Tässä tämä uusi loki, joka tuli Combofixin kautta
ComboFix 08-05-09.1 - Martinez 2008-05-10 23:19:29.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1035.18.1100 [GMT 3:00]
Running from: C:\Users\Martinez\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-04-10 to 2008-05-10 )))))))))))))))))
.
2008-05-10 15:58 . 2008-05-10 15:58 307,200 --a------ C:\Users\Martinez\Nettimittari_welho.exe
2008-05-10 09:45 . 2008-05-10 09:45 <KANSIO> d-------- C:\Program Files\Trend Micro
2008-05-09 21:56 . 2008-05-09 21:56 <KANSIO> d-------- C:\Users\All Users\soft copy bags
2008-05-09 21:56 . 2008-05-09 21:56 <KANSIO> d-------- C:\Users\All Users\Move Bore Curb Tool
2008-05-09 21:56 . 2008-05-09 21:56 <KANSIO> d-------- C:\ProgramData\soft copy bags
2008-05-09 21:56 . 2008-05-09 21:56 <KANSIO> d-------- C:\ProgramData\Move Bore Curb Tool
2008-05-09 21:53 . 2008-05-09 21:53 <KANSIO> d-------- C:\Users\Martinez\AppData\Roaming\Media Player Classic
2008-05-08 16:29 . 2008-05-09 06:47 280,423,278 --a------ C:\Windows\MEMORY.DMP
2008-04-27 17:41 . 2008-04-27 17:41 <KANSIO> d-------- C:\Users\Martinez\AppData\Roaming\dvdcss
2008-04-27 16:28 . 2008-04-27 16:28 <KANSIO> d-------- C:\Windows\System32\FIN
2008-04-27 16:28 . 2007-02-26 11:39 126,976 --a------ C:\Windows\System32\Imsmudlg.exe
2008-04-27 16:27 . 2008-04-27 16:27 <KANSIO> d-------- C:\Users\Martinez\AppData\Roaming\InstallShield
2008-04-27 16:27 . 2008-04-27 16:28 <KANSIO> d-------- C:\Program Files\Intel
2008-04-27 16:26 . 2008-04-27 16:27 <KANSIO> d-------- C:\fsc.tmp
2008-04-26 22:36 . 2008-04-26 22:38 <KANSIO> d-------- C:\Users\All Users\Lavasoft
2008-04-26 22:36 . 2008-04-26 22:38 <KANSIO> d-------- C:\ProgramData\Lavasoft
2008-04-26 22:36 . 2008-04-26 22:36 <KANSIO> d-------- C:\Program Files\Lavasoft
2008-04-26 22:35 . 2008-04-26 22:35 <KANSIO> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-23 22:26 . 2008-04-23 22:26 <KANSIO> d-------- C:\Program Files\Windows Live Toolbar
2008-04-23 22:25 . 2008-04-23 22:25 <KANSIO> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-04-18 23:10 . 2008-04-18 23:10 <KANSIO> d-------- C:\Program Files\Apple Software Update
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-10 14:27 --------- d-----w C:\Users\Martinez\AppData\Roaming\uTorrent
2008-05-09 20:07 --------- d-----w C:\Users\Martinez\AppData\Roaming\mIRC
2008-04-27 13:27 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-09 09:51 --------- d-----w C:\Program Files\Windows Mail
2008-04-09 07:51 --------- d-----w C:\ProgramData\Microsoft Help
2008-04-09 07:24 --------- d-----w C:\Program Files\DivX
2008-04-04 21:29 --------- d-----w C:\Program Files\iTunes
2008-04-04 21:29 --------- d-----w C:\Program Files\iPod
2008-04-04 21:26 --------- d-----w C:\Program Files\QuickTime
2008-03-31 21:25 831,488 ----a-w C:\Windows\System32\divx_xx0a.dll
2008-03-31 21:25 823,296 ----a-w C:\Windows\System32\divx_xx0c.dll
2008-03-31 21:25 823,296 ----a-w C:\Windows\System32\divx_xx07.dll
2008-03-31 21:25 802,816 ----a-w C:\Windows\System32\divx_xx11.dll
2008-03-31 21:25 682,496 ----a-w C:\Windows\System32\DivX.dll
2008-03-31 21:25 161,096 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2008-03-31 15:06 --------- d-----w C:\Program Files\Microsoft Games
2008-03-27 17:22 --------- d-----w C:\Program Files\Java
2008-03-21 20:30 524,288 ----a-w C:\Windows\System32\DivXsm.exe
2008-03-21 20:30 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
2008-03-21 20:30 200,704 ----a-w C:\Windows\System32\ssldivx.dll
