StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

        [{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
        StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser

        [{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
        StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub

        [{7790769C-0471-11d2-AF11-00C04FA35D02}] *
        StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

        [{89820200-ECBD-11cf-8B85-00AA005B4340}] *
        StubPath = regsvr32.exe /s /n /i:U shell32.dll

        [{89820200-ECBD-11cf-8B85-00AA005B4383}] *
        StubPath = %SystemRoot%\system32\ie4uinit.exe

        [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
        StubPath = C:\WINDOWS\System32\Rundll32.exe C:\WINDOWS\System32\mscories.dll,Install

        --------------------------------------------------

        Enumerating ICQ Agent Autostart apps:
        HKCU\Software\Mirabilis\ICQ\Agent\Apps

        *Registry key not found*

        --------------------------------------------------

        Load/Run keys from C:\WINDOWS\WIN.INI:

        load=*INI section not found*
        run=*INI section not found*

        Load/Run keys from Registry:

        HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
        HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
        HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
        HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
        HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
        HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
        HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
        HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
        HKCU\..\Windows NT\CurrentVersion\Windows: load=
        HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
        HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
        HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
        HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

        --------------------------------------------------

        Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

        Shell=*INI section not found*
        SCRNSAVE.EXE=*INI section not found*
        drivers=*INI section not found*

        Shell & screensaver key from Registry:

        Shell=Explorer.exe
        SCRNSAVE.EXE=*Registry value not found*
        drivers=*Registry value not found*

        Policies Shell key:

        HKCU\..\Policies: Shell=*Registry key not found*
        HKLM\..\Policies: Shell=*Registry value not found*

        --------------------------------------------------

        Checking for EXPLORER.EXE instances:

        C:\WINDOWS\Explorer.exe: PRESENT!

        C:\Explorer.exe: not present
        C:\WINDOWS\Explorer\Explorer.exe: not present
        C:\WINDOWS\System\Explorer.exe: not present
        C:\WINDOWS\System32\Explorer.exe: not present
        C:\WINDOWS\Command\Explorer.exe: not present
        C:\WINDOWS\Fonts\Explorer.exe: not present

        --------------------------------------------------

        Checking for superhidden extensions:

        .lnk: HIDDEN! (arrow overlay: yes)
        .pif: HIDDEN! (arrow overlay: yes)
        .exe: not hidden
        .com: not hidden
        .bat: not hidden
        .hta: not hidden
        .scr: not hidden
        .shs: HIDDEN!
        .shb: HIDDEN!
        .vbs: not hidden
        .vbe: not hidden
        .wsh: not hidden
        .scf: HIDDEN! (arrow overlay: NO!)
        .url: HIDDEN! (arrow overlay: yes)
        .js: not hidden
        .jse: not hidden

        --------------------------------------------------

        Verifying REGEDIT.EXE integrity:

        - Regedit.exe found in C:\WINDOWS
        - .reg open command is normal (regedit.exe %1)
        - Regedit.exe has no CompanyName property! It is either missing or named something else.
        - Regedit.exe has no OriginalFilename property! It is either missing or named something else.
        - Regedit.exe has no FileDescription property! It is either missing or named something else.

        Registry check failed!

        --------------------------------------------------

        Enumerating Browser Helper Objects:

        (no name) - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}

        --------------------------------------------------

        Enumerating Task Scheduler jobs:

        A0D03B0D9183B1D5.job
        A9F2EB41918D6259.job
        AB3FD39B918048BB.job
        AD542B189183DEB0.job
        AF90B60D91872761.job

        --------------------------------------------------

        Enumerating Download Program Files:

        [Shockwave ActiveX Control]
        InProcServer32 = C:\WINDOWS\system32\Macromed\Director\SwDir.dll
        CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

        [Windows Genuine Advantage Validation Tool]
        InProcServer32 = C:\WINDOWS\System32\LegitCheckControl.DLL
        CODEBASE = http://go.microsoft.com/fwlink/?linkid=39204

        [WUWebControl Class]
        InProcServer32 = C:\WINDOWS\System32\wuweb.dll
        CODEBASE = http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125666863807

        [Java Plug-in 1.4.2_03]
        InProcServer32 = C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
        CODEBASE = http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab

        [MsnMessengerSetupDownloadControl Class]
        InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.ocx
        CODEBASE = http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab

        [Java Plug-in 1.4.2_03]
        InProcServer32 = C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
        CODEBASE = http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab

        [Shockwave Flash Object]
        InProcServer32 = C:\WINDOWS\System32\macromed\flash\Flash.ocx
        CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

        --------------------------------------------------

        Enumerating Winsock LSP files:

        NameSpace #1: C:\WINDOWS\System32\mswsock.dll
        NameSpace #2: C:\WINDOWS\System32\winrnr.dll
        NameSpace #3: C:\WINDOWS\System32\mswsock.dll
        NameSpace #4: C:\WINDOWS\System32\nwprovau.dll
        Protocol #1: C:\WINDOWS\system32\mswsock.dll
        Protocol #2: C:\WINDOWS\system32\mswsock.dll
        Protocol #3: C:\WINDOWS\system32\mswsock.dll
        Protocol #4: C:\WINDOWS\system32\mswsock.dll
        Protocol #5: C:\WINDOWS\system32\rsvpsp.dll
        Protocol #6: C:\WINDOWS\system32\rsvpsp.dll
        Protocol #7: C:\WINDOWS\system32\mswsock.dll
        Protocol #8: C:\WINDOWS\system32\mswsock.dll
        Protocol #9: C:\WINDOWS\system32\mswsock.dll
        Protocol #10: C:\WINDOWS\system32\mswsock.dll
        Protocol #11: C:\WINDOWS\system32\mswsock.dll
        Protocol #12: C:\WINDOWS\system32\mswsock.dll
        Protocol #13: C:\WINDOWS\system32\mswsock.dll
        Protocol #14: C:\WINDOWS\system32\mswsock.dll
        Protocol #15: C:\WINDOWS\system32\mswsock.dll
        Protocol #16: C:\WINDOWS\system32\mswsock.dll
        Protocol #17: C:\WINDOWS\system32\mswsock.dll
        Protocol #18: C:\WINDOWS\system32\mswsock.dll
        Protocol #19: C:\WINDOWS\system32\mswsock.dll
        Protocol #20: C:\WINDOWS\system32\mswsock.dll
        Protocol #21: C:\WINDOWS\system32\mswsock.dll
        Protocol #22: C:\WINDOWS\system32\mswsock.dll
        Protocol #23: C:\WINDOWS\system32\mswsock.dll
        Protocol #24: C:\WINDOWS\system32\mswsock.dll
        Protocol #25: C:\WINDOWS\system32\mswsock.dll
        Protocol #26: C:\WINDOWS\system32\mswsock.dll
        Protocol #27: C:\WINDOWS\system32\mswsock.dll
        Protocol #28: C:\WINDOWS\system32\mswsock.dll
        Protocol #29: C:\WINDOWS\system32\mswsock.dll

        --------------------------------------------------

        Enumerating Windows NT/2000/XP services

        61883 Unit Device: System32\DRIVERS\61883.sys (manual start)
        A4SII300: System32\drivers\A4SII300.SYS (autostart)
        Microsoft ACPI Driver: System32\DRIVERS\ACPI.sys (system)
        Microsoft Embedded Controller Driver: System32\DRIVERS\ACPIEC.sys (system)
        Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
        AFD Networking Support -ympäristö: \SystemRoot\System32\drivers\afd.sys (system)
        Service for WDM 3D Audio Driver: system32\drivers\ALCXSENS.SYS (manual start)
        Service for Realtek AC97 Audio (WDM): system32\drivers\ALCXWDM.SYS (manual start)
        Hälytys: %SystemRoot%\System32\svchost.exe -k LocalService (disabled)
        Sovelluskerroksen yhdyskäytäväpalvelu: %SystemRoot%\System32\alg.exe (manual start)
        AMD Athlon64 Processor Driver: System32\DRIVERS\AmdK8.sys (system)
        Sovellusten hallinta: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
        1394 ARP -asiakasprotokolla: System32\DRIVERS\arp1394.sys (manual start)
        ASAPIW2K: system32\drivers\ASAPIW2k.sys (manual start)
        ASP.NET-tilapalvelu: %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (manual start)
        RAS Asynchronous Media Driver: System32\DRIVERS\asyncmac.sys (manual start)
        Standardi IDE/ESDI-kiintolevyohjain: System32\DRIVERS\atapi.sys (system)
        Ati HotKey Poller: %SystemRoot%\System32\Ati2evxx.exe (autostart)
        ati2mtag: System32\DRIVERS\ati2mtag.sys (manual start)
        ATM ARP Client -protokolla: System32\DRIVERS\atmarpc.sys (manual start)
        Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Audio Stub Driver: System32\DRIVERS\audstub.sys (manual start)
        AVC-laite: System32\DRIVERS\avc.sys (manual start)
        AVG7 Alert Manager Server: C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (autostart)
        AVG7 Kernel: \SystemRoot\System32\Drivers\avg7core.sys (system)
        AVG7 Wrap Driver: \SystemRoot\System32\Drivers\avg7rsw.sys (system)
        AVG7 Rezident Driver: \SystemRoot\System32\Drivers\avg7rsxp.sys (system)
        AVG7 Update Service: C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (autostart)
        AVG Network Redirector: \??\C:\WINDOWS\System32\Drivers\avgtdi.sys (autostart)
        BITS-tausta-ajo (Background Intelligent Transfer Service): %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        MAC-silta: System32\DRIVERS\bridge.sys (manual start)
        MAC Bridge Miniport: System32\DRIVERS\bridge.sys (manual start)
        Tietokoneiden selaus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        BUFADPT: \??\C:\WINDOWS\System32\BUFADPT.SYS (autostart)
        Closed Caption Decoder: System32\DRIVERS\CCDECODE.sys (manual start)
        CD-ROM-ohjain: System32\DRIVERS\cdrom.sys (system)
        Indeksointipalvelu: %SystemRoot%\system32\cisvc.exe (manual start)
        Leikekirja: %SystemRoot%\system32\clipsrv.exe (disabled)
        Microsoft ACPI Control Method Battery Driver: System32\DRIVERS\CmBatt.sys (manual start)
        Microsoft Composite Battery Driver: System32\DRIVERS\compbatt.sys (system)
        COM -järjestelmäsovellus: C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
        CONAN: system32\drivers\o2mmb.sys (manual start)
        Salauspalvelut: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
        DCOM-palvelinprosessin käynnistys: %SystemRoot%\system32\svchost -k DcomLaunch (autostart)
        DHCP-asiakas: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Levyohjain: System32\DRIVERS\disk.sys (system)
        Loogisen levyn hallinnan valvontapalvelu: %SystemRoot%\System32\dmadmin.exe /com (manual start)
        dmboot: System32\drivers\dmboot.sys (disabled)
        dmio: System32\drivers\dmio.sys (disabled)
        dmload: System32\drivers\dmload.sys (disabled)
        Loogisen levyn hallinta: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
        DNS-asiakas: %SystemRoot%\System32\svchost.exe -k NetworkService (autostart)
        Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
        %1394\031887&040892.DeviceDesc%: System32\DRIVERS\enum1394.sys (manual start)
        Virheraportointipalvelut: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Tapahtumaloki: %SystemRoot%\system32\services.exe (autostart)
        COM -tapahtumajärjestelmä: C:\WINDOWS\System32\svchost.exe -k netsvcs (manual start)
        Nopean käyttäjän vaihdon yhteensopivuus: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        FltMgr: system32\drivers\fltmgr.sys (system)
        Volume Manager -ohjain: System32\DRIVERS\ftdisk.sys (system)
        GearAspiWDM: system32\drivers\gearaspiwdm.sys (manual start)
        Yleinen paketinmääritys: System32\DRIVERS\msgpc.sys (manual start)
        Ohjeet ja tuotetuki: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        HID (Human Interface Device) -liittymä: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
        Microsoft HID -luokkaohjain: System32\DRIVERS\hidusb.sys (manual start)
        HTTP: System32\Drivers\HTTP.sys (manual start)
        HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start)
        i8042-näppäimistö ja PS/2-hiiriohjain: System32\DRIVERS\i8042prt.sys (system)
        CD-Burning Filter Driver: System32\DRIVERS\imapi.sys (system)
        CD-levyjen kirjoittamisen IMAPI COM -palvelu: C:\WINDOWS\System32\imapi.exe (manual start)
        Windowsin IPv6-palomuurin ohjain: system32\drivers\ip6fw.sys (manual start)
        IP Traffic Filter Driver: System32\DRIVERS\ipfltdrv.sys (manual start)
        IP in IP Tunnel Driver: System32\DRIVERS\ipinip.sys (manual start)
        IP Network Address Translator: System32\DRIVERS\ipnat.sys (manual start)
        IPSEC-ohjain: System32\DRIVERS\ipsec.sys (system)
        IrDA-protokolla: System32\DRIVERS\irda.sys (autostart)
        IR Enumerator Service: System32\DRIVERS\irenum.sys (manual start)
        Infrapunavalvonta: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        PnP ISA/EISA -väyläohjain: System32\DRIVERS\isapnp.sys (system)
        Näppäimistön luokkaohjain: System32\DRIVERS\kbdclass.sys (system)
        kbeepm: \??\C:\DOCUME~1\Omistaja\LOCALS~1\Temp\kbeepm.sys (manual start)
        Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
        Palvelin: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Työasema: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        TCP/IP NetBIOS Helper: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
        MbxStby: system32\drivers\MbxStby.sys (manual start)
        Viestinvälitys: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
        NetMeeting etätyöpöydän jakaminen: C:\WINDOWS\System32\mnmsrvc.exe (manual start)
        Unimodem Streaming Filter Device: system32\drivers\MODEMCSA.sys (manual start)
        Hiiren luokkaohjain: System32\DRIVERS\mouclass.sys (system)
        Hiiren HID-ohjain: System32\DRIVERS\mouhid.sys (manual start)
        WebDav Client Redirector: System32\DRIVERS\mrxdav.sys (manual start)
        MRXSMB: System32\DRIVERS\mrxsmb.sys (system)
        Distributed Transaction Coordinator: C:\WINDOWS\System32\msdtc.exe (manual start)
        Microsoft DV Camera and VCR: System32\DRIVERS\msdv.sys (manual start)
        Windows Installer: C:\WINDOWS\System32\msiexec.exe /V (manual start)
        Microsoft Streaming Service -välityspalvelin: system32\drivers\MSKSSRV.sys (manual start)
        Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
        Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
        Microsoft-järjestelmänhallinnan BIOS-ohjain: System32\DRIVERS\mssmbios.sys (manual start)
        Microsoft Streaming Tee/Sink-to-Sink -muunnin: system32\drivers\MSTEE.sys (manual start)
        Mtlmnt5: System32\DRIVERS\Mtlmnt5.sys (manual start)
        Mtlstrm: System32\DRIVERS\Mtlstrm.sys (manual start)
        NABTS/FEC VBI Codec: System32\DRIVERS\NABTSFEC.sys (manual start)
        Microsoft TV/Video Connection: System32\DRIVERS\NdisIP.sys (manual start)
        Remote Access NDIS TAPI Driver: System32\DRIVERS\ndistapi.sys (manual start)
        NDIS Usermode I/O -protokolla: System32\DRIVERS\ndisuio.sys (manual start)
        Remote Access NDIS WAN Driver: System32\DRIVERS\ndiswan.sys (manual start)
        NetBIOS-käyttöliittymä: System32\DRIVERS\netbios.sys (system)
        NetBIOS TCP/IP:n päällä: System32\DRIVERS\netbt.sys (system)
        Verkon DDE: %SystemRoot%\system32\netdde.exe (disabled)
        Verkon DDE DSDM: %SystemRoot%\system32\netdde.exe (disabled)
        Verkkokirjautuminen: %SystemRoot%\System32\lsass.exe (manual start)
        Verkkoyhteydet: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        1394-verkko-ohjain: System32\DRIVERS\nic1394.sys (manual start)
        NLA-nimiavaruus (Network Location Awareness): %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        NSC-infrapunalaiteohjain: System32\DRIVERS\nscirda.sys (manual start)
        NT LM -suojaustuen toimittaja: %SystemRoot%\System32\lsass.exe (manual start)
        Siirrettävät tallennusvälineet: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
        NtMtlFax: System32\DRIVERS\NtMtlFax.sys (manual start)
        IPX Traffic Filter Driver: System32\DRIVERS\nwlnkflt.sys (manual start)
        IPX Traffic Forwarder Driver: System32\DRIVERS\nwlnkfwd.sys (manual start)
        NWLink IPX/SPX/NetBIOS -yhteensopiva kuljetusprotokolla: System32\DRIVERS\nwlnkipx.sys (autostart)
        NWLink NetBIOS: System32\DRIVERS\nwlnknb.sys (autostart)
        NWLink SPX/SPXII -protokolla: System32\DRIVERS\nwlnkspx.sys (autostart)
        SAP-agentti: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Texas Instruments OHCI Compliant IEEE 1394 Host Controller: System32\DRIVERS\ohci1394.sys (system)
        OLYMPUS Digital Camera: System32\Drivers\olcamudp.sys (manual start)
        Rinnakkaisporttiohjain: System32\DRIVERS\parport.sys (manual start)
        PCI Bus Driver: System32\DRIVERS\pci.sys (system)
        PCIIde: System32\DRIVERS\pciide.sys (system)
        Pcmcia: System32\DRIVERS\pcmcia.sys (system)
        PADUS ASPI SHELL: system32\drivers\pfc.sys (manual start)
        Plug and Play: %SystemRoot%\system32\services.exe (autostart)
        IPSEC-palvelut: %SystemRoot%\System32\lsass.exe (autostart)
        WAN Miniport (PPTP): System32\DRIVERS\raspptp.sys (manual start)
        Processor Driver: System32\DRIVERS\processr.sys (system)
        Suojattu tallennuspaikka: %SystemRoot%\system32\lsass.exe (autostart)
        QoS-paketinajoitus: System32\DRIVERS\psched.sys (manual start)
        Direct Parallel Link Driver: System32\DRIVERS\ptilink.sys (manual start)
        PxHelp20: System32\DRIVERS\PxHelp20.sys (system)
        Logitech QuickCam Express: System32\DRIVERS\OVCD.sys (manual start)
        Remote Access Auto Connection -ohjain: System32\DRIVERS\rasacd.sys (system)
        Remote Access Auto Connection -hallinta: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        WAN Miniport (IrDA): System32\DRIVERS\rasirda.sys (manual start)
        WAN Miniport (L2TP): System32\DRIVERS\rasl2tp.sys (manual start)
        Etäkäytön (RAS) yhteyksienhallinta: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        Remote Access PPPOE Driver: System32\DRIVERS\raspppoe.sys (manual start)
        Suora rinnakkainen: System32\DRIVERS\raspti.sys (manual start)
        Rdbss: System32\DRIVERS\rdbss.sys (system)
        RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
        Etätyöpöydän ohjeen istunnonhallinta: C:\WINDOWS\system32\sessmgr.exe (manual start)
        RecAgent: System32\DRIVERS\RecAgent.sys (system)
        Digital CD Audio Playback Filter Driver: System32\DRIVERS\redbook.sys (system)
        Reititys ja etäkäyttö: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Etäproseduurikutsujen (RPC) paikannin: %SystemRoot%\System32\locator.exe (manual start)
        Etäproseduurikutsu (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
        QoS RSVP: %SystemRoot%\System32\rsvp.exe (manual start)
        RT2500 Wireless Driver: System32\DRIVERS\RT2500.sys (manual start)
        Käyttöoikeustilien hallinta: %SystemRoot%\system32\lsass.exe (autostart)
        Älykortti: %SystemRoot%\System32\SCardSvr.exe (manual start)
        Tehtävien ajoitus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Secdrv: System32\DRIVERS\secdrv.sys (autostart)
        Toissijainen kirjautuminen: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Järjestelmätapahtuman ilmoitus: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
        Windowsin palomuuri / Internet-yhteyden jakaminen (ICS): %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Käyttöliittymän laitteistotunnistus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        SiS 163 usb Wireless LAN Adapter Driver: system32\DRIVERS\sis163u.sys (manual start)
        SiS AGP Filter: System32\DRIVERS\SISAGPX.sys (system)
        SiS PCI Fast Ethernet Adapter Driver: System32\DRIVERS\sisnic.sys (manual start)
        BDA Slip De-Framer: System32\DRIVERS\SLIP.sys (manual start)
        SmartLink AMR_PCI Driver: System32\DRIVERS\slntamr.sys (manual start)
        SlNtHal: System32\DRIVERS\Slnthal.sys (manual start)
        SmartLinkService: slserv.exe (autostart)
        SlWdmSup: System32\DRIVERS\SlWdmSup.sys (manual start)
        Sygate Personal Firewall: C:\Program Files\Sygate\SPF\smc.exe (autostart)
        Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
        Taustatulostusohjain: %SystemRoot%\system32\spoolsv.exe (autostart)
        Järjestelmän palautussuodatin -ohjain: System32\DRIVERS\sr.sys (system)
        Järjestelmän palauttaminen -palvelu: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Srv: System32\DRIVERS\srv.sys (manual start)
        SSDP-palvelu (Simple Service Discovery Protocol): %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
        WIA (Windows Image Acquisition): %SystemRoot%\System32\svchost.exe -k imgsvc (autostart)
        BDA IPSink: System32\DRIVERS\StreamIP.sys (manual start)
        Ohjelmistoväyläohjain: System32\DRIVERS\swenum.sys (manual start)
        Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
        MS Software Shadow Copy Provider: C:\WINDOWS\System32\dllhost.exe /Processid:{C9B7B653-CA37-4810-B8AC-6F58CBA0B2B2} (manual start)
        Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
        Resurssilokit ja -hälytykset: %SystemRoot%\system32\smlogsvc.exe (manual start)
        Puhelin: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        TCP/IP-protokollaohjain: System32\DRIVERS\tcpip.sys (system)
        Teefer for NT: SYSTEM32\Drivers\Teefer.sys (system)
        Päätelaiteohjain: System32\DRIVERS\termdd.sys (system)
        Päätepalvelut: %SystemRoot%\System32\svchost -k DComLaunch (manual start)
        Teemat: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Tiedostolinkkijäljityksen asiakas: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
        Windows User Mode Driver Framework: C:\WINDOWS\System32\wdfmgr.exe (autostart)
        Microcode Update -ohjain: System32\DRIVERS\update.sys (manual start)
        Universal Plug & Play -laiteisäntä: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
        UPS: %SystemRoot%\System32\ups.exe (manual start)
        Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: System32\DRIVERS\usbehci.sys (manual start)
        USB2 Enabled Hub: System32\DRIVERS\usbhub.sys (manual start)
        Microsoft USB Open Host Controller Miniport Driver: System32\DRIVERS\usbohci.sys (manual start)
        USB Scanner Driver: System32\DRIVERS\usbscan.sys (manual start)
        USB-massamuistiohjain: System32\DRIVERS\USBSTOR.SYS (manual start)
        VGA-näytönohjain: \SystemRoot\System32\drivers\vga.sys (system)
        Aseman tilannevedos: %SystemRoot%\System32\vssvc.exe (manual start)
        Windows Time: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Remote Access IP ARP Driver: System32\DRIVERS\wanarp.sys (manual start)
        Windows CE USB Serial Host Driver: System32\DRIVERS\wceusbsh.sys (manual start)
        Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
        WebClient: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
        SyGate for NT, wg3n: \SystemRoot\SYSTEM32\Drivers\wg3n.sys (autostart)
        SyGate for NT, wg4n: \SystemRoot\SYSTEM32\Drivers\wg4n.sys (autostart)
        SyGate for NT, wg5n: \SystemRoot\SYSTEM32\Drivers\wg5n.sys (autostart)
        SyGate for NT, wg6n: \SystemRoot\SYSTEM32\Drivers\wg6n.sys (autostart)
        WMI-palvelu (Windows Management Instrumentation): %systemroot%\system32\svchost.exe -k netsvcs (autostart)
        Portable Media Serial Number Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        WMI resurssisovitin: C:\WINDOWS\System32\wbem\wmiapsrv.exe (manual start)
        wpsdrvnt: \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (system)
        Tietoturvakeskus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        World Standard Teletext Codec: System32\DRIVERS\WSTCODEC.SYS (manual start)
        Automaattiset päivitykset: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
        Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Verkon käyttöönottopalvelu: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)


