auttakaa, logini

auttakaa, please

Logfile of HijackThis v1.99.1
Scan saved at 20:07:47, on 5.2.2006
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 SP1 (5.00.2614.3500)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\HIJACKTHIS.EXE

O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
O8 - Extra context menu item: Get siteinfo data (fsc) - C:\Program Files\EMS Free Surfer Companion\fslauncher.htm
O9 - Extra button: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\EMS Free Surfer Companion\FS30.exe
O9 - Extra 'Tools' menuitem: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\EMS Free Surfer Companion\FS30.exe

11

790

    Vastaukset

    Anonyymi (Kirjaudu / Rekisteröidy)
    5000
    • Juu

      Ota tuo työpöydälle

      http://www.derbilk.de/SpSeHjfix109.zip

      pura se omaan kansioon työpöydälle.

      Käynnistä sitte kone vikasietotilassa ja aja se ohjelma.
      Käynnistä sen jälkeen normaalisti ja uus Hijack logi.

      • auttakaa please

        Logfile of HijackThis v1.99.1
        Scan saved at 21:32:15, on 5.2.2006
        Platform: Windows 98 SE (Win9x 4.10.2222A)
        MSIE: Internet Explorer v5.00 SP1 (5.00.2614.3500)

        Running processes:
        C:\WINDOWS\SYSTEM\KERNEL32.DLL
        C:\WINDOWS\SYSTEM\MSGSRV32.EXE
        C:\WINDOWS\SYSTEM\MPREXE.EXE
        C:\WINDOWS\SYSTEM\mmtask.tsk
        C:\WINDOWS\EXPLORER.EXE
        C:\WINDOWS\RUNDLL32.EXE
        C:\HIJACKTHIS.EXE

        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
        O8 - Extra context menu item: Get siteinfo data (fsc) - C:\Program Files\EMS Free Surfer Companion\fslauncher.htm
        O9 - Extra button: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\EMS Free Surfer Companion\FS30.exe
        O9 - Extra 'Tools' menuitem: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\EMS Free Surfer Companion\FS30.exe


      • Juu
        auttakaa please kirjoitti:

        Logfile of HijackThis v1.99.1
        Scan saved at 21:32:15, on 5.2.2006
        Platform: Windows 98 SE (Win9x 4.10.2222A)
        MSIE: Internet Explorer v5.00 SP1 (5.00.2614.3500)

        Running processes:
        C:\WINDOWS\SYSTEM\KERNEL32.DLL
        C:\WINDOWS\SYSTEM\MSGSRV32.EXE
        C:\WINDOWS\SYSTEM\MPREXE.EXE
        C:\WINDOWS\SYSTEM\mmtask.tsk
        C:\WINDOWS\EXPLORER.EXE
        C:\WINDOWS\RUNDLL32.EXE
        C:\HIJACKTHIS.EXE

        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
        O8 - Extra context menu item: Get siteinfo data (fsc) - C:\Program Files\EMS Free Surfer Companion\fslauncher.htm
        O9 - Extra button: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\EMS Free Surfer Companion\FS30.exe
        O9 - Extra 'Tools' menuitem: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\EMS Free Surfer Companion\FS30.exe

        Ei näy mitään,mutta kovin lyhyt tuo logi on.
        Oletko ite poistellu Hijackillä jotain.
        Ton voit scannata tuolla niin näät onko se ok vai ei.

        C:\WINDOWS\RUNDLL32.EXE

        http://virusscan.jotti.org/


      • auttakaa please
        Juu kirjoitti:

        Ei näy mitään,mutta kovin lyhyt tuo logi on.
        Oletko ite poistellu Hijackillä jotain.
        Ton voit scannata tuolla niin näät onko se ok vai ei.

