ComboFix 08-04-24.1 - Scaleo 2008-04-25 19:15:22.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1035.18.192 [GMT 3:00]
Running from: C:\Documents and Settings\Scaleo\Työpöytä\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-03-25 to 2008-04-25 )))))))))))))))))
.
2008-04-25 19:08 . 2008-04-25 19:08 268 --ah----- C:\sqmdata08.sqm
2008-04-25 19:08 . 2008-04-25 19:08 244 --ah----- C:\sqmnoopt08.sqm
2008-04-20 11:14 . 2008-04-20 11:14 <KANSIO> d-------- C:\Documents and Settings\Scaleo\Application Data\Malwarebytes
2008-04-20 11:13 . 2008-04-20 11:14 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-20 11:13 . 2008-04-20 11:13 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-18 20:10 . 2008-04-18 20:10 <KANSIO> d-------- C:\Program Files\Common Files\xing shared
2008-04-18 17:43 . 2008-04-18 17:43 1,517,624 --a------ C:\WINDOWS\system32\umurcnbp.exe
2008-04-18 10:22 . 2008-04-18 10:22 <KANSIO> d-------- C:\Documents and Settings\Järjestelmänvalvoja\Application Data\Grisoft
2008-04-18 10:20 . 2007-02-28 23:36 <KANSIO> d--h----- C:\Documents and Settings\Järjestelmänvalvoja\Verkkoympäristö
2008-04-18 10:20 . 2007-02-28 23:36 <KANSIO> d--h----- C:\Documents and Settings\Järjestelmänvalvoja\Verkkoympäristö
2008-04-18 10:20 . 2007-02-28 23:36 <KANSIO> d-------- C:\Documents and Settings\Järjestelmänvalvoja\Työpöytä
2008-04-18 10:20 . 2007-02-28 23:36 <KANSIO> d-------- C:\Documents and Settings\Järjestelmänvalvoja\Työpöytä
2008-04-18 10:20 . 2007-02-28 23:36 <KANSIO> d--h----- C:\Documents and Settings\Järjestelmänvalvoja\Tulostinympäristö
2008-04-18 10:20 . 2007-02-28 23:36 <KANSIO> d--h----- C:\Documents and Settings\Järjestelmänvalvoja\Tulostinympäristö
2008-04-18 10:20 . 2007-02-28 23:36 <KANSIO> d-------- C:\Documents and Settings\Järjestelmänvalvoja\Suosikit
2008-04-18 10:20 . 2007-02-28 23:36 <KANSIO> d-------- C:\Documents and Settings\Järjestelmänvalvoja\Suosikit
2008-04-18 10:20 . 2007-02-28 23:47 <KANSIO> d--h----- C:\Documents and Settings\Järjestelmänvalvoja\Mallit
2008-04-18 10:20 . 2007-02-28 23:47 <KANSIO> d--h----- C:\Documents and Settings\Järjestelmänvalvoja\Mallit
2008-04-18 10:20 . 2007-02-28 23:36 <KANSIO> dr------- C:\Documents and Settings\Järjestelmänvalvoja\Käynnistä-valikko
2008-04-18 10:20 . 2007-02-28 23:36 <KANSIO> dr------- C:\Documents and Settings\Järjestelmänvalvoja\Käynnistä-valikko
2008-04-18 10:20 . 2008-04-18 10:20 <KANSIO> d-------- C:\Documents and Settings\Järjestelmänvalvoja
2008-04-18 10:20 . 2008-04-25 18:32 1,024 --ah----- C:\Documents and Settings\Järjestelmänvalvoja\ntuser.dat.LOG
2008-04-18 10:20 . 2008-04-25 18:32 1,024 --ah----- C:\Documents and Settings\Järjestelmänvalvoja\ntuser.dat.LOG
2008-04-18 08:03 . 2008-04-18 08:03 <KANSIO> d-------- C:\Program Files\Common Files\PCSuite
2008-04-18 08:03 . 2008-04-18 08:03 <KANSIO> d-------- C:\Program Files\Common Files\Nokia
2008-04-18 08:00 . 2008-04-18 08:00 <KANSIO> d-------- C:\Program Files\PC Connectivity Solution
2008-04-18 08:00 . 2007-09-17 15:53 21,632 --a------ C:\WINDOWS\system32\drivers\pccsmcfd.sys
2008-04-13 19:08 . 2008-04-13 19:08 <KANSIO> d-------- C:\Program Files\Trend Micro
2008-04-10 15:51 . 2008-04-10 15:51 244 --ah----- C:\sqmnoopt07.sqm
2008-04-10 15:51 . 2008-04-10 15:51 232 --ah----- C:\sqmdata07.sqm
2008-04-08 17:19 . 2008-04-08 17:19 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-04-06 14:08 . 2008-04-06 14:13 1,022 --a------ C:\WINDOWS\wininit.ini
2008-04-06 09:47 . 2008-04-06 09:47 <KANSIO> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-06 09:47 . 2008-04-13 20:00 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-06 09:17 . 2008-04-06 09:17 <KANSIO> d-------- C:\Documents and Settings\Scaleo\Application Data\Media Player Classic
2008-04-04 19:30 . 2008-04-04 19:30 <KANSIO> d-------- C:\Program Files\Yahoo!