        --------------------------------------------------

        Enumerating Windows NT logon/logoff scripts:
        *No scripts set to run*

        Windows NT checkdisk command:
        BootExecute =

        Windows NT 'Wininit.ini':
        PendingFileRenameOperations: *Registry value not found*

        --------------------------------------------------

        Enumerating ShellServiceObjectDelayLoad items:

        PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
        CDBurn: C:\WINDOWS\system32\SHELL32.dll
        WebCheck: C:\WINDOWS\System32\webcheck.dll
        SysTray: C:\WINDOWS\System32\stobject.dll

        --------------------------------------------------
        Autorun entries from Registry:
        HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

        *Registry key not found*

        --------------------------------------------------

        End of report, 36 045 bytes
        Report generated in 0,109 seconds

        Command line options:
        /verbose - to add additional info on each section
        /complete - to include empty sections and unsuspicious data
        /full - to include several rarely-important sections
        /force9x - to include Win9x-only startups even if running on WinNT
        /forcent - to include WinNT-only startups even if running on Win9x
        /forceall - to include all Win9x and WinNT startups, regardless of platform
        /history - to list version history only


      • nyt
        Juu kirjoitti:

        Merkkaa ja Fix:saa

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.dieayyvhyurlildjpgiraqhw.uk/T/MMe8s4yFxHr4u6r6vOtVxtR7JYiOKW_aM2Q7suSGLlNtlZI/UHRiLZtwTO9F0z.jpg

        ja sitte pistä se StartupList logi jota jo aikasemmin pyysin.

        StartupList report, 16.9.2005, 19:13:01
        StartupList version: 1.52.2
        Started from : C:\HJT\HijackThis.EXE
        Detected: Windows XP SP2 (WinNT 5.01.2600)
        Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        * Using default options
        * Including empty and uninteresting sections
        * Showing rarely important sections
        ==================================================

        Running processes:

        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\System32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Sygate\SPF\smc.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\Real\RealPlayer\RealPlay.exe
        C:\Program Files\Winamp\winampa.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
        C:\Program Files\Microsoft Office\Office\OSA.EXE
        C:\HJT\HijackThis.exe
        C:\WINDOWS\system32\wuauclt.exe

        --------------------------------------------------

        Listing of startup folders:

        Shell folders Startup:
        [C:\Documents and Settings\Omistaja\Käynnistä-valikko\Ohjelmat\Käynnistys]
        *No files*

        Shell folders AltStartup:
        *Folder not found*

        User shell folders Startup:
        *Folder not found*

        User shell folders AltStartup:
        *Folder not found*

        Shell folders Common Startup:
        [C:\Documents and Settings\All Users\Käynnistä-valikko\Ohjelmat\Käynnistys]
        Microsoft Office Pikahaku.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
        Officen käynnistys.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE

        Shell folders Common AltStartup:
        *Folder not found*

        User shell folders Common Startup:
        *Folder not found*

        User shell folders Alternate Common Startup:
        *Folder not found*

        --------------------------------------------------

        Checking Windows NT UserInit:

        [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
        UserInit = C:\WINDOWS\system32\userinit.exe,

        [HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
        *Registry key not found*

        [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
        *Registry value not found*

        [HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKLM\Software\Microsoft\Windows\CurrentVersion\Run

        SunJavaUpdateSched = C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        SiSUSBRG = C:\WINDOWS\SiSUSBrg.exe
        ATIModeChange = Ati2mdxx.exe
        ATIPTA = C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        SoundMan = SOUNDMAN.EXE
        RealTray = C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
        NeroFilterCheck = C:\WINDOWS\system32\NeroCheck.exe
        PinnacleDriverCheck = C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
        WinampAgent = C:\Program Files\Winamp\winampa.exe
        AVG7_CC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
        AVG7_EMC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
        QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
        SmcService = C:\PROGRA~1\Sygate\SPF\smc.exe -startgui

        --------------------------------------------------

        Autorun entries from Registry:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

        *No values found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

        *No values found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKCU\Software\Microsoft\Windows\CurrentVersion\Run

        CTFMON.EXE = C:\WINDOWS\system32\ctfmon.exe
        H/PC Connection Agent = "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"

        --------------------------------------------------

        Autorun entries from Registry:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

        *No values found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

        *Registry key not found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKLM\Software\Microsoft\Windows\CurrentVersion\Run
        *No subkeys found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
        *No subkeys found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
        *No subkeys found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
        *Registry key not found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
        *Registry key not found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKCU\Software\Microsoft\Windows\CurrentVersion\Run
        *No subkeys found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
        *No subkeys found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
        *Registry key not found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
        *Registry key not found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
        *Registry key not found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
        *Registry key not found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
        *Registry key not found*

        --------------------------------------------------

        File association entry for .EXE:
        HKEY_CLASSES_ROOT\exefile\shell\open\command

        (Default) = "%1" %*

        --------------------------------------------------

        File association entry for .COM:
        HKEY_CLASSES_ROOT\comfile\shell\open\command

        (Default) = "%1" %*

        --------------------------------------------------

        File association entry for .BAT:
        HKEY_CLASSES_ROOT\batfile\shell\open\command

        (Default) = "%1" %*

        --------------------------------------------------

        File association entry for .PIF:
        HKEY_CLASSES_ROOT\piffile\shell\open\command

        (Default) = "%1" %*

        --------------------------------------------------

        File association entry for .SCR:
        HKEY_CLASSES_ROOT\scrfile\shell\open\command

        (Default) = "%1" /S

        --------------------------------------------------

        File association entry for .HTA:
        HKEY_CLASSES_ROOT\htafile\shell\open\command

        (Default) = C:\WINDOWS\System32\mshta.exe "%1" %*

        --------------------------------------------------

        File association entry for .TXT:
        HKEY_CLASSES_ROOT\txtfile\shell\open\command

        (Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

        --------------------------------------------------

        Enumerating Active Setup stub paths:
        HKLM\Software\Microsoft\Active Setup\Installed Components
        (* = disabled by HKCU twin)

        [>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
        StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

        [>{26923b43-4d38-484f-9b9e-de460746276c}] *
        StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE

        [>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
        StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

        [>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
        StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

        [{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
        StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

        [{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
        StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

        [{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
        StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

        [{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
        StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser

        [{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
        StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub

        [{7790769C-0471-11d2-AF11-00C04FA35D02}] *
        StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

        [{89820200-ECBD-11cf-8B85-00AA005B4340}] *
        StubPath = regsvr32.exe /s /n /i:U shell32.dll

        [{89820200-ECBD-11cf-8B85-00AA005B4383}] *
        StubPath = %SystemRoot%\system32\ie4uinit.exe

        [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
        StubPath = C:\WINDOWS\System32\Rundll32.exe C:\WINDOWS\System32\mscories.dll,Install

        --------------------------------------------------

        Enumerating ICQ Agent Autostart apps:
        HKCU\Software\Mirabilis\ICQ\Agent\Apps

        *Registry key not found*

        --------------------------------------------------

        Load/Run keys from C:\WINDOWS\WIN.INI:

        load=*INI section not found*
        run=*INI section not found*

        Load/Run keys from Registry:

        HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
        HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
        HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
        HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
        HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
        HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
        HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
        HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
        HKCU\..\Windows NT\CurrentVersion\Windows: load=
        HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
        HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
        HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
        HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

        --------------------------------------------------

        Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

        Shell=*INI section not found*
        SCRNSAVE.EXE=*INI section not found*
        drivers=*INI section not found*

        Shell & screensaver key from Registry:

        Shell=Explorer.exe
        SCRNSAVE.EXE=*Registry value not found*
        drivers=*Registry value not found*

        Policies Shell key:

        HKCU\..\Policies: Shell=*Registry key not found*
        HKLM\..\Policies: Shell=*Registry value not found*

        --------------------------------------------------

        Checking for EXPLORER.EXE instances:

        C:\WINDOWS\Explorer.exe: PRESENT!

