Compaq_Omistaja - 06-11-28 18:08:16,60 Service Pack 2
ComboFix 06.11.27W - Running from: "C:\Documents and Settings\Compaq_Omistaja\Ty”p”yt„"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\components
C:\Program Files\Common Files\{29EF520F-088C-1035-0324-060507190166}
C:\Program Files\Common Files\{39EF520F-088C-1035-0324-060507190166}
((((((((((((((((((((((((((((((( Files Created from 2006-10-28 to 2006-11-28 ))))))))))))))))))))))))))))))))))
2006-11-28 17:50 <KANSIO> d-------- C:\Kaspersky
2006-11-27 23:15 <KANSIO> d--h-c--- C:\WINDOWS\ie7
2006-11-27 22:12 <KANSIO> d-------- C:\Program Files\Ultimate Defender
2006-11-27 21:59 <KANSIO> dr------- C:\Suosikit
2006-11-27 21:03 <KANSIO> d-------- C:\!KillBox
2006-11-27 18:31 88,340 --a------ C:\WINDOWS\system32\gvtusrvy.exe
2006-11-27 18:31 <KANSIO> d-------- C:\Documents and Settings\Compaq_Omistaja\Application Data\SearchToolbarCorp
2006-11-27 15:38 38,420 --a------ C:\WINDOWS\system32\xdbwtjtx.dll
2006-11-27 07:10 <KANSIO> d-------- C:\VundoFix Backups
2006-11-26 21:29 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\fssg
2006-11-26 20:58 50,080 --a------ C:\WINDOWS\system32\drivers\fsdfw.sys
2006-11-26 20:58 29,472 --a------ C:\WINDOWS\system32\drivers\fsndis5.sys
2006-11-26 20:58 1,716,224 --a------ C:\WINDOWS\system32\winsflte.dll
2006-11-26 20:58 1,236,992 --a------ C:\WINDOWS\system32\cfgmig32.dll
2006-11-26 20:58 1,187,840 --a------ C:\WINDOWS\system32\winsflt.dll
2006-11-26 20:58 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\F-Secure
2006-11-26 20:03 <KANSIO> d-------- C:\Program Files\Common Files\Cisco Systems
2006-11-26 20:02 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Network Associates
2006-11-26 20:01 <KANSIO> d-------- C:\WINDOWS\5DF3D1BB894E4DCD8275159AC9829B43.TMP
2006-11-26 20:01 <KANSIO> d-------- C:\Program Files\Network Associates
2006-11-26 20:01 <KANSIO> d-------- C:\Program Files\Common Files\Network Associates
2006-11-26 19:01 <KANSIO> d-------- C:\Security Task Manager
2006-11-26 19:01 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2006-11-26 15:48 40,973 ---hs---- C:\WINDOWS\system32\mljhifc.dll
2006-11-26 15:33 40,973 ---hs---- C:\WINDOWS\system32\byxxyaw.dll
2006-11-26 12:06 <KANSIO> d-------- C:\WINDOWS\WBEM
2006-11-26 12:06 <KANSIO> d-------- C:\WINDOWS\system32\fi-fi
2006-11-26 12:03 121,856 --------- C:\WINDOWS\system32\xmllite.dll
2006-11-26 12:03 <KANSIO> d-------- C:\WINDOWS\network diagnostic
2006-11-26 11:47 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2006-11-26 11:45 71,168 --a------ C:\WINDOWS\system32\drvlad.dll
2006-11-26 11:45 40,973 ---hs---- C:\WINDOWS\system32\khfgeda.dll
2006-11-26 08:07 40,973 ---hs---- C:\WINDOWS\system32\vtuuust.dll
2006-11-25 21:51 40,973 ---hs---- C:\WINDOWS\system32\nnnnmmj.dll
2006-11-25 21:34 <KANSIO> d-------- C:\Program Files\Spybot - Search & Destroy
2006-11-25 21:34 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2006-11-25 20:39 <KANSIO> d-------- C:\Program Files\Windows Live Safety Center
2006-11-25 20:12 <KANSIO> d-------- C:\HJT
2006-11-25 13:54 93,696 --a------ C:\WINDOWS\system32\vvdkkpe.dll
2006-11-25 13:54 71,680 --a------ C:\WINDOWS\system32\vorenbj.dll
2006-11-25 13:54 40,973 ---hs---- C:\WINDOWS\system32\rqrstur.dll
2006-11-15 07:30 <KANSIO> d-------- C:\Program Files\MSXML 4.0
2006-11-15 07:29 <KANSIO> d-------- C:\d9d468335dedc8f79025
2006-11-10 19:28 19,537 --------- C:\WINDOWS\system32\drivers\BRPAR.SYS
2006-11-10 19:28 188,416 --a------ C:\WINDOWS\system32\Pdrvinst.dll
2006-11-10 18:15 <KANSIO> dr------- C:\Documents and Settings\Compaq_Omistaja\Application Data\Brother