        C:\WINDOWS\RUNDLL32.EXE

        http://virusscan.jotti.org/

        Kyllä itse poistelin, apua. Tämmönen tuli
        Service load: 0% 100%

        File: RUNDLL32.EXE_
        Status: OK
        MD5 3857d93aa630abbd63467db4aeffce2c
        Packers detected: -
        Scanner results
        AntiVir Found nothing
        ArcaVir Found nothing
        Avast Found nothing
        AVG Antivirus Found nothing
        BitDefender Found nothing
        ClamAV Found nothing
        Dr.Web Found nothing
        F-Prot Antivirus Found nothing
        Fortinet Found nothing
        Kaspersky Anti-Virus Found nothing
        NOD32 Found nothing
        Norman Virus Control Found nothing
        UNA Found nothing
        VBA32 Found nothing


      • Juu
        auttakaa please kirjoitti:

        Kyllä itse poistelin, apua. Tämmönen tuli
        Service load: 0% 100%

        File: RUNDLL32.EXE_
        Status: OK
        MD5 3857d93aa630abbd63467db4aeffce2c
        Packers detected: -
        Scanner results
        AntiVir Found nothing
        ArcaVir Found nothing
        Avast Found nothing
        AVG Antivirus Found nothing
        BitDefender Found nothing
        ClamAV Found nothing
        Dr.Web Found nothing
        F-Prot Antivirus Found nothing
        Fortinet Found nothing
        Kaspersky Anti-Virus Found nothing
        NOD32 Found nothing
        Norman Virus Control Found nothing
        UNA Found nothing
        VBA32 Found nothing

        Ootko varma että et poistannu jotain jota ei tarvi poistaa.
        Jos oot epävarma niin palauta ne rivit Hijackin backupeista ja sitte käynnistä kone uudestaan ja uus logi.


    • auttakaa please

      Tässä tuorein logini.

      Logfile of HijackThis v1.99.1
      Scan saved at 22:20:15, on 5.2.2006
      Platform: Windows 98 SE (Win9x 4.10.2222A)
      MSIE: Internet Explorer v5.00 SP1 (5.00.2614.3500)

      Running processes:
      C:\WINDOWS\SYSTEM\KERNEL32.DLL
      C:\WINDOWS\SYSTEM\MSGSRV32.EXE
      C:\WINDOWS\SYSTEM\MPREXE.EXE
      C:\WINDOWS\SYSTEM\mmtask.tsk
      C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
      C:\WINDOWS\EXPLORER.EXE
      C:\WINDOWS\RUNDLL32.EXE
      C:\WINDOWS\RUNDLL32.EXE
      C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
      C:\WINDOWS\MIXER.EXE
      C:\PROGRAM FILES\3DFX INTERACTIVE\3DFX TOOLS\APPS\3DFXMAN.EXE
      C:\WINDOWS\SYSTEM\SYSTRAY.EXE
      C:\WINDOWS\TASKMON.EXE
      C:\WINSTALL.EXE
      C:\PROGRAM FILES\SPAMBUTCHER\SPAMBUTCHER.EXE
      C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
      C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
      C:\WINDOWS\SYSTEM\SPOOL32.EXE
      C:\WINDOWS\SYSTEM\WMIEXE.EXE
      C:\WINDOWS\SYSTEM\E_SICN03.EXE
      C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
      C:\WINDOWS\WINSYSBAN5.EXE
      C:\WINDOWS\SYSTEM\DDHELP.EXE
      C:\HIJACKTHIS.EXE