        C:\Explorer.exe: not present
        C:\WINDOWS\Explorer\Explorer.exe: not present
        C:\WINDOWS\System\Explorer.exe: not present
        C:\WINDOWS\System32\Explorer.exe: not present
        C:\WINDOWS\Command\Explorer.exe: not present
        C:\WINDOWS\Fonts\Explorer.exe: not present

        --------------------------------------------------

        Checking for superhidden extensions:

        .lnk: HIDDEN! (arrow overlay: yes)
        .pif: HIDDEN! (arrow overlay: yes)
        .exe: not hidden
        .com: not hidden
        .bat: not hidden
        .hta: not hidden
        .scr: not hidden
        .shs: HIDDEN!
        .shb: HIDDEN!
        .vbs: not hidden
        .vbe: not hidden
        .wsh: not hidden
        .scf: HIDDEN! (arrow overlay: NO!)
        .url: HIDDEN! (arrow overlay: yes)
        .js: not hidden
        .jse: not hidden

        --------------------------------------------------

        Verifying REGEDIT.EXE integrity:

        - Regedit.exe found in C:\WINDOWS
        - .reg open command is normal (regedit.exe %1)
        - Regedit.exe has no CompanyName property! It is either missing or named something else.
        - Regedit.exe has no OriginalFilename property! It is either missing or named something else.
        - Regedit.exe has no FileDescription property! It is either missing or named something else.

        Registry check failed!

        --------------------------------------------------

        Enumerating Browser Helper Objects:

        (no name) - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}

        --------------------------------------------------

        Enumerating Task Scheduler jobs:

        A0D03B0D9183B1D5.job
        A9F2EB41918D6259.job
        AB3FD39B918048BB.job
        AD542B189183DEB0.job
        AF90B60D91872761.job

        --------------------------------------------------

        Enumerating Download Program Files:

        [Shockwave ActiveX Control]
        InProcServer32 = C:\WINDOWS\system32\Macromed\Director\SwDir.dll
        CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

        [Windows Genuine Advantage Validation Tool]
        InProcServer32 = C:\WINDOWS\System32\LegitCheckControl.DLL
        CODEBASE = http://go.microsoft.com/fwlink/?linkid=39204

        [WUWebControl Class]
        InProcServer32 = C:\WINDOWS\System32\wuweb.dll
        CODEBASE = http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125666863807

        [Java Plug-in 1.4.2_03]
        InProcServer32 = C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
        CODEBASE = http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab

        [MsnMessengerSetupDownloadControl Class]
        InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.ocx
        CODEBASE = http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab

        [Java Plug-in 1.4.2_03]
        InProcServer32 = C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
        CODEBASE = http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab

        [Shockwave Flash Object]
        InProcServer32 = C:\WINDOWS\System32\macromed\flash\Flash.ocx
        CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

        --------------------------------------------------

        Enumerating Winsock LSP files:

        NameSpace #1: C:\WINDOWS\System32\mswsock.dll
        NameSpace #2: C:\WINDOWS\System32\winrnr.dll
        NameSpace #3: C:\WINDOWS\System32\mswsock.dll
        NameSpace #4: C:\WINDOWS\System32\nwprovau.dll
        Protocol #1: C:\WINDOWS\system32\mswsock.dll
        Protocol #2: C:\WINDOWS\system32\mswsock.dll
        Protocol #3: C:\WINDOWS\system32\mswsock.dll
        Protocol #4: C:\WINDOWS\system32\mswsock.dll
        Protocol #5: C:\WINDOWS\system32\rsvpsp.dll
        Protocol #6: C:\WINDOWS\system32\rsvpsp.dll
        Protocol #7: C:\WINDOWS\system32\mswsock.dll
        Protocol #8: C:\WINDOWS\system32\mswsock.dll
        Protocol #9: C:\WINDOWS\system32\mswsock.dll
        Protocol #10: C:\WINDOWS\system32\mswsock.dll
        Protocol #11: C:\WINDOWS\system32\mswsock.dll
        Protocol #12: C:\WINDOWS\system32\mswsock.dll
        Protocol #13: C:\WINDOWS\system32\mswsock.dll
        Protocol #14: C:\WINDOWS\system32\mswsock.dll
        Protocol #15: C:\WINDOWS\system32\mswsock.dll
        Protocol #16: C:\WINDOWS\system32\mswsock.dll
        Protocol #17: C:\WINDOWS\system32\mswsock.dll
        Protocol #18: C:\WINDOWS\system32\mswsock.dll
        Protocol #19: C:\WINDOWS\system32\mswsock.dll
        Protocol #20: C:\WINDOWS\system32\mswsock.dll
        Protocol #21: C:\WINDOWS\system32\mswsock.dll
        Protocol #22: C:\WINDOWS\system32\mswsock.dll
        Protocol #23: C:\WINDOWS\system32\mswsock.dll
        Protocol #24: C:\WINDOWS\system32\mswsock.dll
        Protocol #25: C:\WINDOWS\system32\mswsock.dll
        Protocol #26: C:\WINDOWS\system32\mswsock.dll
        Protocol #27: C:\WINDOWS\system32\mswsock.dll
        Protocol #28: C:\WINDOWS\system32\mswsock.dll
        Protocol #29: C:\WINDOWS\system32\mswsock.dll

        --------------------------------------------------

        Enumerating Windows NT/2000/XP services

        61883 Unit Device: System32\DRIVERS\61883.sys (manual start)
        A4SII300: System32\drivers\A4SII300.SYS (autostart)
        Microsoft ACPI Driver: System32\DRIVERS\ACPI.sys (system)
        Microsoft Embedded Controller Driver: System32\DRIVERS\ACPIEC.sys (system)
        Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
        AFD Networking Support -ympäristö: \SystemRoot\System32\drivers\afd.sys (system)
        Service for WDM 3D Audio Driver: system32\drivers\ALCXSENS.SYS (manual start)
        Service for Realtek AC97 Audio (WDM): system32\drivers\ALCXWDM.SYS (manual start)
        Hälytys: %SystemRoot%\System32\svchost.exe -k LocalService (disabled)
        Sovelluskerroksen yhdyskäytäväpalvelu: %SystemRoot%\System32\alg.exe (manual start)
        AMD Athlon64 Processor Driver: System32\DRIVERS\AmdK8.sys (system)
        Sovellusten hallinta: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
        1394 ARP -asiakasprotokolla: System32\DRIVERS\arp1394.sys (manual start)
        ASAPIW2K: system32\drivers\ASAPIW2k.sys (manual start)
        ASP.NET-tilapalvelu: %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (manual start)
        RAS Asynchronous Media Driver: System32\DRIVERS\asyncmac.sys (manual start)
        Standardi IDE/ESDI-kiintolevyohjain: System32\DRIVERS\atapi.sys (system)
        Ati HotKey Poller: %SystemRoot%\System32\Ati2evxx.exe (autostart)
        ati2mtag: System32\DRIVERS\ati2mtag.sys (manual start)
        ATM ARP Client -protokolla: System32\DRIVERS\atmarpc.sys (manual start)
        Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Audio Stub Driver: System32\DRIVERS\audstub.sys (manual start)
        AVC-laite: System32\DRIVERS\avc.sys (manual start)
        AVG7 Alert Manager Server: C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (autostart)
        AVG7 Kernel: \SystemRoot\System32\Drivers\avg7core.sys (system)
        AVG7 Wrap Driver: \SystemRoot\System32\Drivers\avg7rsw.sys (system)
        AVG7 Rezident Driver: \SystemRoot\System32\Drivers\avg7rsxp.sys (system)
        AVG7 Update Service: C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (autostart)
        AVG Network Redirector: \??\C:\WINDOWS\System32\Drivers\avgtdi.sys (autostart)
        BITS-tausta-ajo (Background Intelligent Transfer Service): %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        MAC-silta: System32\DRIVERS\bridge.sys (manual start)
        MAC Bridge Miniport: System32\DRIVERS\bridge.sys (manual start)
        Tietokoneiden selaus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        BUFADPT: \??\C:\WINDOWS\System32\BUFADPT.SYS (autostart)
        Closed Caption Decoder: System32\DRIVERS\CCDECODE.sys (manual start)
        CD-ROM-ohjain: System32\DRIVERS\cdrom.sys (system)
        Indeksointipalvelu: %SystemRoot%\system32\cisvc.exe (manual start)
        Leikekirja: %SystemRoot%\system32\clipsrv.exe (disabled)
        Microsoft ACPI Control Method Battery Driver: System32\DRIVERS\CmBatt.sys (manual start)
        Microsoft Composite Battery Driver: System32\DRIVERS\compbatt.sys (system)
        COM -järjestelmäsovellus: C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
        CONAN: system32\drivers\o2mmb.sys (manual start)
        Salauspalvelut: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
        DCOM-palvelinprosessin käynnistys: %SystemRoot%\system32\svchost -k DcomLaunch (autostart)
        DHCP-asiakas: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Levyohjain: System32\DRIVERS\disk.sys (system)
        Loogisen levyn hallinnan valvontapalvelu: %SystemRoot%\System32\dmadmin.exe /com (manual start)
        dmboot: System32\drivers\dmboot.sys (disabled)
        dmio: System32\drivers\dmio.sys (disabled)
        dmload: System32\drivers\dmload.sys (disabled)
        Loogisen levyn hallinta: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
        DNS-asiakas: %SystemRoot%\System32\svchost.exe -k NetworkService (autostart)
        Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
        %1394\031887&040892.DeviceDesc%: System32\DRIVERS\enum1394.sys (manual start)
        Virheraportointipalvelut: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Tapahtumaloki: %SystemRoot%\system32\services.exe (autostart)
        COM -tapahtumajärjestelmä: C:\WINDOWS\System32\svchost.exe -k netsvcs (manual start)
        Nopean käyttäjän vaihdon yhteensopivuus: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        FltMgr: system32\drivers\fltmgr.sys (system)
        Volume Manager -ohjain: System32\DRIVERS\ftdisk.sys (system)
        GearAspiWDM: system32\drivers\gearaspiwdm.sys (manual start)
        Yleinen paketinmääritys: System32\DRIVERS\msgpc.sys (manual start)
        Ohjeet ja tuotetuki: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        HID (Human Interface Device) -liittymä: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
        Microsoft HID -luokkaohjain: System32\DRIVERS\hidusb.sys (manual start)
        HTTP: System32\Drivers\HTTP.sys (manual start)
        HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start)
        i8042-näppäimistö ja PS/2-hiiriohjain: System32\DRIVERS\i8042prt.sys (system)
        CD-Burning Filter Driver: System32\DRIVERS\imapi.sys (system)
        CD-levyjen kirjoittamisen IMAPI COM -palvelu: C:\WINDOWS\System32\imapi.exe (manual start)
        Windowsin IPv6-palomuurin ohjain: system32\drivers\ip6fw.sys (manual start)
        IP Traffic Filter Driver: System32\DRIVERS\ipfltdrv.sys (manual start)
        IP in IP Tunnel Driver: System32\DRIVERS\ipinip.sys (manual start)
        IP Network Address Translator: System32\DRIVERS\ipnat.sys (manual start)
        IPSEC-ohjain: System32\DRIVERS\ipsec.sys (system)
        IrDA-protokolla: System32\DRIVERS\irda.sys (autostart)
        IR Enumerator Service: System32\DRIVERS\irenum.sys (manual start)
        Infrapunavalvonta: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        PnP ISA/EISA -väyläohjain: System32\DRIVERS\isapnp.sys (system)
        Näppäimistön luokkaohjain: System32\DRIVERS\kbdclass.sys (system)
        kbeepm: \??\C:\DOCUME~1\Omistaja\LOCALS~1\Temp\kbeepm.sys (manual start)
        Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
        Palvelin: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Työasema: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        TCP/IP NetBIOS Helper: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
        MbxStby: system32\drivers\MbxStby.sys (manual start)
        Viestinvälitys: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
        NetMeeting etätyöpöydän jakaminen: C:\WINDOWS\System32\mnmsrvc.exe (manual start)
        Unimodem Streaming Filter Device: system32\drivers\MODEMCSA.sys (manual start)
        Hiiren luokkaohjain: System32\DRIVERS\mouclass.sys (system)
        Hiiren HID-ohjain: System32\DRIVERS\mouhid.sys (manual start)
        WebDav Client Redirector: System32\DRIVERS\mrxdav.sys (manual start)
        MRXSMB: System32\DRIVERS\mrxsmb.sys (system)
        Distributed Transaction Coordinator: C:\WINDOWS\System32\msdtc.exe (manual start)
        Microsoft DV Camera and VCR: System32\DRIVERS\msdv.sys (manual start)
        Windows Installer: C:\WINDOWS\System32\msiexec.exe /V (manual start)
        Microsoft Streaming Service -välityspalvelin: system32\drivers\MSKSSRV.sys (manual start)
        Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
        Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
        Microsoft-järjestelmänhallinnan BIOS-ohjain: System32\DRIVERS\mssmbios.sys (manual start)
        Microsoft Streaming Tee/Sink-to-Sink -muunnin: system32\drivers\MSTEE.sys (manual start)
        Mtlmnt5: System32\DRIVERS\Mtlmnt5.sys (manual start)
        Mtlstrm: System32\DRIVERS\Mtlstrm.sys (manual start)
        NABTS/FEC VBI Codec: System32\DRIVERS\NABTSFEC.sys (manual start)
        Microsoft TV/Video Connection: System32\DRIVERS\NdisIP.sys (manual start)
        Remote Access NDIS TAPI Driver: System32\DRIVERS\ndistapi.sys (manual start)
        NDIS Usermode I/O -protokolla: System32\DRIVERS\ndisuio.sys (manual start)
        Remote Access NDIS WAN Driver: System32\DRIVERS\ndiswan.sys (manual start)
        NetBIOS-käyttöliittymä: System32\DRIVERS\netbios.sys (system)
        NetBIOS TCP/IP:n päällä: System32\DRIVERS\netbt.sys (system)
        Verkon DDE: %SystemRoot%\system32\netdde.exe (disabled)
        Verkon DDE DSDM: %SystemRoot%\system32\netdde.exe (disabled)
        Verkkokirjautuminen: %SystemRoot%\System32\lsass.exe (manual start)
        Verkkoyhteydet: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        1394-verkko-ohjain: System32\DRIVERS\nic1394.sys (manual start)
        NLA-nimiavaruus (Network Location Awareness): %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        NSC-infrapunalaiteohjain: System32\DRIVERS\nscirda.sys (manual start)
        NT LM -suojaustuen toimittaja: %SystemRoot%\System32\lsass.exe (manual start)
        Siirrettävät tallennusvälineet: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
        NtMtlFax: System32\DRIVERS\NtMtlFax.sys (manual start)
        IPX Traffic Filter Driver: System32\DRIVERS\nwlnkflt.sys (manual start)
        IPX Traffic Forwarder Driver: System32\DRIVERS\nwlnkfwd.sys (manual start)
        NWLink IPX/SPX/NetBIOS -yhteensopiva kuljetusprotokolla: System32\DRIVERS\nwlnkipx.sys (autostart)
        NWLink NetBIOS: System32\DRIVERS\nwlnknb.sys (autostart)
        NWLink SPX/SPXII -protokolla: System32\DRIVERS\nwlnkspx.sys (autostart)
        SAP-agentti: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Texas Instruments OHCI Compliant IEEE 1394 Host Controller: System32\DRIVERS\ohci1394.sys (system)
        OLYMPUS Digital Camera: System32\Drivers\olcamudp.sys (manual start)
        Rinnakkaisporttiohjain: System32\DRIVERS\parport.sys (manual start)
        PCI Bus Driver: System32\DRIVERS\pci.sys (system)
        PCIIde: System32\DRIVERS\pciide.sys (system)
        Pcmcia: System32\DRIVERS\pcmcia.sys (system)
        PADUS ASPI SHELL: system32\drivers\pfc.sys (manual start)
        Plug and Play: %SystemRoot%\system32\services.exe (autostart)
        IPSEC-palvelut: %SystemRoot%\System32\lsass.exe (autostart)
        WAN Miniport (PPTP): System32\DRIVERS\raspptp.sys (manual start)
        Processor Driver: System32\DRIVERS\processr.sys (system)
        Suojattu tallennuspaikka: %SystemRoot%\system32\lsass.exe (autostart)
        QoS-paketinajoitus: System32\DRIVERS\psched.sys (manual start)
        Direct Parallel Link Driver: System32\DRIVERS\ptilink.sys (manual start)
        PxHelp20: System32\DRIVERS\PxHelp20.sys (system)
        Logitech QuickCam Express: System32\DRIVERS\OVCD.sys (manual start)
        Remote Access Auto Connection -ohjain: System32\DRIVERS\rasacd.sys (system)
        Remote Access Auto Connection -hallinta: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        WAN Miniport (IrDA): System32\DRIVERS\rasirda.sys (manual start)
        WAN Miniport (L2TP): System32\DRIVERS\rasl2tp.sys (manual start)
        Etäkäytön (RAS) yhteyksienhallinta: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        Remote Access PPPOE Driver: System32\DRIVERS\raspppoe.sys (manual start)
        Suora rinnakkainen: System32\DRIVERS\raspti.sys (manual start)
        Rdbss: System32\DRIVERS\rdbss.sys (system)
        RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
        Etätyöpöydän ohjeen istunnonhallinta: C:\WINDOWS\system32\sessmgr.exe (manual start)
        RecAgent: System32\DRIVERS\RecAgent.sys (system)
        Digital CD Audio Playback Filter Driver: System32\DRIVERS\redbook.sys (system)
        Reititys ja etäkäyttö: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Etäproseduurikutsujen (RPC) paikannin: %SystemRoot%\System32\locator.exe (manual start)
        Etäproseduurikutsu (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
        QoS RSVP: %SystemRoot%\System32\rsvp.exe (manual start)
        RT2500 Wireless Driver: System32\DRIVERS\RT2500.sys (manual start)
        Käyttöoikeustilien hallinta: %SystemRoot%\system32\lsass.exe (autostart)
        Älykortti: %SystemRoot%\System32\SCardSvr.exe (manual start)
        Tehtävien ajoitus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Secdrv: System32\DRIVERS\secdrv.sys (autostart)
        Toissijainen kirjautuminen: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Järjestelmätapahtuman ilmoitus: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
        Windowsin palomuuri / Internet-yhteyden jakaminen (ICS): %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Käyttöliittymän laitteistotunnistus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        SiS 163 usb Wireless LAN Adapter Driver: system32\DRIVERS\sis163u.sys (manual start)
        SiS AGP Filter: System32\DRIVERS\SISAGPX.sys (system)
        SiS PCI Fast Ethernet Adapter Driver: System32\DRIVERS\sisnic.sys (manual start)
        BDA Slip De-Framer: System32\DRIVERS\SLIP.sys (manual start)
        SmartLink AMR_PCI Driver: System32\DRIVERS\slntamr.sys (manual start)
        SlNtHal: System32\DRIVERS\Slnthal.sys (manual start)
        SmartLinkService: slserv.exe (autostart)
        SlWdmSup: System32\DRIVERS\SlWdmSup.sys (manual start)
        Sygate Personal Firewall: C:\Program Files\Sygate\SPF\smc.exe (autostart)
        Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
        Taustatulostusohjain: %SystemRoot%\system32\spoolsv.exe (autostart)
        Järjestelmän palautussuodatin -ohjain: System32\DRIVERS\sr.sys (system)
        Järjestelmän palauttaminen -palvelu: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Srv: System32\DRIVERS\srv.sys (manual start)
        SSDP-palvelu (Simple Service Discovery Protocol): %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
        WIA (Windows Image Acquisition): %SystemRoot%\System32\svchost.exe -k imgsvc (autostart)
        BDA IPSink: System32\DRIVERS\StreamIP.sys (manual start)
        Ohjelmistoväyläohjain: System32\DRIVERS\swenum.sys (manual start)
        Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
        MS Software Shadow Copy Provider: C:\WINDOWS\System32\dllhost.exe /Processid:{C9B7B653-CA37-4810-B8AC-6F58CBA0B2B2} (manual start)
        Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
        Resurssilokit ja -hälytykset: %SystemRoot%\system32\smlogsvc.exe (manual start)
        Puhelin: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        TCP/IP-protokollaohjain: System32\DRIVERS\tcpip.sys (system)
        Teefer for NT: SYSTEM32\Drivers\Teefer.sys (system)
        Päätelaiteohjain: System32\DRIVERS\termdd.sys (system)
        Päätepalvelut: %SystemRoot%\System32\svchost -k DComLaunch (manual start)
        Teemat: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Tiedostolinkkijäljityksen asiakas: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
        Windows User Mode Driver Framework: C:\WINDOWS\System32\wdfmgr.exe (autostart)
        Microcode Update -ohjain: System32\DRIVERS\update.sys (manual start)
        Universal Plug & Play -laiteisäntä: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
        UPS: %SystemRoot%\System32\ups.exe (manual start)
        Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: System32\DRIVERS\usbehci.sys (manual start)
        USB2 Enabled Hub: System32\DRIVERS\usbhub.sys (manual start)
        Microsoft USB Open Host Controller Miniport Driver: System32\DRIVERS\usbohci.sys (manual start)
        USB Scanner Driver: System32\DRIVERS\usbscan.sys (manual start)
        USB-massamuistiohjain: System32\DRIVERS\USBSTOR.SYS (manual start)
        VGA-näytönohjain: \SystemRoot\System32\drivers\vga.sys (system)
        Aseman tilannevedos: %SystemRoot%\System32\vssvc.exe (manual start)
        Windows Time: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Remote Access IP ARP Driver: System32\DRIVERS\wanarp.sys (manual start)
        Windows CE USB Serial Host Driver: System32\DRIVERS\wceusbsh.sys (manual start)
        Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
        WebClient: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
        SyGate for NT, wg3n: \SystemRoot\SYSTEM32\Drivers\wg3n.sys (autostart)
        SyGate for NT, wg4n: \SystemRoot\SYSTEM32\Drivers\wg4n.sys (autostart)
        SyGate for NT, wg5n: \SystemRoot\SYSTEM32\Drivers\wg5n.sys (autostart)
        SyGate for NT, wg6n: \SystemRoot\SYSTEM32\Drivers\wg6n.sys (autostart)
        WMI-palvelu (Windows Management Instrumentation): %systemroot%\system32\svchost.exe -k netsvcs (autostart)
        Portable Media Serial Number Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        WMI resurssisovitin: C:\WINDOWS\System32\wbem\wmiapsrv.exe (manual start)
        wpsdrvnt: \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (system)
        Tietoturvakeskus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        World Standard Teletext Codec: System32\DRIVERS\WSTCODEC.SYS (manual start)
        Automaattiset päivitykset: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
        Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Verkon käyttöönottopalvelu: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)


