HJT-logi

apua tarvitseva

Ultaa, ohessa logi. Voisiko joku antaa kommenttia mita tarttis tehrä


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:07:07, on 16.12.2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\AVPersonal\AVGNT.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - toimittaja Sonera Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi;;localhost;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Zango /fleok=1D8A83A5C7ED107790AA6A2A1FBB39BFE4976E26CAEDA120180A196D6093 - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll
O2 - BHO: (no name) - {1BDD55B8-3985-4E59-B906-5E0AD56D6710} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: {1dc0ac2a-69f0-bf59-fdd4-cde6ec154d98} - {89d451ce-6edc-4ddf-95fb-0f96a2ca0cd1} - (no file)
O2 - BHO: (no name) - {DAE5EA11-4F68-422C-98BF-53373CF9D52D} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Paikallinen palve')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: TMMonitor.lnk = C:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi
O16 - DPF: {1230CB21-C88D-11CF-B347-000000000000} - http://www.eingang69.de/EroticAccess/Cabs/1854005.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1202051266640
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - Winlogon Notify: qomlmji - qomlmji.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AntiVir Service (AntiVirService) - H BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe

--
End of file - 8395 bytes

18

1286

    Vastaukset

    Anonyymi (Kirjaudu / Rekisteröidy)
    5000
    • vehnäleipäkö

      vaikka kaksi virustorjuntaa toimivaa vielä kaiken lisäksi niin örkejä oikeen roppakaupalla.

      Zango tää visiin on se sango millä vettä kaivoon kannetaan.

      ShoppingReport tää se on se likasenkaupan huijaus rapotti

      O2 - BHO: (no name) - {DAE5EA11-4F68-422C-98BF-53373CF9D52D} - (no file) nää varmaan kuuluu sihen salaseenpalveluun

      O20 - Winlogon Notify: qomlmji - qomlmji.dll (file missing) tää on se kadonnuthenkilö jolla ei ole tunnusta

      kyllä tota kun oikeen kaivaa niin vuuduutakin löytyy

      pornoiluakin on, että höysyt nurkaan ja heilumaan
      O16 - DPF: {1230CB21-C88D-11CF-B347-000000000000} - http://www.eingang69.de/EroticAccess/Cabs/1854005.cab

      • apua tarvitseva

        Hei, miten poistan esim antivir:n kun sitä ei ole oikeen asennettu, ja käynnössä koko uninsallointi puuttuu. Vikasietotilassa deletoidaan antivir:n kansio?

        Saisiko neuvoja miten nämä örkit, jotka edellisessä viestissä oli jo poimittu, poistetaan


      • tuolta...
        apua tarvitseva kirjoitti:

        Hei, miten poistan esim antivir:n kun sitä ei ole oikeen asennettu, ja käynnössä koko uninsallointi puuttuu. Vikasietotilassa deletoidaan antivir:n kansio?

        Saisiko neuvoja miten nämä örkit, jotka edellisessä viestissä oli jo poimittu, poistetaan

        http://www.avira.com/en/support/support_downloads.html
        jos vaikka saisit sen antivirin pois.


    • vehnäleipäkö

      Poista lisää poista sovelutuksesta mikä sanoo noin

      ShoppingReport

      Poista vikasiedossa kansio

      C:\Program Files\>>ShoppingReport

      • apua tarviteva

        tässä Malwarebytes' Anti-Malware 1.31 ja combofix:n logit, sekä hjt . tää on tosiaan kaverin kone ja tuun tekee nuo kaks viimistä skannausta varmaan huomenna... kiitos jos annat väliaika kommentit

        Malwarebytes' Anti-Malware 1.31
        Tietokantaversio: 1456
        Windows 5.1.2600 Service Pack 3

        17.12.2008 18:40:15
        mbam-log-2008-12-17 (18-40-15).txt

        Tarkistustyyppi: Täysi tarkistus (C:\|)
        Tarkistetut kohteet: 110169
        Kulunut aika: 1 hour(s), 5 minute(s), 20 second(s)

        Saastuneita muistiprosesseja: 0
        Saastuneita muistimoduuleja: 0
        Saastuneita rekisteriavaimia: 78
        Saastuneita rekisteriarvoja: 6
        Saastuneita rekisterikohteita: 1
        Saastuneita hakemistoja: 18
        Saastuneita tiedostoja: 19

        Saastuneita muistiprosesseja:
        (Haitallisia kohteita ei löydetty)

        Saastuneita muistimoduuleja:
        (Haitallisia kohteita ei löydetty)

        Saastuneita rekisteriavaimia:
        HKEY_CLASSES_ROOT\shoppingreport.hbax (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\TypeLib\{e343edfc-1e6c-4cb5-aa29-e9c922641c80} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{d8560ac2-21b5-4c1a-bdd4-bd12bc83b082} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{20ea9658-6bc3-4599-a87d-6371fe9295fc} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{a16ad1e9-f69a-45af-9462-b1c286708842} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{c9ccbb35-d123-4a31-affc-9b2933132116} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\shoppingreport.hbax.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\shoppingreport.hbinfoband (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\shoppingreport.hbinfoband.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\shoppingreport.iebutton (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\shoppingreport.iebutton.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\shoppingreport.iebuttona (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\shoppingreport.iebuttona.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\shoppingreport.rprtctrl (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\shoppingreport.rprtctrl.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{00b77587-be1b-4201-b8e9-09fcf50ab771} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{2b81f920-6660-4f76-93bf-b1c67bf5d1a0} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{34e29700-0d13-46aa-b9a5-ace68e21a091} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{3661af2d-c27b-499c-9bcf-66c8502a3806} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{3f0915b8-b238-4c2d-ad1e-60db1e14d27a} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{49155dae-c471-40fa-98ee-b2b3cad115ce} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{4d783385-0dda-4188-a529-c97dc3d67cbd} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{4e8b851b-05b0-4baf-b24d-d0dfe88dded3} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{5a4737a8-b92a-4e54-970e-c2891d98ce3f} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{62b0b239-f9ac-4a5b-bfae-62c7a23f7627} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{6e10479b-31e8-4a3b-81b1-ddaf39097f19} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{726f0ab9-b842-4ae4-90c7-230e233e6a99} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{8ad9ad05-36be-4e40-ba62-5422eb0d02fb} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{99123ac9-7dda-4c82-b252-44c2804bf392} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{ace99e77-aa2a-43c2-8c9d-caf2020fdf2b} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{aebf09e2-0c15-43c8-99bf-928c645d98a0} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{b9cc2b92-5611-453f-8381-8b6f72d9c0b8} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{c4543e64-1498-410d-8e72-4744eea99ab9} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{e0fb1610-b25b-49f6-be20-751b2f230e6f} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{e420a65f-9984-4b8c-9fa9-1ed69d3b0a13} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{ea58c2ea-be26-49dd-9b9a-c8e4e5ca7791} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{fca28ac5-c1e1-4d67-a5ae-c44d6c374d9f} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{bf1bf02c-5a86-4ecf-adac-472c54c4d21e} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{cdca70d8-c6a6-49ee-9bed-7429d6c477a2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{d136987f-e1c4-4ccc-a220-893df03ec5df} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{08755390-f46d-4d09-968c-3430166b3189} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{087c4054-0a2b-4f35-b0db-bed3e21650f4} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{0923208c-e259-4ed5-a778-cb607da350ad} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{229d2451-a617-4b30-b5e8-8138694240cb} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{9720de03-5820-4059-b4a4-639d5e52bd09} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{c23fa5a4-1fea-419f-8b14-f7465df062bc} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{ccc6e232-aa4c-4813-a019-9c14b27776b6} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07aa283a-43d7-4cbe-a064-32a21112d94d} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{54a3f8b7-228e-4ed8-895b-de832b2c3959} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{bfc08cff-c737-4433-bd5a-0ee7efcfee54} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07aa283a-43d7-4cbe-a064-32a21112d94d} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{93b0fa7b-50f6-41b4-ac7e-612a72ce8c3c} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{54a3f8b7-228e-4ed8-895b-de832b2c3959} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{93b0fa7b-50f6-41b4-ac7e-612a72ce8c3c} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\568267acfc5644dab06f058006ddbae3 (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\shoppingreport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\MalwareAlarm (Rogue.Malware.Alarm) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.

        Saastuneita rekisteriarvoja:
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07aa283a-43d7-4cbe-a064-32a21112d94d} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07aa283a-43d7-4cbe-a064-32a21112d94d} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ADP (Rogue.Multiple) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\zango 10.0.314.0 (Adware.Zango) -> Quarantined and deleted successfully.

        Saastuneita rekisterikohteita:
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceActiveDesktopOn (Hijack.Desktop) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

        Saastuneita hakemistoja:
        C:\Program Files\MalwareAlarm (Rogue.Malware.Alarm) -> Quarantined and deleted successfully.
        C:\Program Files\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Program Files\ShoppingReport\Bin (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Program Files\ShoppingReport\Bin\2.0.26 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Program Files\ShoppingReport\cs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Program Files\Instant Access (Adware.EGDAccess) -> Quarantined and deleted successfully.
        C:\Program Files\Instant Access\Center (Adware.EGDAccess) -> Quarantined and deleted successfully.
        C:\Program Files\Instant Access\Multi (Adware.EGDAccess) -> Quarantined and deleted successfully.
        C:\Program Files\Instant Access\Multi\Exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
        C:\Program Files\Instant Access\Multi\Exe\20041125211129 (Adware.EGDAccess) -> Quarantined and deleted successfully.
        C:\Program Files\Instant Access\Multi\Exe\20041125211129\Common (Adware.EGDAccess) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs\db (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs\dwld (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs\report (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs\res2 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\All Users.WINDOWS\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65 (Adware.Seekmo) -> Quarantined and deleted successfully.

        Saastuneita tiedostoja:
        C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{F8098D41-F0D9-4029-BDAC-90A152CF7C5D}\RP1454\A0161773.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
        C:\Program Files\MalwareAlarm\MalwareAlarm.lic (Rogue.Malware.Alarm) -> Quarantined and deleted successfully.
        C:\Program Files\MalwareAlarm\MalwareAlarm0.ma (Rogue.Malware.Alarm) -> Quarantined and deleted successfully.
        C:\Program Files\MalwareAlarm\MalwareAlarm1.ma (Rogue.Malware.Alarm) -> Quarantined and deleted successfully.
        C:\Program Files\ShoppingReport\Uninst.exe (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Program Files\Instant Access\Center\GAMMA.upd (Adware.EGDAccess) -> Quarantined and deleted successfully.
        C:\Program Files\Instant Access\Multi\Exe\20041125211129\Common\show_module.php (Adware.EGDAccess) -> Quarantined and deleted successfully.
        C:\Program Files\Instant Access\Multi\Exe\20041125211129\Common\show_module.php.netID (Adware.EGDAccess) -> Quarantined and deleted successfully.
        C:\Program Files\Instant Access\Multi\Exe\20041125211129\Common\show_module.php_0.loginvis (Adware.EGDAccess) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs\Config.xml (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs\db\Aliases.dbs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs\db\Sites.dbs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs\dwld\WhiteList.xip (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs\report\aggr_storage.xml (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs\report\send_storage.xml (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs\res2\WhiteList.dbs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
        C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.

        eli ei löytyny paskaa :)

        ComboFix 08-12-16.03 - Matti 2008-12-17 20:06:01.1 - NTFSx86
        Sijainti: c:\documents and settings\Matti.MATTI-OFCR7XYKR\Työpöytä\ComboFix.exe

        [COLOR=RED][B]VAROITUS - PALAUTUSKONSOLIA EI OLE ASENNETTU !![/B][/COLOR]
        .

