Jotain hämminkiä

Apuvaa...

Joku mättää nyt koneessa...
Näkyisiköhän tässä mitään?

Logfile of HijackThis v1.99.1
Scan saved at 16:05:00, on 12.2.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Sonera Tietoturva\Common\FSM32.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\Msmsgs.exe
C:\Program Files\MessengerDiscovery\msgdiscoveryx.exe
C:\Program Files\Common Files\Windows\services32.exe
C:\WINDOWS\ATKKBService.exe
C:\PROGRA~1\SONERA~1\backweb\4436233\Program\SERVIC~1.EXE
C:\Program Files\Sonera Tietoturva\Anti-Virus\fsgk32st.exe
C:\Program Files\Sonera Tietoturva\backweb\4436233\Program\fspex.exe
C:\Program Files\Sonera Tietoturva\backweb\4436233\program\fsbwsys.exe
C:\Program Files\Sonera Tietoturva\Anti-Virus\FSGK32.EXE
C:\Program Files\Sonera Tietoturva\Common\FSMA32.EXE
C:\Program Files\Sonera Tietoturva\Common\FSMB32.EXE
C:\Program Files\Sonera Tietoturva\Anti-Virus\fssm32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sonera Tietoturva\Common\FCH32.EXE
C:\Program Files\Sonera Tietoturva\Common\FAMEH32.EXE
C:\Program Files\Sonera Tietoturva\FWES\Program\fsdfwd.exe
C:\Program Files\Sonera Tietoturva\Anti-Virus\fsav32.exe
C:\Program Files\Sonera Tietoturva\FSGUI\fsguiexe.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\nvctrl.exe
C:\WINDOWS\system32\RDSHOST.exe
C:\WINDOWS\system32\sessmgr.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpCtr.exe
C:\WINDOWS\system32\mssearchnet.exe
C:\HjT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchmiracle.com/sp.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soneraplaza.fi
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Sonera Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: (no name) - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINDOWS\system32\hp7FD5.tmp
O3 - Toolbar: Lyric Bar - {9AD83196-4AF7-4f08-8C6F-B763DB67F2D9} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Sonera Tietoturva\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Sonera Tietoturva\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [News Service] "C:\Program Files\Sonera Tietoturva\FSGUI\ispnews.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [blah cast eq ooze] C:\Documents and Settings\All Users\Application Data\HoleOkayBlahCast\film fork.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe
O4 - HKLM\..\Run: [Microsoft Update 64 BIT] winman32.exe
O4 - HKLM\..\Run: [Media Gateway] C:\Program Files\Media Gateway\MediaGateway.exe
O4 - HKLM\..\Run: [31cdg1lm] C:\WINDOWS\system32\31cdg1lm.exe
O4 - HKLM\..\Run: [System service62] C:\WINDOWS\etb\pokapoka63.exe
O4 - HKLM\..\Run: [System service63] C:\WINDOWS\etb\pokapoka63.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [ftshqc] C:\WINDOWS\system32\dlugaht.exe r
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Network] C:\Program Files\Network\network.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\RunServices: [Microsoft Windows DLL Services Configuration] windir32.exe
O4 - HKLM\..\RunServices: [Microsoft Update 64 BIT] winman32.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe /start
O4 - HKCU\..\Run: [Nurb Platform] C:\DOCUME~1\Tero\APPLIC~1\CHICNE~1\Fordmorefirst.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe
O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-58-12-0000080.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\zteam\steam.exe" -silent
O4 - HKCU\..\Run: [MessengerDiscovery] C:\Program Files\MessengerDiscovery\msgdiscoveryx.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Lyric Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)
O9 - Extra 'Tools' menuitem: Lyric Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {5BDBD95C-1E7F-4FB1-8497-20AF879F8B68} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/fi/filesharingctrl.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Sonera Tietoturva (BackWeb Plug-in - 4436233) - Unknown owner - C:\PROGRA~1\SONERA~1\backweb\4436233\Program\SERVIC~1.EXE
O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\Sonera Tietoturva\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\Sonera Tietoturva\backweb\4436233\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Sonera Tietoturva\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Sonera Tietoturva\Common\FSMA32.EXE
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe

14

991

    Vastaukset

    Anonyymi (Kirjaudu / Rekisteröidy)
    5000
    • Juu

      Joo no varmaan mättää täälä on vaikka mitä.
      Alotetaan vaikka näin.

      Lataa viimeisin Ad-Aware SE versio

      http://www.download.com/3000-2144-10045910.html

      Jos se EI ole versio 1.0.6, poista nykyinen versiosi Lisää/Poista sovelluksen kautta ja deletoi kansio: C:\Program Files\Lavasoft sekä tyhjennä roskakori. Lopulta asenna linkistä tuo viimeisin versio.

      Avaa Ad-Aware SE ja käynnistä WebUpdate toiminto. (Klikkaa maapallo-kuvakkeeseen, klikkaa "connect", klikkaa "OK", klikkaa "Finish".)

      JOS sinulla on päivitysten kanssa ongelmia, hae viimeisimmät päivitykset manuaalisesti täältä; http://download.lavasoft.de.edgesuite.net/public/defs.zip

      Lataa Lavasoftin VX2 Puhdistaja plug-in

      http://www.lavasoftusa.com/software/addons/vx2cleaner.shtml

      * Asenna VX2 Cleaner
      * Käynnistä Ad-Aware SE
      * Mene valikkoon nimeltä "Plug-ins"
      * Valitse VX2 Cleaner plug-in ja klikkaa "Run Tool" (Ennen kuin ajat VX2 Cleanerin, varmista että muut Anti-virus & Anti-spyware ohjelmat ovat poissa päältä.)
      * Klikkaa "OK" kun kysytään haluatko ajaa tämän työkalun
      * Jos koneesi ei ole saanut tartuntaa, klikkaa "Close".

      Jos koneesi on saanut tartunnan;

      * Valitse "Clean"
      * Käynnistä uudelleen.
      * Skannaa koneesi Ad-Awarella;

      * Tee asetukset näin:
      * Mene Ad-Awaren määritysikkunaan
      * Valitse General > Safety & Settings: Rastita (vihreäksi) kaikki kolme.
      * Klikkaa Tweak > Cleaning Engine > Poista rastitus "Always try to unload modules before deletion".

      Klikkaa "Proceed"
      Klikkaa "Scan Now"
      Rastita valinta "Search for negligible risk entries"
      Rastita valinta "Search for low-risk threats"
      Aja skanneri käyttämällä Full Scan (Perform full system scan) moodia.
      Kun skannaus on valmis, valitse "Next".
      Skannaus tuloksissa, valitse "Scan Summary" välilehti.
      Rastita boxi jokaisen löydetyn rivin viereen, poistoa varten.
      Klikkaa "Next", klikkaa "OK".

      * Käynnistä koneesi uudelleen

      * Aja vielä toinen skannaus (Ad-Awarella ja VX2 Cleanerilla) varmistaaksesi että kaikki pahat tiedostot on kadonnut koneeltasi.

      Lähetä sen jälkeen uus Hijack logi.
      Siellä on paljo muuta putsattavaa sitte vielä jälellä.

      • eikös

        toi tietoturva (F-secure) sisällä nykyään AdAwarea.


      • kaksin kaunihimpi
        eikös kirjoitti:

        toi tietoturva (F-secure) sisällä nykyään AdAwarea.

        kun *Juu* sanoo.


