Tässä olisi nyt se loki joka tuli ComboFix.in jälkeen
ComboFix 08-05-09.1 - Anni 2008-05-10 21:32:32.1 - NTFSx86
Running from: C:\Documents and Settings\Anni\Työpöytä\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
(((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\newdotnet
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-04-10 to 2008-05-10 )))))))))))))))))
.
2008-05-10 19:47 . 2008-05-10 20:46 <KANSIO> d--h-c--- C:\$AVG8.VAULT$
2008-05-10 19:11 . 2008-05-10 19:14 <KANSIO> d----c--- C:\Windows\system32\drivers\Avg
2008-05-10 19:11 . 2008-05-10 19:11 96,520 --a--c--- C:\Windows\system32\drivers\avgldx86.sys
2008-05-10 19:11 . 2008-05-10 19:11 10,520 --a--c--- C:\Windows\system32\avgrsstx.dll
2008-05-10 19:10 . 2008-05-10 19:10 <KANSIO> d----c--- C:\Program Files\AVG
2008-05-10 19:10 . 2008-05-10 19:10 <KANSIO> d----c--- C:\Documents and Settings\All Users\Application Data\avg8
2008-05-10 16:27 . 2008-05-10 16:27 <KANSIO> d----c--- C:\Windows\system32\fi
2008-05-10 16:27 . 2008-05-10 16:27 <KANSIO> d----c--- C:\Windows\l2schemas
2008-05-10 16:27 . 2008-04-14 09:11 69,120 -----c--- C:\Windows\system32\wlanapi.dll
2008-05-10 16:27 . 2008-04-14 09:11 50,688 -----c--- C:\Windows\system32\tspkg.dll
2008-05-10 16:11 . 2008-04-13 09:36 144,384 -----c--- C:\Windows\system32\drivers\hdaudbus.sys
2008-05-10 16:11 . 2008-04-13 11:40 10,240 -----c--- C:\Windows\system32\drivers\sffp_mmc.sys
2008-05-10 16:05 . 2006-12-28 12:01 19,569 --a--c--- C:\Windows\
005730_.tmp
2008-05-10 00:49 . 2008-05-10 00:49 <KANSIO> d----c--- C:\Windows\ERUNT
2008-05-10 00:48 . 2008-05-10 01:19 <KANSIO> d----c--- C:\SDFix
2008-05-09 23:12 . 2008-05-09 23:12 <KANSIO> d----c--- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-09 23:12 . 2008-05-09 23:12 <KANSIO> d----c--- C:\Documents and Settings\Anni\Application Data\Malwarebytes
2008-05-09 23:12 . 2008-05-09 23:12 <KANSIO> d----c--- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-09 23:12 . 2008-05-05 20:46 27,048 --a--c--- C:\Windows\system32\drivers\mbamcatchme.sys
2008-05-09 23:12 . 2008-05-05 20:46 15,864 --a--c--- C:\Windows\system32\drivers\mbam.sys
2008-05-06 00:25 . 2008-05-06 00:25 <KANSIO> d----c--- C:\Program Files\IObit
2008-05-06 00:25 . 2008-05-06 00:25 <KANSIO> d----c--- C:\Documents and Settings\Anni\Application Data\IObit
2008-05-06 00:25 . 2008-04-17 16:19 90,668 --a--c--- C:\Windows\system32\vobis32.dll
2008-04-14 19:24 . 2008-04-19 13:20 <KANSIO> d-a--c--- C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-14 19:22 . 2008-04-14 19:25 <KANSIO> d----c--- C:\Program Files\NRJKauppa
2008-04-14 08:52 . 2008-04-14 08:52 2,524 -----c--- C:\Windows\system32\pid.inf
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-10 15:59 --------- dc----w C:\Documents and Settings\All Users\Application Data\Avira
2008-04-14 16:44 --------- dc----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-04-14 06:13 21,896 -c--a-w C:\WINDOWS\system32\drivers\tdtcp.sys
2008-04-14 06:13 139,656 -c--a-w C:\WINDOWS\system32\drivers\rdpwd.sys
2008-04-14 06:13 12,040 -c--a-w C:\WINDOWS\system32\drivers\tdpipe.sys