        (((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
        .

        c:\documents and settings\Matti.MATTI-OFCR7XYKR\Käynnistä-valikko\Ohjelmat\MalwareAlarm
        c:\documents and settings\Matti.MATTI-OFCR7XYKR\Käynnistä-valikko\Ohjelmat\MalwareAlarm\MalwareAlarm.lnk
        c:\documents and settings\Matti.MATTI-OFCR7XYKR\Käynnistä-valikko\Ohjelmat\MalwareAlarm\Uninstall.lnk
        c:\program files\Mozilla Firefox\plugins\npclntax_ZangoSA.dll
        c:\windows\system32\bhqbpdfe.ini
        c:\windows\system32\dlkncuhm.ini
        c:\windows\system32\dytoinsi.ini
        c:\windows\system32\edgbyxck.ini
        c:\windows\system32\ewufsaaa.ini
        c:\windows\system32\gjjlm.bak1
        c:\windows\system32\gjjlm.bak2
        c:\windows\system32\gjjlm.ini
        c:\windows\system32\gjjlm.ini2
        c:\windows\system32\gjjlm.tmp
        c:\windows\system32\hebsblvb.ini
        c:\windows\system32\jjhhaoxl.ini
        c:\windows\system32\lfzyf.dat
        c:\windows\system32\lmpikbdc.ini
        c:\windows\system32\njxbxudq.ini
        c:\windows\system32\oaodlyhr.ini
        c:\windows\system32\pisolvks.ini
        c:\windows\system32\sgsianyx.ini
        c:\windows\system32\srfdbvms.ini
        c:\windows\system32\tadhjslt.ini
        c:\windows\system32\txpidrop.ini
        c:\windows\system32\unbxhnfa.ini
        c:\windows\system32\uqqilmhj.ini
        c:\windows\system32\vfedicfc.ini
        c:\windows\system32\wppvwsrc.ini
        c:\windows\system32\wxwmosrv.ini
        c:\windows\system32\xgqcloqm.ini

        .
        ((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-11-17 to 2008-12-17 )))))))))))))))))
        .

        2008-12-17 19:48 . 2008-12-17 19:49      d--------   C:\32788R22FWJFW
        2008-12-17 17:25 . 2008-12-17 17:25      d--------   c:\program files\Malwarebytes' Anti-Malware
        2008-12-17 17:25 . 2008-12-17 17:25      d--------   c:\documents and settings\Matti.MATTI-OFCR7XYKR\Application Data\Malwarebytes
        2008-12-17 17:25 . 2008-12-17 17:25      d--------   c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
        2008-12-17 17:25 . 2008-12-03 19:59   38,496   --a------   c:\windows\system32\drivers\mbamswissarmy.sys
        2008-12-17 17:25 . 2008-12-03 19:59   15,504   --a------   c:\windows\system32\drivers\mbam.sys
        2008-12-16 19:06 . 2008-12-16 19:06      d--------   c:\program files\Trend Micro
        2008-12-16 18:12 . 2008-12-16 18:12   410,984   --a------   c:\windows\system32\deploytk.dll
        2008-12-15 19:30 . 2008-12-15 19:30      d--------   c:\program files\Lavasoft
        2008-12-15 19:30 . 2008-12-15 19:45      d--------   c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft
        2008-12-15 19:29 . 2008-12-15 19:29      d--------   c:\program files\Common Files\Wise Installation Wizard
        2008-12-15 00:19 . 2008-12-15 00:23      d--------   C:\elokuvat
        2008-12-15 00:18 . 2008-12-15 00:18   2,417   --a------   C:\Uusi OpenDocument-piirros.odg
        2008-12-14 19:35 . 2008-12-14 19:35      d--------   c:\documents and settings\Matti.MATTI-OFCR7XYKR\Application Data\vlc
        2008-12-14 19:34 . 2008-12-14 19:35      d--------   c:\program files\CCleaner
        2008-12-14 19:33 . 2008-12-14 19:33      d--------   c:\program files\VideoLAN
        2008-12-14 19:13 . 2008-12-14 19:15      d--------   c:\documents and settings\Matti.MATTI-OFCR7XYKR\Application Data\Winamp
        2008-12-13 16:13 . 2008-12-13 16:32      d--------   C:\MP3

        .
        (((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2008-12-17 11:20   ---------   d-----w   c:\documents and settings\Matti.MATTI-OFCR7XYKR\Application Data\AVG7
        2008-12-16 16:24   ---------   d-----w   c:\program files\Common Files\Adobe
        2008-12-16 16:15   ---------   d-----w   c:\program files\Java
        2008-12-16 16:05   ---------   d-----w   c:\program files\Yahoo!
        2008-12-16 15:48   ---------   d-----w   c:\documents and settings\Matti.MATTI-OFCR7XYKR\Application Data\OpenOffice.org2
        2008-12-16 04:44   ---------   d-----w   c:\program files\OpenOffice.org1.1.4
        2008-12-14 22:46   ---------   d-----w   c:\program files\AVPersonal
        2008-12-14 18:39   ---------   d-----w   c:\documents and settings\All Users.WINDOWS\Application Data\avg7
        2008-12-14 17:35   ---------   d-----w   c:\documents and settings\Matti.MATTI-OFCR7XYKR\Application Data\vlc
        2008-10-24 11:21   455,296   ----a-w   c:\windows\system32\drivers\mrxsmb.sys
        2008-10-23 12:38   286,720   ----a-w   c:\windows\system32\gdi32.dll
        2008-10-22 06:05   ---------   d-----w   c:\program files\Microsoft Silverlight
        2008-10-19 08:35   ---------   d-----w   c:\documents and settings\Matti.MATTI-OFCR7XYKR\Application Data\Apple Computer
        2008-10-16 20:18   826,368   ----a-w   c:\windows\system32\wininet.dll
        2008-10-16 12:13   202,776   ----a-w   c:\windows\system32\wuweb.dll
        2008-10-16 12:13   1,809,944   ----a-w   c:\windows\system32\wuaueng.dll
        2008-10-16 12:12   561,688   ----a-w   c:\windows\system32\wuapi.dll
        2008-10-16 12:12   323,608   ----a-w   c:\windows\system32\wucltui.dll
        2008-10-16 12:09   92,696   ----a-w   c:\windows\system32\cdm.dll
        2008-10-16 12:09   51,224   ----a-w   c:\windows\system32\wuauclt.exe
        2008-10-16 12:09   43,544   ----a-w   c:\windows\system32\wups2.dll
        2008-10-16 12:08   34,328   ----a-w   c:\windows\system32\wups.dll
        2008-10-16 12:06   268,648   ----a-w   c:\windows\system32\mucltui.dll
        2008-10-16 12:06   208,744   ----a-w   c:\windows\system32\muweb.dll
        2008-10-03 10:03   247,326   ----a-w   c:\windows\system32\strmdll.dll
        2008-09-30 14:43   1,286,152   ----a-w   c:\windows\system32\msxml4.dll
        2001-11-22 13:08   712,704   -c--a-w   c:\windows\inf\OTHER\AUDIO3D.DLL
        2008-09-03 21:35   32,768   --sha-w   c:\windows\system32\config\systemprofile\Local Settings\Sivuhistoria\History.IE5\MSHist012008090420080905\index.dat
        .

        (((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
        REGEDIT4

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
        "OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2007-02-08 95800]
        "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "EPSON Stylus CX3200"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" [2002-07-01 74752]
        "SiSUSBRG"="c:\windows\SiSUSBrg.exe" [2002-07-12 106496]
        "EM_EXEC"="c:\progra~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [2002-07-01 28672]
        "AVGCtrl"="c:\program files\AVPersonal\AVGNT.EXE" [2003-09-17 118824]
        "PCSuiteTrayApplication"="c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE" [2006-06-15 229376]
        "AVG7_CC"="c:\progra~1\Grisoft\AVG7\avgcc.exe" [2008-12-15 590848]
        "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-09-12 335872]
        "AGRSMMSG"="AGRSMMSG.exe" [2003-09-23 c:\windows\AGRSMMSG.exe]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
        "NSSInstallation"="c:\windows\system32\Adobe\Shockwave 11\nssstub.exe" [2008-12-07 181624]

        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
        "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
        "AVG7_Run"="c:\progra~1\Grisoft\AVG7\avgw.exe" [2008-02-04 219136]

        c:\documents and settings\All Users.WINDOWS\K„ynnist„-valikko\Ohjelmat\K„ynnistys\
        TMMonitor.lnk - c:\program files\ArcSoft\TotalMedia 3\TMMonitor.exe [2006-12-22 245760]

        [HKEY_LOCAL_MACHINE\software\microsoft\security center]
        "AntiVirusOverride"=dword:00000001

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
        "%windir%\\system32\\sessmgr.exe"=
        "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
        "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
        "c:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
        "c:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
        "c:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
        "c:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
        "c:\\Program Files\\Messenger\\msmsgs.exe"=

        R3 LCcFltr;Logitech USB Filter Driver;c:\windows\system32\drivers\LCcFltr.Sys [2004-02-20 13276]
        S3 avgntdd;avgntdd;\??\c:\program files\AVPersonal\AVGNTDD.SYS [2003-08-12 39844]
        S3 bdacap;%BdaSWCapture.DeviceDesc%;c:\windows\system32\drivers\bdacap.sys [2006-12-22 218624]
        .
        'Ajoitetut tehtävät'-kansion sisältö

        2008-12-17 c:\windows\Tasks\NSSstub.job
        - c:\windows\system32\Adobe\Shockwave 11\nssstub.exe [2008-12-07 20:20]
        .
        - - - - POISTETUT JÄMÄRIVIT - - - -

        BHO-{DAE5EA11-4F68-422C-98BF-53373CF9D52D} - (no file)
        HKLM-Run-Cmaudio - cmicnfg.cpl


        .
        ------- Täydentävä tarkistus -------
        .
        uStart Page = hxxp://www.google.fi/
        uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
        uInternet Connection Wizard,ShellNext = iexplore
        uInternet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi;;localhost;
        uInternet Settings,ProxyServer = proxy.dial.inet.fi:800
        uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
        Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

        O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
        c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
        FF - ProfilePath - c:\documents and settings\Matti.MATTI-OFCR7XYKR\Application Data\Mozilla\Firefox\Profiles\jj6p56xr.default\
        FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30716.0.dll
        FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
        FF - plugin: c:\program files\Mozilla Firefox\plugins\npclntax_ZangoSA.dll
        .