2008-03-21 20:30 1,044,480 ----a-w C:\Windows\System32\libdivx.dll
2008-03-21 20:28 81,920 ----a-w C:\Windows\System32\dpl100.dll
2008-03-21 20:28 593,920 ----a-w C:\Windows\System32\dpuGUI11.dll
2008-03-21 20:28 57,344 ----a-w C:\Windows\System32\dpv11.dll
2008-03-21 20:28 53,248 ----a-w C:\Windows\System32\dpuGUI10.dll
2008-03-21 20:28 344,064 ----a-w C:\Windows\System32\dpus11.dll
2008-03-21 20:28 294,912 ----a-w C:\Windows\System32\dpu11.dll
2008-03-21 20:28 294,912 ----a-w C:\Windows\System32\dpu10.dll
2008-03-21 20:28 196,608 ----a-w C:\Windows\System32\dtu100.dll
2008-03-21 20:28 12,288 ----a-w C:\Windows\System32\DivXWMPExtType.dll
2008-03-17 12:00 --------- d-----w C:\Program Files\Welho Tietoturvapalvelu
2008-03-17 11:53 60,064 ----a-w C:\Windows\system32\drivers\fsdfw.sys
2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll
2008-02-29 04:14 2,028,544 ----a-w C:\Windows\System32\win32k.sys
2008-02-21 20:55 382,352 ----a-w C:\Users\Martinez\jre-6u4-windows-i586-p-iftw.exe
2008-02-21 20:55 15,852,952 ----a-w C:\Users\Martinez\jre-6u4-windows-i586-p.exe
2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll
2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-19 05:10 620,088 ----a-w C:\Windows\System32\ci.dll
2008-02-17 21:54 13,680,533 ----a-w C:\Users\Martinez\jre-6u4-windows-x64.exe
2008-02-14 23:19 944,184 ----a-w C:\Windows\System32\winload.exe
2008-02-13 21:41 48,640 ----a-w C:\Windows\System32\davclnt.dll
2008-02-13 21:41 196,096 ----a-w C:\Windows\System32\WebClnt.dll
2008-02-13 21:38 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-02-13 21:38 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-02-13 21:38 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-02-13 21:37 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2008-02-13 21:37 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-13 21:37 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-13 21:37 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-13 21:37 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2008-02-13 21:37 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-02-13 21:37 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-13 21:37 2,048 ----a-w C:\Windows\System32\asferror.dll
2008-02-13 21:37 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-13 21:37 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-02-13 21:37 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2008-02-13 21:36 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-02-13 21:30 3,505,848 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-02-13 21:30 3,472,056 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-02-13 21:30 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-02-13 21:27 0 ----a-w C:\Users\Martinez\AppData\Roaming\wklnhst.dat
2008-02-13 21:26 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2008-02-13 20:39 53,080 ----a-w C:\Windows\System32\wuauclt.exe
2008-02-13 20:39 43,352 ----a-w C:\Windows\System32\wups2.dll
2008-02-13 20:39 1,712,984 ----a-w C:\Windows\System32\wuaueng.dll
2008-02-13 20:39 1,524,224 ----a-w C:\Windows\System32\wucltux.dll
2008-02-13 20:38 80,896 ----a-w C:\Windows\System32\wudriver.dll
2008-02-13 20:38 549,720 ----a-w C:\Windows\System32\wuapi.dll
2008-02-13 20:38 33,624 ----a-w C:\Windows\System32\wups.dll
2008-02-13 20:37 31,232 ----a-w C:\Windows\System32\wuapp.exe
2008-02-13 20:37 163,000 ----a-w C:\Windows\System32\wuwebv.dll
2007-11-27 19:10 174 --sha-w C:\Program Files\desktop.ini
.