      • Apuvaa...

        Noniin.. kylläpäs sitä sontaa olikin 437 kpl.
        Mutta tässä se uusi logi.

        Logfile of HijackThis v1.99.1
        Scan saved at 20:17:07, on 12.2.2006
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\ATKKBService.exe
        C:\Program Files\Sonera Tietoturva\Anti-Virus\fsgk32st.exe
        C:\Program Files\Sonera Tietoturva\Anti-Virus\FSGK32.EXE
        C:\Program Files\Sonera Tietoturva\Common\FSMA32.EXE
        C:\Program Files\Sonera Tietoturva\Anti-Virus\fssm32.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\mssearchnet.exe
        C:\WINDOWS\system32\nvctrl.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\MessengerPlus! 3\MsgPlus.exe
        C:\WINDOWS\system32\31cdg1lm.exe
        C:\Program Files\Network\network.exe
        C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Messenger\Msmsgs.exe
        C:\Program Files\MSN Messenger\msnmsgr.exe
        C:\Program Files\MessengerDiscovery\msgdiscoveryx.exe
        C:\WINDOWS\system32\RDSHOST.exe
        C:\WINDOWS\system32\sessmgr.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpCtr.exe
        C:\Program Files\Sonera Tietoturva\Common\FSM32.EXE
        C:\Program Files\Sonera Tietoturva\Common\FSMB32.EXE
        C:\Program Files\Sonera Tietoturva\Common\FCH32.EXE
        C:\Program Files\Sonera Tietoturva\backweb\4436233\program\fsbwsys.exe
        C:\Program Files\Sonera Tietoturva\Common\FAMEH32.EXE
        C:\PROGRA~1\SONERA~1\backweb\4436233\Program\SERVIC~1.EXE
        C:\Program Files\Sonera Tietoturva\FWES\Program\fsdfwd.exe
        C:\Program Files\Sonera Tietoturva\Anti-Virus\fsav32.exe
        C:\Program Files\Sonera Tietoturva\backweb\4436233\Program\fspex.exe
        C:\Program Files\Sonera Tietoturva\FSGUI\fsguiexe.exe
        C:\HjT\HijackThis.exe

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soneraplaza.fi
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Sonera Internet
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINDOWS\system32\hpF388.tmp
        O3 - Toolbar: Lyric Bar - {9AD83196-4AF7-4f08-8C6F-B763DB67F2D9} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)
        O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Sonera Tietoturva\Common\FSM32.EXE" /splash
        O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Sonera Tietoturva\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
        O4 - HKLM\..\Run: [News Service] "C:\Program Files\Sonera Tietoturva\FSGUI\ispnews.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
        O4 - HKLM\..\Run: [blah cast eq ooze] C:\Documents and Settings\All Users\Application Data\HoleOkayBlahCast\film fork.exe
        O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
        O4 - HKLM\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe
        O4 - HKLM\..\Run: [Microsoft Update 64 BIT] winman32.exe
        O4 - HKLM\..\Run: [31cdg1lm] C:\WINDOWS\system32\31cdg1lm.exe
        O4 - HKLM\..\Run: [System service62] C:\WINDOWS\etb\pokapoka63.exe
        O4 - HKLM\..\Run: [System service63] C:\WINDOWS\etb\pokapoka63.exe
        O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
        O4 - HKLM\..\Run: [Network] C:\Program Files\Network\network.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
        O4 - HKLM\..\Run: [SpyFalcon] C:\Program Files\SpyFalcon\SpyFalcon.exe /h
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\RunServices: [Microsoft Windows DLL Services Configuration] windir32.exe
        O4 - HKLM\..\RunServices: [Microsoft Update 64 BIT] winman32.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe /start
        O4 - HKCU\..\Run: [Nurb Platform] C:\DOCUME~1\Tero\APPLIC~1\CHICNE~1\Fordmorefirst.exe
        O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
        O4 - HKCU\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe
        O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-58-12-0000080.exe
        O4 - HKCU\..\Run: [Steam] "c:\program files\zteam\steam.exe" -silent
        O4 - HKCU\..\Run: [MessengerDiscovery] C:\Program Files\MessengerDiscovery\msgdiscoveryx.exe
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
        O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O9 - Extra button: Lyric Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)
        O9 - Extra 'Tools' menuitem: Lyric Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi
        O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
        O16 - DPF: {5BDBD95C-1E7F-4FB1-8497-20AF879F8B68} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/fi/filesharingctrl.cab
        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
        O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
        O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
        O23 - Service: Sonera Tietoturva (BackWeb Plug-in - 4436233) - Unknown owner - C:\PROGRA~1\SONERA~1\backweb\4436233\Program\SERVIC~1.EXE
        O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\Sonera Tietoturva\Anti-Virus\fsgk32st.exe
        O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\Sonera Tietoturva\backweb\4436233\program\fsbwsys.exe
        O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Sonera Tietoturva\FWES\Program\fsdfwd.exe
        O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Sonera Tietoturva\Common\FSMA32.EXE
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe


      • Juu
        Apuvaa... kirjoitti:

        Noniin.. kylläpäs sitä sontaa olikin 437 kpl.
        Mutta tässä se uusi logi.

        Logfile of HijackThis v1.99.1
        Scan saved at 20:17:07, on 12.2.2006
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\ATKKBService.exe
        C:\Program Files\Sonera Tietoturva\Anti-Virus\fsgk32st.exe
        C:\Program Files\Sonera Tietoturva\Anti-Virus\FSGK32.EXE
        C:\Program Files\Sonera Tietoturva\Common\FSMA32.EXE
        C:\Program Files\Sonera Tietoturva\Anti-Virus\fssm32.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\mssearchnet.exe
        C:\WINDOWS\system32\nvctrl.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\MessengerPlus! 3\MsgPlus.exe
        C:\WINDOWS\system32\31cdg1lm.exe
        C:\Program Files\Network\network.exe
        C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Messenger\Msmsgs.exe
        C:\Program Files\MSN Messenger\msnmsgr.exe
        C:\Program Files\MessengerDiscovery\msgdiscoveryx.exe
        C:\WINDOWS\system32\RDSHOST.exe
        C:\WINDOWS\system32\sessmgr.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpCtr.exe
        C:\Program Files\Sonera Tietoturva\Common\FSM32.EXE
        C:\Program Files\Sonera Tietoturva\Common\FSMB32.EXE
        C:\Program Files\Sonera Tietoturva\Common\FCH32.EXE
        C:\Program Files\Sonera Tietoturva\backweb\4436233\program\fsbwsys.exe
        C:\Program Files\Sonera Tietoturva\Common\FAMEH32.EXE
        C:\PROGRA~1\SONERA~1\backweb\4436233\Program\SERVIC~1.EXE
        C:\Program Files\Sonera Tietoturva\FWES\Program\fsdfwd.exe
        C:\Program Files\Sonera Tietoturva\Anti-Virus\fsav32.exe
        C:\Program Files\Sonera Tietoturva\backweb\4436233\Program\fspex.exe
        C:\Program Files\Sonera Tietoturva\FSGUI\fsguiexe.exe
        C:\HjT\HijackThis.exe