        **************************************************************************

        catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2008-12-17 20:13:29
        Windows 5.1.2600 Service Pack 3 NTFS

        tarkistaa piilotettuja prosesseja ...

        tarkistaa piilotettuja käynnistysarvoja ...

        tarkistaa piilotettuja tiedostoja ...

        tarkistus on valmis
        piilotetut tiedostot: 0

        **************************************************************************
        .
        --------------------- Prosesseihin ladatut DLLt ---------------------

        - - - - - - - > 'winlogon.exe'(544)
        c:\windows\system32\Ati2evxx.dll
        .
        ------------------------ Muut prosessit ------------------------
        .
        c:\windows\system32\ati2evxx.exe
        c:\program files\Lavasoft\Ad-Aware\aawservice.exe
        c:\windows\system32\ati2evxx.exe
        c:\progra~1\Grisoft\AVG7\avgamsvr.exe
        c:\progra~1\Grisoft\AVG7\avgupsvc.exe
        c:\progra~1\Grisoft\AVG7\avgemc.exe
        c:\program files\Common Files\EPSON\EBAPI\eEBSvc.exe
        c:\program files\Common Files\EPSON\EBAPI\SAgent2.exe
        c:\program files\Java\jre6\bin\jqs.exe
        c:\program files\Windows Media Player\wmpnetwk.exe
        c:\windows\system32\rundll32.exe
        c:\program files\Common Files\PCSuite\Services\ServiceLayer.exe
        c:\progra~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
        .
        **************************************************************************
        .
        Valmistumisajankohta: 2008-12-17 20:23:32 - kone käynnistettiin uudelleen
        ComboFix-quarantined-files.txt 2008-12-17 18:23:26

        Ennen ajoa: 16 220 090 368 tavua vapaana
        Ajon jälkeen: 16,420,384,768 tavua vapaana

        WindowsXP-KB310994-SP2-Pro-BootDisk-FIN.EXE

        192   --- E O F ---   2008-12-16 23:14:28



        ja hjt-logi:
        Scan saved at 20:26:50, on 17.12.2008
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16762)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
        C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
        C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
        C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
        C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\RunDll32.exe
        C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
        C:\Program Files\AVPersonal\AVGNT.EXE
        C:\WINDOWS\AGRSMMSG.exe
        C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
        C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
        C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe
        C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
        C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
        C:\WINDOWS\explorer.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi;;localhost;
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
        O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
        O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
        O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
        O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
        O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\RunOnce: [NSSInstallation] C:\WINDOWS\system32\Adobe\Shockwave 11\nssstub.exe /RunOnce
        O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
        O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
        O4 - Global Startup: TMMonitor.lnk = C:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1202051266640
        O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
        O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        O23 - Service: AntiVir Service (AntiVirService) - H BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
        O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
        O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
        O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
        O23 - Service: AntiVir Update (AVWUpSrv) - H BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
        O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
        O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe

        --
        End of file - 6987 bytes


      • vehnälepäkö
        apua tarviteva kirjoitti:

        tässä Malwarebytes' Anti-Malware 1.31 ja combofix:n logit, sekä hjt . tää on tosiaan kaverin kone ja tuun tekee nuo kaks viimistä skannausta varmaan huomenna... kiitos jos annat väliaika kommentit

        Malwarebytes' Anti-Malware 1.31
        Tietokantaversio: 1456
        Windows 5.1.2600 Service Pack 3

        17.12.2008 18:40:15
        mbam-log-2008-12-17 (18-40-15).txt

        Tarkistustyyppi: Täysi tarkistus (C:\|)
        Tarkistetut kohteet: 110169
        Kulunut aika: 1 hour(s), 5 minute(s), 20 second(s)

        Saastuneita muistiprosesseja: 0
        Saastuneita muistimoduuleja: 0
        Saastuneita rekisteriavaimia: 78
        Saastuneita rekisteriarvoja: 6
        Saastuneita rekisterikohteita: 1
        Saastuneita hakemistoja: 18
        Saastuneita tiedostoja: 19

        Saastuneita muistiprosesseja:
        (Haitallisia kohteita ei löydetty)

        Saastuneita muistimoduuleja:
        (Haitallisia kohteita ei löydetty)

        Saastuneita rekisteriavaimia:
        HKEY_CLASSES_ROOT\shoppingreport.hbax (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\TypeLib\{e343edfc-1e6c-4cb5-aa29-e9c922641c80} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{d8560ac2-21b5-4c1a-bdd4-bd12bc83b082} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{20ea9658-6bc3-4599-a87d-6371fe9295fc} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{a16ad1e9-f69a-45af-9462-b1c286708842} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{c9ccbb35-d123-4a31-affc-9b2933132116} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\shoppingreport.hbax.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\shoppingreport.hbinfoband (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\shoppingreport.hbinfoband.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\shoppingreport.iebutton (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\shoppingreport.iebutton.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\shoppingreport.iebuttona (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\shoppingreport.iebuttona.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\shoppingreport.rprtctrl (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\shoppingreport.rprtctrl.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{00b77587-be1b-4201-b8e9-09fcf50ab771} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{2b81f920-6660-4f76-93bf-b1c67bf5d1a0} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{34e29700-0d13-46aa-b9a5-ace68e21a091} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{3661af2d-c27b-499c-9bcf-66c8502a3806} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{3f0915b8-b238-4c2d-ad1e-60db1e14d27a} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{49155dae-c471-40fa-98ee-b2b3cad115ce} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{4d783385-0dda-4188-a529-c97dc3d67cbd} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{4e8b851b-05b0-4baf-b24d-d0dfe88dded3} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{5a4737a8-b92a-4e54-970e-c2891d98ce3f} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{62b0b239-f9ac-4a5b-bfae-62c7a23f7627} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{6e10479b-31e8-4a3b-81b1-ddaf39097f19} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{726f0ab9-b842-4ae4-90c7-230e233e6a99} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{8ad9ad05-36be-4e40-ba62-5422eb0d02fb} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{99123ac9-7dda-4c82-b252-44c2804bf392} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{ace99e77-aa2a-43c2-8c9d-caf2020fdf2b} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{aebf09e2-0c15-43c8-99bf-928c645d98a0} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{b9cc2b92-5611-453f-8381-8b6f72d9c0b8} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{c4543e64-1498-410d-8e72-4744eea99ab9} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{e0fb1610-b25b-49f6-be20-751b2f230e6f} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{e420a65f-9984-4b8c-9fa9-1ed69d3b0a13} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{ea58c2ea-be26-49dd-9b9a-c8e4e5ca7791} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{fca28ac5-c1e1-4d67-a5ae-c44d6c374d9f} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{bf1bf02c-5a86-4ecf-adac-472c54c4d21e} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{cdca70d8-c6a6-49ee-9bed-7429d6c477a2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{d136987f-e1c4-4ccc-a220-893df03ec5df} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{08755390-f46d-4d09-968c-3430166b3189} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{087c4054-0a2b-4f35-b0db-bed3e21650f4} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{0923208c-e259-4ed5-a778-cb607da350ad} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{229d2451-a617-4b30-b5e8-8138694240cb} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{9720de03-5820-4059-b4a4-639d5e52bd09} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{c23fa5a4-1fea-419f-8b14-f7465df062bc} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{ccc6e232-aa4c-4813-a019-9c14b27776b6} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07aa283a-43d7-4cbe-a064-32a21112d94d} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{54a3f8b7-228e-4ed8-895b-de832b2c3959} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{bfc08cff-c737-4433-bd5a-0ee7efcfee54} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07aa283a-43d7-4cbe-a064-32a21112d94d} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{93b0fa7b-50f6-41b4-ac7e-612a72ce8c3c} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{54a3f8b7-228e-4ed8-895b-de832b2c3959} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{93b0fa7b-50f6-41b4-ac7e-612a72ce8c3c} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\568267acfc5644dab06f058006ddbae3 (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\shoppingreport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\MalwareAlarm (Rogue.Malware.Alarm) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.

        Saastuneita rekisteriarvoja:
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07aa283a-43d7-4cbe-a064-32a21112d94d} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07aa283a-43d7-4cbe-a064-32a21112d94d} (Adware.Zango) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ADP (Rogue.Multiple) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\zango 10.0.314.0 (Adware.Zango) -> Quarantined and deleted successfully.

        Saastuneita rekisterikohteita:
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceActiveDesktopOn (Hijack.Desktop) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

        Saastuneita hakemistoja:
        C:\Program Files\MalwareAlarm (Rogue.Malware.Alarm) -> Quarantined and deleted successfully.
        C:\Program Files\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Program Files\ShoppingReport\Bin (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Program Files\ShoppingReport\Bin\2.0.26 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Program Files\ShoppingReport\cs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Program Files\Instant Access (Adware.EGDAccess) -> Quarantined and deleted successfully.
        C:\Program Files\Instant Access\Center (Adware.EGDAccess) -> Quarantined and deleted successfully.
        C:\Program Files\Instant Access\Multi (Adware.EGDAccess) -> Quarantined and deleted successfully.
        C:\Program Files\Instant Access\Multi\Exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
        C:\Program Files\Instant Access\Multi\Exe\20041125211129 (Adware.EGDAccess) -> Quarantined and deleted successfully.
        C:\Program Files\Instant Access\Multi\Exe\20041125211129\Common (Adware.EGDAccess) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs\db (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs\dwld (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs\report (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs\res2 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\All Users.WINDOWS\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65 (Adware.Seekmo) -> Quarantined and deleted successfully.