------- Sigcheck -------
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-02-14 00:36 1232896]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-02-13 23:27 171448]
"Free Cake"="C:\ProgramData\thunksafesafe.nquubs" [2008-05-09 21:56 364560]
"Curb tool help dart"="C:\ProgramData\thunk dash up.ql870sh" [2008-05-09 21:56 8208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-11-03 16:03 1006264]
"StartCCC"="c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 23:35 90112]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-10 18:01 4431872 C:\Windows\RtHDVCpl.exe]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 19:31 630784]
"recinfo193"="c:\RecInfo\RecInfo.exe" [2007-10-23 15:52 2764800]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-02-26 21:46 153136]
"recinfo"="RecInfo.exe" []
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"F-Secure Manager"="C:\Program Files\Welho Tietoturvapalvelu\Common\FSM32.exe" [2007-04-26 20:12 183208]
"F-Secure TNB"="C:\Program Files\Welho Tietoturvapalvelu\FSGUI\TNBUtil.exe" [2007-04-26 20:10 740208]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-14 00:11 185896]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-02-12 13:37 174872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.mkdmp3enc"= C:\PROGRA~1\CYBERL~1\PowerDV\Kernel\Burner\MKDMP3Enc.ACM
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{991ED4C9-2B8E-491F-928E-6DA70A57221E}"= C:\Program Files\CyberLink\PowerDV\PowerDV.exe:CyberLink PowerDV
"{05510B22-2A7C-4C7C-B211-85A745EFD9DF}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{374A0DB6-0976-4685-B6C6-BF39C824EC94}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{8729AEAD-10F2-450C-B9BF-F90EAB947FEC}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{6E53073B-EDBE-4404-8009-E9A00420F6B4}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{629E7C07-E2A5-4779-98BB-9EC8582479CB}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{860F6EA9-1771-4C33-AB5E-13CC18537406}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{EE20AD40-1A99-4607-B656-59F7049E7387}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 F-Secure HIPS;F-Secure HIPS;C:\Program Files\Welho Tietoturvapalvelu\HIPS\fshs.sys [2008-02-13 23:36]
R1 FSES;F-Secure Email Scanning Driver;C:\Windows\system32\drivers\fses.sys [2007-04-26 20:08]
R1 FSFW;F-Secure Firewall Driver;C:\Windows\system32\drivers\fsdfw.sys [2008-03-17 14:53]
R1 fsvista;F-Secure Vista Support Driver;C:\Program Files\Welho Tietoturvapalvelu\Anti-Virus\minifilter\fsvista.sys [2007-04-26 20:07]
R2 TestHandler;Fujitsu
Siemens Computers Diagnostic Testhandler;C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe [2006-12-08 21:52]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-10-12 01:13]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\Welho Tietoturvapalvelu\Anti-Virus\minifilter\fsgk.sys [2007-04-26 20:07]
R3 itecir;ITECIR Infrared Receiver;C:\Windows\system32\DRIVERS\itecir.sys [2007-04-04 06:57]
S4 F-Secure Filter;F-Secure File System Filter;C:\Program Files\Welho Tietoturvapalvelu\Anti-Virus\Win2K\FSfilter.sys [2007-04-26 20:08]
S4 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\Welho Tietoturvapalvelu\Anti-Virus\Win2K\FSrec.sys [2007-04-26 20:08]
S4 nvrd32;NVIDIA nForce RAID Driver;C:\Windows\system32\drivers\nvrd32.sys [2007-07-02 18:37]
*Newly Created Service* - CATCHME
.
'Ajoitetut tehtävät'-kansion sisältö
"2008-05-10 06:58:03 C:\Windows\Tasks\Scheduled scanning task.job"
- C:\PROGRA~1\WELHOT~1\ANTI-V~1\fsav.exeQ /HARD /POLICY /SCHED /NOBREAK /REPORT=C:\PROGRA~1\WELHOT~1\ANTI-V~1\report.txt
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by
Gmer,
http://www.gmer.net
Rootkit scan 2008-05-10 23:22:39
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-10 23:24:00
ComboFix-quarantined-files.txt 2008-05-10 20:23:30
Pre-Run: 111,741,988,864 tavua vapaana
Post-Run: 111,955,456,000 tavua vapaana
194 --- E O F --- 2008-05-07 19:27:16