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soneraplaza.fi
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Sonera Internet
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINDOWS\system32\hpF388.tmp
        O3 - Toolbar: Lyric Bar - {9AD83196-4AF7-4f08-8C6F-B763DB67F2D9} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)
        O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Sonera Tietoturva\Common\FSM32.EXE" /splash
        O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Sonera Tietoturva\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
        O4 - HKLM\..\Run: [News Service] "C:\Program Files\Sonera Tietoturva\FSGUI\ispnews.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
        O4 - HKLM\..\Run: [blah cast eq ooze] C:\Documents and Settings\All Users\Application Data\HoleOkayBlahCast\film fork.exe
        O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
        O4 - HKLM\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe
        O4 - HKLM\..\Run: [Microsoft Update 64 BIT] winman32.exe
        O4 - HKLM\..\Run: [31cdg1lm] C:\WINDOWS\system32\31cdg1lm.exe
        O4 - HKLM\..\Run: [System service62] C:\WINDOWS\etb\pokapoka63.exe
        O4 - HKLM\..\Run: [System service63] C:\WINDOWS\etb\pokapoka63.exe
        O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
        O4 - HKLM\..\Run: [Network] C:\Program Files\Network\network.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
        O4 - HKLM\..\Run: [SpyFalcon] C:\Program Files\SpyFalcon\SpyFalcon.exe /h
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\RunServices: [Microsoft Windows DLL Services Configuration] windir32.exe
        O4 - HKLM\..\RunServices: [Microsoft Update 64 BIT] winman32.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe /start
        O4 - HKCU\..\Run: [Nurb Platform] C:\DOCUME~1\Tero\APPLIC~1\CHICNE~1\Fordmorefirst.exe
        O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
        O4 - HKCU\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe
        O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-58-12-0000080.exe
        O4 - HKCU\..\Run: [Steam] "c:\program files\zteam\steam.exe" -silent
        O4 - HKCU\..\Run: [MessengerDiscovery] C:\Program Files\MessengerDiscovery\msgdiscoveryx.exe
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
        O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O9 - Extra button: Lyric Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)
        O9 - Extra 'Tools' menuitem: Lyric Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi
        O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
        O16 - DPF: {5BDBD95C-1E7F-4FB1-8497-20AF879F8B68} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/fi/filesharingctrl.cab
        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
        O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
        O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
        O23 - Service: Sonera Tietoturva (BackWeb Plug-in - 4436233) - Unknown owner - C:\PROGRA~1\SONERA~1\backweb\4436233\Program\SERVIC~1.EXE
        O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\Sonera Tietoturva\Anti-Virus\fsgk32st.exe
        O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\Sonera Tietoturva\backweb\4436233\program\fsbwsys.exe
        O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Sonera Tietoturva\FWES\Program\fsdfwd.exe
        O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Sonera Tietoturva\Common\FSMA32.EXE
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe

        Lataa smitrem työpöydälle

        http://noahdfear.geekstogo.com/click counter/click.php?id=1

        Tuplaklikkaa sitä ja Start niin saat smitrem kansion työpöydälle .

        Ota tuo työpöydälle

        http://www.bleepingcomputer.com/files/reg/FixSF.reg

        Sitte tuplaklikkaa sitä ja vastaa myöntävästi.

        Käynnistä sitte kone vikasietotilassa.

        Mee ohjauspaneeliin ja poista

        MessengerPlus3
        SpyFalcon

        jos SpyFalcon käskee käynnistää koneen uudestaan älä käynnistä.

        Sitte poista piilotiedostot näkyvillä

        C :\Windows\System32\dxmpp.dll
        C:\Program Files\SpyFalcon\ < kansio
        -voi olla että ei löydy

        Sen jälkeen avaa smitrem kansio ja tuplaklikkaa RunThis.bat ja seuraa ohjeita.
        Käynnistä sitte normaalisti ja lähetä uus Hijack logi, ja C:\smitfiles.txt logi


      • Apuvaa...
        Juu kirjoitti:

        Lataa smitrem työpöydälle

        http://noahdfear.geekstogo.com/click counter/click.php?id=1

        Tuplaklikkaa sitä ja Start niin saat smitrem kansion työpöydälle .

        Ota tuo työpöydälle

        http://www.bleepingcomputer.com/files/reg/FixSF.reg

        Sitte tuplaklikkaa sitä ja vastaa myöntävästi.

        Käynnistä sitte kone vikasietotilassa.

        Mee ohjauspaneeliin ja poista

        MessengerPlus3
        SpyFalcon

        jos SpyFalcon käskee käynnistää koneen uudestaan älä käynnistä.

        Sitte poista piilotiedostot näkyvillä

        C :\Windows\System32\dxmpp.dll
        C:\Program Files\SpyFalcon\ < kansio
        -voi olla että ei löydy

        Sen jälkeen avaa smitrem kansio ja tuplaklikkaa RunThis.bat ja seuraa ohjeita.
        Käynnistä sitte normaalisti ja lähetä uus Hijack logi, ja C:\smitfiles.txt logi

        Noniin, eli ei löytynyt tuota C:\Windows\System32\dxmpp.dll mutta se toinen löytyi ja poistin.

        Tässä hijack logi:

        Logfile of HijackThis v1.99.1
        Scan saved at 21:35:58, on 12.2.2006
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Sonera Tietoturva\Common\FSM32.EXE
        C:\WINDOWS\ATKKBService.exe
        C:\PROGRA~1\SONERA~1\backweb\4436233\Program\SERVIC~1.EXE
        C:\Program Files\Sonera Tietoturva\FSGUI\ispnews.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\Sonera Tietoturva\Anti-Virus\fsgk32st.exe
        C:\Program Files\Sonera Tietoturva\Anti-Virus\FSGK32.EXE
        C:\Program Files\Sonera Tietoturva\backweb\4436233\Program\fspex.exe
        C:\WINDOWS\system32\31cdg1lm.exe
        C:\Program Files\Sonera Tietoturva\backweb\4436233\program\fsbwsys.exe
        C:\Program Files\Sonera Tietoturva\Common\FSMA32.EXE
        C:\Program Files\Network\network.exe
        C:\Program Files\Sonera Tietoturva\Anti-Virus\fssm32.exe
        C:\Program Files\Sonera Tietoturva\Common\FSMB32.EXE
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Sonera Tietoturva\Common\FCH32.EXE
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Messenger\Msmsgs.exe
        C:\Program Files\Sonera Tietoturva\Common\FAMEH32.EXE
        C:\Program Files\Sonera Tietoturva\FWES\Program\fsdfwd.exe
        C:\WINDOWS\system32\sessmgr.exe
        C:\Program Files\Sonera Tietoturva\Anti-Virus\fsav32.exe
        C:\Program Files\MSN Messenger\msnmsgr.exe
        C:\Program Files\Sonera Tietoturva\FSGUI\fsguiexe.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\WINDOWS\system32\RDSHOST.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpCtr.exe
        C:\HjT\HijackThis.exe