        Saastuneita tiedostoja:
        C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{F8098D41-F0D9-4029-BDAC-90A152CF7C5D}\RP1454\A0161773.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
        C:\Program Files\MalwareAlarm\MalwareAlarm.lic (Rogue.Malware.Alarm) -> Quarantined and deleted successfully.
        C:\Program Files\MalwareAlarm\MalwareAlarm0.ma (Rogue.Malware.Alarm) -> Quarantined and deleted successfully.
        C:\Program Files\MalwareAlarm\MalwareAlarm1.ma (Rogue.Malware.Alarm) -> Quarantined and deleted successfully.
        C:\Program Files\ShoppingReport\Uninst.exe (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Program Files\Instant Access\Center\GAMMA.upd (Adware.EGDAccess) -> Quarantined and deleted successfully.
        C:\Program Files\Instant Access\Multi\Exe\20041125211129\Common\show_module.php (Adware.EGDAccess) -> Quarantined and deleted successfully.
        C:\Program Files\Instant Access\Multi\Exe\20041125211129\Common\show_module.php.netID (Adware.EGDAccess) -> Quarantined and deleted successfully.
        C:\Program Files\Instant Access\Multi\Exe\20041125211129\Common\show_module.php_0.loginvis (Adware.EGDAccess) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs\Config.xml (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs\db\Aliases.dbs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs\db\Sites.dbs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs\dwld\WhiteList.xip (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs\report\aggr_storage.xml (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs\report\send_storage.xml (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Application Data\ShoppingReport\cs\res2\WhiteList.dbs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
        C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.

        eli ei löytyny paskaa :)

        ComboFix 08-12-16.03 - Matti 2008-12-17 20:06:01.1 - NTFSx86
        Sijainti: c:\documents and settings\Matti.MATTI-OFCR7XYKR\Työpöytä\ComboFix.exe

        [COLOR=RED][B]VAROITUS - PALAUTUSKONSOLIA EI OLE ASENNETTU !![/B][/COLOR]
        .

        (((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
        .

        c:\documents and settings\Matti.MATTI-OFCR7XYKR\Käynnistä-valikko\Ohjelmat\MalwareAlarm
        c:\documents and settings\Matti.MATTI-OFCR7XYKR\Käynnistä-valikko\Ohjelmat\MalwareAlarm\MalwareAlarm.lnk
        c:\documents and settings\Matti.MATTI-OFCR7XYKR\Käynnistä-valikko\Ohjelmat\MalwareAlarm\Uninstall.lnk
        c:\program files\Mozilla Firefox\plugins\npclntax_ZangoSA.dll
        c:\windows\system32\bhqbpdfe.ini
        c:\windows\system32\dlkncuhm.ini
        c:\windows\system32\dytoinsi.ini
        c:\windows\system32\edgbyxck.ini
        c:\windows\system32\ewufsaaa.ini
        c:\windows\system32\gjjlm.bak1
        c:\windows\system32\gjjlm.bak2
        c:\windows\system32\gjjlm.ini
        c:\windows\system32\gjjlm.ini2
        c:\windows\system32\gjjlm.tmp
        c:\windows\system32\hebsblvb.ini
        c:\windows\system32\jjhhaoxl.ini
        c:\windows\system32\lfzyf.dat
        c:\windows\system32\lmpikbdc.ini
        c:\windows\system32\njxbxudq.ini
        c:\windows\system32\oaodlyhr.ini
        c:\windows\system32\pisolvks.ini
        c:\windows\system32\sgsianyx.ini
        c:\windows\system32\srfdbvms.ini
        c:\windows\system32\tadhjslt.ini
        c:\windows\system32\txpidrop.ini
        c:\windows\system32\unbxhnfa.ini
        c:\windows\system32\uqqilmhj.ini
        c:\windows\system32\vfedicfc.ini
        c:\windows\system32\wppvwsrc.ini
        c:\windows\system32\wxwmosrv.ini
        c:\windows\system32\xgqcloqm.ini

        .
        ((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-11-17 to 2008-12-17 )))))))))))))))))
        .

        2008-12-17 19:48 . 2008-12-17 19:49      d--------   C:\32788R22FWJFW
        2008-12-17 17:25 . 2008-12-17 17:25      d--------   c:\program files\Malwarebytes' Anti-Malware
        2008-12-17 17:25 . 2008-12-17 17:25      d--------   c:\documents and settings\Matti.MATTI-OFCR7XYKR\Application Data\Malwarebytes
        2008-12-17 17:25 . 2008-12-17 17:25      d--------   c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
        2008-12-17 17:25 . 2008-12-03 19:59   38,496   --a------   c:\windows\system32\drivers\mbamswissarmy.sys
        2008-12-17 17:25 . 2008-12-03 19:59   15,504   --a------   c:\windows\system32\drivers\mbam.sys
        2008-12-16 19:06 . 2008-12-16 19:06      d--------   c:\program files\Trend Micro
        2008-12-16 18:12 . 2008-12-16 18:12   410,984   --a------   c:\windows\system32\deploytk.dll
        2008-12-15 19:30 . 2008-12-15 19:30      d--------   c:\program files\Lavasoft
        2008-12-15 19:30 . 2008-12-15 19:45      d--------   c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft
        2008-12-15 19:29 . 2008-12-15 19:29      d--------   c:\program files\Common Files\Wise Installation Wizard
        2008-12-15 00:19 . 2008-12-15 00:23      d--------   C:\elokuvat
        2008-12-15 00:18 . 2008-12-15 00:18   2,417   --a------   C:\Uusi OpenDocument-piirros.odg
        2008-12-14 19:35 . 2008-12-14 19:35      d--------   c:\documents and settings\Matti.MATTI-OFCR7XYKR\Application Data\vlc
        2008-12-14 19:34 . 2008-12-14 19:35      d--------   c:\program files\CCleaner
        2008-12-14 19:33 . 2008-12-14 19:33      d--------   c:\program files\VideoLAN
        2008-12-14 19:13 . 2008-12-14 19:15      d--------   c:\documents and settings\Matti.MATTI-OFCR7XYKR\Application Data\Winamp
        2008-12-13 16:13 . 2008-12-13 16:32      d--------   C:\MP3

        .
        (((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2008-12-17 11:20   ---------   d-----w   c:\documents and settings\Matti.MATTI-OFCR7XYKR\Application Data\AVG7
        2008-12-16 16:24   ---------   d-----w   c:\program files\Common Files\Adobe
        2008-12-16 16:15   ---------   d-----w   c:\program files\Java
        2008-12-16 16:05   ---------   d-----w   c:\program files\Yahoo!
        2008-12-16 15:48   ---------   d-----w   c:\documents and settings\Matti.MATTI-OFCR7XYKR\Application Data\OpenOffice.org2
        2008-12-16 04:44   ---------   d-----w   c:\program files\OpenOffice.org1.1.4
        2008-12-14 22:46   ---------   d-----w   c:\program files\AVPersonal
        2008-12-14 18:39   ---------   d-----w   c:\documents and settings\All Users.WINDOWS\Application Data\avg7
        2008-12-14 17:35   ---------   d-----w   c:\documents and settings\Matti.MATTI-OFCR7XYKR\Application Data\vlc
        2008-10-24 11:21   455,296   ----a-w   c:\windows\system32\drivers\mrxsmb.sys
        2008-10-23 12:38   286,720   ----a-w   c:\windows\system32\gdi32.dll
        2008-10-22 06:05   ---------   d-----w   c:\program files\Microsoft Silverlight
        2008-10-19 08:35   ---------   d-----w   c:\documents and settings\Matti.MATTI-OFCR7XYKR\Application Data\Apple Computer
        2008-10-16 20:18   826,368   ----a-w   c:\windows\system32\wininet.dll
        2008-10-16 12:13   202,776   ----a-w   c:\windows\system32\wuweb.dll
        2008-10-16 12:13   1,809,944   ----a-w   c:\windows\system32\wuaueng.dll
        2008-10-16 12:12   561,688   ----a-w   c:\windows\system32\wuapi.dll
        2008-10-16 12:12   323,608   ----a-w   c:\windows\system32\wucltui.dll
        2008-10-16 12:09   92,696   ----a-w   c:\windows\system32\cdm.dll
        2008-10-16 12:09   51,224   ----a-w   c:\windows\system32\wuauclt.exe
        2008-10-16 12:09   43,544   ----a-w   c:\windows\system32\wups2.dll
        2008-10-16 12:08   34,328   ----a-w   c:\windows\system32\wups.dll
        2008-10-16 12:06   268,648   ----a-w   c:\windows\system32\mucltui.dll
        2008-10-16 12:06   208,744   ----a-w   c:\windows\system32\muweb.dll
        2008-10-03 10:03   247,326   ----a-w   c:\windows\system32\strmdll.dll
        2008-09-30 14:43   1,286,152   ----a-w   c:\windows\system32\msxml4.dll
        2001-11-22 13:08   712,704   -c--a-w   c:\windows\inf\OTHER\AUDIO3D.DLL
        2008-09-03 21:35   32,768   --sha-w   c:\windows\system32\config\systemprofile\Local Settings\Sivuhistoria\History.IE5\MSHist012008090420080905\index.dat
        .

        (((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
        REGEDIT4

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
        "OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2007-02-08 95800]
        "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "EPSON Stylus CX3200"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" [2002-07-01 74752]
        "SiSUSBRG"="c:\windows\SiSUSBrg.exe" [2002-07-12 106496]
        "EM_EXEC"="c:\progra~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [2002-07-01 28672]
        "AVGCtrl"="c:\program files\AVPersonal\AVGNT.EXE" [2003-09-17 118824]
        "PCSuiteTrayApplication"="c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE" [2006-06-15 229376]
        "AVG7_CC"="c:\progra~1\Grisoft\AVG7\avgcc.exe" [2008-12-15 590848]
        "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-09-12 335872]
        "AGRSMMSG"="AGRSMMSG.exe" [2003-09-23 c:\windows\AGRSMMSG.exe]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
        "NSSInstallation"="c:\windows\system32\Adobe\Shockwave 11\nssstub.exe" [2008-12-07 181624]

        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
        "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
        "AVG7_Run"="c:\progra~1\Grisoft\AVG7\avgw.exe" [2008-02-04 219136]

        c:\documents and settings\All Users.WINDOWS\K„ynnist„-valikko\Ohjelmat\K„ynnistys\
        TMMonitor.lnk - c:\program files\ArcSoft\TotalMedia 3\TMMonitor.exe [2006-12-22 245760]

        [HKEY_LOCAL_MACHINE\software\microsoft\security center]
        "AntiVirusOverride"=dword:00000001

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
        "%windir%\\system32\\sessmgr.exe"=
        "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
        "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
        "c:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
        "c:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
        "c:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
        "c:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
        "c:\\Program Files\\Messenger\\msmsgs.exe"=

        R3 LCcFltr;Logitech USB Filter Driver;c:\windows\system32\drivers\LCcFltr.Sys [2004-02-20 13276]
        S3 avgntdd;avgntdd;\??\c:\program files\AVPersonal\AVGNTDD.SYS [2003-08-12 39844]
        S3 bdacap;%BdaSWCapture.DeviceDesc%;c:\windows\system32\drivers\bdacap.sys [2006-12-22 218624]
        .
        'Ajoitetut tehtävät'-kansion sisältö

        2008-12-17 c:\windows\Tasks\NSSstub.job
        - c:\windows\system32\Adobe\Shockwave 11\nssstub.exe [2008-12-07 20:20]
        .
        - - - - POISTETUT JÄMÄRIVIT - - - -

        BHO-{DAE5EA11-4F68-422C-98BF-53373CF9D52D} - (no file)
        HKLM-Run-Cmaudio - cmicnfg.cpl


        .
        ------- Täydentävä tarkistus -------
        .
        uStart Page = hxxp://www.google.fi/
        uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
        uInternet Connection Wizard,ShellNext = iexplore
        uInternet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi;;localhost;
        uInternet Settings,ProxyServer = proxy.dial.inet.fi:800
        uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
        Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

        O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
        c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
        FF - ProfilePath - c:\documents and settings\Matti.MATTI-OFCR7XYKR\Application Data\Mozilla\Firefox\Profiles\jj6p56xr.default\
        FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30716.0.dll
        FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
        FF - plugin: c:\program files\Mozilla Firefox\plugins\npclntax_ZangoSA.dll
        .