        --------------------------------------------------

        Enumerating Windows NT logon/logoff scripts:
        *No scripts set to run*

        Windows NT checkdisk command:
        BootExecute =

        Windows NT 'Wininit.ini':
        PendingFileRenameOperations: *Registry value not found*

        --------------------------------------------------

        Enumerating ShellServiceObjectDelayLoad items:

        PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
        CDBurn: C:\WINDOWS\system32\SHELL32.dll
        WebCheck: C:\WINDOWS\System32\webcheck.dll
        SysTray: C:\WINDOWS\System32\stobject.dll

        --------------------------------------------------
        Autorun entries from Registry:
        HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

        *Registry key not found*

        --------------------------------------------------

        End of report, 36 010 bytes
        Report generated in 0,110 seconds

        Command line options:
        /verbose - to add additional info on each section
        /complete - to include empty sections and unsuspicious data
        /full - to include several rarely-important sections
        /force9x - to include Win9x-only startups even if running on WinNT
        /forcent - to include WinNT-only startups even if running on Win9x
        /forceall - to include all Win9x and WinNT startups, regardless of platform
        /history - to list version history only
        Logfile of HijackThis v1.99.1
        Scan saved at 19:16:09, on 16.9.2005
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\System32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Sygate\SPF\smc.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\Real\RealPlayer\RealPlay.exe
        C:\Program Files\Winamp\winampa.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
        C:\Program Files\Microsoft Office\Office\OSA.EXE
        C:\HJT\HijackThis.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\WINDOWS\system32\notepad.exe
        C:\Program Files\Opera2\Opera.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
        O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
        O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
        O4 - Global Startup: Microsoft Office Pikahaku.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
        O4 - Global Startup: Officen käynnistys.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
        O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125666863807
        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
        O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
        O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
        O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
        O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\system32\slserv.exe
        O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe


      • nyt kirjoitti:

        StartupList report, 16.9.2005, 19:13:01
        StartupList version: 1.52.2
        Started from : C:\HJT\HijackThis.EXE
        Detected: Windows XP SP2 (WinNT 5.01.2600)
        Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        * Using default options
        * Including empty and uninteresting sections
        * Showing rarely important sections
        ==================================================

        Running processes:

        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\System32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Sygate\SPF\smc.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\Real\RealPlayer\RealPlay.exe
        C:\Program Files\Winamp\winampa.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
        C:\Program Files\Microsoft Office\Office\OSA.EXE
        C:\HJT\HijackThis.exe
        C:\WINDOWS\system32\wuauclt.exe

        --------------------------------------------------

        Listing of startup folders:

        Shell folders Startup:
        [C:\Documents and Settings\Omistaja\Käynnistä-valikko\Ohjelmat\Käynnistys]
        *No files*

        Shell folders AltStartup:
        *Folder not found*

        User shell folders Startup:
        *Folder not found*

        User shell folders AltStartup:
        *Folder not found*

        Shell folders Common Startup:
        [C:\Documents and Settings\All Users\Käynnistä-valikko\Ohjelmat\Käynnistys]
        Microsoft Office Pikahaku.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
        Officen käynnistys.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE

        Shell folders Common AltStartup:
        *Folder not found*

        User shell folders Common Startup:
        *Folder not found*

        User shell folders Alternate Common Startup:
        *Folder not found*

        --------------------------------------------------

        Checking Windows NT UserInit:

        [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
        UserInit = C:\WINDOWS\system32\userinit.exe,

        [HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
        *Registry key not found*

        [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
        *Registry value not found*

        [HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKLM\Software\Microsoft\Windows\CurrentVersion\Run

        SunJavaUpdateSched = C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        SiSUSBRG = C:\WINDOWS\SiSUSBrg.exe
        ATIModeChange = Ati2mdxx.exe
        ATIPTA = C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        SoundMan = SOUNDMAN.EXE
        RealTray = C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
        NeroFilterCheck = C:\WINDOWS\system32\NeroCheck.exe
        PinnacleDriverCheck = C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
        WinampAgent = C:\Program Files\Winamp\winampa.exe
        AVG7_CC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
        AVG7_EMC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
        QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
        SmcService = C:\PROGRA~1\Sygate\SPF\smc.exe -startgui

        --------------------------------------------------

        Autorun entries from Registry:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

        *No values found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

        *No values found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKCU\Software\Microsoft\Windows\CurrentVersion\Run

        CTFMON.EXE = C:\WINDOWS\system32\ctfmon.exe
        H/PC Connection Agent = "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"

        --------------------------------------------------

        Autorun entries from Registry:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

        *No values found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

        *Registry key not found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKLM\Software\Microsoft\Windows\CurrentVersion\Run
        *No subkeys found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
        *No subkeys found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
        *No subkeys found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
        *Registry key not found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
        *Registry key not found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKCU\Software\Microsoft\Windows\CurrentVersion\Run
        *No subkeys found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
        *No subkeys found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
        *Registry key not found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
        *Registry key not found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
        *Registry key not found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
        *Registry key not found*

        --------------------------------------------------

        Autorun entries in Registry subkeys of:
        HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
        *Registry key not found*

        --------------------------------------------------

        File association entry for .EXE:
        HKEY_CLASSES_ROOT\exefile\shell\open\command

        (Default) = "%1" %*

        --------------------------------------------------

        File association entry for .COM:
        HKEY_CLASSES_ROOT\comfile\shell\open\command

        (Default) = "%1" %*

        --------------------------------------------------

        File association entry for .BAT:
        HKEY_CLASSES_ROOT\batfile\shell\open\command

        (Default) = "%1" %*

        --------------------------------------------------

        File association entry for .PIF:
        HKEY_CLASSES_ROOT\piffile\shell\open\command

        (Default) = "%1" %*

        --------------------------------------------------

        File association entry for .SCR:
        HKEY_CLASSES_ROOT\scrfile\shell\open\command

        (Default) = "%1" /S

        --------------------------------------------------

        File association entry for .HTA:
        HKEY_CLASSES_ROOT\htafile\shell\open\command

        (Default) = C:\WINDOWS\System32\mshta.exe "%1" %*

        --------------------------------------------------

        File association entry for .TXT:
        HKEY_CLASSES_ROOT\txtfile\shell\open\command

        (Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

        --------------------------------------------------

        Enumerating Active Setup stub paths:
        HKLM\Software\Microsoft\Active Setup\Installed Components
        (* = disabled by HKCU twin)

        [>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
        StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

        [>{26923b43-4d38-484f-9b9e-de460746276c}] *
        StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE

        [>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
        StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

        [>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
        StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

        [{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
        StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

        [{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
        StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

        [{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
        StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

        [{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
        StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser

        [{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
        StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub

        [{7790769C-0471-11d2-AF11-00C04FA35D02}] *
        StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

        [{89820200-ECBD-11cf-8B85-00AA005B4340}] *
        StubPath = regsvr32.exe /s /n /i:U shell32.dll

        [{89820200-ECBD-11cf-8B85-00AA005B4383}] *
        StubPath = %SystemRoot%\system32\ie4uinit.exe

        [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
        StubPath = C:\WINDOWS\System32\Rundll32.exe C:\WINDOWS\System32\mscories.dll,Install

        --------------------------------------------------

        Enumerating ICQ Agent Autostart apps:
        HKCU\Software\Mirabilis\ICQ\Agent\Apps

        *Registry key not found*

        --------------------------------------------------

        Load/Run keys from C:\WINDOWS\WIN.INI:

        load=*INI section not found*
        run=*INI section not found*

        Load/Run keys from Registry:

        HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
        HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
        HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
        HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
        HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
        HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
        HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
        HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
        HKCU\..\Windows NT\CurrentVersion\Windows: load=
        HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
        HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
        HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
        HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

        --------------------------------------------------

        Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

        Shell=*INI section not found*
        SCRNSAVE.EXE=*INI section not found*
        drivers=*INI section not found*

        Shell & screensaver key from Registry:

        Shell=Explorer.exe
        SCRNSAVE.EXE=*Registry value not found*
        drivers=*Registry value not found*

        Policies Shell key:

        HKCU\..\Policies: Shell=*Registry key not found*
        HKLM\..\Policies: Shell=*Registry value not found*

        --------------------------------------------------

        Checking for EXPLORER.EXE instances:

        C:\WINDOWS\Explorer.exe: PRESENT!

        C:\Explorer.exe: not present
        C:\WINDOWS\Explorer\Explorer.exe: not present
        C:\WINDOWS\System\Explorer.exe: not present
        C:\WINDOWS\System32\Explorer.exe: not present
        C:\WINDOWS\Command\Explorer.exe: not present
        C:\WINDOWS\Fonts\Explorer.exe: not present

        --------------------------------------------------

        Checking for superhidden extensions:

        .lnk: HIDDEN! (arrow overlay: yes)
        .pif: HIDDEN! (arrow overlay: yes)
        .exe: not hidden
        .com: not hidden
        .bat: not hidden
        .hta: not hidden
        .scr: not hidden
        .shs: HIDDEN!
        .shb: HIDDEN!
        .vbs: not hidden
        .vbe: not hidden
        .wsh: not hidden
        .scf: HIDDEN! (arrow overlay: NO!)
        .url: HIDDEN! (arrow overlay: yes)
        .js: not hidden
        .jse: not hidden

        --------------------------------------------------

        Verifying REGEDIT.EXE integrity:

        - Regedit.exe found in C:\WINDOWS
        - .reg open command is normal (regedit.exe %1)
        - Regedit.exe has no CompanyName property! It is either missing or named something else.
        - Regedit.exe has no OriginalFilename property! It is either missing or named something else.
        - Regedit.exe has no FileDescription property! It is either missing or named something else.

        Registry check failed!

