Nitovuori - 06-11-11 18:37:44,25 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\Nitovuori\Ty”p”yt„"
((((((((((((((((((((((((((((((( Files Created from 2006-10-11 to 2006-11-11 ))))))))))))))))))))))))))))))))))
2006-11-10 19:00 76,560 --a--c--- C:\WINDOWS\system32\drivers\tmcomm.sys
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-10 19:00 -------- d----c--- C:\Program Files\Mozilla
Firefox
2006-11-10 18:47 -------- d----c--- C:\Documents and Settings\Nitovuori\Application Data\BSplayer
2006-11-10 18:46 -------- d----c--- C:\Program Files\Webteh
2006-11-10 18:41 -------- d----c--- C:\Program Files\mIRC
2006-11-10 18:40 -------- d----c--- C:\Program Files\ACE Mega CoDecS Pack
2006-10-30 21:19 -------- d----c--- C:\Program Files\DC++
2006-09-13 07:03 1084416 --a--c--- C:\WINDOWS\system32\msxml3.dll
2006-08-25 17:49 617472 --a--c--- C:\WINDOWS\system32\comctl32.dll
2006-08-21 14:26 16896 --a--c--- C:\WINDOWS\system32\fltlib.dll
2006-08-21 11:14 23040 --a--c--- C:\WINDOWS\system32\fltmc.exe
2006-08-16 13:58 100352 --a--c--- C:\WINDOWS\system32\6to4svc.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SoundMAXPnP"="C:\\Program Files\\Analog Devices\\SoundMAX\\SMax4PNP.exe"
"SoundMAX"="\"C:\\Program Files\\Analog Devices\\SoundMAX\\Smax4.exe\" /tray"
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"IMONTRAY"="C:\\Program Files\\Intel\\Intel(R) Active Monitor\\imontray.exe"
"CnxDslTaskBar"="\"C:\\Program Files\\\\TW-IA300C ADSL\\CnxDslTb.exe\""
"F-Secure Manager"="\"C:\\Program Files\\Sonera Tietoturva\\Common\\FSM32.EXE\" /splash"
"F-Secure TNB"="\"C:\\Program Files\\Sonera Tietoturva\\TNB\\TNBUtil.exe\" /CHECKALL /WAITFORSW"
"WinPatrol"="C:\\PROGRA~1\\BILLPS~1\\WINPAT~1\\winpatrol.exe"
"F-Secure Startup Wizard"="\"C:\\Program Files\\Sonera Tietoturva\\FSGUI\\FSSW.EXE\" /reboot"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Nykyinen kotisivu"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,e6,00,00,00,00,00,00,00,9a,03,00,00,34,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3a,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3a,02,\
00,00,01,00,00,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{54D9498B-CF93-414F-8984-8CE7FDE0D391}"="ewido shell guard"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
~ ~ ~ ~ ~ ~ ~ ~
HijackThis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20050603-144503-307
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - file://C:\TempEI4\EI40_\msxml4.cab
backup-20050603-144503-493
O4 - HKCU\..\Run: [Bib Extra] C:\DOCUME~1\NITOVU~1\APPLIC~1\NOUNTH~1\ooze time frag.exe
backup-20050603-144503-160
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll (file missing)
backup-20050603-144503-525
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.wjwacrlzwaanjjjcpqvzfso.com/r...YMG9kdocwH.html
backup-20050603-144503-380
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll (file missing)
Completion time: 06-11-11 18:38:44.82
C:\ComboFix.txt ... 06-11-11 18:38