        **************************************************************************

        catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2008-12-17 20:13:29
        Windows 5.1.2600 Service Pack 3 NTFS

        tarkistaa piilotettuja prosesseja ...

        tarkistaa piilotettuja käynnistysarvoja ...

        tarkistaa piilotettuja tiedostoja ...

        tarkistus on valmis
        piilotetut tiedostot: 0

        **************************************************************************
        .
        --------------------- Prosesseihin ladatut DLLt ---------------------

        - - - - - - - > 'winlogon.exe'(544)
        c:\windows\system32\Ati2evxx.dll
        .
        ------------------------ Muut prosessit ------------------------
        .
        c:\windows\system32\ati2evxx.exe
        c:\program files\Lavasoft\Ad-Aware\aawservice.exe
        c:\windows\system32\ati2evxx.exe
        c:\progra~1\Grisoft\AVG7\avgamsvr.exe
        c:\progra~1\Grisoft\AVG7\avgupsvc.exe
        c:\progra~1\Grisoft\AVG7\avgemc.exe
        c:\program files\Common Files\EPSON\EBAPI\eEBSvc.exe
        c:\program files\Common Files\EPSON\EBAPI\SAgent2.exe
        c:\program files\Java\jre6\bin\jqs.exe
        c:\program files\Windows Media Player\wmpnetwk.exe
        c:\windows\system32\rundll32.exe
        c:\program files\Common Files\PCSuite\Services\ServiceLayer.exe
        c:\progra~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
        .
        **************************************************************************
        .
        Valmistumisajankohta: 2008-12-17 20:23:32 - kone käynnistettiin uudelleen
        ComboFix-quarantined-files.txt 2008-12-17 18:23:26

        Ennen ajoa: 16 220 090 368 tavua vapaana
        Ajon jälkeen: 16,420,384,768 tavua vapaana

        WindowsXP-KB310994-SP2-Pro-BootDisk-FIN.EXE

        192   --- E O F ---   2008-12-16 23:14:28



        ja hjt-logi:
        Scan saved at 20:26:50, on 17.12.2008
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16762)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
        C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
        C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
        C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
        C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\RunDll32.exe
        C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
        C:\Program Files\AVPersonal\AVGNT.EXE
        C:\WINDOWS\AGRSMMSG.exe
        C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
        C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
        C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe
        C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
        C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
        C:\WINDOWS\explorer.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi;;localhost;
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
        O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
        O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
        O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
        O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
        O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\RunOnce: [NSSInstallation] C:\WINDOWS\system32\Adobe\Shockwave 11\nssstub.exe /RunOnce
        O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
        O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
        O4 - Global Startup: TMMonitor.lnk = C:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1202051266640
        O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
        O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        O23 - Service: AntiVir Service (AntiVirService) - H BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
        O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
        O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
        O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
        O23 - Service: AntiVir Update (AVWUpSrv) - H BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
        O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
        O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe

        --
        End of file - 6987 bytes

        Kopioi / liitä seuraava teksti alapuolella tyhjään muistioFiluun
        Varmista että tiedoston tyyppi on "all Files" ja tallenna se Poisto.bat. nimisenä
        työpöydällesi.

        @echo off
        sc stop AntiVirService
        sc delete AntiVirService
        sc stop AVWUpSrv

        Tupla-klikkaa Poisto.bat. filua työpöydälläsi , ikkuna avautuu ja Sulkeutuu tämä on normaalia.

        ----------------------------

        Poista vikasiedossa kansio

        C:\Program Files\>> AVPersonal


      • apua tarvitseva
        vehnälepäkö kirjoitti:

        Kopioi / liitä seuraava teksti alapuolella tyhjään muistioFiluun
        Varmista että tiedoston tyyppi on "all Files" ja tallenna se Poisto.bat. nimisenä
        työpöydällesi.

        @echo off
        sc stop AntiVirService
        sc delete AntiVirService
        sc stop AVWUpSrv

        Tupla-klikkaa Poisto.bat. filua työpöydälläsi , ikkuna avautuu ja Sulkeutuu tämä on normaalia.

        ----------------------------

        Poista vikasiedossa kansio

        C:\Program Files\>> AVPersonal

        Moro... ohessa taas logia yms.

        SDFix:
        [b]SDFix: Version 1.240 [/b]
        Run by Matti on to 18.12.2008 at 17:06
        Microsoft Windows XP [versio 5.1.2600]
        Running From: C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Ty”p”yt„\SDFix

        [b]Checking Services [/b]:

        Restoring Default Security Values
        Restoring Default Hosts File

        Rebooting

        [b]Checking Files [/b]:

        No Trojan Files Found

        Removing Temp Files

        [b]ADS Check [/b]:
        [b]Final Check [/b]:

        catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2008-12-18 17:18:32
        Windows 5.1.2600 Service Pack 3 NTFS

        scanning hidden processes ...

        scanning hidden services & system hive ...

        scanning hidden registry entries ...

        scanning hidden files ...

        scan completed successfully
        hidden processes: 0
        hidden services: 0
        hidden files: 0

        [b]Remaining Services [/b]:

        Authorized Application Key Export:

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
        "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
        "C:\\Program Files\\ArcSoft\\TotalMedia 3\\TotalMedia.exe"="C:\\Program Files\\ArcSoft\\TotalMedia 3\\TotalMedia.exe:LocalSubNet:Enabled:ArcSoft TotalMedia 3"
        "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
        "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
        "C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
        "C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
        "C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
        "C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc.exe"
        "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
        "C:\\Documents and Settings\\Matti.MATTI-OFCR7XYKR\\Omat tiedostot\\Bitcomet\\BitComet.exe"="C:\\Documents and Settings\\Matti.MATTI-OFCR7XYKR\\Omat tiedostot\\Bitcomet\\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
        "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
        "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
        "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
        "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 6.2"

        [b]Remaining Files [/b]:

        [b]Files with Hidden Attributes [/b]:

        Fri 20 Feb 2004 27,030 A..HR --- "C:\Undo MATTI-OFCR7XYKR 20040220 185227.Reg"
        Thu 31 May 2007 2,324,048 ...H. --- "C:\Program Files\Bejeweled 2\WinBej2.exe"
        Fri 4 May 2007 2,482,176 ...H. --- "C:\Program Files\Cradle of Rome\Cradle of Rome.exe"
        Mon 22 Jul 2002 418,816 ...HR --- "C:\WINDOWS\system32\Tools\All.exe"
        Fri 19 Jul 2002 390,144 ...HR --- "C:\WINDOWS\system32\Tools\Change.exe"
        Fri 19 Jul 2002 574,464 ...HR --- "C:\WINDOWS\system32\Tools\CheckPath.exe"
        Tue 20 Aug 2002 430,592 ...HR --- "C:\WINDOWS\system32\Tools\Counter.exe"
        Tue 23 Jul 2002 390,656 ...HR --- "C:\WINDOWS\system32\Tools\DelFolders.exe"
        Fri 22 Nov 2002 399,872 ...HR --- "C:\WINDOWS\system32\Tools\DirectSetup.exe"
        Fri 19 Jul 2002 388,096 ...HR --- "C:\WINDOWS\system32\Tools\RegClean.exe"
        Fri 19 Jul 2002 388,608 ...HR --- "C:\WINDOWS\system32\Tools\Regexe.exe"
        Mon 2 Dec 2002 431,616 ...HR --- "C:\WINDOWS\system32\Tools\Restart.exe"
        Fri 19 Jul 2002 388,096 ...HR --- "C:\WINDOWS\system32\Tools\RunRegexe.exe"
        Sun 13 Jan 2008 0 A.SH. --- "C:\Documents and Settings\All Users.WINDOWS\DRM\Cache\Indiv01.tmp"

        [b]Finished![/b]


        HJT uuninstall managerin alla oli seuraavaa:
        ehdota vain mitkä hyövää poistaa

