ComboFix 08-05-09.1 - Koti 2008-05-10 7:16:58.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1035.18.266 [GMT 3:00]
Running from: C:\Documents and Settings\Koti\Työpöytä\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-04-10 to 2008-05-10 )))))))))))))))))
.
2008-05-09 17:44 . 2008-05-09 17:44 2,880 --a------ C:\WINDOWS\system32\tmp.reg
2008-05-09 17:42 . 2008-05-09 17:41 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-05-09 17:42 . 2008-05-09 17:41 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-05-09 17:42 . 2008-05-09 17:41 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-05-09 17:42 . 2008-05-09 17:41 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-05-09 17:42 . 2008-05-09 17:41 82,944 --a------ C:\WINDOWS\system32\404Fix.exe
2008-05-09 17:42 . 2008-05-09 17:41 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-05-09 17:42 . 2008-05-09 17:41 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-05-09 17:42 . 2008-05-09 17:41 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-05-07 21:43 . 2008-05-10 07:27 497,696 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-07 21:43 . 2008-05-09 22:30 6,332 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-05-07 21:40 . 2008-05-07 21:40 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-05-07 21:39 . 2007-09-06 16:14 75,248 --a------ C:\WINDOWS\zllsputility.exe
2008-05-07 21:39 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2008-05-07 21:39 . 2008-05-07 21:41 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-05-07 21:37 . 2008-05-07 21:39 <KANSIO> d-------- C:\WINDOWS\system32\ZoneLabs
2008-05-07 21:37 . 2008-05-07 21:37 <KANSIO> d-------- C:\Program Files\Zone Labs
2008-05-07 21:37 . 2007-09-06 16:14 1,086,952 --a------ C:\WINDOWS\system32\zpeng24.dll
2008-05-07 21:37 . 2008-05-10 07:03 353,247 --a------ C:\WINDOWS\system32\vsconfig.xml
2008-05-07 21:36 . 2008-05-10 07:26 <KANSIO> d-------- C:\WINDOWS\Internet Logs
2008-05-07 21:32 . 2007-05-30 15:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-05-05 21:56 . 2008-05-05 21:56 <KANSIO> d-------- C:\Documents and Settings\Koti\Application Data\Malwarebytes
2008-05-05 21:55 . 2008-05-05 21:55 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-05 21:55 . 2008-05-05 21:55 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-05 21:00 . 2008-05-05 21:00 <KANSIO> d-------- C:\Program Files\Trend Micro
2008-04-10 20:49 . 2008-04-10 20:49 <KANSIO> d-------- C:\Documents and Settings\Koti\e-Safekey
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-10 04:10 --------- d-----w C:\Documents and Settings\Koti\Application Data\Skype
2008-05-10 04:06 --------- d-----w C:\Documents and Settings\Koti\Application Data\skypePM
2008-04-06 09:15 --------- d-----w C:\Program Files\Avira
2008-04-06 09:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-04-06 09:11 --------- d-----w C:\Program Files\CCleaner
2008-04-06 09:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-04-06 09:04 --------- d-----w C:\Documents and Settings\Koti\Application Data\AVG7
2008-04-06 09:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-05 13:19 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-03-03 16:45 127,034 ------r C:\WINDOWS\bwUnin-8.1.1.50-8876480SL.exe
2008-03-01 15:31 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-02-29 08:56 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-02-29 08:55 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-02-22 10:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:38 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:38 45,568 ----a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:38 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-02-15 05:44 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2005-05-26 15:52 15360]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2005-06-24 14:08 860160]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-02-06 19:24 21898024]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-26 15:54 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2005-05-26 15:54 77824 C:\WINDOWS\SOUNDMAN.EXE]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-26 15:42 344064]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-07-26 00:14 188416]
"DataLayer"="C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe" [2005-06-07 11:31 819712]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2005-06-29 15:29 176128]
"Norman ZANDA"="C:\Norman\Nvc\BIN\ZLH.exe" [2003-11-27 15:14 90112]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-08-17 21:38 98304]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-16 12:28 262401]
"!
AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 12:25 6731312]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14 919016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2005-05-26 15:52 15360]
C:\Documents and Settings\All Users\K„ynnist„-valikko\Ohjelmat\K„ynnistys\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 20:28:24 258048]
HP Image Zone -pikak„ynnistys.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 20:50:52 53248]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Käynnistä-valikko^Ohjelmat^Käynnistys^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Käynnistä-valikko\Ohjelmat\Käynnistys\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2007-07-08 14:21 1836544 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2005-06-24 15:16 278528 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2005-05-26 15:53 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2005-08-17 21:38 98304 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 01:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-06-26 15:54 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPodService"=3 (0x3)
"gusvc"=3 (0x3)
"GoogleDesktopManager"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by
Gmer,
http://www.gmer.net
Rootkit scan 2008-05-10 07:27:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-10 7:33:10
ComboFix-quarantined-files.txt 2008-05-10 04:32:41
Pre-Run: 149,742,034,944 tavua vapaana
Post-Run: 149,898,407,936 tavua vapaana
150 --- E O F --- 2008-04-09 20:43:40