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/space.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/space.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
      O2 - BHO: (no name) - {4EE3DAE0-9695-11DA-B467-008062EE814E} - C:\WINDOWS\SYSTEM\PPCD.DLL
      O3 - Toolbar: &etcetera - {1111954A-58B9-4677-8358-A04FF4A75778} - C:\PROGRAM FILES\ETCETERA\ETCETERA.DLL
      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar.dll
      O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
      O4 - HKLM\..\Run: [gimmygames] C:\WINDOWS\GIMMYGAMES.exe
      O4 - HKLM\..\Run: [mwavscan] "C:\KASPERSKY\MWAVSCAN.COM" /s
      O4 - HKLM\..\Run: [winsysban] C:\WINDOWS\WINSYSBAN5.exe
      O4 - HKLM\..\Run: [winsysupd] C:\WINDOWS\WINSYSUPD5.exe
      O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\SYSTEM\paytime.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
      O4 - HKLM\..\Run: [3dfx Task Manager] "C:\Program Files\3dfx Interactive\3dfx Tools\Apps\3dfxMan.exe"
      O4 - HKLM\..\Run: [3dfx Tools] rundll32.exe 3dfxCmn.dll,CMNUpdateOnBoot
      O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
      O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
      O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
      O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
      O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
      O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
      O4 - HKCU\..\Run: [Registry Cleaner] "C:\PROGRAM FILES\TPT REGISTRY_CLEANER (TRIAL)\REGCLEAN.EXE"
      O4 - HKCU\..\Run: [SpySheriff] C:\PROGRAM FILES\SPYSHERIFF\SpySheriff.exe
      O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
      O4 - HKCU\..\Run: [Shell] "C:\WINDOWS\SYSTEM\ibm00001.exe"
      O4 - Startup: SpamButcher.lnk = C:\Program Files\SpamButcher\spambutcher.exe
      O4 - Startup: Microsoft Office Pikahaku.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
      O4 - Startup: Officen käynnistys.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
      O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
      O4 - Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\SYSTEM\E_SRCV03.EXE
      O8 - Extra context menu item: Get siteinfo data (fsc) - C:\Program Files\EMS Free Surfer Companion\fslauncher.htm
      O8 - Extra context menu item: [e] Refine Search - C:\PROGRAM FILES\ETCETERA\Support\Refine.htm
      O8 - Extra context menu item: [e] Search - C:\PROGRAM FILES\ETCETERA\Support\Search.htm
      O8 - Extra context menu item: [e] Deny popups for this site - C:\PROGRAM FILES\ETCETERA\Support\DenyPopup.htm
      O8 - Extra context menu item: [e] Allow popups for this site - C:\PROGRAM FILES\ETCETERA\Support\AllowPopup.htm
      O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmsearch.html
      O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmcache.html
      O8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmsimilar.html
      O8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmbacklinks.html
      O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmtrans.html
      O9 - Extra button: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\EMS Free Surfer Companion\FS30.exe
      O9 - Extra 'Tools' menuitem: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\EMS Free Surfer Companion\FS30.exe
      O18 - Filter: text/plain - {AF6355E0-9694-11DA-B467-00800CB37AAD} - C:\WINDOWS\SYSTEM\PPCD.DLL
      O18 - Filter: text/html - {AF6355E0-9694-11DA-B467-00800CB37AAD} - C:\WINDOWS\SYSTEM\PPCD.DLL
      O21 - SSODL: YWTwoSnJEOEt - {22151CEC-88BF-B646-5DD3-91985AA09148} - (no file)

      • Juu

        Olit poistellu pikkasen likaa.
        Pistä ensin se Hijackki omaan kansioon.

        Ota smitrem ja säästä se työpöydälle

        http://noahdfear.geekstogo.com/click counter/click.php?id=1

        Tuplaklikkaa sitä ja Start niin saat smitrem kansion työpöydälle .

        Käynnistä sitte kone vikasietotilassa.

        Sitte poista

        C:\WINDOWS\WINSYSBAN5.EXE

        Sitte avaa smitrem kansio ja tuplaklikkaa RunThis.bat ja seuraa ohjeita.

        Sen jälkeen aja se SpSeHjfix109 uudestaan


        Käynnistä sitte normaalisti ja uus Hijack logi ja smitrem logi (C:\smitfiles.txt.)


    • auttakaa please

      Kaikki toivo mennyt!

      Logfile of HijackThis v1.99.1
      Scan saved at 23:27:11, on 5.2.2006
      Platform: Windows 98 SE (Win9x 4.10.2222A)
      MSIE: Internet Explorer v5.00 SP1 (5.00.2614.3500)

      Running processes:
      C:\WINDOWS\SYSTEM\KERNEL32.DLL
      C:\WINDOWS\SYSTEM\MSGSRV32.EXE
      C:\WINDOWS\SYSTEM\MPREXE.EXE
      C:\WINDOWS\SYSTEM\mmtask.tsk
      C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
      C:\WINDOWS\EXPLORER.EXE
      C:\WINDOWS\RUNDLL32.EXE
      C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
      C:\WINDOWS\MIXER.EXE
      C:\PROGRAM FILES\3DFX INTERACTIVE\3DFX TOOLS\APPS\3DFXMAN.EXE
      C:\WINDOWS\SYSTEM\SYSTRAY.EXE
      C:\WINDOWS\TASKMON.EXE
      C:\WINSTALL.EXE
      C:\PROGRAM FILES\SPAMBUTCHER\SPAMBUTCHER.EXE
      C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
      C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
      C:\WINDOWS\SYSTEM\WMIEXE.EXE
      C:\WINDOWS\SYSTEM\SPOOL32.EXE
      C:\WINDOWS\SYSTEM\E_SICN03.EXE
      C:\HIJACKTHIS.EXE