        Ad-Aware
        Adobe Flash Player Plugin
        Adobe Reader 8.1.3
        Adobe Shockwave Player 11
        Adobe® Photoshop® Album Starter Edition 3.0
        AIDA32 v3.85
        AntiVir/XP
        ArcSoft PhotoImpression
        ArcSoft TotalMedia 3
        ATI Control Panel
        ATI Display Driver
        ATI HydraVision
        ATI-ohjelmiston poisto-ohjelma
        AVG 7.5
        Bejeweled 2 Deluxe (remove only)
        BitComet 1.07
        BSPlayer
        CCleaner (remove only)
        C-Media 3D Audio
        C-Media WDM Audio Driver
        Cover Gold Pro Version 1.7.1
        CoverPro 7.2.1
        Cradle of Rome (remove only)
        Creative Modem Blaster V.92 DI5733
        DVD Cover Print
        EasyCleaner
        eMedia Codec 4.0
        EPSON Copy Utility
        EPSON Photo Print
        EPSON PhotoQuicker3.2
        EPSON Printer Software
        EPSON Smart Panel
        EPSON TWAIN 5
        Google Toolbar for Internet Explorer
        Google Toolbar for Internet Explorer
        HijackThis 2.0.2
        Hotfix for Windows Media Format 11 SDK (KB929399)
        Hotfix-korjauspäivitys Windows Media Player 11:lle (KB939683)
        Hotfix-päivitys Windows Internet Explorer 7:lle (KB947864)
        Hotfix-päivitys Windows XP:lle (KB952287)
        Java(TM) 6 Update 11
        Java(TM) 6 Update 7
        Jippii
        Logitech Desktop Messenger
        Logitech MouseWare 9.70
        Macromedia Shockwave Player
        Malwarebytes' Anti-Malware
        Media Library Management Wizard
        Microsoft .NET Framework 1.1
        Microsoft .NET Framework 1.1
        Microsoft .NET Framework 1.1 Finnish Language Pack
        Microsoft .NET Framework 1.1 Hotfix (KB928366)
        Microsoft .NET Framework 2.0 Language Pack - FIN
        Microsoft .NET Framework 2.0 Service Pack 1
        Microsoft .NET Framework 3.0
        Microsoft .NET Framework 3.0
        Microsoft .NET Framework 3.0 Finnish Language Pack
        Microsoft .NET Framework 3.0:n suomen kielipaketti
        Microsoft Base Smart Card Cryptographic Service Provider Package
        Microsoft Compression Client Pack 1.0 for Windows XP
        Microsoft Data Access Components KB870669
        Microsoft Internationalized Domain Names Mitigation APIs
        Microsoft National Language Support Downlevel APIs
        Microsoft Office Excel Viewer 2003
        Microsoft Office PowerPoint Viewer 2003
        Microsoft Office Word Viewer 2003
        Microsoft Silverlight
        Microsoft User-Mode Driver Framework Feature Pack 1.0
        Microsoft Windows Journal Viewer
        Microsoft Windows XP -käyttöjärjestelmän ohjatun CD-levylle tallentamisen HighMAT-laajennus
        Microsoft Visual C 2005 Redistributable
        Movie Maker Background Music Files
        Movie Maker Sound Effects
        Movie Maker Title Images
        Mozilla Firefox (3.0.4)
        Mozilla Thunderbird (2.0.0.6)
        MSXML 4.0 SP2 (KB936181)
        MSXML 4.0 SP2 (KB954430)
        MSXML 4.0 SP2 Parser and SDK
        MSXML 6.0 Parser (KB933579)
        Nokia Connectivity Cable Driver
        Nokia Lifeblog 2.1
        Nokia Map Loader
        Nokia MTP driver
        Nokia Nseries Skin for Microsoft Windows Media Player
        Nokia PC Connectivity Solution
        Nokia PC Suite
        Nokia themes for your device
        Ohjattu henkilökohtaisten käyttöoikeuksien päivittäminen
        OLYMPUS Master 2
        OpenOffice.org 2.3
        Personal License Update Wizard for Windows Media Player
        Piilotietojen poistamistyökalu
        Päivitys Windows XP:lle (KB951072-v2)
        Päivitys Windows XP:lle (KB951978)
        Päivitys Windows XP:lle (KB955839)
        QuickTime
        RealPlayer
        ScanToWeb
        Shockwave
        SiS 900 PCI Fast Ethernet Adapter Driver
        Spybot - Search & Destroy 1.2
        Suojauspäivitys ohjelmistolle Windows XP (KB941569)
        Suojauspäivitys Windows Internet Explorer 7:lle (KB938127)
        Suojauspäivitys Windows Internet Explorer 7:lle (KB942615)
        Suojauspäivitys Windows Internet Explorer 7:lle (KB944533)
        Suojauspäivitys Windows Internet Explorer 7:lle (KB950759)
        Suojauspäivitys Windows Internet Explorer 7:lle (KB953838)
        Suojauspäivitys Windows Internet Explorer 7:lle (KB956390)
        Suojauspäivitys Windows Internet Explorer 7:lle (KB958215)
        Suojauspäivitys Windows Media Encoder -ohjelmistolle (KB954156)
        Suojauspäivitys Windows Media Player 10:lle (KB911565)
        Suojauspäivitys Windows Media Player 10:lle (KB917734)
        Suojauspäivitys Windows Media Player 10:lle (KB936782)
        Suojauspäivitys Windows Media Player 11:lle (KB936782)
        Suojauspäivitys Windows Media Player 11:lle (KB954154)
        Suojauspäivitys Windows Media Playerille (KB952069)
        Suojauspäivitys Windows XP:lle (KB938464)
        Suojauspäivitys Windows XP:lle (KB946648)
        Suojauspäivitys Windows XP:lle (KB950760)
        Suojauspäivitys Windows XP:lle (KB950762)
        Suojauspäivitys Windows XP:lle (KB950974)
        Suojauspäivitys Windows XP:lle (KB951066)
        Suojauspäivitys Windows XP:lle (KB951376)
        Suojauspäivitys Windows XP:lle (KB951376-v2)
        Suojauspäivitys Windows XP:lle (KB951698)
        Suojauspäivitys Windows XP:lle (KB951748)
        Suojauspäivitys Windows XP:lle (KB952954)
        Suojauspäivitys Windows XP:lle (KB953839)
        Suojauspäivitys Windows XP:lle (KB954211)
        Suojauspäivitys Windows XP:lle (KB954459)
        Suojauspäivitys Windows XP:lle (KB954600)
        Suojauspäivitys Windows XP:lle (KB955069)
        Suojauspäivitys Windows XP:lle (KB956391)
        Suojauspäivitys Windows XP:lle (KB956802)
        Suojauspäivitys Windows XP:lle (KB956803)
        Suojauspäivitys Windows XP:lle (KB956841)
        Suojauspäivitys Windows XP:lle (KB957095)
        Suojauspäivitys Windows XP:lle (KB957097)
        Suojauspäivitys Windows XP:lle (KB958644)
        USB EHCI Driver
        VESO2000
        Windows Communication Foundation
        Windows Driver Package - Nokia Modem (06/12/2006 6.81.0.21)
        Windows Genuine Advantage v1.3.0254.0
        Windows Imaging Component
        Windows Media Bonus Pack for Windows XP
        Windows Media Encoder 9 Series
        Windows Media Encoder 9 Series
        Windows Media Format 11 runtime
        Windows Media Format 11 runtime
        Windows Media Player 11
        Windows Media Player 11
        Windows Media Player Playlist Import to Excel Wizard
        Windows Media Player Skin Importer
        Windows Media Player Tray Control
        Windows Presentation Foundation
        Windows Presentation Foundation Language Pack (FIN)
        Windows Workflow Foundation
        Windows Workflow Foundation FI Language Pack
        Windows XP Service Pack 3
        WinRAR archiver
        VLC media player 0.9.6
        XML Paper Specification Shared Components Language Pack 1.0

        Se Antivir kansio, program filesin alla, AVpersonal ei poistuonut täysin, koska alkoi herjaamaan AVSHLEXT.DLL tiedostoa,herjausteksti oli: käyttöestetty. varmista ettei se ole kirjoitussuojattu tai käynnissä.. tein kirjaimellisesti ohjeittesi mukaan poistoyrityksen. käytännössä sinne avpersonal-kansion alle jäi nyt vaan tuo dll-tiedosto


      • apua tarvitseva
        vehnälepäkö kirjoitti:

        Kopioi / liitä seuraava teksti alapuolella tyhjään muistioFiluun
        Varmista että tiedoston tyyppi on "all Files" ja tallenna se Poisto.bat. nimisenä
        työpöydällesi.

        @echo off
        sc stop AntiVirService
        sc delete AntiVirService
        sc stop AVWUpSrv

        Tupla-klikkaa Poisto.bat. filua työpöydälläsi , ikkuna avautuu ja Sulkeutuu tämä on normaalia.

        ----------------------------

        Poista vikasiedossa kansio

        C:\Program Files\>> AVPersonal

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 17:53:10, on 18.12.2008
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16762)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
        C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
        C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
        C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
        C:\WINDOWS\AGRSMMSG.exe
        C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
        C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
        C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
        C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
        C:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe
        C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi;;localhost;
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\tools\BitCometBHO_1.2.8.7.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
        O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
        O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
        O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
        O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
        O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
        O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\RunOnce: [NSSInstallation] C:\WINDOWS\system32\Adobe\Shockwave 11\nssstub.exe /RunOnce
        O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
        O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
        O4 - Global Startup: TMMonitor.lnk = C:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe
        O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\BitComet.exe/AddLink.htm
        O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\BitComet.exe/AddVideo.htm
        O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\BitComet.exe/AddAllLink.htm
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
        O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1202051266640
        O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
        O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
        O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
        O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
        O23 - Service: AntiVir Update (AVWUpSrv) - Unknown owner - C:\Program Files\AVPersonal\AVWUPSRV.EXE (file missing)
        O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
        O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe

        --
        End of file - 7922 bytes


      • apua tarvitseva
        vehnälepäkö kirjoitti:

        Kopioi / liitä seuraava teksti alapuolella tyhjään muistioFiluun
        Varmista että tiedoston tyyppi on "all Files" ja tallenna se Poisto.bat. nimisenä
        työpöydällesi.

        @echo off
        sc stop AntiVirService
        sc delete AntiVirService
        sc stop AVWUpSrv

        Tupla-klikkaa Poisto.bat. filua työpöydälläsi , ikkuna avautuu ja Sulkeutuu tämä on normaalia.

        ----------------------------

        Poista vikasiedossa kansio

        C:\Program Files\>> AVPersonal

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 18:50:08, on 18.12.2008
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16762)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
        C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
        C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
        C:\WINDOWS\AGRSMMSG.exe
        C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
        C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
        C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
        C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
        C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
        C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe
        C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
        C:\WINDOWS\system32\taskmgr.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi;;localhost;
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\tools\BitCometBHO_1.2.8.7.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
        O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
        O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
        O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
        O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
        O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\RunOnce: [NSSInstallation] C:\WINDOWS\system32\Adobe\Shockwave 11\nssstub.exe /RunOnce
        O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
        O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
        O4 - Global Startup: TMMonitor.lnk = C:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe
        O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\BitComet.exe/AddLink.htm
        O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\BitComet.exe/AddVideo.htm
        O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\BitComet.exe/AddAllLink.htm
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
        O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1202051266640
        O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
        O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
        O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
        O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
        O23 - Service: AntiVir Update (AVWUpSrv) - Unknown owner - C:\Program Files\AVPersonal\AVWUPSRV.EXE (file missing)
        O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
        O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe

        --
        End of file - 7867 bytes


      • apua tarvitseva
        vehnälepäkö kirjoitti:

        Kopioi / liitä seuraava teksti alapuolella tyhjään muistioFiluun
        Varmista että tiedoston tyyppi on "all Files" ja tallenna se Poisto.bat. nimisenä
        työpöydällesi.

        @echo off
        sc stop AntiVirService
        sc delete AntiVirService
        sc stop AVWUpSrv

        Tupla-klikkaa Poisto.bat. filua työpöydälläsi , ikkuna avautuu ja Sulkeutuu tämä on normaalia.

        ----------------------------

        Poista vikasiedossa kansio

        C:\Program Files\>> AVPersonal

        kirjotellaan tässä nyt sitte ihan urakalla kun oottelen samalla kommenttiasi

        Toimiiko AVG myös palomuurina? Vai asennetaanko erillinen.. esim sygate?

        Ainakin wintoosan oma balomuuri on nyt päällä. Mikäli asennetaan erillinen palomuuri, niin otetaanko wintoosan oma palomuuri pois päältä asennuksen jälkeen.. semmosta


      • Vehnäleipäkö
        apua tarvitseva kirjoitti:

        Moro... ohessa taas logia yms.