2008-04-14 06:12 69,632 -c--a-w C:\WINDOWS\notepad.exe
2008-04-14 06:12 40,840 -c--a-w C:\WINDOWS\system32\drivers\termdd.sys
2008-04-14 06:12 283,648 -c--a-w C:\WINDOWS\winhlp32.exe
2008-04-14 06:12 146,944 -c--a-w C:\WINDOWS\regedit.exe
2008-04-14 06:12 10,752 -c--a-w C:\WINDOWS\hh.exe
2008-04-14 06:12 1,034,240 -c--a-w C:\WINDOWS\explorer.exe
2008-04-14 05:51 80,256 -c--a-w C:\WINDOWS\system32\drivers\parport.sys
2008-04-14 05:51 73,344 -c--a-w C:\WINDOWS\system32\drivers\sr.sys
2008-04-14 05:51 68,096 -c--a-w C:\WINDOWS\system32\drivers\pci.sys
2008-04-14 05:51 46,720 -c--a-w C:\WINDOWS\system32\drivers\p3.sys
2008-04-14 05:51 120,064 -c--a-w C:\WINDOWS\system32\drivers\pcmcia.sys
2008-04-14 05:47 800,000 -c--a-w C:\WINDOWS\system32\drivers\dmboot.sys
2008-04-14 05:47 154,112 -c--a-w C:\WINDOWS\system32\drivers\dmio.sys
2008-04-14 05:46 37,120 -c--a-w C:\WINDOWS\system32\drivers\isapnp.sys
2008-04-14 05:46 24,576 -c--a-w C:\WINDOWS\system32\drivers\kbdclass.sys
2008-04-14 05:46 14,720 -c--a-w C:\WINDOWS\system32\drivers\kbdhid.sys
2008-04-14 05:45 5,504 -c--a-w C:\WINDOWS\system32\drivers\intelide.sys
2008-04-14 05:45 40,704 -c--a-w C:\WINDOWS\system32\drivers\crusoe.sys
2008-04-14 05:45 40,320 -c--a-w C:\WINDOWS\system32\drivers\intelppm.sys
2008-04-14 05:43 64,512 -c--a-w C:\WINDOWS\system32\drivers\serial.sys
2008-04-14 05:43 52,096 -c--a-w C:\WINDOWS\system32\drivers\i8042prt.sys
2008-04-14 05:42 25,600 -c----w C:\WINDOWS\system32\drivers\hidbth.sys
2008-04-14 05:40 57,472 -c--a-w C:\WINDOWS\system32\drivers\redbook.sys
2008-04-14 05:40 272,896 -c----w C:\WINDOWS\system32\drivers\bthport.sys
2008-04-14 05:39 51,840 -c--a-w C:\WINDOWS\system32\drivers\volsnap.sys
2008-04-14 05:39 44,544 -c--a-w C:\WINDOWS\system32\drivers\fips.sys
2008-04-14 05:38 39,808 -c--a-w C:\WINDOWS\system32\drivers\processr.sys
2008-04-14 05:37 41,728 -c--a-w C:\WINDOWS\system32\drivers\amdk7.sys
2008-04-14 05:37 41,344 -c--a-w C:\WINDOWS\system32\drivers\amdk6.sys
2008-04-14 05:36 30,080 -c--a-w C:\WINDOWS\system32\drivers\modem.sys
2008-04-14 05:36 23,040 -c--a-w C:\WINDOWS\system32\drivers\mouclass.sys
2008-04-14 05:36 187,904 -c--a-w C:\WINDOWS\system32\drivers\acpi.sys
2008-04-13 09:28 175,744 -c--a-w C:\WINDOWS\system32\drivers\rdbss.sys
2008-04-13 09:21 162,816 -c--a-w C:\WINDOWS\system32\drivers\netbt.sys
2008-04-13 09:20 91,520 -c--a-w C:\WINDOWS\system32\drivers\ndiswan.sys
2008-04-13 09:20 361,344 -c--a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-04-13 09:20 182,656 -c--a-w C:\WINDOWS\system32\drivers\ndis.sys
2008-04-13 09:19 75,264 -c--a-w C:\WINDOWS\system32\drivers\ipsec.sys
2008-04-13 09:19 51,328 -c--a-w C:\WINDOWS\system32\drivers\rasl2tp.sys
2008-04-13 09:19 48,384 -c--a-w C:\WINDOWS\system32\drivers\raspptp.sys
2008-04-13 09:19 146,048 -c--a-w C:\WINDOWS\system32\drivers\portcls.sys
2008-04-13 09:19 138,112 -c--a-w C:\WINDOWS\system32\drivers\afd.sys
2008-04-13 09:17 83,072 -c--a-w C:\WINDOWS\system32\drivers\wdmaud.sys
2008-04-13 09:17 456,576 -c--a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2008-04-13 09:17 105,344 -c--a-w C:\WINDOWS\system32\drivers\mup.sys
