Eli ensimmäisellä kerralla kun tein niin tää sulki just ennen raportti a ohjelman joten ajoin uusiksi ja tiedä sitten onko tää raportti hyödytön.. kohta perässä tulee tuon toisen ohjelman tiedot kunhan kerkeen sen jutut tehdä
ComboFix 08-05-12.1 - pp 2008-05-14 19:15:49.2 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1035.18.567 [GMT 3:00]
Running from: C:\Documents and Settings\pp\Työpöytä\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
(((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\system32\plugin1.dat
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NWSAPAGENT
-------\Service_NwSapAgent
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-04-14 to 2008-05-14 )))))))))))))))))
.
2008-05-14 14:11 . 2008-05-14 14:11 <KANSIO> d-------- C:\Documents and Settings\pp\Application Data\BSplayer Pro
2008-05-12 01:19 . 2008-05-12 01:19 268 --ah----- C:\sqmdata02.sqm
2008-05-12 01:19 . 2008-05-12 01:19 244 --ah----- C:\sqmnoopt02.sqm
2008-05-10 00:14 . 2008-05-10 00:14 <KANSIO> d-------- C:\hijackthis
2008-05-09 08:24 . 2008-05-14 14:13 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-09 08:24 . 2008-05-09 08:24 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-22 19:46 . 2008-04-22 19:46 <KANSIO> d-------- C:\Program Files\PAF
Diamond Poker
2008-04-21 21:31 . 2008-04-21 21:35 9,270,090 --a------ C:\All Grand Theft Auto Cracks!.zip
2008-04-21 21:28 . 2008-04-21 21:28 <KANSIO> d-------- C:\PC_GTA San Andreas -Ultimate- (read
nfo)-.direct.play.-ToeD
2008-04-19 01:21 . 2008-04-19 01:21 <KANSIO> d-------- C:\fsaua.data
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-11 18:14 1,854,883 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
2008-04-05 09:31 1,818 ----a-w C:\cc_20080405_1231.reg
2008-03-29 10:15 2,190 ----a-w C:\cc_20080329_1315.reg
2008-03-28 21:49 --------- d-----w C:\Program Files\SpywareBlaster
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\dllcache\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\dllcache\msjint40.dll
2008-03-20 20:11 3,786 ----a-w C:\cc_20080320_2311.reg
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-18 17:33 --------- d-----w C:\Documents and Settings\pp\Application Data\Nokia Multimedia Player
2008-03-07 21:07 1,216 ----a-w C:\cc_20080308_0007.reg
2008-03-01 15:31 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-02-29 08:56 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-02-29 08:55 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-02-25 14:38 2,540 ----a-w C:\cc_20080225_1738.reg
2008-02-22 10:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:38 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:38 45,568 ----a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:38 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-02-15 05:44 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-07-09 10:13 889 ----a-w C:\Program Files\Config.ini
2007-07-01 10:46 162 ----a-w C:\Program Files\sysinfo.txt
2006-08-15 07:38 81,920 ----a-w C:\Documents and Settings\pp\Application Data\ezpinst.exe
2006-08-15 07:38 47,360 ----a-w C:\Documents and Settings\pp\Application Data\pcouffin.sys
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-10-04 23:06 1135968 --a------ C:\Program Files\Winamp Toolbar\winamptb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= "C:\Program Files\Winamp Toolbar\winamptb.dll" [2007-10-04 23:06 1135968]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-10-04 23:06 1135968]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-15 20:00 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2005-09-22 16:42 90112 C:\WINDOWS\soundman.exe]
"AspireService"="C:\Program Files\Acer\Acer eMode Management\AspireService.exe" [2005-09-29 16:07 114688]
"wltray.exe"="C:\WINDOWS\system32\wltray.exe" [2005-06-08 17:32 778318]
"EPGServiceTool"="C:\PROGRA~1\WINTV\EPG Services\System\EPGClient.exe" [2007-08-01 04:26 675840]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-11-17 19:31 7286784]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 15:10 271360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-15 20:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-12-05 18:28 219136]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 10:17 1241088]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.enc"= ITIG726.acm
"MSACM.MSNAUDIO"= msnaudio.acm
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe
"Orb"="C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0\bin\jusched.exe
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
"LaunchApp"=Alaunch
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
"nwiz"=nwiz.exe /install
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
"MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
"ntiMUI"=c:\Program Files\NewTech Infosystems\NTI
CD &
DVD-Maker 7\ntiMUI.exe
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
"NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
"OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
"PCSuiteTrayApplication"=C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" -hide
"eRecoveryService"=C:\Acer\Empowering Technology\eRecovery\Monitor.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\mIRC1\\mirc.exe"=
"C:\\Program Files\\Mozilla Firefox\\FIREFOX.EXE"=
"D:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\ABC\\ABC.exe"=
"C:\\Program Files\\Last.fm\\LastFM.exe"=
"C:\\Kaspersky\\kavupd.exe"=
"C:\\Program Files\\Sunbelt Software\\Personal Firewall\\kpf4gui.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-02-20 13:34]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-02-20 13:34]
R1 oreans32;oreans32;C:\WINDOWS\system32\drivers\oreans32.sys [2006-09-11 11:10]
R2 EPGService;EPGService;C:\PROGRA~1\WINTV\EPG Services\System\EPGService.exe [2007-09-05 17:46]
R3 HCW713x;Hauppauge 713x VU PCI TV Card;C:\WINDOWS\system32\DRIVERS\HCW713x.sys [2007-03-26 18:46]
.
'Ajoitetut tehtävät'-kansion sisältö
"2007-09-17 08:24:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-14 15:54:02 C:\WINDOWS\Tasks\Tarkistetaan Windows Live -työkalurivin päivitykset.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-05-14 16:10:42 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by
Gmer,
http://www.gmer.net
Rootkit scan 2008-05-14 19:19:41
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-14 19:21:17
ComboFix-quarantined-files.txt 2008-05-14 16:21:12
Pre-Run: 58,014,367,744 tavua vapaana
Post-Run: 57,998,770,176 tavua vapaana
172 --- E O F --- 2008-05-14 15:00:39