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soneraplaza.fi
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Sonera Internet
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O3 - Toolbar: Lyric Bar - {9AD83196-4AF7-4f08-8C6F-B763DB67F2D9} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)
        O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Sonera Tietoturva\Common\FSM32.EXE" /splash
        O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Sonera Tietoturva\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
        O4 - HKLM\..\Run: [News Service] "C:\Program Files\Sonera Tietoturva\FSGUI\ispnews.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [blah cast eq ooze] C:\Documents and Settings\All Users\Application Data\HoleOkayBlahCast\film fork.exe
        O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
        O4 - HKLM\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe
        O4 - HKLM\..\Run: [Microsoft Update 64 BIT] winman32.exe
        O4 - HKLM\..\Run: [31cdg1lm] C:\WINDOWS\system32\31cdg1lm.exe
        O4 - HKLM\..\Run: [System service62] C:\WINDOWS\etb\pokapoka63.exe
        O4 - HKLM\..\Run: [System service63] C:\WINDOWS\etb\pokapoka63.exe
        O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
        O4 - HKLM\..\Run: [Network] C:\Program Files\Network\network.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\RunServices: [Microsoft Windows DLL Services Configuration] windir32.exe
        O4 - HKLM\..\RunServices: [Microsoft Update 64 BIT] winman32.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe /start
        O4 - HKCU\..\Run: [Nurb Platform] C:\DOCUME~1\Tero\APPLIC~1\CHICNE~1\Fordmorefirst.exe
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
        O4 - HKCU\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe
        O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-58-12-0000080.exe
        O4 - HKCU\..\Run: [Steam] "c:\program files\zteam\steam.exe" -silent
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
        O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O9 - Extra button: Lyric Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)
        O9 - Extra 'Tools' menuitem: Lyric Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi
        O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
        O16 - DPF: {5BDBD95C-1E7F-4FB1-8497-20AF879F8B68} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/fi/filesharingctrl.cab
        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
        O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
        O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
        O23 - Service: Sonera Tietoturva (BackWeb Plug-in - 4436233) - Unknown owner - C:\PROGRA~1\SONERA~1\backweb\4436233\Program\SERVIC~1.EXE
        O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\Sonera Tietoturva\Anti-Virus\fsgk32st.exe
        O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\Sonera Tietoturva\backweb\4436233\program\fsbwsys.exe
        O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Sonera Tietoturva\FWES\Program\fsdfwd.exe
        O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Sonera Tietoturva\Common\FSMA32.EXE
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe



        Tässä smitfiles.txt:


        smitRem © log file
        version 2.8

        by noahdfear


        Microsoft Windows XP [versio 5.1.2600]

        Running from
        C:\Documents and Settings\Tero\Ty”p”yt„\smitRem

        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        Pre-run SharedTask Export

        (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
        Copyright(C) 2006 BleepingComputer.com

        Registry Pseudo-Format Mode (Not a valid reg file):

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
        "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
        "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
        @="%SystemRoot%\system32\browseui.dll"


        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
        @="%SystemRoot%\system32\browseui.dll"


        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        checking for ShudderLTD key

        ShudderLTD key not present!

        checking for PSGuard.com key


        PSGuard.com key not present!


        checking for WinHound.com key


        WinHound.com key not present!

        spyaxe uninstaller NOT present
        Winhound uninstaller NOT present
        SpywareStrike uninstaller NOT present

        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        Existing Pre-run Files


        ~~~ Program Files ~~~



        ~~~ Shortcuts ~~~



        ~~~ Favorites ~~~



        ~~~ system32 folder ~~~

        1024 dir
        msvol.tlb
        ld****.tmp
        mssearchnet.exe
        ncompat.tlb
        nvctrl.exe
        mscornet.exe
        hp***.tmp


        ~~~ Icons in System32 ~~~

        ts.ico
        ot.ico


        ~~~ Windows directory ~~~



        ~~~ Drive root ~~~


        ~~~ Miscellaneous Files/folders ~~~




        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
        Copyright(C) 2002-2003 [email protected]
        Killing PID 788 'explorer.exe'

        Starting registry repairs

        Registry repairs complete

        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        SharedTask Export after registry fix

        (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
        Copyright(C) 2006 BleepingComputer.com

        Registry Pseudo-Format Mode (Not a valid reg file):

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
        "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
        "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
        @="%SystemRoot%\system32\browseui.dll"


        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
        @="%SystemRoot%\system32\browseui.dll"


        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        Deleting files

        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        Remaining Post-run Files


        ~~~ Program Files ~~~



        ~~~ Shortcuts ~~~



        ~~~ Favorites ~~~



        ~~~ system32 folder ~~~



        ~~~ Icons in System32 ~~~



        ~~~ Windows directory ~~~



        ~~~ Drive root ~~~


        ~~~ Miscellaneous Files/folders ~~~


        ~~~ Wininet.dll ~~~

        CLEAN! :)


      • Juu
        Apuvaa... kirjoitti:

        Noniin, eli ei löytynyt tuota C:\Windows\System32\dxmpp.dll mutta se toinen löytyi ja poistin.

        Tässä hijack logi:

        Logfile of HijackThis v1.99.1
        Scan saved at 21:35:58, on 12.2.2006
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Sonera Tietoturva\Common\FSM32.EXE
        C:\WINDOWS\ATKKBService.exe
        C:\PROGRA~1\SONERA~1\backweb\4436233\Program\SERVIC~1.EXE
        C:\Program Files\Sonera Tietoturva\FSGUI\ispnews.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\Sonera Tietoturva\Anti-Virus\fsgk32st.exe
        C:\Program Files\Sonera Tietoturva\Anti-Virus\FSGK32.EXE
        C:\Program Files\Sonera Tietoturva\backweb\4436233\Program\fspex.exe
        C:\WINDOWS\system32\31cdg1lm.exe
        C:\Program Files\Sonera Tietoturva\backweb\4436233\program\fsbwsys.exe
        C:\Program Files\Sonera Tietoturva\Common\FSMA32.EXE
        C:\Program Files\Network\network.exe
        C:\Program Files\Sonera Tietoturva\Anti-Virus\fssm32.exe
        C:\Program Files\Sonera Tietoturva\Common\FSMB32.EXE
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Sonera Tietoturva\Common\FCH32.EXE
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Messenger\Msmsgs.exe
        C:\Program Files\Sonera Tietoturva\Common\FAMEH32.EXE
        C:\Program Files\Sonera Tietoturva\FWES\Program\fsdfwd.exe
        C:\WINDOWS\system32\sessmgr.exe
        C:\Program Files\Sonera Tietoturva\Anti-Virus\fsav32.exe
        C:\Program Files\MSN Messenger\msnmsgr.exe
        C:\Program Files\Sonera Tietoturva\FSGUI\fsguiexe.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\WINDOWS\system32\RDSHOST.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpCtr.exe
        C:\HjT\HijackThis.exe