2008-04-13 09:16 49,536 -c--a-w C:\WINDOWS\system32\drivers\classpnp.sys
2008-04-13 09:16 141,056 -c--a-w C:\WINDOWS\system32\drivers\ks.sys
2008-04-13 09:15 60,800 -c--a-w C:\WINDOWS\system32\drivers\sysaudio.sys
2008-04-13 09:15 574,976 -c--a-w C:\WINDOWS\system32\drivers\ntfs.sys
2008-04-13 09:15 334,848 -c--a-w C:\WINDOWS\system32\drivers\srv.sys
2008-04-13 09:14 63,744 -c--a-w C:\WINDOWS\system32\drivers\cdfs.sys
2008-04-13 09:14 143,744 -c--a-w C:\WINDOWS\system32\drivers\fastfat.sys
2008-04-13 09:00 225,664 -c--a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-04-13 09:00 19,072 -c--a-w C:\WINDOWS\system32\drivers\tdi.sys
2008-04-13 08:57 41,472 -c--a-w C:\WINDOWS\system32\drivers\raspppoe.sys
2008-04-13 08:57 40,576 -c--a-w C:\WINDOWS\system32\drivers\ndproxy.sys
2008-04-13 08:57 34,560 -c--a-w C:\WINDOWS\system32\drivers\wanarp.sys
2008-04-13 08:57 20,864 -c--a-w C:\WINDOWS\system32\drivers\ipinip.sys
2008-04-13 08:57 152,832 -c--a-w C:\WINDOWS\system32\drivers\ipnat.sys
2008-04-13 08:57 14,336 -c--a-w C:\WINDOWS\system32\drivers\asyncmac.sys
2008-04-13 08:57 10,112 -c--a-w C:\WINDOWS\system32\drivers\ndistapi.sys
2008-04-13 08:56 88,320 -c--a-w C:\WINDOWS\system32\drivers\nwlnkipx.sys
2008-04-13 08:56 69,120 -c--a-w C:\WINDOWS\system32\drivers\psched.sys
2008-04-13 08:56 35,072 -c--a-w C:\WINDOWS\system32\drivers\msgpc.sys
2008-04-13 08:56 34,688 -c--a-w C:\WINDOWS\system32\drivers\netbios.sys
2008-04-13 08:56 30,592 -c--a-w C:\WINDOWS\system32\drivers\rndismp.sys
2008-04-13 08:56 30,592 -c----w C:\WINDOWS\system32\drivers\rndismpx.sys
2008-04-13 08:56 14,592 -c--a-w C:\WINDOWS\system32\drivers\ndisuio.sys
2008-04-13 08:56 12,800 -c--a-w C:\WINDOWS\system32\drivers\usb8023.sys
2008-04-13 08:56 12,800 -c----w C:\WINDOWS\system32\drivers\usb8023x.sys
2008-04-13 08:56 12,288 -c--a-w C:\WINDOWS\system32\drivers\tunmp.sys
2008-04-13 08:55 202,624 -c--a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-13 08:54 88,192 -c--a-w C:\WINDOWS\system32\drivers\irda.sys
2008-04-13 08:54 28,672 -c--a-w C:\WINDOWS\system32\drivers\nscirda.sys
2008-04-13 08:54 11,264 -c--a-w C:\WINDOWS\system32\drivers\irenum.sys
2008-04-13 08:53 71,552 -c--a-w C:\WINDOWS\system32\drivers\bridge.sys
2008-04-13 08:53 40,320 -c--a-w C:\WINDOWS\system32\drivers\nmnt.sys
2008-04-13 08:53 36,608 -c----w C:\WINDOWS\system32\drivers\ip6fw.sys
2008-04-13 08:53 264,832 -c----w C:\WINDOWS\system32\drivers\http.sys
2008-04-13 08:51 61,824 -c--a-w C:\WINDOWS\system32\drivers\nic1394.sys
2008-04-13 08:51 60,800 -c--a-w C:\WINDOWS\system32\drivers\arp1394.sys
2008-04-13 08:51 59,904 -c--a-w C:\WINDOWS\system32\drivers\atmarpc.sys
2008-04-13 08:51 55,808 -c--a-w C:\WINDOWS\system32\drivers\atmlane.sys
2008-04-13 08:51 101,120 -c----w C:\WINDOWS\system32\drivers\bthpan.sys
2008-04-13 08:46 61,696 -c--a-w C:\WINDOWS\system32\drivers\ohci1394.sys
2008-04-13 08:46 59,136 -c----w C:\WINDOWS\system32\drivers\rfcomm.sys
2008-04-13 08:46 53,376 -c--a-w C:\WINDOWS\system32\drivers\1394bus.sys
2008-04-13 08:46 37,888 -c----w C:\WINDOWS\system32\drivers\bthmodem.sys
