auttakaa

kalamies69

Sain eilen mainoksen spyware virustorjuntaohjelmasta, poistin sen ja sen jälkeen hyökkäsi W32/Nsag.B virus, sain poistettua luultavasti sen ja päivitin uudet tietoturvapäivitykset.
Nyt kuiten kin usein alapalkkiin tulee keltainen kolmio joka kehoittaa avaamaa ja lataamaan spyware ohjelman, poisto ei auta, edes ohjauspaneelin kautta, sekä saan pelimainoksia sillointällöin.Minulla on haittaohjelmien poistoohjelma sekä msn työkalut missä pop-up esto.
Mitä voin tehdä, että saan mainokset ja spywaren poistettua.
kehotettii pistämää logi johonkin vaan en tiedä näist asioista mitään, saiskos rautalangasta vääntämällä apua

18

3386

    Vastaukset

    Anonyymi (Kirjaudu / Rekisteröidy)
    5000
    • on jo
      • moka

        katsoin väärin palstan.
        Olithan jo oikealla palstalla, sori!


    • Juu
      • kalamies69

        Logfile of HijackThis v1.99.1
        Scan saved at 17:23:03, on 21.10.2005
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\nvctrl.exe
        C:\WINDOWS\system32\mssearchnet.exe
        C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
        C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
        C:\WINDOWS\system32\MMTray.exe
        C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
        C:\Program Files\AVPersonal\AVSched32.EXE
        C:\windows\system32\dxvid.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\AVPersonal\AVGNT.EXE
        C:\Program Files\Skype\Phone\Skype.exe
        C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fi-fi\bin\WindowsSearch.exe
        C:\Program Files\MRU-Blaster\scheduler.exe
        C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fi-fi\bin\WindowsSearchIndexer.exe
        C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE
        C:\Program Files\AVPersonal\AVWUPSRV.EXE
        C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
        C:\WINDOWS\System32\nvsvc32.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\ZoneLabs\vsmon.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\DOCUMENTS AND SETTINGS\OMISTAJA\TYÖPÖYTÄ\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fi/0SEFIFI/SAOS01?FORM=TOOLBR
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.fi/0SEFIFI/SAOS01?FORM=TOOLBR
        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fi/0SEFIFI/SAOS01?FORM=TOOLBR
        O2 - BHO: HomepageBHO - {3bf1f86f-b1a8-489b-8d8b-43781d51411f} - C:\WINDOWS\system32\hp6DDD.tmp
        O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll (file missing)
        O3 - Toolbar: MSN Search -työkalurivi - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fi-fi\msntb.dll
        O3 - Toolbar: SecurityToolbar - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - C:\Program Files\Security Toolbar\Security Toolbar.dll
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
        O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
        O4 - HKLM\..\Run: [MMTray] MMTray.exe
        O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O5 "LPT1:" /M "Stylus Photo RX420"
        O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series (Kopioi 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P42 "EPSON Stylus Photo RX420 Series (Kopioi 1)" /O6 "USB001" /M "Stylus Photo RX420"
        O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSched32.EXE /min
        O4 - HKLM\..\Run: [dxvid] c:\windows\system32\dxvid.exe /nocomm
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [P.S.Guard] C:\Program Files\P.S.Guard\PSGuard.exe
        O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
        O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
        O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot
        O4 - Startup: MRU-Blaster Scheduler.lnk = C:\Program Files\MRU-Blaster\scheduler.exe
        O4 - Startup: MRU-Blaster Silent Clean.lnk = C:\Program Files\MRU-Blaster\mrublaster.exe
        O4 - Global Startup: Windows-työpöytähaku.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fi-fi\bin\WindowsSearch.exe
        O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fi-fi\msntb.dll/search.htm
        O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZCfox000
        O8 - Extra context menu item: Avaa uuteen etuvälilehteen - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fi-fi\msntabres.dll/230?9dbfbe1a8c6845e28f196f336cf1862d
        O8 - Extra context menu item: Avaa uuteen taustavälilehteen - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fi-fi\msntabres.dll/229?9dbfbe1a8c6845e28f196f336cf1862d
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
        O16 - DPF: {F72BC3F0-6C20-4793-9DDA-258589D8A907} - http://akamai.downloadv3.com/binaries/IA/netslv32_EN_XP.cab
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
        O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
        O23 - Service: AntiVir Service (AntiVirService) - H BEDV Datentechnik GmbH - C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE
        O23 - Service: AntiVir Update (AVWUpSrv) - H BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
        O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