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soneraplaza.fi
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Sonera Internet
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O3 - Toolbar: Lyric Bar - {9AD83196-4AF7-4f08-8C6F-B763DB67F2D9} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)
        O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Sonera Tietoturva\Common\FSM32.EXE" /splash
        O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Sonera Tietoturva\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
        O4 - HKLM\..\Run: [News Service] "C:\Program Files\Sonera Tietoturva\FSGUI\ispnews.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [blah cast eq ooze] C:\Documents and Settings\All Users\Application Data\HoleOkayBlahCast\film fork.exe
        O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
        O4 - HKLM\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe
        O4 - HKLM\..\Run: [Microsoft Update 64 BIT] winman32.exe
        O4 - HKLM\..\Run: [31cdg1lm] C:\WINDOWS\system32\31cdg1lm.exe
        O4 - HKLM\..\Run: [System service62] C:\WINDOWS\etb\pokapoka63.exe
        O4 - HKLM\..\Run: [System service63] C:\WINDOWS\etb\pokapoka63.exe
        O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
        O4 - HKLM\..\Run: [Network] C:\Program Files\Network\network.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\RunServices: [Microsoft Windows DLL Services Configuration] windir32.exe
        O4 - HKLM\..\RunServices: [Microsoft Update 64 BIT] winman32.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe /start
        O4 - HKCU\..\Run: [Nurb Platform] C:\DOCUME~1\Tero\APPLIC~1\CHICNE~1\Fordmorefirst.exe
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
        O4 - HKCU\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe
        O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-58-12-0000080.exe
        O4 - HKCU\..\Run: [Steam] "c:\program files\zteam\steam.exe" -silent
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
        O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O9 - Extra button: Lyric Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)
        O9 - Extra 'Tools' menuitem: Lyric Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi
        O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
        O16 - DPF: {5BDBD95C-1E7F-4FB1-8497-20AF879F8B68} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/fi/filesharingctrl.cab
        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
        O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
        O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
        O23 - Service: Sonera Tietoturva (BackWeb Plug-in - 4436233) - Unknown owner - C:\PROGRA~1\SONERA~1\backweb\4436233\Program\SERVIC~1.EXE
        O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\Sonera Tietoturva\Anti-Virus\fsgk32st.exe
        O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\Sonera Tietoturva\backweb\4436233\program\fsbwsys.exe
        O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Sonera Tietoturva\FWES\Program\fsdfwd.exe
        O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Sonera Tietoturva\Common\FSMA32.EXE
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe



        Tässä smitfiles.txt:


        smitRem © log file
        version 2.8

        by noahdfear


        Microsoft Windows XP [versio 5.1.2600]

        Running from
        C:\Documents and Settings\Tero\Ty”p”yt„\smitRem

        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        Pre-run SharedTask Export

        (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
        Copyright(C) 2006 BleepingComputer.com

        Registry Pseudo-Format Mode (Not a valid reg file):

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
        "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
        "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
        @="%SystemRoot%\system32\browseui.dll"


        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
        @="%SystemRoot%\system32\browseui.dll"


        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        checking for ShudderLTD key

        ShudderLTD key not present!

        checking for PSGuard.com key


        PSGuard.com key not present!


        checking for WinHound.com key


        WinHound.com key not present!

        spyaxe uninstaller NOT present
        Winhound uninstaller NOT present
        SpywareStrike uninstaller NOT present

        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        Existing Pre-run Files


        ~~~ Program Files ~~~



        ~~~ Shortcuts ~~~



        ~~~ Favorites ~~~



        ~~~ system32 folder ~~~

        1024 dir
        msvol.tlb
        ld****.tmp
        mssearchnet.exe
        ncompat.tlb
        nvctrl.exe
        mscornet.exe
        hp***.tmp


        ~~~ Icons in System32 ~~~

        ts.ico
        ot.ico


        ~~~ Windows directory ~~~



        ~~~ Drive root ~~~


        ~~~ Miscellaneous Files/folders ~~~




        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
        Copyright(C) 2002-2003 [email protected]
        Killing PID 788 'explorer.exe'

        Starting registry repairs

        Registry repairs complete

        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        SharedTask Export after registry fix

        (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
        Copyright(C) 2006 BleepingComputer.com

        Registry Pseudo-Format Mode (Not a valid reg file):

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
        "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
        "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
        @="%SystemRoot%\system32\browseui.dll"


        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
        @="%SystemRoot%\system32\browseui.dll"


        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        Deleting files

        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        Remaining Post-run Files


        ~~~ Program Files ~~~



        ~~~ Shortcuts ~~~



        ~~~ Favorites ~~~



        ~~~ system32 folder ~~~



        ~~~ Icons in System32 ~~~



        ~~~ Windows directory ~~~



        ~~~ Drive root ~~~


        ~~~ Miscellaneous Files/folders ~~~


        ~~~ Wininet.dll ~~~

        CLEAN! :)

        Kyllä ne örvelöt pikkuhiljaa vähenee.
        Scannaa nuo yksitellen tuolla ja ilmoita tulokset

        C:\WINDOWS\system32\31cdg1lm.exe
        C:\Program Files\Network\network.exe

        http://virusscan.jotti.org/


      • Apuvaa...
        Juu kirjoitti:

        Kyllä ne örvelöt pikkuhiljaa vähenee.
        Scannaa nuo yksitellen tuolla ja ilmoita tulokset

        C:\WINDOWS\system32\31cdg1lm.exe
        C:\Program Files\Network\network.exe

        http://virusscan.jotti.org/

        Tarkoitikohan näitä tuloksia?

        File: network.exe
        Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
        MD5 72f91f50d4315411cf79a3cb6a02c2fe
        Packers detected: -
        Scanner results
        AntiVir Found nothing
        ArcaVir Found nothing
        Avast Found nothing
        AVG Antivirus Found nothing
        BitDefender Found nothing
        ClamAV Found nothing
        Dr.Web Found Trojan.DownLoader.6610
        F-Prot Antivirus Found nothing
        Fortinet Found Dloader.H!tr
        Kaspersky Anti-Virus Found not-a-virus:AdWare.Win32.Maxifiles.y
        NOD32 Found probably unknown WIN32 (probable variant)
        Norman Virus Control Found nothing
        UNA Found Adware.Maxifiles
        VBA32 Found AdWare.Win32.Maxifiles.y

        Ja

        File: 31cdg1lm.exe
        Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
        MD5 681523655b8a5436484d03cbf5aec59d
        Packers detected: -
        Scanner results
        AntiVir Found nothing
        ArcaVir Found nothing
        Avast Found Win32:Adan-003
        AVG Antivirus Found nothing
        BitDefender Found nothing
        ClamAV Found Adware.Shopathome
        Dr.Web Found Adware.SAHAgent
        F-Prot Antivirus Found nothing
        Fortinet Found Adware/ShopAtHomeSelect
        Kaspersky Anti-Virus Found not-a-virus:AdWare.Win32.Sahat.au
        NOD32 Found nothing
        Norman Virus Control Found nothing
        UNA Found nothing
        VBA32 Found AdWare.Win32.Sahat.au


      • Juu
        Apuvaa... kirjoitti:

        Noniin, eli ei löytynyt tuota C:\Windows\System32\dxmpp.dll mutta se toinen löytyi ja poistin.

        Tässä hijack logi:

        Logfile of HijackThis v1.99.1
        Scan saved at 21:35:58, on 12.2.2006
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Sonera Tietoturva\Common\FSM32.EXE
        C:\WINDOWS\ATKKBService.exe
        C:\PROGRA~1\SONERA~1\backweb\4436233\Program\SERVIC~1.EXE
        C:\Program Files\Sonera Tietoturva\FSGUI\ispnews.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\Sonera Tietoturva\Anti-Virus\fsgk32st.exe
        C:\Program Files\Sonera Tietoturva\Anti-Virus\FSGK32.EXE
        C:\Program Files\Sonera Tietoturva\backweb\4436233\Program\fspex.exe
        C:\WINDOWS\system32\31cdg1lm.exe
        C:\Program Files\Sonera Tietoturva\backweb\4436233\program\fsbwsys.exe
        C:\Program Files\Sonera Tietoturva\Common\FSMA32.EXE
        C:\Program Files\Network\network.exe
        C:\Program Files\Sonera Tietoturva\Anti-Virus\fssm32.exe
        C:\Program Files\Sonera Tietoturva\Common\FSMB32.EXE
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Sonera Tietoturva\Common\FCH32.EXE
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Messenger\Msmsgs.exe
        C:\Program Files\Sonera Tietoturva\Common\FAMEH32.EXE
        C:\Program Files\Sonera Tietoturva\FWES\Program\fsdfwd.exe
        C:\WINDOWS\system32\sessmgr.exe
        C:\Program Files\Sonera Tietoturva\Anti-Virus\fsav32.exe
        C:\Program Files\MSN Messenger\msnmsgr.exe
        C:\Program Files\Sonera Tietoturva\FSGUI\fsguiexe.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\WINDOWS\system32\RDSHOST.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpCtr.exe
        C:\HjT\HijackThis.exe