2006-11-10 17:39 25,856 --------- C:\WINDOWS\system32\drivers\usbprint.sys
2006-11-07 21:03 6,049,280 --------- C:\WINDOWS\system32\ieframe.dll
2006-11-07 21:03 50,688 --------- C:\WINDOWS\system32\msfeedsbs.dll
2006-11-07 21:03 458,752 --------- C:\WINDOWS\system32\msfeeds.dll
2006-11-07 21:03 180,736 --------- C:\WINDOWS\system32\ieui.dll
2006-11-07 03:26 13,312 --a------ C:\WINDOWS\system32\ieudinit.exe
2006-11-04 14:14 1,245,696 --a------ C:\WINDOWS\system32\msxml4.dll
2006-10-29 16:36 <KANSIO> d-------- C:\LVI
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-28 18:08 -------- d-------- C:\Program Files\Common Files
2006-11-27 23:19 -------- d-------- C:\Program Files\Internet Explorer
2006-11-27 22:18 -------- d-------- C:\Program Files\Mozilla
Firefox
2006-11-26 21:41 -------- d-------- C:\Documents and Settings\Compaq_Omistaja\Application Data\F-Secure
2006-11-26 21:35 -------- d-------- C:\Program Files\F-Secure Internet Security
2006-11-26 20:47 -------- d-------- C:\Documents and Settings\Compaq_Omistaja\Application Data\Lavasoft
2006-11-26 20:25 -------- d-------- C:\Program Files\F-Secure
2006-11-25 13:53 -------- d-------- C:\Program Files\DC++
2006-11-10 21:49 -------- d-------- C:\Program Files\Common Files\InstallShield
2006-11-10 19:28 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-11-07 21:03 413696 --a------ C:\WINDOWS\system32\vbscript.dll
2006-11-07 21:03 231424 --a------ C:\WINDOWS\system32\webcheck.dll
2006-11-07 21:03 156160 --a------ C:\WINDOWS\system32\msls31.dll
2006-11-07 03:27 382976 --a------ C:\WINDOWS\system32\iedkcs32.dll
2006-11-07 03:27 229376 --a------ C:\WINDOWS\system32\ieaksie.dll
2006-11-07 03:26 71680 --a------ C:\WINDOWS\system32\admparse.dll
2006-11-07 03:26 55296 --a------ C:\WINDOWS\system32\iesetup.dll
2006-11-07 03:26 54784 --a------ C:\WINDOWS\system32\ie4uinit.exe
2006-11-07 03:26 43008 --a------ C:\WINDOWS\system32\iernonce.dll
2006-11-07 03:26 152064 --a------ C:\WINDOWS\system32\ieakeng.dll
2006-11-07 03:26 123904 --a------ C:\WINDOWS\system32\advpack.dll
2006-11-07 03:25 161792 --a------ C:\WINDOWS\system32\ieakui.dll
2006-10-27 17:31 -------- d-------- C:\Program Files\Ifi
2006-10-27 17:31 -------- d-------- C:\Documents and Settings\Compaq_Omistaja\Application Data\Ifi
2006-10-17 12:06 78336 --a------ C:\WINDOWS\system32\ieencode.dll
2006-10-17 12:05 40960 --a------ C:\WINDOWS\system32\licmgr10.dll
2006-10-17 12:05 206336 --------- C:\WINDOWS\system32\WinFXDocObj.exe
2006-10-17 12:05 105984 --a------ C:\WINDOWS\system32\url.dll
2006-10-17 12:04 101376 --a------ C:\WINDOWS\system32\occache.dll
2006-10-17 12:03 17408 --a------ C:\WINDOWS\system32\corpol.dll
2006-10-17 11:58 61952 --------- C:\WINDOWS\system32\icardie.dll
2006-10-17 11:58 12288 --------- C:\WINDOWS\system32\msfeedssync.exe
2006-10-17 11:57 36352 --a------ C:\WINDOWS\system32\imgutil.dll
2006-10-17 11:57 266752 --------- C:\WINDOWS\system32\iertutil.dll
2006-10-17 11:56 45568 --a------ C:\WINDOWS\system32\mshta.exe
2006-10-17 11:28 48128 --a------ C:\WINDOWS\system32\mshtmler.dll
2006-10-17 11:27 380928 --------- C:\WINDOWS\system32\ieapfltr.dll
2006-10-13 14:37 142336 --a------ C:\WINDOWS\system32\nwprovau.dll
2006-10-01 20:11 24576 --a------ C:\WINDOWS\TEMPIadHide3.dll
2006-10-01 20:08 -------- d-------- C:\Program Files\Symantec
2006-10-01 20:08 -------- d-------- C:\Program Files\Common Files\Symantec Shared
2006-10-01 07:48 -------- d-------- C:\Documents and Settings\Compaq_Omistaja\Application Data\PEX
2006-10-01 07:46 -------- d-------- C:\Documents and Settings\Compaq_Omistaja\Application Data\ispnews