      • Juu
        kalamies69 kirjoitti:

        Logfile of HijackThis v1.99.1
        Scan saved at 17:23:03, on 21.10.2005
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\nvctrl.exe
        C:\WINDOWS\system32\mssearchnet.exe
        C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
        C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
        C:\WINDOWS\system32\MMTray.exe
        C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
        C:\Program Files\AVPersonal\AVSched32.EXE
        C:\windows\system32\dxvid.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\AVPersonal\AVGNT.EXE
        C:\Program Files\Skype\Phone\Skype.exe
        C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fi-fi\bin\WindowsSearch.exe
        C:\Program Files\MRU-Blaster\scheduler.exe
        C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fi-fi\bin\WindowsSearchIndexer.exe
        C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE
        C:\Program Files\AVPersonal\AVWUPSRV.EXE
        C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
        C:\WINDOWS\System32\nvsvc32.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\ZoneLabs\vsmon.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\DOCUMENTS AND SETTINGS\OMISTAJA\TYÖPÖYTÄ\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fi/0SEFIFI/SAOS01?FORM=TOOLBR
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.fi/0SEFIFI/SAOS01?FORM=TOOLBR
        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fi/0SEFIFI/SAOS01?FORM=TOOLBR
        O2 - BHO: HomepageBHO - {3bf1f86f-b1a8-489b-8d8b-43781d51411f} - C:\WINDOWS\system32\hp6DDD.tmp
        O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll (file missing)
        O3 - Toolbar: MSN Search -työkalurivi - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fi-fi\msntb.dll
        O3 - Toolbar: SecurityToolbar - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - C:\Program Files\Security Toolbar\Security Toolbar.dll
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
        O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
        O4 - HKLM\..\Run: [MMTray] MMTray.exe
        O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O5 "LPT1:" /M "Stylus Photo RX420"
        O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series (Kopioi 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P42 "EPSON Stylus Photo RX420 Series (Kopioi 1)" /O6 "USB001" /M "Stylus Photo RX420"
        O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSched32.EXE /min
        O4 - HKLM\..\Run: [dxvid] c:\windows\system32\dxvid.exe /nocomm
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [P.S.Guard] C:\Program Files\P.S.Guard\PSGuard.exe
        O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
        O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
        O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot
        O4 - Startup: MRU-Blaster Scheduler.lnk = C:\Program Files\MRU-Blaster\scheduler.exe
        O4 - Startup: MRU-Blaster Silent Clean.lnk = C:\Program Files\MRU-Blaster\mrublaster.exe
        O4 - Global Startup: Windows-työpöytähaku.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fi-fi\bin\WindowsSearch.exe
        O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fi-fi\msntb.dll/search.htm
        O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZCfox000
        O8 - Extra context menu item: Avaa uuteen etuvälilehteen - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fi-fi\msntabres.dll/230?9dbfbe1a8c6845e28f196f336cf1862d
        O8 - Extra context menu item: Avaa uuteen taustavälilehteen - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fi-fi\msntabres.dll/229?9dbfbe1a8c6845e28f196f336cf1862d
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
        O16 - DPF: {F72BC3F0-6C20-4793-9DDA-258589D8A907} - http://akamai.downloadv3.com/binaries/IA/netslv32_EN_XP.cab
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
        O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
        O23 - Service: AntiVir Service (AntiVirService) - H BEDV Datentechnik GmbH - C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE
        O23 - Service: AntiVir Update (AVWUpSrv) - H BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
        O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

        Scannaa tuo tuolla ja ilmoita tulos,niin jatketaan

        C:\Program Files\Security Toolbar\Security Toolbar.dll

        http://virusscan.jotti.org/

        siis scannaa tuo Security Toolbar.dll tuolla linkissä


      • kalamies69
        Juu kirjoitti:

        Scannaa tuo tuolla ja ilmoita tulos,niin jatketaan

        C:\Program Files\Security Toolbar\Security Toolbar.dll

        http://virusscan.jotti.org/

        siis scannaa tuo Security Toolbar.dll tuolla linkissä

        anteeksi tyhmyyteni vaan pitikö tulos skannata vai avata tuo virusscan.jotti, eli selitätkö umpiuunolle tarkemmin


      • Juu
        kalamies69 kirjoitti:

        anteeksi tyhmyyteni vaan pitikö tulos skannata vai avata tuo virusscan.jotti, eli selitätkö umpiuunolle tarkemmin

        Avaa se linkki ja klikkaa selaa.
        Sitte kopioi ja liitä tuo rivi sinne kenttään

        C:\Program Files\Security Toolbar\Security Toolbar.dll

        aukase se sinne ja klikkaa Submit ja oota tulosta ja kopioi tänne.


      • kalamies69
        Juu kirjoitti:

        Avaa se linkki ja klikkaa selaa.
        Sitte kopioi ja liitä tuo rivi sinne kenttään

        C:\Program Files\Security Toolbar\Security Toolbar.dll

        aukase se sinne ja klikkaa Submit ja oota tulosta ja kopioi tänne.

        Jotti's malware scan 2.99-TRANSITION_TO_3.00
        File to upload & scan: Virus

        Service
        Service load:
        0% 100%
        File: hijackthis.log
        Status:
        OK
        MD5 6c18fe731d488bbc7ffb6941ac2c29fa
        Packers detected:
        -
        Scanner results
        AntiVir
        Found nothing
        ArcaVir
        Found nothing
        Avast
        Found nothing
        AVG Antivirus
        Found nothing
        BitDefender
        Found nothing
        ClamAV
        Found nothing
        Dr.Web
        Found nothing
        F-Prot Antivirus
        Found nothing
        Fortinet
        Found nothing
        Kaspersky Anti-Virus
        Found nothing
        NOD32
        Found nothing
        Norman Virus Control
        Found nothing
        UNA
        Found nothing
        VBA32
        Found nothing

        Powered by
        images/antivir.png images/arcabit.png images/avast.png images/avg.gif images/bitdefender.png images/clamav-logo1.png images/drweb.gif images/f-prot.png images/fortinet.gif images/kaspersky.png images/nod32.gif images/norman.png images/una_logo.jpg images/vba32.png
        Disclaimer
        This service is by no means 100% safe. If this scanner says 'OK', it does not necessarily mean the file is clean. There could be a whole new virus on the loose. NEVER EVER rely on one single product only, not even this service, even though it utilizes several products. Therefore, We cannot and will not be held responsible for any damage caused by results presented by this non-profit online service.

        Also, we are aware of the implications of a setup like this. We are sure this whole thing is by no means scientifically correct, since this is a fully automated service (although manual correction is possible). We are aware, in spite of efforts to proactively counter these, false positives might occur, for example. We do not consider this a very big issue, so please do not e-mail us about it. This is a simple online scan service, not the university of Wichita.

        Scanning can take a while, since several scanners are being used, plus the fact some scanners use very high levels of (time consuming) heuristics. Scanners used are Linux versions, differences with Windows scanners may or may not occur. Another note: some scanners will only report one virus when scanning archives with multiple pieces of malware.

        Virus definitions are updated every hour. There is a 15Mb limit per file. Please refrain from uploading tons of hex-edited or repacked variants of the same sample.

        Please do not ask for viruses uploaded here, unless you work for an anti-virus vendor. They are not for trade. This is a legitimate service, not a VX site. Viruses uploaded here will be distributed to antivirus vendors without exception.

        Sponsored by donations (in random order) from: Stormbyte Technologies LLC, The ClamAV project, James Love, Gideon Pertzov, Malcolm Murray, Nigel Thomas, Wendy Dickerson, Anthony Midmore, "ethereal", Mark Rubins, Steve S., Eric Johansen, Eric Schechter, Paul Bokel, Wilders Security, Wilfried Lilie, Prevx, SonicWALL, Lance Mueller, and some people who prefer to remain anonymous... many thanks to all!

