sepi - 06-12-03 15:04:23,26 Service Pack 2
ComboFix 06.11.27W - Running from: "C:\Documents and Settings\sepi\Ty”p”yt„"
((((((((((((((((((((((((((((((( Files Created from 2006-11-03 to 2006-12-03 ))))))))))))))))))))))))))))))))))
2006-12-02 20:54 <KANSIO> d-------- C:\WINDOWS\system32\Kaspersky Lab
2006-12-01 21:06 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2006-12-01 20:28 <KANSIO> d-------- C:\Program Files\MagicISO
2006-12-01 16:42 <KANSIO> d-------- C:\Program Files\Ping Plotter
2006-11-30 16:16 <KANSIO> d-------- C:\Program Files\BSplayerPro
2006-11-30 16:16 <KANSIO> d-------- C:\Documents and Settings\sepi\Application Data\BSplayer Pro
2006-11-30 16:09 <KANSIO> d-------- C:\Program Files\Setup
2006-11-30 16:00 <KANSIO> d-------- C:\Documents and Settings\sepi\Application Data\BSplayer
2006-11-28 18:51 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2006-11-28 17:57 <KANSIO> d--h----- C:\WINDOWS\msdownld.tmp
2006-11-26 16:10 <KANSIO> d-------- C:\Program Files\uTorrent
2006-11-24 18:50 <KANSIO> d-------- C:\Program Files\TuneUp Utilities 2007
2006-11-21 18:28 <KANSIO> dr-h----- C:\Documents and Settings\sepi\Recent
2006-11-17 15:30 <KANSIO> d-------- C:\Program Files\Teamspeak2_RC2
2006-11-10 14:02 <KANSIO> d-------- C:\Program Files\Bridge Builder
2006-11-09 18:21 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Disney Interactive
2006-11-09 18:19 <KANSIO> d-------- C:\Program Files\Disney Interactive
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-12-03 15:02 -------- d-------- C:\Program Files\cFosSpeed
2006-12-03 14:53 -------- d-------- C:\Program Files\Mozilla
Firefox
2006-12-02 20:28 -------- d-------- C:\Documents and Settings\sepi\Application Data\uTorrent
2006-12-02 17:26 4674541 --a------ C:\WINDOWS\system32\koti.dll
2006-12-02 17:08 -------- d-------- C:\Documents and Settings\sepi\Application Data\foobar2000
2006-12-01 21:06 -------- d---s---- C:\Documents and Settings\sepi\Application Data\Microsoft
2006-12-01 19:32 -------- d-------- C:\Program Files\mIRC
2006-12-01 17:36 -------- d--h----- C:\Program Files\Zero G Registry
2006-12-01 17:31 -------- d-------- C:\Program Files\No-IP
2006-12-01 12:32 -------- d-------- C:\Documents and Settings\sepi\Application Data\teamspeak2
2006-11-28 17:06 -------- d-------- C:\Program Files\IconChanger
2006-11-27 17:54 -------- d-------- C:\Program Files\Advanced System Optimizer
2006-11-26 17:19 -------- d-------- C:\Program Files\WinRAR
2006-11-24 18:56 -------- d-------- C:\Program Files\BitComet
2006-11-24 15:37 -------- d-------- C:\Program Files\Common Files\Wise Installation Wizard
2006-11-23 20:17 -------- d-------- C:\Documents and Settings\sepi\Application Data\Azureus
2006-11-19 21:01 -------- d-------- C:\Program Files\Internet Explorer
2006-11-19 14:59 34308 --a------ C:\WINDOWS\system32\BASSMOD.dll
2006-11-16 20:58 -------- d-------- C:\Program Files\SpeedFan
2006-11-15 11:21 24072 --a------ C:\WINDOWS\system32\uxtuneup.dll
2006-11-14 19:22 -------- d-------- C:\Program Files\CCleaner
2006-11-09 18:21 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-11-01 20:50 -------- d-------- C:\Program Files\GanymedeNet
2006-11-01 20:43 -------- d-------- C:\Documents and Settings\sepi\Application Data\AdShield
2006-11-01 20:23 -------- d-------- C:\Program Files\AllStar
2006-10-29 18:40 -------- d-------- C:\Documents and Settings\sepi\Application Data\Talkback
2006-10-29 17:12 -------- d-------- C:\Program Files\Webteh
2006-10-26 19:05 -------- d-------- C:\Documents and Settings\sepi\Application Data\dvdcss
2006-10-24 14:39 -------- d-------- C:\Documents and Settings\sepi\Application Data\Adobe
2006-10-23 21:08 -------- d-------- C:\Program Files\foobar2000
2006-10-21 20:22 -------- d-------- C:\Program Files\The All-Seeing Eye
2006-10-20 20:05 -------- d-------- C:\Documents and Settings\sepi\Application Data\Mozilla
2006-10-13 14:37 65536 --a------ C:\WINDOWS\system32\nwwks.dll
2006-10-13 14:37 64000 --a------ C:\WINDOWS\system32\nwapi32.dll
2006-10-13 14:37 142336 --a------ C:\WINDOWS\system32\nwprovau.dll