        SDFix:
        [b]SDFix: Version 1.240 [/b]
        Run by Matti on to 18.12.2008 at 17:06
        Microsoft Windows XP [versio 5.1.2600]
        Running From: C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Ty”p”yt„\SDFix

        [b]Checking Services [/b]:

        Restoring Default Security Values
        Restoring Default Hosts File

        Rebooting

        [b]Checking Files [/b]:

        No Trojan Files Found

        Removing Temp Files

        [b]ADS Check [/b]:
        [b]Final Check [/b]:

        catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2008-12-18 17:18:32
        Windows 5.1.2600 Service Pack 3 NTFS

        scanning hidden processes ...

        scanning hidden services & system hive ...

        scanning hidden registry entries ...

        scanning hidden files ...

        scan completed successfully
        hidden processes: 0
        hidden services: 0
        hidden files: 0

        [b]Remaining Services [/b]:

        Authorized Application Key Export:

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
        "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
        "C:\\Program Files\\ArcSoft\\TotalMedia 3\\TotalMedia.exe"="C:\\Program Files\\ArcSoft\\TotalMedia 3\\TotalMedia.exe:LocalSubNet:Enabled:ArcSoft TotalMedia 3"
        "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
        "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
        "C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
        "C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
        "C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
        "C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc.exe"
        "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
        "C:\\Documents and Settings\\Matti.MATTI-OFCR7XYKR\\Omat tiedostot\\Bitcomet\\BitComet.exe"="C:\\Documents and Settings\\Matti.MATTI-OFCR7XYKR\\Omat tiedostot\\Bitcomet\\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
        "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
        "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
        "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
        "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 6.2"

        [b]Remaining Files [/b]:

        [b]Files with Hidden Attributes [/b]:

        Fri 20 Feb 2004 27,030 A..HR --- "C:\Undo MATTI-OFCR7XYKR 20040220 185227.Reg"
        Thu 31 May 2007 2,324,048 ...H. --- "C:\Program Files\Bejeweled 2\WinBej2.exe"
        Fri 4 May 2007 2,482,176 ...H. --- "C:\Program Files\Cradle of Rome\Cradle of Rome.exe"
        Mon 22 Jul 2002 418,816 ...HR --- "C:\WINDOWS\system32\Tools\All.exe"
        Fri 19 Jul 2002 390,144 ...HR --- "C:\WINDOWS\system32\Tools\Change.exe"
        Fri 19 Jul 2002 574,464 ...HR --- "C:\WINDOWS\system32\Tools\CheckPath.exe"
        Tue 20 Aug 2002 430,592 ...HR --- "C:\WINDOWS\system32\Tools\Counter.exe"
        Tue 23 Jul 2002 390,656 ...HR --- "C:\WINDOWS\system32\Tools\DelFolders.exe"
        Fri 22 Nov 2002 399,872 ...HR --- "C:\WINDOWS\system32\Tools\DirectSetup.exe"
        Fri 19 Jul 2002 388,096 ...HR --- "C:\WINDOWS\system32\Tools\RegClean.exe"
        Fri 19 Jul 2002 388,608 ...HR --- "C:\WINDOWS\system32\Tools\Regexe.exe"
        Mon 2 Dec 2002 431,616 ...HR --- "C:\WINDOWS\system32\Tools\Restart.exe"
        Fri 19 Jul 2002 388,096 ...HR --- "C:\WINDOWS\system32\Tools\RunRegexe.exe"
        Sun 13 Jan 2008 0 A.SH. --- "C:\Documents and Settings\All Users.WINDOWS\DRM\Cache\Indiv01.tmp"

        [b]Finished![/b]


        HJT uuninstall managerin alla oli seuraavaa:
        ehdota vain mitkä hyövää poistaa

        Ad-Aware
        Adobe Flash Player Plugin
        Adobe Reader 8.1.3
        Adobe Shockwave Player 11
        Adobe® Photoshop® Album Starter Edition 3.0
        AIDA32 v3.85
        AntiVir/XP
        ArcSoft PhotoImpression
        ArcSoft TotalMedia 3
        ATI Control Panel
        ATI Display Driver
        ATI HydraVision
        ATI-ohjelmiston poisto-ohjelma
        AVG 7.5
        Bejeweled 2 Deluxe (remove only)
        BitComet 1.07
        BSPlayer
        CCleaner (remove only)
        C-Media 3D Audio
        C-Media WDM Audio Driver
        Cover Gold Pro Version 1.7.1
        CoverPro 7.2.1
        Cradle of Rome (remove only)
        Creative Modem Blaster V.92 DI5733
        DVD Cover Print
        EasyCleaner
        eMedia Codec 4.0
        EPSON Copy Utility
        EPSON Photo Print
        EPSON PhotoQuicker3.2
        EPSON Printer Software
        EPSON Smart Panel
        EPSON TWAIN 5
        Google Toolbar for Internet Explorer
        Google Toolbar for Internet Explorer
        HijackThis 2.0.2
        Hotfix for Windows Media Format 11 SDK (KB929399)
        Hotfix-korjauspäivitys Windows Media Player 11:lle (KB939683)
        Hotfix-päivitys Windows Internet Explorer 7:lle (KB947864)
        Hotfix-päivitys Windows XP:lle (KB952287)
        Java(TM) 6 Update 11
        Java(TM) 6 Update 7
        Jippii
        Logitech Desktop Messenger
        Logitech MouseWare 9.70
        Macromedia Shockwave Player
        Malwarebytes' Anti-Malware
        Media Library Management Wizard
        Microsoft .NET Framework 1.1
        Microsoft .NET Framework 1.1
        Microsoft .NET Framework 1.1 Finnish Language Pack
        Microsoft .NET Framework 1.1 Hotfix (KB928366)
        Microsoft .NET Framework 2.0 Language Pack - FIN
        Microsoft .NET Framework 2.0 Service Pack 1
        Microsoft .NET Framework 3.0
        Microsoft .NET Framework 3.0
        Microsoft .NET Framework 3.0 Finnish Language Pack
        Microsoft .NET Framework 3.0:n suomen kielipaketti
        Microsoft Base Smart Card Cryptographic Service Provider Package
        Microsoft Compression Client Pack 1.0 for Windows XP
        Microsoft Data Access Components KB870669
        Microsoft Internationalized Domain Names Mitigation APIs
        Microsoft National Language Support Downlevel APIs
        Microsoft Office Excel Viewer 2003
        Microsoft Office PowerPoint Viewer 2003
        Microsoft Office Word Viewer 2003
        Microsoft Silverlight
        Microsoft User-Mode Driver Framework Feature Pack 1.0
        Microsoft Windows Journal Viewer
        Microsoft Windows XP -käyttöjärjestelmän ohjatun CD-levylle tallentamisen HighMAT-laajennus
        Microsoft Visual C 2005 Redistributable
        Movie Maker Background Music Files
        Movie Maker Sound Effects
        Movie Maker Title Images
        Mozilla Firefox (3.0.4)
        Mozilla Thunderbird (2.0.0.6)
        MSXML 4.0 SP2 (KB936181)
        MSXML 4.0 SP2 (KB954430)
        MSXML 4.0 SP2 Parser and SDK
        MSXML 6.0 Parser (KB933579)
        Nokia Connectivity Cable Driver
        Nokia Lifeblog 2.1
        Nokia Map Loader
        Nokia MTP driver
        Nokia Nseries Skin for Microsoft Windows Media Player
        Nokia PC Connectivity Solution
        Nokia PC Suite
        Nokia themes for your device
        Ohjattu henkilökohtaisten käyttöoikeuksien päivittäminen
        OLYMPUS Master 2
        OpenOffice.org 2.3
        Personal License Update Wizard for Windows Media Player
        Piilotietojen poistamistyökalu
        Päivitys Windows XP:lle (KB951072-v2)
        Päivitys Windows XP:lle (KB951978)
        Päivitys Windows XP:lle (KB955839)
        QuickTime
        RealPlayer
        ScanToWeb
        Shockwave
        SiS 900 PCI Fast Ethernet Adapter Driver
        Spybot - Search & Destroy 1.2
        Suojauspäivitys ohjelmistolle Windows XP (KB941569)
        Suojauspäivitys Windows Internet Explorer 7:lle (KB938127)
        Suojauspäivitys Windows Internet Explorer 7:lle (KB942615)
        Suojauspäivitys Windows Internet Explorer 7:lle (KB944533)
        Suojauspäivitys Windows Internet Explorer 7:lle (KB950759)
        Suojauspäivitys Windows Internet Explorer 7:lle (KB953838)
        Suojauspäivitys Windows Internet Explorer 7:lle (KB956390)
        Suojauspäivitys Windows Internet Explorer 7:lle (KB958215)
        Suojauspäivitys Windows Media Encoder -ohjelmistolle (KB954156)
        Suojauspäivitys Windows Media Player 10:lle (KB911565)
        Suojauspäivitys Windows Media Player 10:lle (KB917734)
        Suojauspäivitys Windows Media Player 10:lle (KB936782)
        Suojauspäivitys Windows Media Player 11:lle (KB936782)
        Suojauspäivitys Windows Media Player 11:lle (KB954154)
        Suojauspäivitys Windows Media Playerille (KB952069)
        Suojauspäivitys Windows XP:lle (KB938464)
        Suojauspäivitys Windows XP:lle (KB946648)
        Suojauspäivitys Windows XP:lle (KB950760)
        Suojauspäivitys Windows XP:lle (KB950762)
        Suojauspäivitys Windows XP:lle (KB950974)
        Suojauspäivitys Windows XP:lle (KB951066)
        Suojauspäivitys Windows XP:lle (KB951376)
        Suojauspäivitys Windows XP:lle (KB951376-v2)
        Suojauspäivitys Windows XP:lle (KB951698)
        Suojauspäivitys Windows XP:lle (KB951748)
        Suojauspäivitys Windows XP:lle (KB952954)
        Suojauspäivitys Windows XP:lle (KB953839)
        Suojauspäivitys Windows XP:lle (KB954211)
        Suojauspäivitys Windows XP:lle (KB954459)
        Suojauspäivitys Windows XP:lle (KB954600)
        Suojauspäivitys Windows XP:lle (KB955069)
        Suojauspäivitys Windows XP:lle (KB956391)
        Suojauspäivitys Windows XP:lle (KB956802)
        Suojauspäivitys Windows XP:lle (KB956803)
        Suojauspäivitys Windows XP:lle (KB956841)
        Suojauspäivitys Windows XP:lle (KB957095)
        Suojauspäivitys Windows XP:lle (KB957097)
        Suojauspäivitys Windows XP:lle (KB958644)
        USB EHCI Driver
        VESO2000
        Windows Communication Foundation
        Windows Driver Package - Nokia Modem (06/12/2006 6.81.0.21)
        Windows Genuine Advantage v1.3.0254.0
        Windows Imaging Component
        Windows Media Bonus Pack for Windows XP
        Windows Media Encoder 9 Series
        Windows Media Encoder 9 Series
        Windows Media Format 11 runtime
        Windows Media Format 11 runtime
        Windows Media Player 11
        Windows Media Player 11
        Windows Media Player Playlist Import to Excel Wizard
        Windows Media Player Skin Importer
        Windows Media Player Tray Control
        Windows Presentation Foundation
        Windows Presentation Foundation Language Pack (FIN)
        Windows Workflow Foundation
        Windows Workflow Foundation FI Language Pack
        Windows XP Service Pack 3
        WinRAR archiver
        VLC media player 0.9.6
        XML Paper Specification Shared Components Language Pack 1.0