        --------------------------------------------------

        Enumerating Browser Helper Objects:

        (no name) - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}

        --------------------------------------------------

        Enumerating Task Scheduler jobs:

        A0D03B0D9183B1D5.job
        A9F2EB41918D6259.job
        AB3FD39B918048BB.job
        AD542B189183DEB0.job
        AF90B60D91872761.job

        --------------------------------------------------

        Enumerating Download Program Files:

        [Shockwave ActiveX Control]
        InProcServer32 = C:\WINDOWS\system32\Macromed\Director\SwDir.dll
        CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

        [Windows Genuine Advantage Validation Tool]
        InProcServer32 = C:\WINDOWS\System32\LegitCheckControl.DLL
        CODEBASE = http://go.microsoft.com/fwlink/?linkid=39204

        [WUWebControl Class]
        InProcServer32 = C:\WINDOWS\System32\wuweb.dll
        CODEBASE = http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125666863807

        [Java Plug-in 1.4.2_03]
        InProcServer32 = C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
        CODEBASE = http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab

        [MsnMessengerSetupDownloadControl Class]
        InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.ocx
        CODEBASE = http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab

        [Java Plug-in 1.4.2_03]
        InProcServer32 = C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
        CODEBASE = http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab

        [Shockwave Flash Object]
        InProcServer32 = C:\WINDOWS\System32\macromed\flash\Flash.ocx
        CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

        --------------------------------------------------

        Enumerating Winsock LSP files:

        NameSpace #1: C:\WINDOWS\System32\mswsock.dll
        NameSpace #2: C:\WINDOWS\System32\winrnr.dll
        NameSpace #3: C:\WINDOWS\System32\mswsock.dll
        NameSpace #4: C:\WINDOWS\System32\nwprovau.dll
        Protocol #1: C:\WINDOWS\system32\mswsock.dll
        Protocol #2: C:\WINDOWS\system32\mswsock.dll
        Protocol #3: C:\WINDOWS\system32\mswsock.dll
        Protocol #4: C:\WINDOWS\system32\mswsock.dll
        Protocol #5: C:\WINDOWS\system32\rsvpsp.dll
        Protocol #6: C:\WINDOWS\system32\rsvpsp.dll
        Protocol #7: C:\WINDOWS\system32\mswsock.dll
        Protocol #8: C:\WINDOWS\system32\mswsock.dll
        Protocol #9: C:\WINDOWS\system32\mswsock.dll
        Protocol #10: C:\WINDOWS\system32\mswsock.dll
        Protocol #11: C:\WINDOWS\system32\mswsock.dll
        Protocol #12: C:\WINDOWS\system32\mswsock.dll
        Protocol #13: C:\WINDOWS\system32\mswsock.dll
        Protocol #14: C:\WINDOWS\system32\mswsock.dll
        Protocol #15: C:\WINDOWS\system32\mswsock.dll
        Protocol #16: C:\WINDOWS\system32\mswsock.dll
        Protocol #17: C:\WINDOWS\system32\mswsock.dll
        Protocol #18: C:\WINDOWS\system32\mswsock.dll
        Protocol #19: C:\WINDOWS\system32\mswsock.dll
        Protocol #20: C:\WINDOWS\system32\mswsock.dll
        Protocol #21: C:\WINDOWS\system32\mswsock.dll
        Protocol #22: C:\WINDOWS\system32\mswsock.dll
        Protocol #23: C:\WINDOWS\system32\mswsock.dll
        Protocol #24: C:\WINDOWS\system32\mswsock.dll
        Protocol #25: C:\WINDOWS\system32\mswsock.dll
        Protocol #26: C:\WINDOWS\system32\mswsock.dll
        Protocol #27: C:\WINDOWS\system32\mswsock.dll
        Protocol #28: C:\WINDOWS\system32\mswsock.dll
        Protocol #29: C:\WINDOWS\system32\mswsock.dll

        --------------------------------------------------

        Enumerating Windows NT/2000/XP services

        61883 Unit Device: System32\DRIVERS\61883.sys (manual start)
        A4SII300: System32\drivers\A4SII300.SYS (autostart)
        Microsoft ACPI Driver: System32\DRIVERS\ACPI.sys (system)
        Microsoft Embedded Controller Driver: System32\DRIVERS\ACPIEC.sys (system)
        Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
        AFD Networking Support -ympäristö: \SystemRoot\System32\drivers\afd.sys (system)
        Service for WDM 3D Audio Driver: system32\drivers\ALCXSENS.SYS (manual start)
        Service for Realtek AC97 Audio (WDM): system32\drivers\ALCXWDM.SYS (manual start)
        Hälytys: %SystemRoot%\System32\svchost.exe -k LocalService (disabled)
        Sovelluskerroksen yhdyskäytäväpalvelu: %SystemRoot%\System32\alg.exe (manual start)
        AMD Athlon64 Processor Driver: System32\DRIVERS\AmdK8.sys (system)
        Sovellusten hallinta: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
        1394 ARP -asiakasprotokolla: System32\DRIVERS\arp1394.sys (manual start)
        ASAPIW2K: system32\drivers\ASAPIW2k.sys (manual start)
        ASP.NET-tilapalvelu: %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (manual start)
        RAS Asynchronous Media Driver: System32\DRIVERS\asyncmac.sys (manual start)
        Standardi IDE/ESDI-kiintolevyohjain: System32\DRIVERS\atapi.sys (system)
        Ati HotKey Poller: %SystemRoot%\System32\Ati2evxx.exe (autostart)
        ati2mtag: System32\DRIVERS\ati2mtag.sys (manual start)
        ATM ARP Client -protokolla: System32\DRIVERS\atmarpc.sys (manual start)
        Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Audio Stub Driver: System32\DRIVERS\audstub.sys (manual start)
        AVC-laite: System32\DRIVERS\avc.sys (manual start)
        AVG7 Alert Manager Server: C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (autostart)
        AVG7 Kernel: \SystemRoot\System32\Drivers\avg7core.sys (system)
        AVG7 Wrap Driver: \SystemRoot\System32\Drivers\avg7rsw.sys (system)
        AVG7 Rezident Driver: \SystemRoot\System32\Drivers\avg7rsxp.sys (system)
        AVG7 Update Service: C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (autostart)
        AVG Network Redirector: \??\C:\WINDOWS\System32\Drivers\avgtdi.sys (autostart)
        BITS-tausta-ajo (Background Intelligent Transfer Service): %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        MAC-silta: System32\DRIVERS\bridge.sys (manual start)
        MAC Bridge Miniport: System32\DRIVERS\bridge.sys (manual start)
        Tietokoneiden selaus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        BUFADPT: \??\C:\WINDOWS\System32\BUFADPT.SYS (autostart)
        Closed Caption Decoder: System32\DRIVERS\CCDECODE.sys (manual start)
        CD-ROM-ohjain: System32\DRIVERS\cdrom.sys (system)
        Indeksointipalvelu: %SystemRoot%\system32\cisvc.exe (manual start)
        Leikekirja: %SystemRoot%\system32\clipsrv.exe (disabled)
        Microsoft ACPI Control Method Battery Driver: System32\DRIVERS\CmBatt.sys (manual start)
        Microsoft Composite Battery Driver: System32\DRIVERS\compbatt.sys (system)
        COM -järjestelmäsovellus: C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
        CONAN: system32\drivers\o2mmb.sys (manual start)
        Salauspalvelut: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
        DCOM-palvelinprosessin käynnistys: %SystemRoot%\system32\svchost -k DcomLaunch (autostart)
        DHCP-asiakas: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Levyohjain: System32\DRIVERS\disk.sys (system)
        Loogisen levyn hallinnan valvontapalvelu: %SystemRoot%\System32\dmadmin.exe /com (manual start)
        dmboot: System32\drivers\dmboot.sys (disabled)
        dmio: System32\drivers\dmio.sys (disabled)
        dmload: System32\drivers\dmload.sys (disabled)
        Loogisen levyn hallinta: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
        DNS-asiakas: %SystemRoot%\System32\svchost.exe -k NetworkService (autostart)
        Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
        %1394\031887&040892.DeviceDesc%: System32\DRIVERS\enum1394.sys (manual start)
        Virheraportointipalvelut: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Tapahtumaloki: %SystemRoot%\system32\services.exe (autostart)
        COM -tapahtumajärjestelmä: C:\WINDOWS\System32\svchost.exe -k netsvcs (manual start)
        Nopean käyttäjän vaihdon yhteensopivuus: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        FltMgr: system32\drivers\fltmgr.sys (system)
        Volume Manager -ohjain: System32\DRIVERS\ftdisk.sys (system)
        GearAspiWDM: system32\drivers\gearaspiwdm.sys (manual start)
        Yleinen paketinmääritys: System32\DRIVERS\msgpc.sys (manual start)
        Ohjeet ja tuotetuki: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        HID (Human Interface Device) -liittymä: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
        Microsoft HID -luokkaohjain: System32\DRIVERS\hidusb.sys (manual start)
        HTTP: System32\Drivers\HTTP.sys (manual start)
        HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start)
        i8042-näppäimistö ja PS/2-hiiriohjain: System32\DRIVERS\i8042prt.sys (system)
        CD-Burning Filter Driver: System32\DRIVERS\imapi.sys (system)
        CD-levyjen kirjoittamisen IMAPI COM -palvelu: C:\WINDOWS\System32\imapi.exe (manual start)
        Windowsin IPv6-palomuurin ohjain: system32\drivers\ip6fw.sys (manual start)
        IP Traffic Filter Driver: System32\DRIVERS\ipfltdrv.sys (manual start)
        IP in IP Tunnel Driver: System32\DRIVERS\ipinip.sys (manual start)
        IP Network Address Translator: System32\DRIVERS\ipnat.sys (manual start)
        IPSEC-ohjain: System32\DRIVERS\ipsec.sys (system)
        IrDA-protokolla: System32\DRIVERS\irda.sys (autostart)
        IR Enumerator Service: System32\DRIVERS\irenum.sys (manual start)
        Infrapunavalvonta: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        PnP ISA/EISA -väyläohjain: System32\DRIVERS\isapnp.sys (system)
        Näppäimistön luokkaohjain: System32\DRIVERS\kbdclass.sys (system)
        kbeepm: \??\C:\DOCUME~1\Omistaja\LOCALS~1\Temp\kbeepm.sys (manual start)
        Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
        Palvelin: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Työasema: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        TCP/IP NetBIOS Helper: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
        MbxStby: system32\drivers\MbxStby.sys (manual start)
        Viestinvälitys: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
        NetMeeting etätyöpöydän jakaminen: C:\WINDOWS\System32\mnmsrvc.exe (manual start)
        Unimodem Streaming Filter Device: system32\drivers\MODEMCSA.sys (manual start)
        Hiiren luokkaohjain: System32\DRIVERS\mouclass.sys (system)
        Hiiren HID-ohjain: System32\DRIVERS\mouhid.sys (manual start)
        WebDav Client Redirector: System32\DRIVERS\mrxdav.sys (manual start)
        MRXSMB: System32\DRIVERS\mrxsmb.sys (system)
        Distributed Transaction Coordinator: C:\WINDOWS\System32\msdtc.exe (manual start)
        Microsoft DV Camera and VCR: System32\DRIVERS\msdv.sys (manual start)
        Windows Installer: C:\WINDOWS\System32\msiexec.exe /V (manual start)
        Microsoft Streaming Service -välityspalvelin: system32\drivers\MSKSSRV.sys (manual start)
        Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
        Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
        Microsoft-järjestelmänhallinnan BIOS-ohjain: System32\DRIVERS\mssmbios.sys (manual start)
        Microsoft Streaming Tee/Sink-to-Sink -muunnin: system32\drivers\MSTEE.sys (manual start)
        Mtlmnt5: System32\DRIVERS\Mtlmnt5.sys (manual start)
        Mtlstrm: System32\DRIVERS\Mtlstrm.sys (manual start)
        NABTS/FEC VBI Codec: System32\DRIVERS\NABTSFEC.sys (manual start)
        Microsoft TV/Video Connection: System32\DRIVERS\NdisIP.sys (manual start)
        Remote Access NDIS TAPI Driver: System32\DRIVERS\ndistapi.sys (manual start)
        NDIS Usermode I/O -protokolla: System32\DRIVERS\ndisuio.sys (manual start)
        Remote Access NDIS WAN Driver: System32\DRIVERS\ndiswan.sys (manual start)
        NetBIOS-käyttöliittymä: System32\DRIVERS\netbios.sys (system)
        NetBIOS TCP/IP:n päällä: System32\DRIVERS\netbt.sys (system)
        Verkon DDE: %SystemRoot%\system32\netdde.exe (disabled)
        Verkon DDE DSDM: %SystemRoot%\system32\netdde.exe (disabled)
        Verkkokirjautuminen: %SystemRoot%\System32\lsass.exe (manual start)
        Verkkoyhteydet: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        1394-verkko-ohjain: System32\DRIVERS\nic1394.sys (manual start)
        NLA-nimiavaruus (Network Location Awareness): %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        NSC-infrapunalaiteohjain: System32\DRIVERS\nscirda.sys (manual start)
        NT LM -suojaustuen toimittaja: %SystemRoot%\System32\lsass.exe (manual start)
        Siirrettävät tallennusvälineet: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
        NtMtlFax: System32\DRIVERS\NtMtlFax.sys (manual start)
        IPX Traffic Filter Driver: System32\DRIVERS\nwlnkflt.sys (manual start)
        IPX Traffic Forwarder Driver: System32\DRIVERS\nwlnkfwd.sys (manual start)
        NWLink IPX/SPX/NetBIOS -yhteensopiva kuljetusprotokolla: System32\DRIVERS\nwlnkipx.sys (autostart)
        NWLink NetBIOS: System32\DRIVERS\nwlnknb.sys (autostart)
        NWLink SPX/SPXII -protokolla: System32\DRIVERS\nwlnkspx.sys (autostart)
        SAP-agentti: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Texas Instruments OHCI Compliant IEEE 1394 Host Controller: System32\DRIVERS\ohci1394.sys (system)
        OLYMPUS Digital Camera: System32\Drivers\olcamudp.sys (manual start)
        Rinnakkaisporttiohjain: System32\DRIVERS\parport.sys (manual start)
        PCI Bus Driver: System32\DRIVERS\pci.sys (system)
        PCIIde: System32\DRIVERS\pciide.sys (system)
        Pcmcia: System32\DRIVERS\pcmcia.sys (system)
        PADUS ASPI SHELL: system32\drivers\pfc.sys (manual start)
        Plug and Play: %SystemRoot%\system32\services.exe (autostart)
        IPSEC-palvelut: %SystemRoot%\System32\lsass.exe (autostart)
        WAN Miniport (PPTP): System32\DRIVERS\raspptp.sys (manual start)
        Processor Driver: System32\DRIVERS\processr.sys (system)
        Suojattu tallennuspaikka: %SystemRoot%\system32\lsass.exe (autostart)
        QoS-paketinajoitus: System32\DRIVERS\psched.sys (manual start)
        Direct Parallel Link Driver: System32\DRIVERS\ptilink.sys (manual start)
        PxHelp20: System32\DRIVERS\PxHelp20.sys (system)
        Logitech QuickCam Express: System32\DRIVERS\OVCD.sys (manual start)
        Remote Access Auto Connection -ohjain: System32\DRIVERS\rasacd.sys (system)
        Remote Access Auto Connection -hallinta: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        WAN Miniport (IrDA): System32\DRIVERS\rasirda.sys (manual start)
        WAN Miniport (L2TP): System32\DRIVERS\rasl2tp.sys (manual start)
        Etäkäytön (RAS) yhteyksienhallinta: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        Remote Access PPPOE Driver: System32\DRIVERS\raspppoe.sys (manual start)
        Suora rinnakkainen: System32\DRIVERS\raspti.sys (manual start)
        Rdbss: System32\DRIVERS\rdbss.sys (system)
        RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
        Etätyöpöydän ohjeen istunnonhallinta: C:\WINDOWS\system32\sessmgr.exe (manual start)
        RecAgent: System32\DRIVERS\RecAgent.sys (system)
        Digital CD Audio Playback Filter Driver: System32\DRIVERS\redbook.sys (system)
        Reititys ja etäkäyttö: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Etäproseduurikutsujen (RPC) paikannin: %SystemRoot%\System32\locator.exe (manual start)
        Etäproseduurikutsu (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
        QoS RSVP: %SystemRoot%\System32\rsvp.exe (manual start)
        RT2500 Wireless Driver: System32\DRIVERS\RT2500.sys (manual start)
        Käyttöoikeustilien hallinta: %SystemRoot%\system32\lsass.exe (autostart)
        Älykortti: %SystemRoot%\System32\SCardSvr.exe (manual start)
        Tehtävien ajoitus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Secdrv: System32\DRIVERS\secdrv.sys (autostart)
        Toissijainen kirjautuminen: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Järjestelmätapahtuman ilmoitus: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
        Windowsin palomuuri / Internet-yhteyden jakaminen (ICS): %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Käyttöliittymän laitteistotunnistus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        SiS 163 usb Wireless LAN Adapter Driver: system32\DRIVERS\sis163u.sys (manual start)
        SiS AGP Filter: System32\DRIVERS\SISAGPX.sys (system)
        SiS PCI Fast Ethernet Adapter Driver: System32\DRIVERS\sisnic.sys (manual start)
        BDA Slip De-Framer: System32\DRIVERS\SLIP.sys (manual start)
        SmartLink AMR_PCI Driver: System32\DRIVERS\slntamr.sys (manual start)
        SlNtHal: System32\DRIVERS\Slnthal.sys (manual start)
        SmartLinkService: slserv.exe (autostart)
        SlWdmSup: System32\DRIVERS\SlWdmSup.sys (manual start)
        Sygate Personal Firewall: C:\Program Files\Sygate\SPF\smc.exe (autostart)
        Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
        Taustatulostusohjain: %SystemRoot%\system32\spoolsv.exe (autostart)
        Järjestelmän palautussuodatin -ohjain: System32\DRIVERS\sr.sys (system)
        Järjestelmän palauttaminen -palvelu: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Srv: System32\DRIVERS\srv.sys (manual start)
        SSDP-palvelu (Simple Service Discovery Protocol): %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
        WIA (Windows Image Acquisition): %SystemRoot%\System32\svchost.exe -k imgsvc (autostart)
        BDA IPSink: System32\DRIVERS\StreamIP.sys (manual start)
        Ohjelmistoväyläohjain: System32\DRIVERS\swenum.sys (manual start)
        Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
        MS Software Shadow Copy Provider: C:\WINDOWS\System32\dllhost.exe /Processid:{C9B7B653-CA37-4810-B8AC-6F58CBA0B2B2} (manual start)
        Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
        Resurssilokit ja -hälytykset: %SystemRoot%\system32\smlogsvc.exe (manual start)
        Puhelin: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        TCP/IP-protokollaohjain: System32\DRIVERS\tcpip.sys (system)
        Teefer for NT: SYSTEM32\Drivers\Teefer.sys (system)
        Päätelaiteohjain: System32\DRIVERS\termdd.sys (system)
        Päätepalvelut: %SystemRoot%\System32\svchost -k DComLaunch (manual start)
        Teemat: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Tiedostolinkkijäljityksen asiakas: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
        Windows User Mode Driver Framework: C:\WINDOWS\System32\wdfmgr.exe (autostart)
        Microcode Update -ohjain: System32\DRIVERS\update.sys (manual start)
        Universal Plug & Play -laiteisäntä: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
        UPS: %SystemRoot%\System32\ups.exe (manual start)
        Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: System32\DRIVERS\usbehci.sys (manual start)
        USB2 Enabled Hub: System32\DRIVERS\usbhub.sys (manual start)
        Microsoft USB Open Host Controller Miniport Driver: System32\DRIVERS\usbohci.sys (manual start)
        USB Scanner Driver: System32\DRIVERS\usbscan.sys (manual start)
        USB-massamuistiohjain: System32\DRIVERS\USBSTOR.SYS (manual start)
        VGA-näytönohjain: \SystemRoot\System32\drivers\vga.sys (system)
        Aseman tilannevedos: %SystemRoot%\System32\vssvc.exe (manual start)
        Windows Time: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Remote Access IP ARP Driver: System32\DRIVERS\wanarp.sys (manual start)
        Windows CE USB Serial Host Driver: System32\DRIVERS\wceusbsh.sys (manual start)
        Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
        WebClient: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
        SyGate for NT, wg3n: \SystemRoot\SYSTEM32\Drivers\wg3n.sys (autostart)
        SyGate for NT, wg4n: \SystemRoot\SYSTEM32\Drivers\wg4n.sys (autostart)
        SyGate for NT, wg5n: \SystemRoot\SYSTEM32\Drivers\wg5n.sys (autostart)
        SyGate for NT, wg6n: \SystemRoot\SYSTEM32\Drivers\wg6n.sys (autostart)
        WMI-palvelu (Windows Management Instrumentation): %systemroot%\system32\svchost.exe -k netsvcs (autostart)
        Portable Media Serial Number Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
        WMI resurssisovitin: C:\WINDOWS\System32\wbem\wmiapsrv.exe (manual start)
        wpsdrvnt: \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (system)
        Tietoturvakeskus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        World Standard Teletext Codec: System32\DRIVERS\WSTCODEC.SYS (manual start)
        Automaattiset päivitykset: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
        Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
        Verkon käyttöönottopalvelu: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)


