ComboFix 08-05-11.1 - AvaRaGane 2008-05-13 0:25:18.1 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1035.18.1069 [GMT 3:00]
Running from: C:\Users\AvaRaGane\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
.
(((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
F:\Autorun.inf
.
((((( Tiedostot, jotka on luotu seuraavalla aikav„lill„: 2008-04-12 to 2008-05-12 )))))))))))))))))
.
Tiedostoja ei ole luotu t„ll„ aikav„lill„
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-12 21:36 --------- d-----w C:\Users\AvaRaGane\AppData\Roaming\uTorrent
2008-05-12 20:44 --------- d-----w C:\ProgramData\Symantec
2008-05-12 20:24 --------- d-----w C:\Program Files\Java
2008-05-12 19:21 --------- d-----w C:\Program Files\Trend Micro
2008-05-08 20:40 --------- d-----w C:\Program Files\Spyware Doctor
2008-05-08 19:04 --------- d-----w C:\Users\AvaRaGane\AppData\Roaming\PC Tools
2008-05-07 16:09 --------- d-----w C:\Program Files\Automotix
2008-05-06 06:29 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-05 07:48 --------- d-----w C:\ProgramData\Apple
2008-05-05 07:48 --------- d-----w C:\Program Files\Apple Software Update
2008-05-04 16:11 --------- d-----w C:\Program Files\Sun
2008-05-03 20:30 --------- d-----w C:\Program Files\DAMN
NFO Viewer
2008-04-30 12:21 --------- d-----w C:\Users\AvaRaGane\AppData\Roaming\Automotix
2008-04-29 19:01 --------- d-----w C:\Program Files\QuickTime
2008-04-29 19:00 --------- d-----w C:\ProgramData\Apple Computer
2008-04-28 20:57 --------- d-----w C:\Program Files\Common Files\Macromedia
2008-04-28 20:54 --------- d-----w C:\Program Files\Macromedia
2008-04-28 15:16 --------- d-----w C:\Users\AvaRaGane\AppData\Roaming\PC Suite
2008-04-28 12:38 --------- d-----w C:\Users\AvaRaGane\AppData\Roaming\Nokia
2008-04-27 14:51 --------- d-----w C:\Users\AvaRaGane\AppData\Roaming\Nokia Multimedia Player
2008-04-27 14:42 0 ---ha-w C:\Windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-04-23 21:14 --------- d-----w C:\ProgramData\Nokia
2008-04-23 21:12 --------- d-----w C:\Program Files\Nokia
2008-04-23 21:09 --------- d-----w C:\Program Files\Connectivity Cable Driver
2008-04-23 21:07 --------- d-----w C:\Program Files\Common Files\Nokia
2008-04-23 21:04 --------- d-----w C:\ProgramData\Installations
2008-04-14 22:46 --------- d-----w C:\Program Files\uTorrent
2008-04-14 03:27 --------- d-----w C:\ProgramData\Microsoft Help
2008-04-14 03:20 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-04-13 19:59 --------- d-----w C:\Program Files\Afree
MP4 to
AVI FLV MPEG WMV MOV Converter
2008-04-10 07:56 --------- d-----w C:\Program Files\Windows Mail
2008-04-09 22:42 944,184 ----a-w C:\Windows\System32\winload.exe
2008-04-09 22:42 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll
2008-04-09 22:42 620,088 ----a-w C:\Windows\System32\ci.dll
2008-04-09 22:42 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-04-09 22:42 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-04-09 22:42 371,712 ----a-w C:\Windows\System32\srcore.dll
2008-04-09 22:42 313,856 ----a-w C:\Windows\System32\rstrui.exe
2008-04-09 22:42 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-04-09 22:42 16,384 ----a-w C:\Windows\System32\srdelayed.exe
2008-04-09 22:38 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-04-09 22:38 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-04-09 22:38 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-04-09 22:38 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-04-09 00:02 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2008-04-09 00:01 83,968 ----a-w C:\Windows\System32\dnsrslvr.dll
2008-04-09 00:01 296,448 ----a-w C:\Windows\System32\gdi32.dll
2008-04-09 00:01 24,576 ----a-w C:\Windows\System32\dnscacheugc.exe
2008-04-08 21:28 --------- d-----w C:\ProgramData\Office Genuine Advantage
2008-03-30 00:19 174 --sha-w C:\Program Files\desktop.ini
2008-03-29 17:14 8,138,240 ----a-w C:\Windows\System32\ssBranded.scr
2008-03-18 09:31 --------- d-----w C:\Program Files\Windows Calendar
2008-03-18 01:03 8,192 ----a-w C:\Windows\System32\riched32.dll
2008-03-18 01:03 77,824 ----a-w C:\Windows\System32\rascfg.dll
2008-03-18 01:03 61,952 ----a-w C:\Windows\system32\drivers\wanarp.sys
2008-03-18 01:03 52,736 ----a-w C:\Windows\System32\rasdiag.dll
2008-03-18 01:03 48,640 ----a-w C:\Windows\system32\drivers\ndproxy.sys
2008-03-18 01:03 384,000 ----a-w C:\Windows\System32\netcfgx.dll