        Statistics
        Last file scanned at least one scanner reported something about: winsecure.exe, detected by:

        Scanner Malware name
        AntiVir Backdoor-Server/Iroffer.1227
        ArcaVir Trojan.Iroffer.1227
        Avast X
        AVG Antivirus BackDoor.Small.23.AC
        BitDefender Backdoor.Iroffer.1227.D
        ClamAV X
        Dr.Web X
        F-Prot Antivirus X
        Fortinet W32/Iroffer
        Kaspersky Anti-Virus Backdoor.Win32.Iroffer.1227
        NOD32 a variant of Win32/Iroffer
        Norman Virus Control X
        UNA Backdoor.Iroffer.1227
        VBA32 Backdoor.Win32.Iroffer.1227

        You're free to (mis)interpret these automated, flawed statistics at your own discretion. For antivirus comparisons, visit AV comparatives
        We are not affiliated with any third parties that conduct tests using this service.


      • kalamies69
        kalamies69 kirjoitti:

        Jotti's malware scan 2.99-TRANSITION_TO_3.00
        File to upload & scan: Virus

        Service
        Service load:
        0% 100%
        File: hijackthis.log
        Status:
        OK
        MD5 6c18fe731d488bbc7ffb6941ac2c29fa
        Packers detected:
        -
        Scanner results
        AntiVir
        Found nothing
        ArcaVir
        Found nothing
        Avast
        Found nothing
        AVG Antivirus
        Found nothing
        BitDefender
        Found nothing
        ClamAV
        Found nothing
        Dr.Web
        Found nothing
        F-Prot Antivirus
        Found nothing
        Fortinet
        Found nothing
        Kaspersky Anti-Virus
        Found nothing
        NOD32
        Found nothing
        Norman Virus Control
        Found nothing
        UNA
        Found nothing
        VBA32
        Found nothing

        Powered by
        images/antivir.png images/arcabit.png images/avast.png images/avg.gif images/bitdefender.png images/clamav-logo1.png images/drweb.gif images/f-prot.png images/fortinet.gif images/kaspersky.png images/nod32.gif images/norman.png images/una_logo.jpg images/vba32.png
        Disclaimer
        This service is by no means 100% safe. If this scanner says 'OK', it does not necessarily mean the file is clean. There could be a whole new virus on the loose. NEVER EVER rely on one single product only, not even this service, even though it utilizes several products. Therefore, We cannot and will not be held responsible for any damage caused by results presented by this non-profit online service.

        Also, we are aware of the implications of a setup like this. We are sure this whole thing is by no means scientifically correct, since this is a fully automated service (although manual correction is possible). We are aware, in spite of efforts to proactively counter these, false positives might occur, for example. We do not consider this a very big issue, so please do not e-mail us about it. This is a simple online scan service, not the university of Wichita.

        Scanning can take a while, since several scanners are being used, plus the fact some scanners use very high levels of (time consuming) heuristics. Scanners used are Linux versions, differences with Windows scanners may or may not occur. Another note: some scanners will only report one virus when scanning archives with multiple pieces of malware.

        Virus definitions are updated every hour. There is a 15Mb limit per file. Please refrain from uploading tons of hex-edited or repacked variants of the same sample.

        Please do not ask for viruses uploaded here, unless you work for an anti-virus vendor. They are not for trade. This is a legitimate service, not a VX site. Viruses uploaded here will be distributed to antivirus vendors without exception.

        Sponsored by donations (in random order) from: Stormbyte Technologies LLC, The ClamAV project, James Love, Gideon Pertzov, Malcolm Murray, Nigel Thomas, Wendy Dickerson, Anthony Midmore, "ethereal", Mark Rubins, Steve S., Eric Johansen, Eric Schechter, Paul Bokel, Wilders Security, Wilfried Lilie, Prevx, SonicWALL, Lance Mueller, and some people who prefer to remain anonymous... many thanks to all!