2006-09-13 07:03 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-09-06 16:43 22752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2006-09-05 19:29 73216 --a------ C:\WINDOWS\ST6UNST.EXE
2006-09-05 19:29 249856 --------- C:\WINDOWS\Setup1.exe
2006-08-12 17:00 14702 --a------ C:\Documents and Settings\Compaq_Omistaja\Application Data\NMM-MetaData.db
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"PcSync"="C:\\Program Files\\Nokia\\Nokia PC Suite 6\\PcSync2.exe /NoDialog"
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Ahead\\lib\\NMBgMonitor.exe\""
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\Ultimate Defender.install]
@="\"C:\\DOCUME~1\\COMPAQ~1\\LOCALS~1\\Temp\\tinst3.exe\" continue"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Recguard"="C:\\WINDOWS\\SMINST\\RECGUARD.EXE"
"HPBootOp"="\"C:\\Program Files\\Hewlett-Packard\\HP Boot Optimizer\\HPBootOp.exe\" /run"
"Reminder"="\"C:\\Windows\\Creator\\Remind_XP.exe\""
"HP Software Update"=hex(2):43,3a,5c,50,72,6f,67,72,61,6d,20,46,69,6c,65,73,5c,\
48,50,5c,48,50,20,53,6f,66,74,77,61,72,65,20,55,70,64,61,74,65,5c,48,50,77,\
75,53,63,68,64,32,2e,65,78,65,00
"AME_CSA"="rundll32 amecsa.cpl,RUN_DLL"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"PCSuiteTrayApplication"="C:\\PROGRA~1\\Nokia\\NOKIAP~1\\LAUNCH~1.EXE -startup"
"BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"KBD"="C:\\HP\\KBD\\KBD.EXE"
"anysee_TR"="C:\\Program Files\\anysee\\anysee-E30\\anysee_TR.exe"
"ISUSPM Startup"="C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\ISUSPM.exe -startup"
"vvdkkpe.dll"="C:\\WINDOWS\\system32\\rundll32.exe \"C:\\Documents and Settings\\Compaq_Omistaja\\Local Settings\\Application Data\\vvdkkpe.dll\",agkxvbc"
"McAfeeUpdaterUI"="\"C:\\Program Files\\Network Associates\\Common Framework\\UpdaterUI.exe\" /StartedFromRunKey"
"F-Secure Manager"="\"C:\\Program Files\\F-Secure Internet Security\\Common\\FSM32.EXE\" /splash"
"F-Secure TNB"="\"C:\\Program Files\\F-Secure Internet Security\\FSGUI\\TNBUtil.exe\" /CHECKALL /WAITFORSW"
"News Service"="\"C:\\Program Files\\F-Secure Internet Security\\FSGUI\\ispnews.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
~ ~ ~ ~ ~ ~ ~ ~
HijackThis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20061127-191945-234
O20 - Winlogon Notify: jkklk - C:\WINDOWS\system32\jkklk.dll
backup-20061127-191945-205
O2 - BHO: (no name) - {013A653B-49A6-4f76-8B68-E4875EA6BA54} - C:\WINDOWS\system32\xdbwtjtx.dll
backup-20061127-191922-934
O20 - Winlogon Notify: jkklk - C:\WINDOWS\system32\jkklk.dll
backup-20061127-191739-795
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.safety.live.com/resource...lscbase8460.cab
backup-20061127-191739-560
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
backup-20061127-191617-198
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
backup-20061127-191606-662
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
backup-20061127-191530-212
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
backup-20061127-191530-461
O3 - Toolbar: (no name) - {C004DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
backup-20061127-191530-170
O2 - BHO: (no name) - {CB06B9DA-1FA4-474A-A59E-4656FFF789DD} - C:\WINDOWS\system32\awvvu.dll (file missing)
backup-20061127-003204-287
O20 - Winlogon Notify: winmmt32 - winmmt32.dll (file missing)
backup-20061127-003204-490
O20 - Winlogon Notify: nnnnmmj - C:\WINDOWS\SYSTEM32\nnnnmmj.dll
backup-20061127-003204-923
O20 - Winlogon Notify: awvvu - C:\WINDOWS\system32\awvvu.dll
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Scheduled scanning task.job
Completion time: 06-11-28 18:08:57.76
C:\ComboFix.txt ... 06-11-28 18:08