2008-04-04 19:29 . 2008-04-04 19:31 <KANSIO> d-------- C:\Program Files\CCleaner
2008-04-04 18:26 . 2008-04-04 18:26 <KANSIO> d-------- C:\Documents and Settings\Scaleo\Application Data\Grisoft
2008-04-04 18:22 . 2007-05-30 15:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-28 20:14 . 2008-03-28 20:17 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\PC Suite
2008-03-28 20:10 . 2008-03-28 20:10 <KANSIO> d-------- C:\Program Files\DIFX
2008-03-28 20:10 . 2008-03-28 20:51 <KANSIO> d-------- C:\Documents and Settings\Scaleo\Application Data\Nokia
2008-03-28 20:08 . 2008-04-18 08:03 <KANSIO> d-------- C:\Program Files\Nokia
2008-03-28 20:08 . 2008-03-28 20:17 <KANSIO> d-------- C:\Documents and Settings\Scaleo\Application Data\PC Suite
2008-03-28 20:05 . 2008-04-18 07:57 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Installations
2008-03-26 08:19 . 2008-03-26 08:19 268 --ah----- C:\sqmdata06.sqm
2008-03-26 08:19 . 2008-03-26 08:19 244 --ah----- C:\sqmnoopt06.sqm
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-25 16:07 --------- d-----w C:\Documents and Settings\Scaleo\Application Data\uTorrent
2008-04-18 17:05 --------- d-----w C:\Program Files\Common Files\Real
2008-04-13 15:28 --------- d-----w C:\Program Files\PAFPoker
2008-04-12 10:22 --------- d-----w C:\Program Files\Elaborate Bytes
2008-04-06 15:12 --------- d-----w C:\Program Files\Java
2008-04-06 15:08 --------- d-----w C:\Program Files\SlySoft
2008-04-04 15:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-28 05:57 --------- d-----w C:\Program Files\Virtual Hottie 2
2008-03-28 05:53 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-03-28 05:53 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-28 05:52 --------- d-----w C:\Program Files\xchat
2008-03-28 05:34 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-28 05:30 --------- d-----w C:\Program Files\FinnishIRC XP
2008-03-21 17:54 --------- d-----w C:\Documents and Settings\Scaleo\Application Data\Teleca
2008-03-21 17:52 --------- d-----w C:\Program Files\Common Files\Teleca Shared
2008-03-21 17:05 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-21 16:28 --------- d-----w C:\Program Files\Norton Security Scan
2008-03-20 08:09 1,845,504 ------w C:\WINDOWS\system32\win32k.sys
2008-03-01 13:01 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:38 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-01 09:17 586,752 ----a-w C:\WINDOWS\WLXPGSS.SCR
.
((((((((((((((((((((((((((((( snapshot@2008-04-25_18.42.27,09 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-20 07:31:50 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-25 16:06:18 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-01-15 17:14 147456]
"OM2_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2007-09-11 19:43 95536]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"Creative Live! Cam Manager"="C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe" [2007-05-02 11:30 151552]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-14 17:12 15360]
"uTorrent"="E:\ohjelmia\uTorrent\utorrent.exe" [2008-01-31 16:27 219952]
"SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2008-01-02 21:15 103712]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2008-03-28 11:20 1079296]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe" [2008-03-26 18:41 1232896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2006-10-13 01:00 577536 C:\WINDOWS\SOUNDMAN.EXE]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2005-08-25 08:56 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2005-08-25 08:56 126976]
"PtiuPbmd"="ulutil2.dll" [2003-11-06 05:06 110592 C:\WINDOWS\system32\ulutil2.dll]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2008-04-16 08:45 579584]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-12-06 19:37 69216]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 23:55 54832]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40 155648]
"AVFX Engine"="C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe" [2007-04-09 10:58 20480]
"V0350Mon.exe"="C:\WINDOWS\V0350Mon.exe" [2007-03-28 20:01 32768]
"SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2008-01-02 21:15 103712]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"!
AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 12:25 6731312]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-04-18 19:47 185896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-09-14 17:12 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-24 08:44 219136]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2008-03-26 18:41 1232896]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"E:\\ohjelmia\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\B2BPOKER\\Pokerihuone\\jre\\bin\\javaw.exe"=
"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\javaw.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\SightSpeed\\SightSpeed.exe"=
R0 dontgo;Promise Removable Disk Control Driver;C:\WINDOWS\system32\DRIVERS\DontGo.sys [2004-06-30 01:25]
R0 ulsata2;ulsata2;C:\WINDOWS\system32\DRIVERS\ulsata2.sys [2005-06-30 03:44]
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\
000.fcl [2006-11-02 17:51]
R3 VF0350Afx;VF0350 Audio FX;C:\WINDOWS\system32\Drivers\V0350Afx.sys [2007-04-01 20:01]
R3 VF0350Vfx;VF0350 Video FX;C:\WINDOWS\system32\DRIVERS\V0350VFx.sys [2007-03-05 13:45]
R3 VF0350Vid;Live! Cam Video IM (VF0350);C:\WINDOWS\system32\DRIVERS\V0350Vid.sys [2007-04-22 20:01]
S3 pccsmcfd;PCCS Mode Change Filter Driver;C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 15:53]
.
'Ajoitetut tehtävät'-kansion sisältö
"2008-04-25 16:09:02 C:\WINDOWS\Tasks\Tarkistetaan Windows Live -työkalurivin päivitykset.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by
Gmer,
http://www.gmer.net
Rootkit scan 2008-04-25 19:19:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\C:\Program Files\CyberLink\PowerDVD\
000.fcl"
.
Completion time: 2008-04-25 19:24:06
ComboFix-quarantined-files.txt 2008-04-25 16:23:42
ComboFix2.txt 2008-04-25 15:43:48
Pre-Run: 4,034,924,544 tavua vapaana
Post-Run: 4,025,819,136 tavua vapaana
162 --- E O F --- 2008-04-10 00:24:58