        Statistics
        Last file scanned at least one scanner reported something about: winsecure.exe, detected by:

        Scanner Malware name
        AntiVir Backdoor-Server/Iroffer.1227
        ArcaVir Trojan.Iroffer.1227
        Avast X
        AVG Antivirus BackDoor.Small.23.AC
        BitDefender Backdoor.Iroffer.1227.D
        ClamAV X
        Dr.Web X
        F-Prot Antivirus X
        Fortinet W32/Iroffer
        Kaspersky Anti-Virus Backdoor.Win32.Iroffer.1227
        NOD32 a variant of Win32/Iroffer
        Norman Virus Control X
        UNA Backdoor.Iroffer.1227
        VBA32 Backdoor.Win32.Iroffer.1227

        You're free to (mis)interpret these automated, flawed statistics at your own discretion. For antivirus comparisons, visit AV comparatives
        We are not affiliated with any third parties that conduct tests using this service.

        toivottavsati saat selkoa


      • kalamies69
        kalamies69 kirjoitti:

        toivottavsati saat selkoa

        siellä sakannaussivulla oli joku rekisterin puhdistusohjelma, voisko siint olla apuu


      • Juu
        kalamies69 kirjoitti:

        Jotti's malware scan 2.99-TRANSITION_TO_3.00
        File to upload & scan: Virus

        Service
        Service load:
        0% 100%
        File: hijackthis.log
        Status:
        OK
        MD5 6c18fe731d488bbc7ffb6941ac2c29fa
        Packers detected:
        -
        Scanner results
        AntiVir
        Found nothing
        ArcaVir
        Found nothing
        Avast
        Found nothing
        AVG Antivirus
        Found nothing
        BitDefender
        Found nothing
        ClamAV
        Found nothing
        Dr.Web
        Found nothing
        F-Prot Antivirus
        Found nothing
        Fortinet
        Found nothing
        Kaspersky Anti-Virus
        Found nothing
        NOD32
        Found nothing
        Norman Virus Control
        Found nothing
        UNA
        Found nothing
        VBA32
        Found nothing

        Powered by
        images/antivir.png images/arcabit.png images/avast.png images/avg.gif images/bitdefender.png images/clamav-logo1.png images/drweb.gif images/f-prot.png images/fortinet.gif images/kaspersky.png images/nod32.gif images/norman.png images/una_logo.jpg images/vba32.png
        Disclaimer
        This service is by no means 100% safe. If this scanner says 'OK', it does not necessarily mean the file is clean. There could be a whole new virus on the loose. NEVER EVER rely on one single product only, not even this service, even though it utilizes several products. Therefore, We cannot and will not be held responsible for any damage caused by results presented by this non-profit online service.

        Also, we are aware of the implications of a setup like this. We are sure this whole thing is by no means scientifically correct, since this is a fully automated service (although manual correction is possible). We are aware, in spite of efforts to proactively counter these, false positives might occur, for example. We do not consider this a very big issue, so please do not e-mail us about it. This is a simple online scan service, not the university of Wichita.

        Scanning can take a while, since several scanners are being used, plus the fact some scanners use very high levels of (time consuming) heuristics. Scanners used are Linux versions, differences with Windows scanners may or may not occur. Another note: some scanners will only report one virus when scanning archives with multiple pieces of malware.

        Virus definitions are updated every hour. There is a 15Mb limit per file. Please refrain from uploading tons of hex-edited or repacked variants of the same sample.

        Please do not ask for viruses uploaded here, unless you work for an anti-virus vendor. They are not for trade. This is a legitimate service, not a VX site. Viruses uploaded here will be distributed to antivirus vendors without exception.

        Sponsored by donations (in random order) from: Stormbyte Technologies LLC, The ClamAV project, James Love, Gideon Pertzov, Malcolm Murray, Nigel Thomas, Wendy Dickerson, Anthony Midmore, "ethereal", Mark Rubins, Steve S., Eric Johansen, Eric Schechter, Paul Bokel, Wilders Security, Wilfried Lilie, Prevx, SonicWALL, Lance Mueller, and some people who prefer to remain anonymous... many thanks to all!