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/space.html
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/space.html
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
      O3 - Toolbar: &etcetera - {1111954A-58B9-4677-8358-A04FF4A75778} - C:\PROGRAM FILES\ETCETERA\ETCETERA.DLL
      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar.dll
      O4 - HKLM\..\Run: [gimmygames] C:\WINDOWS\GIMMYGAMES.exe
      O4 - HKLM\..\Run: [mwavscan] "C:\KASPERSKY\MWAVSCAN.COM" /s
      O4 - HKLM\..\Run: [winsysupd] C:\WINDOWS\WINSYSUPD5.exe
      O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\SYSTEM\paytime.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
      O4 - HKLM\..\Run: [3dfx Task Manager] "C:\Program Files\3dfx Interactive\3dfx Tools\Apps\3dfxMan.exe"
      O4 - HKLM\..\Run: [3dfx Tools] rundll32.exe 3dfxCmn.dll,CMNUpdateOnBoot
      O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
      O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
      O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
      O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
      O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
      O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
      O4 - HKCU\..\Run: [Registry Cleaner] "C:\PROGRAM FILES\TPT REGISTRY_CLEANER (TRIAL)\REGCLEAN.EXE"
      O4 - HKCU\..\Run: [SpySheriff] C:\PROGRAM FILES\SPYSHERIFF\SpySheriff.exe
      O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
      O4 - HKCU\..\Run: [Shell] "C:\WINDOWS\SYSTEM\ibm00001.exe"
      O4 - Startup: SpamButcher.lnk = C:\Program Files\SpamButcher\spambutcher.exe
      O4 - Startup: Microsoft Office Pikahaku.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
      O4 - Startup: Officen käynnistys.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
      O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
      O4 - Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\SYSTEM\E_SRCV03.EXE
      O8 - Extra context menu item: Get siteinfo data (fsc) - C:\Program Files\EMS Free Surfer Companion\fslauncher.htm
      O8 - Extra context menu item: [e] Refine Search - C:\PROGRAM FILES\ETCETERA\Support\Refine.htm
      O8 - Extra context menu item: [e] Search - C:\PROGRAM FILES\ETCETERA\Support\Search.htm
      O8 - Extra context menu item: [e] Deny popups for this site - C:\PROGRAM FILES\ETCETERA\Support\DenyPopup.htm
      O8 - Extra context menu item: [e] Allow popups for this site - C:\PROGRAM FILES\ETCETERA\Support\AllowPopup.htm
      O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmsearch.html
      O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmcache.html
      O8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmsimilar.html
      O8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmbacklinks.html
      O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmtrans.html
      O9 - Extra button: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\EMS Free Surfer Companion\FS30.exe
      O9 - Extra 'Tools' menuitem: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\EMS Free Surfer Companion\FS30.exe
      O21 - SSODL: YWTwoSnJEOEt - {22151CEC-88BF-B646-5DD3-91985AA09148} - (no file)

      • lokintutkija

        tämä osa on vielä tekemättä

        Ota smitrem ja säästä se työpöydälle
        http://noahdfear.geekstogo.com/click counter/click.ph p?id=1
        Tuplaklikkaa sitä ja Start niin saat smitrem kansion työpöydälle .

        Käynnistä sitte kone vikasietotilassa.
        Sitte avaa smitrem kansio ja tuplaklikkaa RunThis.bat ja seuraa ohjeita.
        Käynnistä sitte normaalisti ja uus Hijack logi ja smitrem logi (C:\smitfiles.txt.)


      • auttakaa please
        lokintutkija kirjoitti:

        tämä osa on vielä tekemättä

        Ota smitrem ja säästä se työpöydälle
        http://noahdfear.geekstogo.com/click counter/click.ph p?id=1
        Tuplaklikkaa sitä ja Start niin saat smitrem kansion työpöydälle .

