Logfile of HijackThis v1.99.0
Scan saved at 16:37:13, on 27.1.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
C:Program FilesCyberLink DVD SolutionPowerDVDPDVDServ.exe
C:PROGRA~1B'SCLI~1Win2KBSCLIP.exe
C:Program FilesMSN AppsUpdater 1.02.3000.1001fimsnappau.exe
C:Program FilesQuickTimeqttask.exe
C:Program FilesLogitechVideoLogiTray.exe
C:Program FilesF-Secure Internet SecurityCommonFSM32.EXE
C:Program FilesATI TechnologiesATI HYDRAVISIONHydraDM.exe
C:Program FilesMicrosoft AntiSpywaregcasServ.exe
C:Program FilesD-Toolsdaemon.exe
C:Program FilesMSN MessengerMsnMsgr.Exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesSpybot - Search & DestroyTeaTimer.exe
C:Program FilesLogitechDesktop Messenger8876480ProgramBackWeb-8876480.exe
C:Program FilesiISystem WiperSystemWiper.exe
C:Program FilesInterVideoCommonBinWinCinemaMgr.exe
C:Program FilesLogitechSetPointKEM.exe
C:WINDOWSsystem32RAMASST.exe
C:Program FilesWinZipWZQKPICK.EXE
C:Program FilesLogitechSetPointKHALMNPR.EXE
C:WINDOWSsystem32LVComsX.exe
C:PROGRA~1F-SECU~1backweb4476822ProgramSERVIC~1.EXE
C:WINDOWSsystem32CTsvcCDA.EXE
C:WINDOWSSystem32DVDRAMSV.exe
C:Program FilesF-Secure Internet SecurityAnti-Virusfsgk32st.exe
C:Program FilesF-Secure Internet Securitybackweb4476822Programfspex.exe
C:Program FilesF-Secure Internet SecurityAnti-VirusFSGK32.EXE
C:Program FilesF-Secure Internet SecurityAnti-Virusfssm32.exe
C:Program FilesF-Secure Internet Securitybackweb4476822programfsbwsys.exe
C:Program FilesLogitechVideoFxSvr2.exe
C:Program FilesF-Secure Internet SecurityCommonFSMA32.EXE
C:Program FilesF-Secure Internet SecurityCommonFSMB32.EXE
C:Program FilesF-Secure Internet SecurityCommonFCH32.EXE
C:WINDOWSSystem32svchost.exe
C:Program FilesF-Secure Internet SecurityCommonFAMEH32.EXE
C:Program FilesF-Secure Internet SecurityFSPCfspc.exe
C:Program FilesF-Secure Internet SecurityAnti-Virusfsav32.exe
C:Program FilesF-Secure Internet SecurityFWESProgramfsdfwd.exe
C:Program FilesF-Secure Internet SecurityFSGUIfsguiexe.exe
C:Program FilesMicrosoft AntiSpywaregcasDtServ.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:WINDOWSsystem32wuauclt.exe
C:Documents and Settings-------TyöpöytäHijackThis.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar =
http://g.msn.fi/0SEFIFI/SAOS01
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar =
http://g.msn.fi/0SEFIFI/SAOS01
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = proxy.jyu.fi:8080
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = localhost
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Linkit
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:Program FilesMSN AppsST 1.02.3000.1002en-xustmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:program filesgooglegoogletoolbar2.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:Program FilesMSN AppsMSN Toolbar 1.02.3000.1001fimsntb.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:Program FilesMSN AppsMSN Toolbar 1.02.3000.1001fimsntb.dll
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:program filesgooglegoogletoolbar2.dll
O4 - HKLM..Run: [ATIPTA] C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
O4 - HKLM..Run: [RemoteControl] "C:Program FilesCyberLink DVD SolutionPowerDVDPDVDServ.exe"
O4 - HKLM..Run: [B'sCLiP] C:PROGRA~1B'SCLI~1Win2KBSCLIP.exe
O4 - HKLM..Run: [msnappau] "C:Program FilesMSN AppsUpdater 1.02.3000.1001fimsnappau.exe"
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [LogitechVideoRepair] C:Program FilesLogitechVideoISStart.exe
O4 - HKLM..Run: [LogitechVideoTray] C:Program FilesLogitechVideoLogiTray.exe
O4 - HKLM..Run: [F-Secure Manager] "C:Program FilesF-Secure Internet SecurityCommonFSM32.EXE" /splash
O4 - HKLM..Run: [F-Secure TNB] "C:Program FilesF-Secure Internet SecurityTNBTNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM..Run: [F-Secure Startup Wizard] "C:Program FilesF-Secure Internet SecurityFSGUIFSSW.EXE" /reboot
O4 - HKLM..Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM..Run: [HydraVisionDesktopManager] C:Program FilesATI TechnologiesATI HYDRAVISIONHydraDM.exe
O4 - HKLM..Run: [gcasServ] "C:Program FilesMicrosoft AntiSpywaregcasServ.exe"
O4 - HKLM..Run: [DAEMON Tools-1033] "C:Program FilesD-Toolsdaemon.exe" -lang 1033
O4 - HKCU..Run: [MsnMsgr] "C:Program FilesMSN MessengerMsnMsgr.Exe" /background
O4 - HKCU..Run: [Steam] C:ValveSteamSteam.exe -silent
O4 - HKCU..Run: [RAM Medic] C:Program FilesIomaticRAM MedicRAMMedic.exe
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [SpybotSD TeaTimer] C:Program FilesSpybot - Search & DestroyTeaTimer.exe
O4 - HKCU..Run: [LogitechSoftwareUpdate] "C:Program FilesLogitechVideoManifestEngine.exe" boot