        --------------------------------------------------

        Enumerating Windows NT logon/logoff scripts:
        *No scripts set to run*

        Windows NT checkdisk command:
        BootExecute =

        Windows NT 'Wininit.ini':
        PendingFileRenameOperations: *Registry value not found*

        --------------------------------------------------

        Enumerating ShellServiceObjectDelayLoad items:

        PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
        CDBurn: C:\WINDOWS\system32\SHELL32.dll
        WebCheck: C:\WINDOWS\System32\webcheck.dll
        SysTray: C:\WINDOWS\System32\stobject.dll

        --------------------------------------------------
        Autorun entries from Registry:
        HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

        *Registry key not found*

        --------------------------------------------------

        Autorun entries from Registry:
        HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

        *Registry key not found*

        --------------------------------------------------

        End of report, 36 010 bytes
        Report generated in 0,110 seconds

        Command line options:
        /verbose - to add additional info on each section
        /complete - to include empty sections and unsuspicious data
        /full - to include several rarely-important sections
        /force9x - to include Win9x-only startups even if running on WinNT
        /forcent - to include WinNT-only startups even if running on Win9x
        /forceall - to include all Win9x and WinNT startups, regardless of platform
        /history - to list version history only
        Logfile of HijackThis v1.99.1
        Scan saved at 19:16:09, on 16.9.2005
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\System32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Sygate\SPF\smc.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\Real\RealPlayer\RealPlay.exe
        C:\Program Files\Winamp\winampa.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
        C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
        C:\Program Files\Microsoft Office\Office\OSA.EXE
        C:\HJT\HijackThis.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\WINDOWS\system32\notepad.exe
        C:\Program Files\Opera2\Opera.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
        O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
        O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
        O4 - Global Startup: Microsoft Office Pikahaku.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
        O4 - Global Startup: Officen käynnistys.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
        O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125666863807
        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
        O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
        O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
        O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
        O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\system32\slserv.exe
        O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

        Juu ei ilmeisesti ole paikalla...

        mutta tässä lisää poistettavaa..

        Mene ohjauspaneeli--> ajoitetut tehtävät

        Siellä pitäisi näkyä seuraavat tehtävät:

        A0D03B0D9183B1D5.job
        A9F2EB41918D6259.job
        AB3FD39B918048BB.job
        AD542B189183DEB0.job
        AF90B60D91872761.job

        poista ylläolevat tehtävät vaikka yksitellen menemällä rivin päälle ja hiiren oikealla painikkeella valitse POISTA.
        .
        .


      • mut ku
        Ad-Aware kirjoitti:

        Juu ei ilmeisesti ole paikalla...

        mutta tässä lisää poistettavaa..

        Mene ohjauspaneeli--> ajoitetut tehtävät

        Siellä pitäisi näkyä seuraavat tehtävät:

        A0D03B0D9183B1D5.job
        A9F2EB41918D6259.job
        AB3FD39B918048BB.job
        AD542B189183DEB0.job
        AF90B60D91872761.job

        poista ylläolevat tehtävät vaikka yksitellen menemällä rivin päälle ja hiiren oikealla painikkeella valitse POISTA.
        .
        .

        ei ole ajoitetuissa mitään.


      • mut ku kirjoitti:

        ei ole ajoitetuissa mitään.

        Katso löytyykö ne seuraavasta polusta

        C:\WINDOWS\Tasks

        .
        .


      • nono
        Ad-Aware kirjoitti:

        Katso löytyykö ne seuraavasta polusta

        C:\WINDOWS\Tasks

        .
        .

        eipä sielläkään mitään.


      • mutta

      • nono kirjoitti:

        eipä sielläkään mitään.

        Hae tuolta KillBox

        http://www.bleepingcomputer.com/files/killbox.php

        Pura ja asenna se vaikka työpöydälle.

        "Maalaa" ja kopioi allaolevat viisi riviä...

        C:\WINDOWS\Tasks\A0D03B0D9183B1D5.job
        C:\WINDOWS\Tasks\A9F2EB41918D6259.job
        C:\WINDOWS\Tasks\AB3FD39B918048BB.job
        C:\WINDOWS\Tasks\AD542B189183DEB0.job
        C:\WINDOWS\Tasks\AF90B60D91872761.job

        Avaa killbox.exe
        Klikkaa siihen riville missä lukee
        Full Path of to Delete
        niin,että siinä alkaa kursori vilkkuu..

        sitten ylhäältä File
        -->Paste from Clipboard

        ja siinä pitäisi näkyä nyt joku noista ylläolevista riveistä.

        Laita "täppi" kohtaan Delete on Reboot ja painat sen jälkeen oikealla olevaa punaista ympyrää jossa on valkoinen rasti.
        Vastaat vain kysymyksiin OK ja annat koneen buutata itsensä.
        Jos ei buuttaa itse niin buuttaa kone "käsin".

        Buutin jälkeen pistä uusi HijackThis logi ja StartupList logi.
        .
        .


      • Juu
        Ad-Aware kirjoitti:

        Juu ei ilmeisesti ole paikalla...

        mutta tässä lisää poistettavaa..

        Mene ohjauspaneeli--> ajoitetut tehtävät

        Siellä pitäisi näkyä seuraavat tehtävät:

        A0D03B0D9183B1D5.job
        A9F2EB41918D6259.job
        AB3FD39B918048BB.job
        AD542B189183DEB0.job
        AF90B60D91872761.job

        poista ylläolevat tehtävät vaikka yksitellen menemällä rivin päälle ja hiiren oikealla painikkeella valitse POISTA.
        .
        .

        Just joo nuo jobit oli mielessä ku pyysin StartupList logii ku oli niin paljo loppia koneella.


      • maalaan
        Ad-Aware kirjoitti:

        Hae tuolta KillBox

        http://www.bleepingcomputer.com/files/killbox.php

        Pura ja asenna se vaikka työpöydälle.

        "Maalaa" ja kopioi allaolevat viisi riviä...

        C:\WINDOWS\Tasks\A0D03B0D9183B1D5.job
        C:\WINDOWS\Tasks\A9F2EB41918D6259.job
        C:\WINDOWS\Tasks\AB3FD39B918048BB.job
        C:\WINDOWS\Tasks\AD542B189183DEB0.job
        C:\WINDOWS\Tasks\AF90B60D91872761.job

        Avaa killbox.exe
        Klikkaa siihen riville missä lukee
        Full Path of to Delete
        niin,että siinä alkaa kursori vilkkuu..

        sitten ylhäältä File
        -->Paste from Clipboard

        ja siinä pitäisi näkyä nyt joku noista ylläolevista riveistä.

        Laita "täppi" kohtaan Delete on Reboot ja painat sen jälkeen oikealla olevaa punaista ympyrää jossa on valkoinen rasti.
        Vastaat vain kysymyksiin OK ja annat koneen buutata itsensä.
        Jos ei buuttaa itse niin buuttaa kone "käsin".

        Buutin jälkeen pistä uusi HijackThis logi ja StartupList logi.
        .
        .

        mistä maalaan kun en löydä rivejä muutakuin startuplistasta ja sieltä niitä taitaa olla turha maalailla?


    • toimivan

      SUURI KIITOS KAIKILLE,kone tuntuu nyt olevan ihan ok vaikka nuo .job tehtävät tuolla kummittelevatkin!!!!!!!!
      Jos joku vielä keksii miten niistä pääsee tai mitä ne ovat niin vinkkejä otetaan vastaan avoimin mielin.
      KIITOS!!!!!!!

      • ---

        "vaikka nuo .job tehtävät tuolla kummittelevatkin!!!!!!!!Jos joku vielä keksii miten niistä pääsee tai mitä ne ovat niin vinkkejä otetaan vastaan avoimin mielin."

        Mitähän tapahtuisi jos tekisit niinkun nimim. Ad-Aware neuvoi????????


      • mutta

        aja uudestaan se escan siintä se logi tänne jos jotain tulee sen lisäksi se uusi hjt logi.

        Jos nämä nyt tekisit niin *juu, juggis tai ad-aware*

        Sekkaavat sen odota niiltä ohjeita tämän jälkeen.

        Huomaat kyllä oikeat OHJEET jos vähänkin maltat katsoa mitä neuvovat.


      • ohjeet

        Ohje,
        Kirjoittanut: Ad-Aware 17.9.2005 klo 11.36

        Hae tuolta KillBox

        http://www.bleepingcomputer.com/files/killbox.php

        Pura ja asenna se vaikka työpöydälle.

        "MAALAA" JA KOPIOI ALLA OLEVAT VIISI RIVIÄ...

        C:\WINDOWS\Tasks\A0D03B0D9183B1D5.job
        C:\WINDOWS\Tasks\A9F2EB41918D6259.job
        C:\WINDOWS\Tasks\AB3FD39B918048BB.job
        C:\WINDOWS\Tasks\AD542B189183DEB0.job
        C:\WINDOWS\Tasks\AF90B60D91872761.job

        Avaa killbox.exe
        Klikkaa siihen riville missä lukee
        Full Path of to Delete
        niin,että siinä alkaa kursori vilkkuu..

        sitten ylhäältä File
        -->Paste from Clipboard

        ja siinä pitäisi näkyä nyt joku noista ylläolevista riveistä.

        Laita "täppi" kohtaan Delete on Reboot ja painat sen jälkeen oikealla olevaa punaista ympyrää jossa on valkoinen rasti.
        Vastaat vain kysymyksiin OK ja annat koneen buutata itsensä.
        Jos ei buuttaa itse niin buuttaa kone "käsin".

        Buutin jälkeen pistä uusi HijackThis logi ja StartupList logi.


    • auttoi

      Sori hätäilyni nyt mä hokasin. :)
      Logfile of HijackThis v1.99.1
      Scan saved at 10:12:14, on 18.9.2005
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\System32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Sygate\SPF\smc.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      C:\WINDOWS\system32\slserv.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\Real\RealPlayer\RealPlay.exe
      C:\Program Files\Winamp\winampa.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
      C:\Program Files\Microsoft Office\Office\OSA.EXE
      C:\HJT\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
      O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
      O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
      O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
      O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
      O4 - Global Startup: Microsoft Office Pikahaku.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
      O4 - Global Startup: Officen käynnistys.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
      O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
      O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125666863807
      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
      O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
      O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
      O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
      O23 - Service: TrueVector Internet Monitor (vsmon) - Unknown owner - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (file missing)

      ja starttilista
      StartupList report, 18.9.2005, 10:13:52
      StartupList version: 1.52.2
      Started from : C:\HJT\HijackThis.EXE
      Detected: Windows XP SP2 (WinNT 5.01.2600)
      Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      * Using default options
      * Including empty and uninteresting sections
      * Showing rarely important sections
      ==================================================

      Running processes:

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\System32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Sygate\SPF\smc.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      C:\WINDOWS\system32\slserv.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\Real\RealPlayer\RealPlay.exe
      C:\Program Files\Winamp\winampa.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
      C:\Program Files\Microsoft Office\Office\OSA.EXE
      C:\HJT\HijackThis.exe
      C:\WINDOWS\system32\NOTEPAD.EXE

      --------------------------------------------------

      Listing of startup folders:

      Shell folders Startup:
      [C:\Documents and Settings\Omistaja\Käynnistä-valikko\Ohjelmat\Käynnistys]
      *No files*

      Shell folders AltStartup:
      *Folder not found*

      User shell folders Startup:
      *Folder not found*

      User shell folders AltStartup:
      *Folder not found*

      Shell folders Common Startup:
      [C:\Documents and Settings\All Users\Käynnistä-valikko\Ohjelmat\Käynnistys]
      Microsoft Office Pikahaku.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
      Officen käynnistys.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE

      Shell folders Common AltStartup:
      *Folder not found*

      User shell folders Common Startup:
      *Folder not found*

      User shell folders Alternate Common Startup:
      *Folder not found*

      --------------------------------------------------

      Checking Windows NT UserInit:

      [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
      UserInit = C:\WINDOWS\system32\userinit.exe,

      [HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
      *Registry key not found*

      [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
      *Registry value not found*

      [HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
      *Registry key not found*

      --------------------------------------------------

      Autorun entries from Registry:
      HKLM\Software\Microsoft\Windows\CurrentVersion\Run