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soneraplaza.fi
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Sonera Internet
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O3 - Toolbar: Lyric Bar - {9AD83196-4AF7-4f08-8C6F-B763DB67F2D9} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)
        O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Sonera Tietoturva\Common\FSM32.EXE" /splash
        O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Sonera Tietoturva\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
        O4 - HKLM\..\Run: [News Service] "C:\Program Files\Sonera Tietoturva\FSGUI\ispnews.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [blah cast eq ooze] C:\Documents and Settings\All Users\Application Data\HoleOkayBlahCast\film fork.exe
        O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
        O4 - HKLM\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe
        O4 - HKLM\..\Run: [Microsoft Update 64 BIT] winman32.exe
        O4 - HKLM\..\Run: [31cdg1lm] C:\WINDOWS\system32\31cdg1lm.exe
        O4 - HKLM\..\Run: [System service62] C:\WINDOWS\etb\pokapoka63.exe
        O4 - HKLM\..\Run: [System service63] C:\WINDOWS\etb\pokapoka63.exe
        O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
        O4 - HKLM\..\Run: [Network] C:\Program Files\Network\network.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\RunServices: [Microsoft Windows DLL Services Configuration] windir32.exe
        O4 - HKLM\..\RunServices: [Microsoft Update 64 BIT] winman32.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe /start
        O4 - HKCU\..\Run: [Nurb Platform] C:\DOCUME~1\Tero\APPLIC~1\CHICNE~1\Fordmorefirst.exe
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
        O4 - HKCU\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe
        O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-58-12-0000080.exe
        O4 - HKCU\..\Run: [Steam] "c:\program files\zteam\steam.exe" -silent
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
        O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O9 - Extra button: Lyric Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)
        O9 - Extra 'Tools' menuitem: Lyric Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi
        O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
        O16 - DPF: {5BDBD95C-1E7F-4FB1-8497-20AF879F8B68} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/fi/filesharingctrl.cab
        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
        O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
        O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
        O23 - Service: Sonera Tietoturva (BackWeb Plug-in - 4436233) - Unknown owner - C:\PROGRA~1\SONERA~1\backweb\4436233\Program\SERVIC~1.EXE
        O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\Sonera Tietoturva\Anti-Virus\fsgk32st.exe
        O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\Sonera Tietoturva\backweb\4436233\program\fsbwsys.exe
        O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Sonera Tietoturva\FWES\Program\fsdfwd.exe
        O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Sonera Tietoturva\Common\FSMA32.EXE
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe



        Tässä smitfiles.txt:


        smitRem © log file
        version 2.8

        by noahdfear


        Microsoft Windows XP [versio 5.1.2600]

        Running from
        C:\Documents and Settings\Tero\Ty”p”yt„\smitRem

        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        Pre-run SharedTask Export

        (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
        Copyright(C) 2006 BleepingComputer.com

        Registry Pseudo-Format Mode (Not a valid reg file):

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
        "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
        "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
        @="%SystemRoot%\system32\browseui.dll"


        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
        @="%SystemRoot%\system32\browseui.dll"


        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        checking for ShudderLTD key

        ShudderLTD key not present!

        checking for PSGuard.com key


        PSGuard.com key not present!


        checking for WinHound.com key


        WinHound.com key not present!

        spyaxe uninstaller NOT present
        Winhound uninstaller NOT present
        SpywareStrike uninstaller NOT present

        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        Existing Pre-run Files


        ~~~ Program Files ~~~



        ~~~ Shortcuts ~~~



        ~~~ Favorites ~~~



        ~~~ system32 folder ~~~

        1024 dir
        msvol.tlb
        ld****.tmp
        mssearchnet.exe
        ncompat.tlb
        nvctrl.exe
        mscornet.exe
        hp***.tmp


        ~~~ Icons in System32 ~~~

        ts.ico
        ot.ico


        ~~~ Windows directory ~~~



        ~~~ Drive root ~~~


        ~~~ Miscellaneous Files/folders ~~~




        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
        Copyright(C) 2002-2003 [email protected]
        Killing PID 788 'explorer.exe'

        Starting registry repairs

        Registry repairs complete

        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        SharedTask Export after registry fix

        (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
        Copyright(C) 2006 BleepingComputer.com

        Registry Pseudo-Format Mode (Not a valid reg file):

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
        "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
        "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
        @="%SystemRoot%\system32\browseui.dll"


        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
        @="%SystemRoot%\system32\browseui.dll"


        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        Deleting files

        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

        Remaining Post-run Files


        ~~~ Program Files ~~~



        ~~~ Shortcuts ~~~



        ~~~ Favorites ~~~



        ~~~ system32 folder ~~~



        ~~~ Icons in System32 ~~~



        ~~~ Windows directory ~~~



        ~~~ Drive root ~~~


        ~~~ Miscellaneous Files/folders ~~~


        ~~~ Wininet.dll ~~~

        CLEAN! :)

        Merkkaa nuo sulje selain ja paina Fix checked

        O3 - Toolbar: Lyric Bar - {9AD83196-4AF7-4f08-8C6F-B763DB67F2D9} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)
        O4 - HKLM\..\Run: [blah cast eq ooze] C:\Documents and Settings\All Users\Application Data\HoleOkayBlahCast\film fork.exe
        O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
        O4 - HKLM\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe
        O4 - HKLM\..\Run: [Microsoft Update 64 BIT] winman32.exe
        O4 - HKLM\..\Run: [31cdg1lm] C:\WINDOWS\system32\31cdg1lm.exe
        O4 - HKLM\..\Run: [System service62] C:\WINDOWS\etb\pokapoka63.exe
        O4 - HKLM\..\Run: [System service63] C:\WINDOWS\etb\pokapoka63.exe
        O4 - HKLM\..\Run: [Network] C:\Program Files\Network\network.exe
        O4 - HKLM\..\RunServices: [Microsoft Windows DLL Services Configuration] windir32.exe
        O4 - HKLM\..\RunServices: [Microsoft Update 64 BIT] winman32.exe
        O4 - HKCU\..\Run: [Nurb Platform] C:\DOCUME~1\Tero\APPLIC~1\CHICNE~1\Fordmorefirst.exe
        O4 - HKCU\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe
        O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-58-12-0000080.exe
        O9 - Extra button: Lyric Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)
        O9 - Extra 'Tools' menuitem: Lyric Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)


        Käynnistä sitte vikasietotilassa ja poista piilotiedostot näkyvillä

        C:\WINDOWS\system32\31cdg1lm.exe
        C:\Program Files\Network\network.exe
        - tai koko tuo Network kansio jos siellä ei ole muuta järkevää\tarpeellista
        C:\Program Files\Common Files\Windows\mc-58-12-0000080.exe

        C:\Documents and Settings\All Users\Application Data\HoleOkayBlahCast\ < kansio
        C:\DOCUME~1\Tero\APPLIC~1\CHICNE~1\ < kansio

        Älä käytä Etsi toimintoo noitten kansioiden haussa vaan seuraa noita polkuja.