        Käynnistä sitte kone vikasietotilassa.
        Sitte avaa smitrem kansio ja tuplaklikkaa RunThis.bat ja seuraa ohjeita.
        Käynnistä sitte normaalisti ja uus Hijack logi ja smitrem logi (C:\smitfiles.txt.)

        C:Smitfiles/txt ei löydy??


        Logfile of HijackThis v1.99.1
        Scan saved at 23:47:24, on 5.2.2006
        Platform: Windows 98 SE (Win9x 4.10.2222A)
        MSIE: Internet Explorer v5.00 SP1 (5.00.2614.3500)

        Running processes:
        C:\WINDOWS\SYSTEM\KERNEL32.DLL
        C:\WINDOWS\SYSTEM\MSGSRV32.EXE
        C:\WINDOWS\SYSTEM\MPREXE.EXE
        C:\WINDOWS\SYSTEM\mmtask.tsk
        C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
        C:\WINDOWS\EXPLORER.EXE
        C:\WINDOWS\RUNDLL32.EXE
        C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
        C:\WINDOWS\MIXER.EXE
        C:\PROGRAM FILES\3DFX INTERACTIVE\3DFX TOOLS\APPS\3DFXMAN.EXE
        C:\WINDOWS\SYSTEM\SYSTRAY.EXE
        C:\WINDOWS\TASKMON.EXE
        C:\PROGRAM FILES\SPAMBUTCHER\SPAMBUTCHER.EXE
        C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
        C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
        C:\WINDOWS\SYSTEM\WMIEXE.EXE
        C:\WINDOWS\SYSTEM\SPOOL32.EXE
        C:\WINDOWS\SYSTEM\E_SICN03.EXE
        C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
        C:\HIJACKTHIS.EXE

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/space.html
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
        O3 - Toolbar: &etcetera - {1111954A-58B9-4677-8358-A04FF4A75778} - C:\PROGRAM FILES\ETCETERA\ETCETERA.DLL
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar.dll
        O4 - HKLM\..\Run: [gimmygames] C:\WINDOWS\GIMMYGAMES.exe
        O4 - HKLM\..\Run: [mwavscan] "C:\KASPERSKY\MWAVSCAN.COM" /s
        O4 - HKLM\..\Run: [winsysupd] C:\WINDOWS\WINSYSUPD5.exe
        O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\SYSTEM\paytime.exe
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
        O4 - HKLM\..\Run: [3dfx Task Manager] "C:\Program Files\3dfx Interactive\3dfx Tools\Apps\3dfxMan.exe"
        O4 - HKLM\..\Run: [3dfx Tools] rundll32.exe 3dfxCmn.dll,CMNUpdateOnBoot
        O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
        O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
        O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
        O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
        O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
        O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
        O4 - HKCU\..\Run: [Registry Cleaner] "C:\PROGRAM FILES\TPT REGISTRY_CLEANER (TRIAL)\REGCLEAN.EXE"
        O4 - HKCU\..\Run: [Shell] "C:\WINDOWS\SYSTEM\ibm00001.exe"
        O4 - Startup: SpamButcher.lnk = C:\Program Files\SpamButcher\spambutcher.exe
        O4 - Startup: Microsoft Office Pikahaku.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
        O4 - Startup: Officen käynnistys.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
        O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
        O4 - Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\SYSTEM\E_SRCV03.EXE
        O8 - Extra context menu item: Get siteinfo data (fsc) - C:\Program Files\EMS Free Surfer Companion\fslauncher.htm
        O8 - Extra context menu item: [e] Refine Search - C:\PROGRAM FILES\ETCETERA\Support\Refine.htm
        O8 - Extra context menu item: [e] Search - C:\PROGRAM FILES\ETCETERA\Support\Search.htm
        O8 - Extra context menu item: [e] Deny popups for this site - C:\PROGRAM FILES\ETCETERA\Support\DenyPopup.htm
        O8 - Extra context menu item: [e] Allow popups for this site - C:\PROGRAM FILES\ETCETERA\Support\AllowPopup.htm
        O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmsearch.html
        O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmcache.html
        O8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmsimilar.html
        O8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmbacklinks.html
        O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmtrans.html
        O9 - Extra button: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\EMS Free Surfer Companion\FS30.exe
        O9 - Extra 'Tools' menuitem: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\EMS Free Surfer Companion\FS30.exe
        O21 - SSODL: YWTwoSnJEOEt - {22151CEC-88BF-B646-5DD3-91985AA09148} - (no file)


      • auttakaa please
        auttakaa please kirjoitti:

        C:Smitfiles/txt ei löydy??