O4 - HKCU..Run: [LDM] C:Program FilesLogitechDesktop Messenger8876480ProgramBackWeb-8876480.exe
O4 - HKCU..Run: [iIWiper] C:Program FilesiISystem WiperSystemWiper.exe m
O4 - HKCU..Run: [HandyPassword] C:ProgramFilesHandyPasswordHandyPassword.exe /Tray
O4 - Startup: Xfire.lnk = C:Program FilesXfireXfire.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:Program FilesInterVideoCommonBinWinCinemaMgr.exe
O4 - Global Startup: Java SATARaid.lnk = C:Program FilesSilicon ImageJava SATARaidrun.bat
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:Program FilesLogitechDesktop Messenger8876480ProgramLDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:Program FilesLogitechSetPointKEM.exe
O4 - Global Startup: RAMASST.lnk = C:WINDOWSsystem32RAMASST.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:Program FilesWinZipWZQKPICK.EXE
O8 - Extra context menu item: &Google Search -
res://c:program filesgoogleGoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links -
res://c:program filesgoogleGoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page -
res://c:program filesgoogleGoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages -
res://c:program filesgoogleGoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English -
res://c:program filesgoogleGoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Web-suodatin - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:Program FilesF-Secure Internet SecurityFSPCfspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:Program FilesF-Secure Internet SecurityFSPCfspcmsie.dll
O9 - Extra 'Tools' menuitem: Näytä &Web-sivuluettelo... - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:Program FilesF-Secure Internet SecurityFSPCfspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:Program FilesF-Secure Internet SecurityFSPCfspcmsie.dll
O9 - Extra 'Tools' menuitem: &Keskeytä Web-sivujen suodatus - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:Program FilesF-Secure Internet SecurityFSPCfspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:Program FilesF-Secure Internet SecurityFSPCfspcmsie.dll
O9 - Extra 'Tools' menuitem: &Kiellä tämä Web-sivusto - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:Program FilesF-Secure Internet SecurityFSPCfspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:Program FilesF-Secure Internet SecurityFSPCfspcmsie.dll
O9 - Extra 'Tools' menuitem: &Salli tämä Web-sivusto - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:Program FilesF-Secure Internet SecurityFSPCfspcmsie.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O10 - Broken Internet access because of LSP provider 'xfire_lsp_10650.dll' missing
O16 - DPF: {33288993-5664-11D4-8B5B-00D0B73B3518} (ell Class) -
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) -
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSsystem32Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - C:WINDOWSsystem32ati2sgag.exe
O23 - Service: F-Secure Internet Security 2005 - Unknown - C:PROGRA~1F-SECU~1backweb4476822ProgramSERVIC~1.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:WINDOWSsystem32CTsvcCDA.EXE
O23 - Service: Loogisen levyn hallinnan valvontapalvelu - Unknown - C:WINDOWSSystem32dmadmin.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:WINDOWSSystem32DVDRAMSV.exe
O23 - Service: Tapahtumaloki - Unknown - C:WINDOWSsystem32services.exe
O23 - Service: F-Secure Gatekeeper Handler Starter - Unknown - C:Program FilesF-Secure Internet SecurityAnti-Virusfsgk32st.exe
O23 - Service: fsbwsys - Unknown - C:Program FilesF-Secure Internet Securitybackweb4476822programfsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon - F-Secure Corporation - C:Program FilesF-Secure Internet SecurityFWESProgramfsdfwd.exe
O23 - Service: F-Secure HTTP Server - F-Secure Corporation - C:Program FilesF-Secure Internet SecurityFSPCfshttpsfshttps.exe
O23 - Service: F-Secure Management Agent - F-Secure Corporation - C:Program FilesF-Secure Internet SecurityCommonFSMA32.EXE
O23 - Service: CD-levyjen kirjoittamisen IMAPI COM -palvelu - Unknown - C:WINDOWSSystem32imapi.exe
O23 - Service: NetMeeting etätyöpöydän jakaminen - Unknown - C:WINDOWSSystem32mnmsrvc.exe
O23 - Service: Plug and Play - Unknown - C:WINDOWSsystem32services.exe
O23 - Service: Etätyöpöydän ohjeen istunnonhallinta - Unknown - C:WINDOWSsystem32sessmgr.exe
O23 - Service: Älykortti - Unknown - C:WINDOWSSystem32SCardSvr.exe
O23 - Service: Resurssilokit ja -hälytykset - Unknown - C:WINDOWSsystem32smlogsvc.exe
O23 - Service: Aseman tilannevedos - Unknown - C:WINDOWSSystem32vssvc.exe
O23 - Service: WMI resurssisovitin - Unknown - C:WINDOWSSystem32wbemwmiapsrv.exe