        Käynnistä sitte normaalisti.

        Ota LQfix.exe työpöydälle

        http://www.downloads.subratam.org/LQfix.exe

        * Tupla-klikkaa LQfix.exe ja klikkaa Next > Next > Install.
        * Jätä asetukset kuten ne on, jos vaihdat ne, korjaus epäonnistuu!
        * Tarvitset aktiivisen Internet-yhteyden, joten varmista ettet ole estämässä mitään yhteyttä nyt.
        * Varmista että "Launch LQfix" boxi on rastitettu.
        * Klikkaa Finish valintaa, fixi alkaa.
        * Seuraa ohjeita screeniltä.
        * Koneesi käynnistyy uusiksi kun työkalu on fixannut.
        * Ole kärsivällinen uudelleenkäynnistymisen jälkeen, taustalla on scripti käynnissä

        Lähetä uus Hijack logi sen jälkeen.


      • Apuvaa...
        Juu kirjoitti:

        Merkkaa nuo sulje selain ja paina Fix checked

        O3 - Toolbar: Lyric Bar - {9AD83196-4AF7-4f08-8C6F-B763DB67F2D9} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)
        O4 - HKLM\..\Run: [blah cast eq ooze] C:\Documents and Settings\All Users\Application Data\HoleOkayBlahCast\film fork.exe
        O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
        O4 - HKLM\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe
        O4 - HKLM\..\Run: [Microsoft Update 64 BIT] winman32.exe
        O4 - HKLM\..\Run: [31cdg1lm] C:\WINDOWS\system32\31cdg1lm.exe
        O4 - HKLM\..\Run: [System service62] C:\WINDOWS\etb\pokapoka63.exe
        O4 - HKLM\..\Run: [System service63] C:\WINDOWS\etb\pokapoka63.exe
        O4 - HKLM\..\Run: [Network] C:\Program Files\Network\network.exe
        O4 - HKLM\..\RunServices: [Microsoft Windows DLL Services Configuration] windir32.exe
        O4 - HKLM\..\RunServices: [Microsoft Update 64 BIT] winman32.exe
        O4 - HKCU\..\Run: [Nurb Platform] C:\DOCUME~1\Tero\APPLIC~1\CHICNE~1\Fordmorefirst.exe
        O4 - HKCU\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe
        O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-58-12-0000080.exe
        O9 - Extra button: Lyric Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)
        O9 - Extra 'Tools' menuitem: Lyric Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\RARELY~1\Toolbar\lyricbar.dll (file missing)


        Käynnistä sitte vikasietotilassa ja poista piilotiedostot näkyvillä

        C:\WINDOWS\system32\31cdg1lm.exe
        C:\Program Files\Network\network.exe
        - tai koko tuo Network kansio jos siellä ei ole muuta järkevää\tarpeellista
        C:\Program Files\Common Files\Windows\mc-58-12-0000080.exe

        C:\Documents and Settings\All Users\Application Data\HoleOkayBlahCast\ < kansio
        C:\DOCUME~1\Tero\APPLIC~1\CHICNE~1\ < kansio

        Älä käytä Etsi toimintoo noitten kansioiden haussa vaan seuraa noita polkuja.

        Käynnistä sitte normaalisti.

        Ota LQfix.exe työpöydälle

        http://www.downloads.subratam.org/LQfix.exe

        * Tupla-klikkaa LQfix.exe ja klikkaa Next > Next > Install.
        * Jätä asetukset kuten ne on, jos vaihdat ne, korjaus epäonnistuu!
        * Tarvitset aktiivisen Internet-yhteyden, joten varmista ettet ole estämässä mitään yhteyttä nyt.
        * Varmista että "Launch LQfix" boxi on rastitettu.
        * Klikkaa Finish valintaa, fixi alkaa.
        * Seuraa ohjeita screeniltä.
        * Koneesi käynnistyy uusiksi kun työkalu on fixannut.
        * Ole kärsivällinen uudelleenkäynnistymisen jälkeen, taustalla on scripti käynnissä

        Lähetä uus Hijack logi sen jälkeen.

        Noniin taas jatkuu...
        Ei löytynyt tuota C:\Program Files\Common Files\Windows\mc-58-12-0000080.exe
        Muut löytyivät kyllä.

        Tässä uusi logi:

        Logfile of HijackThis v1.99.1
        Scan saved at 16:05:19, on 13.2.2006
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\ATKKBService.exe
        C:\PROGRA~1\SONERA~1\backweb\4436233\Program\SERVIC~1.EXE
        C:\Program Files\Sonera Tietoturva\Anti-Virus\fsgk32st.exe
        C:\Program Files\Sonera Tietoturva\backweb\4436233\program\fsbwsys.exe
        C:\Program Files\Sonera Tietoturva\Anti-Virus\FSGK32.EXE
        C:\Program Files\Sonera Tietoturva\Common\FSMA32.EXE
        C:\Program Files\Sonera Tietoturva\backweb\4436233\Program\fspex.exe
        C:\Program Files\Sonera Tietoturva\Anti-Virus\fssm32.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Program Files\Sonera Tietoturva\Common\FSMB32.EXE
        C:\WINDOWS\system32\slserv.exe
        C:\Program Files\Sonera Tietoturva\Common\FCH32.EXE
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Sonera Tietoturva\Common\FAMEH32.EXE
        C:\Program Files\Sonera Tietoturva\Anti-Virus\fsav32.exe
        C:\Program Files\Sonera Tietoturva\FWES\Program\fsdfwd.exe
        C:\Program Files\Sonera Tietoturva\Common\FSM32.EXE
        C:\WINDOWS\system32\sessmgr.exe
        C:\Program Files\Sonera Tietoturva\FSGUI\ispnews.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Messenger\Msmsgs.exe
        C:\program files\zteam\steam.exe
        C:\Program Files\MSN Messenger\msnmsgr.exe
        C:\Program Files\Sonera Tietoturva\FSGUI\fsguiexe.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\WINDOWS\system32\RDSHOST.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpCtr.exe
        C:\HjT\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soneraplaza.fi
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Sonera Internet
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Sonera Tietoturva\Common\FSM32.EXE" /splash
        O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Sonera Tietoturva\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
        O4 - HKLM\..\Run: [News Service] "C:\Program Files\Sonera Tietoturva\FSGUI\ispnews.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe /start
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
        O4 - HKCU\..\Run: [Steam] "c:\program files\zteam\steam.exe" -silent
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
        O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi
        O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
        O16 - DPF: {5BDBD95C-1E7F-4FB1-8497-20AF879F8B68} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/fi/filesharingctrl.cab
        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
        O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
        O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
        O23 - Service: Sonera Tietoturva (BackWeb Plug-in - 4436233) - Unknown owner - C:\PROGRA~1\SONERA~1\backweb\4436233\Program\SERVIC~1.EXE
        O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\Sonera Tietoturva\Anti-Virus\fsgk32st.exe
        O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\Sonera Tietoturva\backweb\4436233\program\fsbwsys.exe
        O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Sonera Tietoturva\FWES\Program\fsdfwd.exe
        O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Sonera Tietoturva\Common\FSMA32.EXE
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe


      • Juu
        Apuvaa... kirjoitti:

        Noniin taas jatkuu...
        Ei löytynyt tuota C:\Program Files\Common Files\Windows\mc-58-12-0000080.exe
        Muut löytyivät kyllä.