        Logfile of HijackThis v1.99.1
        Scan saved at 23:47:24, on 5.2.2006
        Platform: Windows 98 SE (Win9x 4.10.2222A)
        MSIE: Internet Explorer v5.00 SP1 (5.00.2614.3500)

        Running processes:
        C:\WINDOWS\SYSTEM\KERNEL32.DLL
        C:\WINDOWS\SYSTEM\MSGSRV32.EXE
        C:\WINDOWS\SYSTEM\MPREXE.EXE
        C:\WINDOWS\SYSTEM\mmtask.tsk
        C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
        C:\WINDOWS\EXPLORER.EXE
        C:\WINDOWS\RUNDLL32.EXE
        C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
        C:\WINDOWS\MIXER.EXE
        C:\PROGRAM FILES\3DFX INTERACTIVE\3DFX TOOLS\APPS\3DFXMAN.EXE
        C:\WINDOWS\SYSTEM\SYSTRAY.EXE
        C:\WINDOWS\TASKMON.EXE
        C:\PROGRAM FILES\SPAMBUTCHER\SPAMBUTCHER.EXE
        C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
        C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
        C:\WINDOWS\SYSTEM\WMIEXE.EXE
        C:\WINDOWS\SYSTEM\SPOOL32.EXE
        C:\WINDOWS\SYSTEM\E_SICN03.EXE
        C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
        C:\HIJACKTHIS.EXE

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/space.html
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
        O3 - Toolbar: &etcetera - {1111954A-58B9-4677-8358-A04FF4A75778} - C:\PROGRAM FILES\ETCETERA\ETCETERA.DLL
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar.dll
        O4 - HKLM\..\Run: [gimmygames] C:\WINDOWS\GIMMYGAMES.exe
        O4 - HKLM\..\Run: [mwavscan] "C:\KASPERSKY\MWAVSCAN.COM" /s
        O4 - HKLM\..\Run: [winsysupd] C:\WINDOWS\WINSYSUPD5.exe
        O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\SYSTEM\paytime.exe
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
        O4 - HKLM\..\Run: [3dfx Task Manager] "C:\Program Files\3dfx Interactive\3dfx Tools\Apps\3dfxMan.exe"
        O4 - HKLM\..\Run: [3dfx Tools] rundll32.exe 3dfxCmn.dll,CMNUpdateOnBoot
        O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
        O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
        O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
        O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
        O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
        O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
        O4 - HKCU\..\Run: [Registry Cleaner] "C:\PROGRAM FILES\TPT REGISTRY_CLEANER (TRIAL)\REGCLEAN.EXE"
        O4 - HKCU\..\Run: [Shell] "C:\WINDOWS\SYSTEM\ibm00001.exe"
        O4 - Startup: SpamButcher.lnk = C:\Program Files\SpamButcher\spambutcher.exe
        O4 - Startup: Microsoft Office Pikahaku.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
        O4 - Startup: Officen käynnistys.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
        O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
        O4 - Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\SYSTEM\E_SRCV03.EXE
        O8 - Extra context menu item: Get siteinfo data (fsc) - C:\Program Files\EMS Free Surfer Companion\fslauncher.htm
        O8 - Extra context menu item: [e] Refine Search - C:\PROGRAM FILES\ETCETERA\Support\Refine.htm
        O8 - Extra context menu item: [e] Search - C:\PROGRAM FILES\ETCETERA\Support\Search.htm
        O8 - Extra context menu item: [e] Deny popups for this site - C:\PROGRAM FILES\ETCETERA\Support\DenyPopup.htm
        O8 - Extra context menu item: [e] Allow popups for this site - C:\PROGRAM FILES\ETCETERA\Support\AllowPopup.htm
        O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmsearch.html
        O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmcache.html
        O8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmsimilar.html
        O8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmbacklinks.html
        O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR.DLL/cmtrans.html
        O9 - Extra button: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\EMS Free Surfer Companion\FS30.exe
        O9 - Extra 'Tools' menuitem: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\EMS Free Surfer Companion\FS30.exe
        O21 - SSODL: YWTwoSnJEOEt - {22151CEC-88BF-B646-5DD3-91985AA09148} - (no file)

        smitRem © log file
        version 2.8

        by noahdfear


        Windows 98 [Version 4.10.2222]