        Se Antivir kansio, program filesin alla, AVpersonal ei poistuonut täysin, koska alkoi herjaamaan AVSHLEXT.DLL tiedostoa,herjausteksti oli: käyttöestetty. varmista ettei se ole kirjoitussuojattu tai käynnissä.. tein kirjaimellisesti ohjeittesi mukaan poistoyrityksen. käytännössä sinne avpersonal-kansion alle jäi nyt vaan tuo dll-tiedosto

        Java(TM) 6 Update 7
        Logitech Desktop Messenger


      • Vehnäleipäkö
        apua tarvitseva kirjoitti:

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 18:50:08, on 18.12.2008
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16762)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
        C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
        C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
        C:\WINDOWS\AGRSMMSG.exe
        C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
        C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
        C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
        C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
        C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
        C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe
        C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
        C:\WINDOWS\system32\taskmgr.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi;;localhost;
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\tools\BitCometBHO_1.2.8.7.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
        O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
        O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
        O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
        O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
        O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\RunOnce: [NSSInstallation] C:\WINDOWS\system32\Adobe\Shockwave 11\nssstub.exe /RunOnce
        O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
        O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
        O4 - Global Startup: TMMonitor.lnk = C:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe
        O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\BitComet.exe/AddLink.htm
        O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\BitComet.exe/AddVideo.htm
        O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\BitComet.exe/AddAllLink.htm
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
        O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1202051266640
        O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
        O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
        O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
        O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
        O23 - Service: AntiVir Update (AVWUpSrv) - Unknown owner - C:\Program Files\AVPersonal\AVWUPSRV.EXE (file missing)
        O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
        O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe

        --
        End of file - 7867 bytes

        ei lähe vai

        Kopioi / liitä seuraava teksti alapuolella tyhjään muistioFiluun
        Varmista että tiedoston tyyppi on "all Files" ja tallenna se Poisto.bat. nimisenä
        työpöydällesi.

        @echo off
        sc stop AVWUpSrv
        sc delete AVWUpSrv

        Tupla-klikkaa Poisto.bat. filua työpöydälläsi , ikkuna avautuu ja Sulkeutuu tämä on normaalia.


      • Vehnäleipäkö
        apua tarvitseva kirjoitti:

        kirjotellaan tässä nyt sitte ihan urakalla kun oottelen samalla kommenttiasi

        Toimiiko AVG myös palomuurina? Vai asennetaanko erillinen.. esim sygate?

        Ainakin wintoosan oma balomuuri on nyt päällä. Mikäli asennetaan erillinen palomuuri, niin otetaanko wintoosan oma palomuuri pois päältä asennuksen jälkeen.. semmosta

        >>>>Ainakin wintoosan oma balomuuri on nyt päällä. Mikäli asennetaan erillinen palomuuri, niin otetaanko wintoosan oma palomuuri pois päältä asennuksen jälkeen.. semmosta Toimiiko AVG myös palomuurina


      • apua tarvitseva
        Vehnäleipäkö kirjoitti:

        >>>>Ainakin wintoosan oma balomuuri on nyt päällä. Mikäli asennetaan erillinen palomuuri, niin otetaanko wintoosan oma palomuuri pois päältä asennuksen jälkeen.. semmosta Toimiiko AVG myös palomuurina

        eiköhän nyt taas vähän aikaa pärjätä ja pietään woodoot yms poissa koneelta.... seuraavaan kertaan asti x)


      • vehnäleipäkö
        apua tarvitseva kirjoitti:

        eiköhän nyt taas vähän aikaa pärjätä ja pietään woodoot yms poissa koneelta.... seuraavaan kertaan asti x)

        Kirjoita Suorita luukkuun

        ComboFix /u

        Klikkaa ok

        --------

        Lataa http://oldtimer.geekstogo.com/OTMoveIt3.exe
        OTMoveIt ja tallenna se työpöydällesi.

        Tuplaklikkaa OTMoveIt.exe.
        Klikkaa CleanUp!.
        Valitse Yes kun kysytään "Begin cleanup Process?".
        Jos pyydetään, että saako koneen käynnistää uudeelleen, valitse Yes.OTMoveIt poistaa itsensä kun se on valmis, jos näin ei käy poista se itse.


        HUOM: Jos palomuurisi tai joku muu tietoturvaohjelma varoittaa, että OTMoveIt yrittää päästä nettin, niin anna sen päästä sinne.

        ----------

        vielä aft cleanerilla päälle


      • apua tarvitseva
        vehnäleipäkö kirjoitti:

        Kirjoita Suorita luukkuun

        ComboFix /u

        Klikkaa ok

        --------

        Lataa http://oldtimer.geekstogo.com/OTMoveIt3.exe
        OTMoveIt ja tallenna se työpöydällesi.

        Tuplaklikkaa OTMoveIt.exe.
        Klikkaa CleanUp!.
        Valitse Yes kun kysytään "Begin cleanup Process?".
        Jos pyydetään, että saako koneen käynnistää uudeelleen, valitse Yes.OTMoveIt poistaa itsensä kun se on valmis, jos näin ei käy poista se itse.


        HUOM: Jos palomuurisi tai joku muu tietoturvaohjelma varoittaa, että OTMoveIt yrittää päästä nettin, niin anna sen päästä sinne.

        ----------

        vielä aft cleanerilla päälle

        moro, katokko kertaallen vielä läpi että tartteeko mitään enää tehä

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 15:32:52, on 21.12.2008
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16762)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Sygate\SPF\smc.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
        C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
        C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
        C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
        C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\WINDOWS\System32\svchost.exe
        C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
        C:\WINDOWS\AGRSMMSG.exe
        C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
        C:\WINDOWS\system32\taskmgr.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi;;localhost;
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\tools\BitCometBHO_1.2.8.7.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
        O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
        O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
        O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
        O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
        O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
        O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
        O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
        O4 - Global Startup: TMMonitor.lnk = C:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe
        O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\BitComet.exe/AddLink.htm
        O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\BitComet.exe/AddVideo.htm
        O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\BitComet.exe/AddAllLink.htm
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
        O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1202051266640
        O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
        O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
        O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
        O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
        O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
        O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
        O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

        --
        End of file - 7796 bytes


      • vehnäleipäkö
        apua tarvitseva kirjoitti:

        moro, katokko kertaallen vielä läpi että tartteeko mitään enää tehä

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 15:32:52, on 21.12.2008
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16762)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Sygate\SPF\smc.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
        C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
        C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
        C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
        C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\WINDOWS\System32\svchost.exe
        C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
        C:\WINDOWS\AGRSMMSG.exe
        C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
        C:\WINDOWS\system32\taskmgr.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dial.inet.fi:800
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fi;*.*.fi;*.*.*.fi;;localhost;
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\tools\BitCometBHO_1.2.8.7.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
        O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
        O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
        O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
        O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
        O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
        O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
        O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
        O4 - Global Startup: TMMonitor.lnk = C:\Program Files\ArcSoft\TotalMedia 3\TMMonitor.exe
        O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\BitComet.exe/AddLink.htm
        O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\BitComet.exe/AddVideo.htm
        O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\BitComet.exe/AddAllLink.htm
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
        O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Documents and Settings\Matti.MATTI-OFCR7XYKR\Omat tiedostot\Bitcomet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=http://www.soneraplaza.fi
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1202051266640
        O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
        O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
        O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
        O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
        O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
        O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
        O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

        --
        End of file - 7796 bytes

        scannaa hjt:llä merkkaa Klikkaa Fix checked

        O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

        --------

        Muuta ei tarvii tehdä


      • apua tarvitseva
        vehnäleipäkö kirjoitti:

        scannaa hjt:llä merkkaa Klikkaa Fix checked

        O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

        --------

        Muuta ei tarvii tehdä

        vehnäleivälle (kkö) kiitokset ja hyvää joulun odotusta


    Ketjusta on poistettu 0 sääntöjenvastaista viestiä.

    Luetuimmat keskustelut

    1. Kotkalainen Demari Riku Pirinen vangittu Saksassa lapsipornosta

      https://www.kymensanomat.fi/paikalliset/8081054 Kotkalainen Demari Riku Pirinen vangittu Saksassa lapsipornon hallussapi
      Kotka
      130
      3221
    2. Vanhalle ukon rähjälle

      Satutit mua niin paljon kun erottiin. Oletko todella niin itsekäs että kuvittelet että huolisin sut kaiken tapahtuneen
      Ikävä
      38
      2563
    3. Olen tosi outo....

      Päättelen palstajuttujen perusteella mitä mieltä minun kaipauksen kohde minusta on. Joskus kuvittelen tänne selkeitä tap
      Ikävä
      30
      2445
    4. Maisa on SALAKUVATTU huumepoliisinsa kanssa!

      https://www.seiska.fi/vain-seiskassa/ensimmainen-yhteiskuva-maisa-torpan-ja-poliisikullan-lahiorakkaus-roihuaa/1525663
      Kotimaiset julkkisjuorut
      114
      2248
    5. Oletko sä luovuttanut

      Mun suhteeni
      Ikävä
      114
      1720
    6. Nurmossa kuoli 2 Lasta..

      Autokolarissa. Näin kertovat iltapäivälehdet juuri nyt. 22.11. Ja aina ennen Joulua näitä tulee. . .
      Seinäjoki
      28
      1674
    7. Hommaatko kinkkua jouluksi?

      Itse tein pakastimeen n. 3Kg:n murekkeen sienillä ja juustokuorrutuksella. Voihan se olla, että jonkun pienen, valmiin k
      Sinkut
      174
      1418
    8. Mikko Koivu yrittää pestä mustan valkoiseksi

      Ilmeisesti huomannut, että Helenan tukijoukot kasvaa kasvamistaan. Riistakamera paljasti hiljattain kylmän totuuden Mi
      Kotimaiset julkkisjuorut
      300
      1321
    9. Aatteleppa ite!

      Jos ei oltaisikaan nyt NATOssa, olisimme puolueettomana sivustakatsojia ja elelisimme tyytyväisenä rauhassa maassamme.
      Maailman menoa
      304
      1282
    10. Onko se ikä

      Alkanut haitata?
      Ikävä
      63
      1110
    Aihe