      SunJavaUpdateSched = C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      SiSUSBRG = C:\WINDOWS\SiSUSBrg.exe
      ATIModeChange = Ati2mdxx.exe
      ATIPTA = C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      SoundMan = SOUNDMAN.EXE
      RealTray = C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
      NeroFilterCheck = C:\WINDOWS\system32\NeroCheck.exe
      PinnacleDriverCheck = C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
      WinampAgent = C:\Program Files\Winamp\winampa.exe
      AVG7_CC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
      AVG7_EMC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
      QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
      SmcService = C:\PROGRA~1\Sygate\SPF\smc.exe -startgui

      --------------------------------------------------

      Autorun entries from Registry:
      HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

      *No values found*

      --------------------------------------------------

      Autorun entries from Registry:
      HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

      *No values found*

      --------------------------------------------------

      Autorun entries from Registry:
      HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

      *Registry key not found*

      --------------------------------------------------

      Autorun entries from Registry:
      HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

      *Registry key not found*

      --------------------------------------------------

      Autorun entries from Registry:
      HKCU\Software\Microsoft\Windows\CurrentVersion\Run

      CTFMON.EXE = C:\WINDOWS\system32\ctfmon.exe
      H/PC Connection Agent = "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"

      --------------------------------------------------

      Autorun entries from Registry:
      HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

      *No values found*

      --------------------------------------------------

      Autorun entries from Registry:
      HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

      *Registry key not found*

      --------------------------------------------------

      Autorun entries from Registry:
      HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

      *Registry key not found*

      --------------------------------------------------

      Autorun entries from Registry:
      HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

      *Registry key not found*

      --------------------------------------------------

      Autorun entries from Registry:
      HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

      *Registry key not found*

      --------------------------------------------------

      Autorun entries from Registry:
      HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

      *Registry key not found*

      --------------------------------------------------

      Autorun entries in Registry subkeys of:
      HKLM\Software\Microsoft\Windows\CurrentVersion\Run
      *No subkeys found*

      --------------------------------------------------

      Autorun entries in Registry subkeys of:
      HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
      *No subkeys found*

      --------------------------------------------------

      Autorun entries in Registry subkeys of:
      HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
      *No subkeys found*

      --------------------------------------------------

      Autorun entries in Registry subkeys of:
      HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
      *Registry key not found*

      --------------------------------------------------

      Autorun entries in Registry subkeys of:
      HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
      *Registry key not found*

      --------------------------------------------------

      Autorun entries in Registry subkeys of:
      HKCU\Software\Microsoft\Windows\CurrentVersion\Run
      *No subkeys found*

      --------------------------------------------------

      Autorun entries in Registry subkeys of:
      HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
      *No subkeys found*

      --------------------------------------------------

      Autorun entries in Registry subkeys of:
      HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
      *Registry key not found*

      --------------------------------------------------

      Autorun entries in Registry subkeys of:
      HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
      *Registry key not found*

      --------------------------------------------------

      Autorun entries in Registry subkeys of:
      HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
      *Registry key not found*

      --------------------------------------------------

      Autorun entries in Registry subkeys of:
      HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
      *Registry key not found*

      --------------------------------------------------

      Autorun entries in Registry subkeys of:
      HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
      *Registry key not found*

      --------------------------------------------------

      File association entry for .EXE:
      HKEY_CLASSES_ROOT\exefile\shell\open\command

      (Default) = "%1" %*

      --------------------------------------------------

      File association entry for .COM:
      HKEY_CLASSES_ROOT\comfile\shell\open\command

      (Default) = "%1" %*

      --------------------------------------------------

      File association entry for .BAT:
      HKEY_CLASSES_ROOT\batfile\shell\open\command

      (Default) = "%1" %*

      --------------------------------------------------

      File association entry for .PIF:
      HKEY_CLASSES_ROOT\piffile\shell\open\command

      (Default) = "%1" %*

      --------------------------------------------------

      File association entry for .SCR:
      HKEY_CLASSES_ROOT\scrfile\shell\open\command

      (Default) = "%1" /S

      --------------------------------------------------

      File association entry for .HTA:
      HKEY_CLASSES_ROOT\htafile\shell\open\command

      (Default) = C:\WINDOWS\System32\mshta.exe "%1" %*

      --------------------------------------------------

      File association entry for .TXT:
      HKEY_CLASSES_ROOT\txtfile\shell\open\command

      (Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

      --------------------------------------------------

      Enumerating Active Setup stub paths:
      HKLM\Software\Microsoft\Active Setup\Installed Components
      (* = disabled by HKCU twin)

      [>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
      StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

      [>{26923b43-4d38-484f-9b9e-de460746276c}] *
      StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE

      [>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
      StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

      [>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
      StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

      [{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
      StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

      [{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
      StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

      [{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
      StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

      [{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
      StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser

      [{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
      StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub

      [{7790769C-0471-11d2-AF11-00C04FA35D02}] *
      StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

      [{89820200-ECBD-11cf-8B85-00AA005B4340}] *
      StubPath = regsvr32.exe /s /n /i:U shell32.dll

      [{89820200-ECBD-11cf-8B85-00AA005B4383}] *
      StubPath = %SystemRoot%\system32\ie4uinit.exe

      [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
      StubPath = C:\WINDOWS\System32\Rundll32.exe C:\WINDOWS\System32\mscories.dll,Install

      --------------------------------------------------

      Enumerating ICQ Agent Autostart apps:
      HKCU\Software\Mirabilis\ICQ\Agent\Apps

      *Registry key not found*

      --------------------------------------------------

      Load/Run keys from C:\WINDOWS\WIN.INI:

      load=*INI section not found*
      run=*INI section not found*

      Load/Run keys from Registry:

      HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
      HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
      HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
      HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
      HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
      HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
      HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
      HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
      HKCU\..\Windows NT\CurrentVersion\Windows: load=
      HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
      HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
      HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
      HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

      --------------------------------------------------

      Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

      Shell=*INI section not found*
      SCRNSAVE.EXE=*INI section not found*
      drivers=*INI section not found*

      Shell & screensaver key from Registry:

      Shell=Explorer.exe
      SCRNSAVE.EXE=*Registry value not found*
      drivers=*Registry value not found*

      Policies Shell key:

      HKCU\..\Policies: Shell=*Registry key not found*
      HKLM\..\Policies: Shell=*Registry value not found*

      --------------------------------------------------

      Checking for EXPLORER.EXE instances:

      C:\WINDOWS\Explorer.exe: PRESENT!

      C:\Explorer.exe: not present
      C:\WINDOWS\Explorer\Explorer.exe: not present
      C:\WINDOWS\System\Explorer.exe: not present
      C:\WINDOWS\System32\Explorer.exe: not present
      C:\WINDOWS\Command\Explorer.exe: not present
      C:\WINDOWS\Fonts\Explorer.exe: not present

      --------------------------------------------------

      Checking for superhidden extensions:

      .lnk: HIDDEN! (arrow overlay: yes)
      .pif: HIDDEN! (arrow overlay: yes)
      .exe: not hidden
      .com: not hidden
      .bat: not hidden
      .hta: not hidden
      .scr: not hidden
      .shs: HIDDEN!
      .shb: HIDDEN!
      .vbs: not hidden
      .vbe: not hidden
      .wsh: not hidden
      .scf: HIDDEN! (arrow overlay: NO!)
      .url: HIDDEN! (arrow overlay: yes)
      .js: not hidden
      .jse: not hidden

      --------------------------------------------------

      Verifying REGEDIT.EXE integrity:

      - Regedit.exe found in C:\WINDOWS
      - .reg open command is normal (regedit.exe %1)
      - Regedit.exe has no CompanyName property! It is either missing or named something else.
      - Regedit.exe has no OriginalFilename property! It is either missing or named something else.
      - Regedit.exe has no FileDescription property! It is either missing or named something else.

      Registry check failed!

      --------------------------------------------------

      Enumerating Browser Helper Objects:

      (no name) - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}

      --------------------------------------------------

      Enumerating Task Scheduler jobs:

      *No jobs found*

      --------------------------------------------------

      Enumerating Download Program Files:

      [Shockwave ActiveX Control]
      InProcServer32 = C:\WINDOWS\system32\Macromed\Director\SwDir.dll
      CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

      [Windows Genuine Advantage Validation Tool]
      InProcServer32 = C:\WINDOWS\System32\LegitCheckControl.DLL
      CODEBASE = http://go.microsoft.com/fwlink/?linkid=39204

      [WUWebControl Class]
      InProcServer32 = C:\WINDOWS\System32\wuweb.dll
      CODEBASE = http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125666863807

      [Java Plug-in 1.4.2_03]
      InProcServer32 = C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      CODEBASE = http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab

      [MsnMessengerSetupDownloadControl Class]
      InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.ocx
      CODEBASE = http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab

      [Java Plug-in 1.4.2_03]
      InProcServer32 = C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      CODEBASE = http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab

      [Shockwave Flash Object]
      InProcServer32 = C:\WINDOWS\System32\macromed\flash\Flash.ocx
      CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

      --------------------------------------------------

      Enumerating Winsock LSP files:

      NameSpace #1: C:\WINDOWS\System32\mswsock.dll
      NameSpace #2: C:\WINDOWS\System32\winrnr.dll
      NameSpace #3: C:\WINDOWS\System32\mswsock.dll
      NameSpace #4: C:\WINDOWS\System32\nwprovau.dll
      Protocol #1: C:\WINDOWS\system32\mswsock.dll
      Protocol #2: C:\WINDOWS\system32\mswsock.dll
      Protocol #3: C:\WINDOWS\system32\mswsock.dll
      Protocol #4: C:\WINDOWS\system32\mswsock.dll
      Protocol #5: C:\WINDOWS\system32\rsvpsp.dll
      Protocol #6: C:\WINDOWS\system32\rsvpsp.dll
      Protocol #7: C:\WINDOWS\system32\mswsock.dll
      Protocol #8: C:\WINDOWS\system32\mswsock.dll
      Protocol #9: C:\WINDOWS\system32\mswsock.dll
      Protocol #10: C:\WINDOWS\system32\mswsock.dll
      Protocol #11: C:\WINDOWS\system32\mswsock.dll
      Protocol #12: C:\WINDOWS\system32\mswsock.dll
      Protocol #13: C:\WINDOWS\system32\mswsock.dll
      Protocol #14: C:\WINDOWS\system32\mswsock.dll
      Protocol #15: C:\WINDOWS\system32\mswsock.dll
      Protocol #16: C:\WINDOWS\system32\mswsock.dll
      Protocol #17: C:\WINDOWS\system32\mswsock.dll
      Protocol #18: C:\WINDOWS\system32\mswsock.dll
      Protocol #19: C:\WINDOWS\system32\mswsock.dll
      Protocol #20: C:\WINDOWS\system32\mswsock.dll
      Protocol #21: C:\WINDOWS\system32\mswsock.dll
      Protocol #22: C:\WINDOWS\system32\mswsock.dll
      Protocol #23: C:\WINDOWS\system32\mswsock.dll
      Protocol #24: C:\WINDOWS\system32\mswsock.dll
      Protocol #25: C:\WINDOWS\system32\mswsock.dll
      Protocol #26: C:\WINDOWS\system32\mswsock.dll
      Protocol #27: C:\WINDOWS\system32\mswsock.dll
      Protocol #28: C:\WINDOWS\system32\mswsock.dll
      Protocol #29: C:\WINDOWS\system32\mswsock.dll
      Protocol #30: C:\WINDOWS\system32\mswsock.dll
      Protocol #31: C:\WINDOWS\system32\mswsock.dll