        Statistics
        Last file scanned at least one scanner reported something about: winsecure.exe, detected by:

        Scanner Malware name
        AntiVir Backdoor-Server/Iroffer.1227
        ArcaVir Trojan.Iroffer.1227
        Avast X
        AVG Antivirus BackDoor.Small.23.AC
        BitDefender Backdoor.Iroffer.1227.D
        ClamAV X
        Dr.Web X
        F-Prot Antivirus X
        Fortinet W32/Iroffer
        Kaspersky Anti-Virus Backdoor.Win32.Iroffer.1227
        NOD32 a variant of Win32/Iroffer
        Norman Virus Control X
        UNA Backdoor.Iroffer.1227
        VBA32 Backdoor.Win32.Iroffer.1227

        You're free to (mis)interpret these automated, flawed statistics at your own discretion. For antivirus comparisons, visit AV comparatives
        We are not affiliated with any third parties that conduct tests using this service.

        Siis sää scannasit oman Hijack login siellä

        File: hijackthis.log

        Tee noin:

        Avaa se linkki ja klikkaa selaa.
        Sitte kopioi ja liitä tuo rivi sinne kenttään

        C:\Program Files\Security Toolbar\Security Toolbar.dll

        aukase se sinne ja klikkaa Submit ja oota tulosta ja kopioi tänne.


      • kalamies69
        Juu kirjoitti:

        Siis sää scannasit oman Hijack login siellä

        File: hijackthis.log

        Tee noin:

        Avaa se linkki ja klikkaa selaa.
        Sitte kopioi ja liitä tuo rivi sinne kenttään

        C:\Program Files\Security Toolbar\Security Toolbar.dll

        aukase se sinne ja klikkaa Submit ja oota tulosta ja kopioi tänne.

        avasin ja skannsasin ja tuloksen minkä sain ja tänne laitoin , sen skannasin siellä ja sen tuloksen laitoin toho


      • kalamies69
        Juu kirjoitti:

        Siis sää scannasit oman Hijack login siellä

        File: hijackthis.log

        Tee noin:

        Avaa se linkki ja klikkaa selaa.
        Sitte kopioi ja liitä tuo rivi sinne kenttään

        C:\Program Files\Security Toolbar\Security Toolbar.dll

        aukase se sinne ja klikkaa Submit ja oota tulosta ja kopioi tänne.

        eli skannasin tuon File: hijackthis.log siellä ja tuloksen laitoin sen mukaan kaikki olisi ok


      • Juu
        kalamies69 kirjoitti:

        eli skannasin tuon File: hijackthis.log siellä ja tuloksen laitoin sen mukaan kaikki olisi ok

        Scannasikko ton siellä linkissä

        C:\Program Files\Security Toolbar\Security Toolbar.dll

        > Security Toolbar.dll


      • kalamies69
        Juu kirjoitti:

        Scannasikko ton siellä linkissä

        C:\Program Files\Security Toolbar\Security Toolbar.dll

        > Security Toolbar.dll

        siis avasin
        http://virusscan.jotti.org/
        ja seillä ylhäällä etsin lokeroon sen tuloksen muistista ja painoin submit ja sen tuloksen laitoin toho


      • Juu
        kalamies69 kirjoitti:

        Logfile of HijackThis v1.99.1
        Scan saved at 17:23:03, on 21.10.2005
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\nvctrl.exe
        C:\WINDOWS\system32\mssearchnet.exe
        C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
        C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
        C:\WINDOWS\system32\MMTray.exe
        C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
        C:\Program Files\AVPersonal\AVSched32.EXE
        C:\windows\system32\dxvid.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\AVPersonal\AVGNT.EXE
        C:\Program Files\Skype\Phone\Skype.exe
        C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fi-fi\bin\WindowsSearch.exe
        C:\Program Files\MRU-Blaster\scheduler.exe
        C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fi-fi\bin\WindowsSearchIndexer.exe
        C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE
        C:\Program Files\AVPersonal\AVWUPSRV.EXE
        C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
        C:\WINDOWS\System32\nvsvc32.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\ZoneLabs\vsmon.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\DOCUMENTS AND SETTINGS\OMISTAJA\TYÖPÖYTÄ\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fi/0SEFIFI/SAOS01?FORM=TOOLBR
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.fi/0SEFIFI/SAOS01?FORM=TOOLBR
        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fi/0SEFIFI/SAOS01?FORM=TOOLBR
        O2 - BHO: HomepageBHO - {3bf1f86f-b1a8-489b-8d8b-43781d51411f} - C:\WINDOWS\system32\hp6DDD.tmp
        O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll (file missing)
        O3 - Toolbar: MSN Search -työkalurivi - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fi-fi\msntb.dll
        O3 - Toolbar: SecurityToolbar - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - C:\Program Files\Security Toolbar\Security Toolbar.dll
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
        O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
        O4 - HKLM\..\Run: [MMTray] MMTray.exe
        O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O5 "LPT1:" /M "Stylus Photo RX420"
        O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series (Kopioi 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P42 "EPSON Stylus Photo RX420 Series (Kopioi 1)" /O6 "USB001" /M "Stylus Photo RX420"
        O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSched32.EXE /min
        O4 - HKLM\..\Run: [dxvid] c:\windows\system32\dxvid.exe /nocomm
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [P.S.Guard] C:\Program Files\P.S.Guard\PSGuard.exe
        O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
        O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
        O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot
        O4 - Startup: MRU-Blaster Scheduler.lnk = C:\Program Files\MRU-Blaster\scheduler.exe
        O4 - Startup: MRU-Blaster Silent Clean.lnk = C:\Program Files\MRU-Blaster\mrublaster.exe
        O4 - Global Startup: Windows-työpöytähaku.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fi-fi\bin\WindowsSearch.exe
        O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fi-fi\msntb.dll/search.htm
        O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZCfox000
        O8 - Extra context menu item: Avaa uuteen etuvälilehteen - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fi-fi\msntabres.dll/230?9dbfbe1a8c6845e28f196f336cf1862d
        O8 - Extra context menu item: Avaa uuteen taustavälilehteen - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fi-fi\msntabres.dll/229?9dbfbe1a8c6845e28f196f336cf1862d
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
        O16 - DPF: {F72BC3F0-6C20-4793-9DDA-258589D8A907} - http://akamai.downloadv3.com/binaries/IA/netslv32_EN_XP.cab
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
        O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
        O23 - Service: AntiVir Service (AntiVirService) - H BEDV Datentechnik GmbH - C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE
        O23 - Service: AntiVir Update (AVWUpSrv) - H BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
        O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

        Siirrä ensin se Hijackki omaan kansioon tonne
        C:\HjT\HijackThis.exe

        Poista Lisää/Poista paneelista jos näkyy

        Spyware Cleaner

        Ota tuo smitrem ja säästä se työpöydälle

        http://noahdfear.geekstogo.com/click counter/click.php?id=1

        Tuplaklikkaa sitä ja Start niin saat smitrem kansion työpöydälle

        Käynnistä sitte kone vikasietotilassa.

        Scannaa Hijackillä merkka ja Fix:saa nuo rivit

        O2 - BHO: HomepageBHO - {3bf1f86f-b1a8-489b-8d8b-43781d51411f} - C:\WINDOWS\system32\hp6DDD.tmp
        O4 - HKLM\..\Run: [dxvid] c:\windows\system32\dxvid.exe /nocomm
        O4 - HKLM\..\Run: [P.S.Guard] C:\Program Files\P.S.Guard\PSGuard.exe
        O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot
        O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZCfox000
        O16 - DPF: {F72BC3F0-6C20-4793-9DDA-258589D8A907} - http://akamai.downloadv3.com/binaries/IA/netslv32_EN_XP.cab

        Sitte poista jos löytyy piilotiedostot näkyvillä

        c:\windows\system32\dxvid.exe /nocomm

        C:\Program Files\Spyware Cleaner\ < kansio

        Sitte avaa smitrem kansio ja tuplaklikkaa RunThis.bat ja seuraa ohjeita.

        Käynnistä sitte normaalisti ja uus Hijack logi ja smitrem logi (C:\smitfiles.txt.)


      • Juu
        kalamies69 kirjoitti:

        siis avasin
        http://virusscan.jotti.org/
        ja seillä ylhäällä etsin lokeroon sen tuloksen muistista ja painoin submit ja sen tuloksen laitoin toho

        Kumman sää scannasit siellä

        Oman hijack logisi vai ton

        C:\Program Files\Security Toolbar\Security Toolbar.dll


      • kalamies69
        Juu kirjoitti:

        Siirrä ensin se Hijackki omaan kansioon tonne
        C:\HjT\HijackThis.exe

        Poista Lisää/Poista paneelista jos näkyy

        Spyware Cleaner

        Ota tuo smitrem ja säästä se työpöydälle

        http://noahdfear.geekstogo.com/click counter/click.php?id=1

        Tuplaklikkaa sitä ja Start niin saat smitrem kansion työpöydälle

        Käynnistä sitte kone vikasietotilassa.