2006-10-13 12:23 163584 --a------ C:\WINDOWS\system32\drivers\nwrdr.sys
2006-10-10 16:31 -------- d-------- C:\Documents and Settings\sepi\Application Data\Seven Zip
2006-10-10 16:17 -------- d-------- C:\Program Files\RM Converter
2006-10-06 15:37 -------- d-------- C:\Program Files\Stabenfeldt
2006-10-03 18:06 -------- d-------- C:\Documents and Settings\sepi\Application Data\vtcmovies
2006-10-03 18:06 -------- d-------- C:\Documents and Settings\sepi\Application Data\vtc_demo_setup
2006-09-24 15:28 5248 --a------ C:\WINDOWS\system32\speedfan.sys
2006-09-14 14:33 2314 --a------ C:\Program Files\uninstal.log
2006-09-13 07:03 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-09-09 01:29 715776 --------- C:\WINDOWS\system32\WindowsCodecs.dll
2006-09-09 01:29 411648 --------- C:\WINDOWS\system32\photometadatahandler.dll
2006-09-09 01:29 352256 --------- C:\WINDOWS\system32\WindowsCodecsExt.dll
2006-09-09 01:29 274432 --------- C:\WINDOWS\system32\WMPhoto.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Ahead\\Lib\\NMBgMonitor.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"avgnt"="\"C:\\Program Files\\AntiVir PersonalEdition Classic\\avgnt.exe\" /min"
"SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui"
"NeroFilterCheck"="C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"
"cFosSpeed"="C:\\Program Files\\cFosSpeed\\cFosSpeed.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Nykyinen kotisivu"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,e6,00,00,00,00,00,00,00,9a,03,00,00,42,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,72,03,00,00,23,00,00,00,fc,00,00,00,f2,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="\"C:\\QuickTimePlayer\\qttask.exe\" -atboottime"
"SoundMan"="SOUNDMAN.EXE"
"NeroFilterCheck"="C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"
"DAEMON Tools-1033"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
~ ~ ~ ~ ~ ~ ~ ~
HijackThis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20061202-203314-233
F3 - REG:win.ini: run=C:\WINDOWS\SYSTEM32\Msocket.exe
backup-20061202-203314-681
O4 - HKLM\..\Run: [Msocket] C:\WINDOWS\SYSTEM32\Msocket.exe
backup-20061201-174223-211
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20061201-174223-204
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
backup-20061201-174223-865
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20061201-172547-114
O18 - Protocol: msnim - 0 - (no file)
backup-20061201-172522-312
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
backup-20061201-171901-685
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
backup-20061201-171901-786
O20 - Winlogon Notify: winhoo32 - winhoo32.dll (file missing)
backup-20061126-155749-511
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
backup-20061126-155749-568
O8 - Extra context menu item: Add to &Exclude List... - C:\PROGRA~1\AllStar\AdShield\restrict.htm
backup-20061126-155749-433
O8 - Extra context menu item: AdShield Option &Settings... - C:\PROGRA~1\AllStar\AdShield\settings.htm
backup-20061126-155749-627
O8 - Extra context menu item: Add to &Block List... - C:\PROGRA~1\AllStar\AdShield\suppress.htm
backup-20061126-155749-902
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
backup-20061126-155749-634
O8 - Extra context menu item: &Maintain Block List... - C:\PROGRA~1\AllStar\AdShield\maintain.htm
backup-20061126-155626-162
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
backup-20061126-155626-771
O4 - HKCU\..\Run: [Driver Development Kit] C:\WINDOWS\system32\ddk.exe
backup-20061126-155626-509
O2 - BHO: IEPlugin Class - {CF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\Advanced System Optimizer\IEHelper.dll
backup-20061126-155626-451
O2 - BHO: AdShield.AdShield - {7559B76E-0222-4d77-9499-CCE9EB4EDC2F} - C:\PROGRA~1\AllStar\AdShield\AdShield.dll
backup-20061126-155506-950
O9 - Extra button: AdShield - {4FB6C25E-7B37-4c93-B592-16ECD8D18361} - C:\PROGRA~1\AllStar\AdShield\AdShield.dll (HKCU)
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\1-Klick-Wartung.job
Completion time: 06-12-03 15:05:12.26
C:\ComboFix.txt ... 06-12-03 15:05
tuossa olis tuo loki nyt ^^