2008-04-13 08:46 36,480 -c----w C:\WINDOWS\system32\drivers\bthprint.sys
2008-04-13 08:46 25,344 -c--a-w C:\WINDOWS\system32\drivers\sonydcam.sys
2008-04-13 08:46 18,944 -c----w C:\WINDOWS\system32\drivers\bthusb.sys
2008-04-13 08:46 17,024 -c----w C:\WINDOWS\system32\drivers\bthenum.sys
2008-04-13 08:46 121,984 -c----w C:\WINDOWS\system32\drivers\usbvideo.sys
2008-04-13 08:44 81,664 -c--a-w C:\WINDOWS\system32\drivers\videoprt.sys
2008-04-13 08:44 20,992 -c--a-w C:\WINDOWS\system32\drivers\vga.sys
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6208C419-06B8-4B89-AED6-5705B92C8942}]
C:\WINDOWS\lbbho.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"Advanced WindowsCare 3"="C:\Program Files\IObit\Advanced WindowsCare 3 Beta\AWC.exe" [2008-04-22 17:01 2024200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-09-29 17:16 32881]
"ATIPTA"="C:\ATI-CPanel\atiptaxx.exe" [2004-11-03 22:10 344064]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-07 11:49 98304]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-07 11:49 536576]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24 286720]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 14:20 227328]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 17:24 28672 C:\Windows\system32\Ati2mdxx.exe]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-10 19:10 1177368]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 09:12 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 16:58 1744896]
C:\Documents and Settings\All Users\K„ynnist„-valikko\Ohjelmat\K„ynnistys\
Gigaset
WLAN Adapter Monitor.lnk - C:\Program Files\Siemens\Gigaset PC Card 54\GigasetWLANMonitor.exe [2005-10-31 17:51:45 552960]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverUpdaterPro]
C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
-
ra--c--- 2001-07-09 13:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\eMule\\eMule.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
R0 NDIS_RD;Firewall Engine Type-R2;C:\WINDOWS\system32\drivers\NDIS_RD.sys [2004-07-18 16:29]
R1 AvgLdx86;AVG
AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-10 19:11]
R1 TDI_RD;Firewall Engine Type-R;C:\WINDOWS\System32\drivers\tdi_rd.sys [2004-06-27 18:55]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-10 19:10]
R3 DP83815;National Semiconductor Corp. DP83815/816 NDIS 5.0 Miniport Driver;C:\WINDOWS\system32\DRIVERS\DP83815.SYS [2004-05-04 15:24]
S3 cdiskdun;cdiskdun;C:\DOCUME~1\Anni\LOCALS~1\Temp\cdiskdun.sys []
.
'Ajoitetut tehtävät'-kansion sisältö
"2008-05-06 20:19:10 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2005-01-24 09:31:42 C:\WINDOWS\Tasks\XoftSpy.job"
- C:\Program Files\XoftSpy\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by
Gmer,
http://www.gmer.net
Rootkit scan 2008-05-10 21:40:39
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
folder error: C:\DOCUME~1\Anni\LOCALS~1\Temp\
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-10 21:45:49
ComboFix-quarantined-files.txt 2008-05-10 18:45:26
Pre-Run: 7,155,965,952 tavua vapaana
Post-Run: 7,156,510,720 tavua vapaana
216 --- E O F --- 2008-04-10 13:35:37