        Scannaa Hijackillä merkka ja Fix:saa nuo rivit

        O2 - BHO: HomepageBHO - {3bf1f86f-b1a8-489b-8d8b-43781d51411f} - C:\WINDOWS\system32\hp6DDD.tmp
        O4 - HKLM\..\Run: [dxvid] c:\windows\system32\dxvid.exe /nocomm
        O4 - HKLM\..\Run: [P.S.Guard] C:\Program Files\P.S.Guard\PSGuard.exe
        O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot
        O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZCfox000
        O16 - DPF: {F72BC3F0-6C20-4793-9DDA-258589D8A907} - http://akamai.downloadv3.com/binaries/IA/netslv32_EN_XP.cab

        Sitte poista jos löytyy piilotiedostot näkyvillä

        c:\windows\system32\dxvid.exe /nocomm

        C:\Program Files\Spyware Cleaner\ < kansio

        Sitte avaa smitrem kansio ja tuplaklikkaa RunThis.bat ja seuraa ohjeita.

        Käynnistä sitte normaalisti ja uus Hijack logi ja smitrem logi (C:\smitfiles.txt.)

        kiitoksia , kokeilen noita juttuja.kiitos avusta.


    Ketjusta on poistettu 0 sääntöjenvastaista viestiä.

    Luetuimmat keskustelut

    1. en vaan saa häntä pois

      Mielestäni pyörimästä. Onko kellekään toiselle käynyt näin? Ihastuin pakkomielteisesti noin vuosi sitten erääseen naiseen. Ei vaan katoa mielestä va
      Ikävä
      176
      2074
    2. Suomi24 kysely: ihmisten kuplautumista ei pääosin koeta vakavaksi ongelmaksi

      “Kuplautumista on mahdotonta estää. Ihmiset ovat aina viihtyneet samankaltaiset arvot ja maailmankatsomuksen jakavassa seurassa ja muodostaneet sen pe
      Suomi24 Blogi ★
      36
      1733
    3. Ohhoh! Glamourmalli Elena, 29, teetti tiimalasivartalon - Vei rahaa ja tuotti tuskaa - Katso kuvat!

      Transtaustainen glamourmalli Elena Vikström on käynyt vuosien ajan plastiikkakirurgisissa toimenpiteissä. Tästä näet lopputuloksen: https://www.suomi
      Kotimaiset julkkisjuorut
      10
      1412
    4. Ostiko Martina uuden ponin tyttärelleen, vai oliko myös Stefan itsekkin valitsemassa ponia .?

      Kiva kun on tyttärelle mielekäs harrastus annettu, ehkä vielä on tulevaisuudessa hänelle tärkeä ja valitsee sen perusteella tulevan ammatin.
      Kotimaiset julkkisjuorut
      229
      1213
    5. Sinä olet tärkeä

      Herätät minussa kunnioitusta. Kiehdot minua. En oikein saa kiinni sinusta. Ehkä juuri siksi. Aistin että sinäkin pidät minusta. Vetovoima on ollut alu
      Ihastuminen
      59
      1203
    6. Varisjärvellä mersu.

      Varisjärven tiellä tuli vanhamersu kylkiedellä mutkassa vastaan ja vähällä keulaan mutta tökkäs penkkaan, hyppäsin omasta autosta ulos ja kävin kiskas
      Suomussalmi
      16
      1048
    7. Mitähän ajattelet J

      Tästä kaikesta? Mä välitän susta oikeasti.
      Ikävä
      60
      962
    8. Belorf haistattaa seuraajiaan "You can hate me now"...

      Vai haistattaako lompakkoa, joka taisi viimeinkin ymmärtää häipyä Sofian ulottumattomiin ? Sofia raukka on niin typerä, että ottaa nostetta "omasta tv
      Kotimaiset julkkisjuorut
      58
      961
    Aihe