      --------------------------------------------------

      Enumerating Windows NT/2000/XP services

      61883 Unit Device: System32\DRIVERS\61883.sys (manual start)
      A4SII300: System32\drivers\A4SII300.SYS (autostart)
      Microsoft ACPI Driver: System32\DRIVERS\ACPI.sys (system)
      Microsoft Embedded Controller Driver: System32\DRIVERS\ACPIEC.sys (system)
      Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
      AFD Networking Support -ympäristö: \SystemRoot\System32\drivers\afd.sys (system)
      Service for WDM 3D Audio Driver: system32\drivers\ALCXSENS.SYS (manual start)
      Service for Realtek AC97 Audio (WDM): system32\drivers\ALCXWDM.SYS (manual start)
      Hälytys: %SystemRoot%\System32\svchost.exe -k LocalService (disabled)
      Sovelluskerroksen yhdyskäytäväpalvelu: %SystemRoot%\System32\alg.exe (manual start)
      AMD Athlon64 Processor Driver: System32\DRIVERS\AmdK8.sys (system)
      Sovellusten hallinta: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
      1394 ARP -asiakasprotokolla: System32\DRIVERS\arp1394.sys (manual start)
      ASAPIW2K: system32\drivers\ASAPIW2k.sys (manual start)
      ASP.NET-tilapalvelu: %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (manual start)
      RAS Asynchronous Media Driver: System32\DRIVERS\asyncmac.sys (manual start)
      Standardi IDE/ESDI-kiintolevyohjain: System32\DRIVERS\atapi.sys (system)
      Ati HotKey Poller: %SystemRoot%\System32\Ati2evxx.exe (autostart)
      ati2mtag: System32\DRIVERS\ati2mtag.sys (manual start)
      ATM ARP Client -protokolla: System32\DRIVERS\atmarpc.sys (manual start)
      Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
      Audio Stub Driver: System32\DRIVERS\audstub.sys (manual start)
      AVC-laite: System32\DRIVERS\avc.sys (manual start)
      AVG7 Alert Manager Server: C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (autostart)
      AVG7 Kernel: \SystemRoot\System32\Drivers\avg7core.sys (system)
      AVG7 Wrap Driver: \SystemRoot\System32\Drivers\avg7rsw.sys (system)
      AVG7 Rezident Driver: \SystemRoot\System32\Drivers\avg7rsxp.sys (system)
      AVG7 Update Service: C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (autostart)
      AVG Network Redirector: \??\C:\WINDOWS\System32\Drivers\avgtdi.sys (autostart)
      BITS-tausta-ajo (Background Intelligent Transfer Service): %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
      MAC-silta: System32\DRIVERS\bridge.sys (manual start)
      MAC Bridge Miniport: System32\DRIVERS\bridge.sys (manual start)
      Tietokoneiden selaus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
      BUFADPT: \??\C:\WINDOWS\System32\BUFADPT.SYS (autostart)
      Closed Caption Decoder: System32\DRIVERS\CCDECODE.sys (manual start)
      CD-ROM-ohjain: System32\DRIVERS\cdrom.sys (system)
      Indeksointipalvelu: %SystemRoot%\system32\cisvc.exe (manual start)
      Leikekirja: %SystemRoot%\system32\clipsrv.exe (disabled)
      Microsoft ACPI Control Method Battery Driver: System32\DRIVERS\CmBatt.sys (manual start)
      Microsoft Composite Battery Driver: System32\DRIVERS\compbatt.sys (system)
      COM -järjestelmäsovellus: C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
      CONAN: system32\drivers\o2mmb.sys (manual start)
      Salauspalvelut: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
      DCOM-palvelinprosessin käynnistys: %SystemRoot%\system32\svchost -k DcomLaunch (autostart)
      DHCP-asiakas: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
      Levyohjain: System32\DRIVERS\disk.sys (system)
      Loogisen levyn hallinnan valvontapalvelu: %SystemRoot%\System32\dmadmin.exe /com (manual start)
      dmboot: System32\drivers\dmboot.sys (disabled)
      dmio: System32\drivers\dmio.sys (disabled)
      dmload: System32\drivers\dmload.sys (disabled)
      Loogisen levyn hallinta: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
      Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
      DNS-asiakas: %SystemRoot%\System32\svchost.exe -k NetworkService (autostart)
      Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
      %1394\031887&040892.DeviceDesc%: System32\DRIVERS\enum1394.sys (manual start)
      Virheraportointipalvelut: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
      Tapahtumaloki: %SystemRoot%\system32\services.exe (autostart)
      COM -tapahtumajärjestelmä: C:\WINDOWS\System32\svchost.exe -k netsvcs (manual start)
      Nopean käyttäjän vaihdon yhteensopivuus: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
      FltMgr: system32\drivers\fltmgr.sys (system)
      Volume Manager -ohjain: System32\DRIVERS\ftdisk.sys (system)
      GearAspiWDM: system32\drivers\gearaspiwdm.sys (manual start)
      Yleinen paketinmääritys: System32\DRIVERS\msgpc.sys (manual start)
      Ohjeet ja tuotetuki: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
      HID (Human Interface Device) -liittymä: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
      Microsoft HID -luokkaohjain: System32\DRIVERS\hidusb.sys (manual start)
      HTTP: System32\Drivers\HTTP.sys (manual start)
      HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start)
      i8042-näppäimistö ja PS/2-hiiriohjain: System32\DRIVERS\i8042prt.sys (system)
      CD-Burning Filter Driver: System32\DRIVERS\imapi.sys (system)
      CD-levyjen kirjoittamisen IMAPI COM -palvelu: C:\WINDOWS\System32\imapi.exe (manual start)
      Windowsin IPv6-palomuurin ohjain: system32\drivers\ip6fw.sys (manual start)
      IP Traffic Filter Driver: System32\DRIVERS\ipfltdrv.sys (manual start)
      IP in IP Tunnel Driver: System32\DRIVERS\ipinip.sys (manual start)
      IP Network Address Translator: System32\DRIVERS\ipnat.sys (manual start)
      IPSEC-ohjain: System32\DRIVERS\ipsec.sys (system)
      IrDA-protokolla: System32\DRIVERS\irda.sys (autostart)
      IR Enumerator Service: System32\DRIVERS\irenum.sys (manual start)
      Infrapunavalvonta: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
      PnP ISA/EISA -väyläohjain: System32\DRIVERS\isapnp.sys (system)
      Näppäimistön luokkaohjain: System32\DRIVERS\kbdclass.sys (system)
      kbeepm: \??\C:\DOCUME~1\Omistaja\LOCALS~1\Temp\kbeepm.sys (manual start)
      Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
      Palvelin: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
      Työasema: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
      TCP/IP NetBIOS Helper: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
      MbxStby: system32\drivers\MbxStby.sys (manual start)
      Viestinvälitys: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
      NetMeeting etätyöpöydän jakaminen: C:\WINDOWS\System32\mnmsrvc.exe (manual start)
      Unimodem Streaming Filter Device: system32\drivers\MODEMCSA.sys (manual start)
      Hiiren luokkaohjain: System32\DRIVERS\mouclass.sys (system)
      Hiiren HID-ohjain: System32\DRIVERS\mouhid.sys (manual start)
      WebDav Client Redirector: System32\DRIVERS\mrxdav.sys (manual start)
      MRXSMB: System32\DRIVERS\mrxsmb.sys (system)
      Distributed Transaction Coordinator: C:\WINDOWS\System32\msdtc.exe (manual start)
      Microsoft DV Camera and VCR: System32\DRIVERS\msdv.sys (manual start)
      Windows Installer: C:\WINDOWS\System32\msiexec.exe /V (manual start)
      Microsoft Streaming Service -välityspalvelin: system32\drivers\MSKSSRV.sys (manual start)
      Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
      Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
      Microsoft-järjestelmänhallinnan BIOS-ohjain: System32\DRIVERS\mssmbios.sys (manual start)
      Microsoft Streaming Tee/Sink-to-Sink -muunnin: system32\drivers\MSTEE.sys (manual start)
      Mtlmnt5: System32\DRIVERS\Mtlmnt5.sys (manual start)
      Mtlstrm: System32\DRIVERS\Mtlstrm.sys (manual start)
      NABTS/FEC VBI Codec: System32\DRIVERS\NABTSFEC.sys (manual start)
      Microsoft TV/Video Connection: System32\DRIVERS\NdisIP.sys (manual start)
      Remote Access NDIS TAPI Driver: System32\DRIVERS\ndistapi.sys (manual start)
      NDIS Usermode I/O -protokolla: System32\DRIVERS\ndisuio.sys (manual start)
      Remote Access NDIS WAN Driver: System32\DRIVERS\ndiswan.sys (manual start)
      NetBIOS-käyttöliittymä: System32\DRIVERS\netbios.sys (system)
      NetBIOS TCP/IP:n päällä: System32\DRIVERS\netbt.sys (system)
      Verkon DDE: %SystemRoot%\system32\netdde.exe (disabled)
      Verkon DDE DSDM: %SystemRoot%\system32\netdde.exe (disabled)
      Verkkokirjautuminen: %SystemRoot%\System32\lsass.exe (manual start)
      Verkkoyhteydet: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
      1394-verkko-ohjain: System32\DRIVERS\nic1394.sys (manual start)
      NLA-nimiavaruus (Network Location Awareness): %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
      NSC-infrapunalaiteohjain: System32\DRIVERS\nscirda.sys (manual start)
      NT LM -suojaustuen toimittaja: %SystemRoot%\System32\lsass.exe (manual start)
      Siirrettävät tallennusvälineet: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
      NtMtlFax: System32\DRIVERS\NtMtlFax.sys (manual start)
      IPX Traffic Filter Driver: System32\DRIVERS\nwlnkflt.sys (manual start)
      IPX Traffic Forwarder Driver: System32\DRIVERS\nwlnkfwd.sys (manual start)
      NWLink IPX/SPX/NetBIOS -yhteensopiva kuljetusprotokolla: System32\DRIVERS\nwlnkipx.sys (autostart)
      NWLink NetBIOS: System32\DRIVERS\nwlnknb.sys (autostart)
      NWLink SPX/SPXII -protokolla: System32\DRIVERS\nwlnkspx.sys (autostart)
      SAP-agentti: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
      Texas Instruments OHCI Compliant IEEE 1394 Host Controller: System32\DRIVERS\ohci1394.sys (system)
      OLYMPUS Digital Camera: System32\Drivers\olcamudp.sys (manual start)
      Rinnakkaisporttiohjain: System32\DRIVERS\parport.sys (manual start)
      PCI Bus Driver: System32\DRIVERS\pci.sys (system)
      PCIIde: System32\DRIVERS\pciide.sys (system)
      Pcmcia: System32\DRIVERS\pcmcia.sys (system)
      PADUS ASPI SHELL: system32\drivers\pfc.sys (manual start)
      Plug and Play: %SystemRoot%\system32\services.exe (autostart)
      IPSEC-palvelut: %SystemRoot%\System32\lsass.exe (autostart)
      WAN Miniport (PPTP): System32\DRIVERS\raspptp.sys (manual start)
      Processor Driver: System32\DRIVERS\processr.sys (system)
      Suojattu tallennuspaikka: %SystemRoot%\system32\lsass.exe (autostart)
      QoS-paketinajoitus: System32\DRIVERS\psched.sys (manual start)
      Direct Parallel Link Driver: System32\DRIVERS\ptilink.sys (manual start)
      PxHelp20: System32\DRIVERS\PxHelp20.sys (system)
      Logitech QuickCam Express: System32\DRIVERS\OVCD.sys (manual start)
      Remote Access Auto Connection -ohjain: System32\DRIVERS\rasacd.sys (system)
      Remote Access Auto Connection -hallinta: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
      WAN Miniport (IrDA): System32\DRIVERS\rasirda.sys (manual start)
      WAN Miniport (L2TP): System32\DRIVERS\rasl2tp.sys (manual start)
      Etäkäytön (RAS) yhteyksienhallinta: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
      Remote Access PPPOE Driver: System32\DRIVERS\raspppoe.sys (manual start)
      Suora rinnakkainen: System32\DRIVERS\raspti.sys (manual start)
      Rdbss: System32\DRIVERS\rdbss.sys (system)
      RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
      Etätyöpöydän ohjeen istunnonhallinta: C:\WINDOWS\system32\sessmgr.exe (manual start)
      RecAgent: System32\DRIVERS\RecAgent.sys (system)
      Digital CD Audio Playback Filter Driver: System32\DRIVERS\redbook.sys (system)
      Reititys ja etäkäyttö: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
      Etäproseduurikutsujen (RPC) paikannin: %SystemRoot%\System32\locator.exe (manual start)
      Etäproseduurikutsu (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
      QoS RSVP: %SystemRoot%\System32\rsvp.exe (manual start)
      RT2500 Wireless Driver: System32\DRIVERS\RT2500.sys (manual start)
      Käyttöoikeustilien hallinta: %SystemRoot%\system32\lsass.exe (autostart)
      Älykortti: %SystemRoot%\System32\SCardSvr.exe (manual start)
      Tehtävien ajoitus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
      Secdrv: System32\DRIVERS\secdrv.sys (autostart)
      Toissijainen kirjautuminen: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
      Järjestelmätapahtuman ilmoitus: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
      Windowsin palomuuri / Internet-yhteyden jakaminen (ICS): %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
      Käyttöliittymän laitteistotunnistus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
      SiS 163 usb Wireless LAN Adapter Driver: system32\DRIVERS\sis163u.sys (manual start)
      SiS AGP Filter: System32\DRIVERS\SISAGPX.sys (system)
      SiS PCI Fast Ethernet Adapter Driver: System32\DRIVERS\sisnic.sys (manual start)
      BDA Slip De-Framer: System32\DRIVERS\SLIP.sys (manual start)
      SmartLink AMR_PCI Driver: System32\DRIVERS\slntamr.sys (manual start)
      SlNtHal: System32\DRIVERS\Slnthal.sys (manual start)
      SmartLinkService: slserv.exe (autostart)
      SlWdmSup: System32\DRIVERS\SlWdmSup.sys (manual start)
      Sygate Personal Firewall: C:\Program Files\Sygate\SPF\smc.exe (autostart)
      Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
      Taustatulostusohjain: %SystemRoot%\system32\spoolsv.exe (autostart)
      Järjestelmän palautussuodatin -ohjain: System32\DRIVERS\sr.sys (system)
      Järjestelmän palauttaminen -palvelu: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
      Srv: System32\DRIVERS\srv.sys (manual start)
      SSDP-palvelu (Simple Service Discovery Protocol): %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
      WIA (Windows Image Acquisition): %SystemRoot%\System32\svchost.exe -k imgsvc (autostart)
      BDA IPSink: System32\DRIVERS\StreamIP.sys (manual start)
      Ohjelmistoväyläohjain: System32\DRIVERS\swenum.sys (manual start)
      Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
      MS Software Shadow Copy Provider: C:\WINDOWS\System32\dllhost.exe /Processid:{C9B7B653-CA37-4810-B8AC-6F58CBA0B2B2} (manual start)
      Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
      Resurssilokit ja -hälytykset: %SystemRoot%\system32\smlogsvc.exe (manual start)
      Puhelin: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
      TCP/IP-protokollaohjain: System32\DRIVERS\tcpip.sys (system)
      Teefer for NT: SYSTEM32\Drivers\Teefer.sys (system)
      Päätelaiteohjain: System32\DRIVERS\termdd.sys (system)
      Päätepalvelut: %SystemRoot%\System32\svchost -k DComLaunch (manual start)
      Teemat: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
      Tiedostolinkkijäljityksen asiakas: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
      Windows User Mode Driver Framework: C:\WINDOWS\System32\wdfmgr.exe (autostart)
      Microcode Update -ohjain: System32\DRIVERS\update.sys (manual start)
      Universal Plug & Play -laiteisäntä: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
      UPS: %SystemRoot%\System32\ups.exe (manual start)
      Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: System32\DRIVERS\usbehci.sys (manual start)
      USB2 Enabled Hub: System32\DRIVERS\usbhub.sys (manual start)
      Microsoft USB Open Host Controller Miniport Driver: System32\DRIVERS\usbohci.sys (manual start)
      USB Scanner Driver: System32\DRIVERS\usbscan.sys (manual start)
      USB-massamuistiohjain: System32\DRIVERS\USBSTOR.SYS (manual start)
      VGA-näytönohjain: \SystemRoot\System32\drivers\vga.sys (system)
      TrueVector Internet Monitor: C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service (autostart)
      Aseman tilannevedos: %SystemRoot%\System32\vssvc.exe (manual start)
      Windows Time: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
      Remote Access IP ARP Driver: System32\DRIVERS\wanarp.sys (manual start)
      Windows CE USB Serial Host Driver: System32\DRIVERS\wceusbsh.sys (manual start)
      Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
      WebClient: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
      SyGate for NT, wg3n: \SystemRoot\SYSTEM32\Drivers\wg3n.sys (autostart)
      SyGate for NT, wg4n: \SystemRoot\SYSTEM32\Drivers\wg4n.sys (autostart)
      SyGate for NT, wg5n: \SystemRoot\SYSTEM32\Drivers\wg5n.sys (autostart)
      SyGate for NT, wg6n: \SystemRoot\SYSTEM32\Drivers\wg6n.sys (autostart)
      WMI-palvelu (Windows Management Instrumentation): %systemroot%\system32\svchost.exe -k netsvcs (autostart)
      Portable Media Serial Number Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
      WMI resurssisovitin: C:\WINDOWS\System32\wbem\wmiapsrv.exe (manual start)
      wpsdrvnt: \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (system)
      Tietoturvakeskus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
      World Standard Teletext Codec: System32\DRIVERS\WSTCODEC.SYS (manual start)
      Automaattiset päivitykset: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
      Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
      Verkon käyttöönottopalvelu: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)


      --------------------------------------------------

      Enumerating Windows NT logon/logoff scripts:
      *No scripts set to run*

      Windows NT checkdisk command:
      BootExecute =

      Windows NT 'Wininit.ini':
      PendingFileRenameOperations: *Registry value not found*

      --------------------------------------------------

      Enumerating ShellServiceObjectDelayLoad items:

      PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
      CDBurn: C:\WINDOWS\system32\SHELL32.dll
      WebCheck: C:\WINDOWS\System32\webcheck.dll
      SysTray: C:\WINDOWS\System32\stobject.dll

      --------------------------------------------------
      Autorun entries from Registry:
      HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

      *Registry key not found*

      --------------------------------------------------

      Autorun entries from Registry:
      HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

      *Registry key not found*

      --------------------------------------------------

      End of report, 36 101 bytes
      Report generated in 0,109 seconds

      Command line options:
      /verbose - to add additional info on each section
      /complete - to include empty sections and unsuspicious data
      /full - to include several rarely-important sections
      /force9x - to include Win9x-only startups even if running on WinNT
      /forcent - to include WinNT-only startups even if running on Win9x
      /forceall - to include all Win9x and WinNT startups, regardless of platform
      /history - to list version history only

      • Juu

        Hyvä on.


      • mutta

    Ketjusta on poistettu 0 sääntöjenvastaista viestiä.

    Luetuimmat keskustelut

    1. Kanki kovana; ei tiedä pornovideoista mitään

      Kaikkosen erityis­avustajan asunnossa kuvattiin pornoa. Väittää ettei tiedä asiasta yhtään mitään. https://www.is.fi/po
      Maailman menoa
      121
      6030
    2. Halaisin sua mies

      Jos voisin 💗
      Ikävä
      29
      2120
    3. Onkohan meillä kummallakin joku pakkomielle toisiimme

      Vähän luulen että on..
      Ikävä
      177
      1952
    4. Mitä tämä on

      Ajatella, olen viimeksi nähnyt sinua melkein vuosi sitten ohimennen. Ja silloinkin sinä välttelit minua. En ole kuullut
      Tunteet
      10
      1123
    5. Ei monet elä kuin alle 60 v, mikä vaikuttaa?

      gulp, gulp.. Juice Leskinen eli 56 vuotta. Matti Nykänen eli 55 vuotta. Topi Sorsakoski eli 58 vuotta.
      Maailman menoa
      66
      1114
    6. Hyvää yötä kaivatulleni

      En pysty tekemään kokemaan mitään sielussa tuntuvaa, syvää, vaikuttavaa, ilman että rinnastan sen sinuun. Niin kävi tänä
      Tunteet
      24
      997
    7. Olen valmis

      Kohtaamaan sinut tänä kesänä, jos sellainen sattuma osuu kohdalleni.
      Ikävä
      73
      987
    8. Nyt on konstit vähänä.

      Nimittäin tuulivoiman vastustajilla, kun pitää perättömiä ilmiantoja tehdä. Alkaa olla koko vastustajien sakki leimattu,
      Kiuruvesi
      24
      902
    9. Tilinpäätösvaltuusto 27.5

      Samalla viimeinen kokous ennen uudenvaltuustokauden alkamista. Vanhat antavat itselleen erinomaiset arvosanat, ja siirty
      Pyhäjärvi
      42
      897
    10. Hevoset ajoteillä Karhulanvaaralla

      Minkä ihmeen takia osaamattomat ihmiset tuovat hevosia ajoteille ja pyöräteille? Eilen oli kolari lähellä tämän takia. I
      Suomussalmi
      12
      765
    Aihe