        Running from
        C:\WINDOWS\Desktop\smitRem

        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        Pre-run SharedTask Export

        (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
        Copyright(C) 2006 BleepingComputer.com

        Registry Pseudo-Format Mode (Not a valid reg file):

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
        "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
        "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
        @="C:\WINDOWS\SYSTEM\BROWSEUI.DLL"


        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
        @="C:\WINDOWS\SYSTEM\BROWSEUI.DLL"


        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
        spyaxe uninstaller NOT present
        Winhound uninstaller NOT present
        SpywareStrike uninstaller NOT present

        Existing Pre-run Files


        ~~~ Program Files ~~~



        ~~~ Shortcuts ~~~



        ~~~ Favorites ~~~



        ~~~ system folder ~~~




        ~~~ Icons in system folder ~~~



        ~~~ Windows directory ~~~

        secure32.html


        ~~~ Drive root ~~~

        secure32.html
        winstall.exe


        ~~~ Miscellaneous Files/folders ~~~



        ~~~~ wininet.dll ~~~~

        wininet.dll Present!!


        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        Starting registry repairs
        Registry repairs complete

        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        SharedTask Export after registry fix

        (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
        Copyright(C) 2006 BleepingComputer.com

        Registry Pseudo-Format Mode (Not a valid reg file):

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
        "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
        "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
        @="C:\WINDOWS\SYSTEM\BROWSEUI.DLL"


        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
        @="C:\WINDOWS\SYSTEM\BROWSEUI.DLL"


        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        Deleting files

        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        Remaining Post-run Files


        ~~~ Program Files ~~~



        ~~~ Shortcuts ~~~



        ~~~ Favorites ~~~



        ~~~ system folder ~~~




        ~~~ Icons in system folder ~~~



        ~~~ Windows directory ~~~

        secure32.html


        ~~~ Drive root ~~~

        secure32.html

        ~~~ Miscellaneous Files/folders ~~~





        ~~~~ wininet.dll ~~~~

        wininet.dll Clean!! :)


    Ketjusta on poistettu 0 sääntöjenvastaista viestiä.

    Luetuimmat keskustelut

    1. Virkamiehille tarvitaan tuntuvat palkankorotukset

      Naistenpäivänä on syytä muistuttaa, että virkamiehen euro on vain 80 senttiä. Palkat tulee saattaa samalle tasolle yksi
      Maailman menoa
      40
      3711
    2. Riikka Purran kaudella nousi bensan hinta yli 2 euron

      Muistatteko kuinka edellisen vasemmistohallituksen aikana, ns. Marinin aikakaudella, bensiiniä sai 1,3 euron litrahinnal
      Maailman menoa
      33
      3304
    3. Jäikö meidän välit

      Mielestäsi Kesken?
      Ikävä
      69
      2918
    4. Olisipa saanut sinuun

      Tutustua paremmin. Harmi että aloin lopulta jännittämään kun näytit tunteesi niin voimakkaasti ja lähestyit niin voimaak
      Ikävä
      91
      2760
    5. Miks tän meidän

      Rakkauden on pitänyt olla näin vaikeaa?
      Ikävä
      35
      1778
    6. Mitäs nyt sijoittajat?

      Pörssit laskevat maailmalla Iranin sodan takia ja muutenkin ovat olleet Trumpin vallan alla epävarmat. Ainoa, mikä on no
      Maailman menoa
      81
      1739
    7. muista olla

      VAROVAINEN! m
      Ikävä
      24
      1589
    8. Elän vastoin

      Kaikkia arvoja kun en pysy sinusta erossa.
      Ikävä
      28
      1537
    9. Onneksi on edes yksi kuva

      Susta mitä voin välillä ihastella ja kaipailla sua😔
      Ikävä
      29
      1519
    10. Olisitpa se hellä

      Ja herkkä minkä kuvan sain sinusta irl. Haluaisin että elämässäni olisi sellainen joka arvostaa minua juuri sellaisena k
      Ikävä
      23
      1514
    Aihe