        Tässä uusi logi:

        Logfile of HijackThis v1.99.1
        Scan saved at 16:05:19, on 13.2.2006
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\ATKKBService.exe
        C:\PROGRA~1\SONERA~1\backweb\4436233\Program\SERVIC~1.EXE
        C:\Program Files\Sonera Tietoturva\Anti-Virus\fsgk32st.exe
        C:\Program Files\Sonera Tietoturva\backweb\4436233\program\fsbwsys.exe
        C:\Program Files\Sonera Tietoturva\Anti-Virus\FSGK32.EXE
        C:\Program Files\Sonera Tietoturva\Common\FSMA32.EXE
        C:\Program Files\Sonera Tietoturva\backweb\4436233\Program\fspex.exe
        C:\Program Files\Sonera Tietoturva\Anti-Virus\fssm32.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Program Files\Sonera Tietoturva\Common\FSMB32.EXE
        C:\WINDOWS\system32\slserv.exe
        C:\Program Files\Sonera Tietoturva\Common\FCH32.EXE
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Sonera Tietoturva\Common\FAMEH32.EXE
        C:\Program Files\Sonera Tietoturva\Anti-Virus\fsav32.exe
        C:\Program Files\Sonera Tietoturva\FWES\Program\fsdfwd.exe
        C:\Program Files\Sonera Tietoturva\Common\FSM32.EXE
        C:\WINDOWS\system32\sessmgr.exe
        C:\Program Files\Sonera Tietoturva\FSGUI\ispnews.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Messenger\Msmsgs.exe
        C:\program files\zteam\steam.exe
        C:\Program Files\MSN Messenger\msnmsgr.exe
        C:\Program Files\Sonera Tietoturva\FSGUI\fsguiexe.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\WINDOWS\system32\RDSHOST.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpCtr.exe
        C:\HjT\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.soneraplaza.fi
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Sonera Internet
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Sonera Tietoturva\Common\FSM32.EXE" /splash
        O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Sonera Tietoturva\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
        O4 - HKLM\..\Run: [News Service] "C:\Program Files\Sonera Tietoturva\FSGUI\ispnews.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe /start
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
        O4 - HKCU\..\Run: [Steam] "c:\program files\zteam\steam.exe" -silent
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
        O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi
        O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
        O16 - DPF: {5BDBD95C-1E7F-4FB1-8497-20AF879F8B68} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/fi/filesharingctrl.cab
        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
        O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
        O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
        O23 - Service: Sonera Tietoturva (BackWeb Plug-in - 4436233) - Unknown owner - C:\PROGRA~1\SONERA~1\backweb\4436233\Program\SERVIC~1.EXE
        O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\Sonera Tietoturva\Anti-Virus\fsgk32st.exe
        O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\Sonera Tietoturva\backweb\4436233\program\fsbwsys.exe
        O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Sonera Tietoturva\FWES\Program\fsdfwd.exe
        O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Sonera Tietoturva\Common\FSMA32.EXE
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe

        Logi on ok,mutta aja vielä varalta tuo

        Hae aproposfix

        http://swandog46.geekstogo.com/aproposfix.exe

        säästä se työpöydälle
        Käynnistä sitte kone vikasietotilassa ja pura se työpöydälle.
        Sitte tuplaklikkaa RunThis.bat ja seuraa ohjeita.
        Ku se on valmiiks ajettu niin käynnistä normaalisti ja lähetä sen logi = log.txt


      • Apuvaa...
        Juu kirjoitti:

        Logi on ok,mutta aja vielä varalta tuo

        Hae aproposfix

        http://swandog46.geekstogo.com/aproposfix.exe

        säästä se työpöydälle
        Käynnistä sitte kone vikasietotilassa ja pura se työpöydälle.
        Sitte tuplaklikkaa RunThis.bat ja seuraa ohjeita.
        Ku se on valmiiks ajettu niin käynnistä normaalisti ja lähetä sen logi = log.txt

        Tässä tämä logi:

        Log of AproposFix v1.1

        ************

        Running from directory:
        C:\Documents and Settings\Tero\Ty”p”yt„\aproposfix

        ************



        Registry entries found:


        ************

        No service found!

        Removing hidden folder:
        No folder found!

        Deleting files:


        Backing up files:
        Done!

        Removing registry entries:

        REGEDIT4


        Done!

        Finished!


      • Juu
        Apuvaa... kirjoitti:

        Tässä tämä logi:

        Log of AproposFix v1.1

        ************

        Running from directory:
        C:\Documents and Settings\Tero\Ty”p”yt„\aproposfix

        ************



        Registry entries found:


        ************

        No service found!

        Removing hidden folder:
        No folder found!

        Deleting files:


        Backing up files:
        Done!

        Removing registry entries:

        REGEDIT4


        Done!

        Finished!

        Ei ollu mitään,ja viimesin Hijack logi oli ok joten homma selvä,login perusteella.


      • Apuvaa...
        Juu kirjoitti:

        Ei ollu mitään,ja viimesin Hijack logi oli ok joten homma selvä,login perusteella.

        Todella ISO kiitos sinulle!! Kaikki ilmoitukset sun muut härpäkät hävisivät. Ei tee enää virheilmoituksia eikä varoittele jatkuvasti ja nyt jopa netissäkin pääsee sinne mihin on tarkoituskin.


    Ketjusta on poistettu 0 sääntöjenvastaista viestiä.

    Luetuimmat keskustelut

    1. Virkamiehille tarvitaan tuntuvat palkankorotukset

      Naistenpäivänä on syytä muistuttaa, että virkamiehen euro on vain 80 senttiä. Palkat tulee saattaa samalle tasolle yksi
      Maailman menoa
      43
      4006
    2. Riikka Purran kaudella nousi bensan hinta yli 2 euron

      Muistatteko kuinka edellisen vasemmistohallituksen aikana, ns. Marinin aikakaudella, bensiiniä sai 1,3 euron litrahinnal
      Maailman menoa
      51
      3651
    3. Jäikö meidän välit

      Mielestäsi Kesken?
      Ikävä
      70
      3218
    4. Olisipa saanut sinuun

      Tutustua paremmin. Harmi että aloin lopulta jännittämään kun näytit tunteesi niin voimakkaasti ja lähestyit niin voimaak
      Ikävä
      93
      3087
    5. Mitäs nyt sijoittajat?

      Pörssit laskevat maailmalla Iranin sodan takia ja muutenkin ovat olleet Trumpin vallan alla epävarmat. Ainoa, mikä on no
      Maailman menoa
      88
      2066
    6. Miks tän meidän

      Rakkauden on pitänyt olla näin vaikeaa?
      Ikävä
      35
      2028
    7. muista olla

      VAROVAINEN! m
      Ikävä
      24
      1889
    8. Elän vastoin

      Kaikkia arvoja kun en pysy sinusta erossa.
      Ikävä
      31
      1841
    9. Onneksi on edes yksi kuva

      Susta mitä voin välillä ihastella ja kaipailla sua😔
      Ikävä
      34
      1830
    10. Olisitpa se hellä

      Ja herkkä minkä kuvan sain sinusta irl. Haluaisin että elämässäni olisi sellainen joka arvostaa minua juuri sellaisena k
      Ikävä
      23
      1774
    Aihe