2008-03-18 01:03 32,768 ----a-w C:\Windows\System32\rasmxs.dll
2008-03-18 01:03 22,016 ----a-w C:\Windows\System32\rasser.dll
2008-03-18 01:03 20,480 ----a-w C:\Windows\system32\drivers\ndistapi.sys
2008-03-18 01:03 13,824 ----a-w C:\Windows\System32\icsunattend.exe
2008-03-17 15:34 --------- d-----w C:\Users\AvaRaGane\AppData\Roaming\InterVideo
2008-03-12 17:54 --------- d-----w C:\Program Files\Windows Live
2008-03-12 17:52 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-12 17:47 --------- d-----w C:\ProgramData\WLInstaller
2008-03-12 17:31 41,984 ----a-w C:\Windows\system32\drivers\monitor.sys
2008-03-12 17:31 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
2008-03-12 17:30 --------- d-----w C:\Program Files\MSXML 4.0
2008-03-12 01:03 613,888 ----a-w C:\Windows\System32\wpd_ci.dll
2008-03-12 01:03 260,096 ----a-w C:\Windows\System32\dpx.dll
2008-03-12 01:03 224,824 ----a-w C:\Windows\System32\clfs.sys
2008-03-12 01:03 221,696 ----a-w C:\Windows\System32\umpnpmgr.dll
2008-03-12 01:03 19,456 ----a-w C:\Windows\System32\cfgmgr32.dll
2008-03-12 01:03 101,888 ----a-w C:\Windows\System32\drvinst.exe
2008-03-09 03:11 57,856 ----a-w C:\Windows\System32\SLUINotify.dll
2008-03-09 03:11 566,784 ----a-w C:\Windows\System32\SLCommDlg.dll
2008-03-09 03:11 39,936 ----a-w C:\Windows\System32\slcinst.dll
2008-03-09 03:11 351,232 ----a-w C:\Windows\System32\SLUI.exe
2008-03-09 03:11 33,280 ----a-w C:\Windows\System32\slwmi.dll
2008-03-09 03:11 268,288 ----a-w C:\Windows\System32\mcbuilder.exe
2008-03-09 03:11 223,232 ----a-w C:\Windows\System32\SLC.dll
2008-03-09 03:11 2,605,568 ----a-w C:\Windows\System32\SLsvc.exe
2008-03-09 03:11 186,368 ----a-w C:\Windows\System32\SLLUA.exe
2008-03-06 11:57 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2008-03-06 11:57 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2008-03-06 11:57 542,720 ----a-w C:\Windows\System32\sysmain.dll
2008-03-06 11:57 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2008-03-06 11:57 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2008-03-06 11:57 297,984 ----a-w C:\Windows\System32\wlansec.dll
2008-03-06 11:57 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
2008-03-06 11:57 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2008-03-06 11:57 2,923,520 ----a-w C:\Windows\explorer.exe
2008-03-06 11:56 86,016 ----a-w C:\Windows\System32\icfupgd.dll
2008-03-06 11:56 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL
2008-03-06 11:56 7,680 ----a-w C:\Windows\System32\spwmp.dll
2008-03-06 11:56 61,952 ----a-w C:\Windows\System32\cmifw.dll
2008-03-06 11:56 4,096 ----a-w C:\Windows\System32\dxmasf.dll
2008-03-06 11:56 396,800 ----a-w C:\Windows\System32\MPSSVC.dll
2008-03-06 11:56 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll
.
------- Sigcheck -------
.
(((((((((((((((((((((((((((((( Rekisterin k„ynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhji„ arvoja ja laillisia oletusarvoja ei n„ytet„
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-03-05 04:55 1232896]
"StartCCC"="c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 13:35 90112]
"LightScribe Control Panel"="C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-04-19 13:26 484904]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-02-14 02:09 486856]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 15:34 201728]
"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe" [2008-04-15 01:44 219952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-07-13 04:28 1006264]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-12-15 14:08 1097728]
"PDF Complete"="C:\Program Files\PDF Complete\pdfsty.exe" [2007-05-08 08:38 331552]
"PTHOSTTR"="C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.exe" [2007-01-09 15:52 145184]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-12 16:36 827392]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 13:18 472776]
"WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 16:12 317128]
"HP Health Check Scheduler"="C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-03-12 11:54 50696]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-05-02 16:17 163840]
"CognizanceTS"="C:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll" [2003-12-22 20:12 17920]
"HP Software Update"="c:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]
"PCSuiteTrayApplication"="C:\Program Files\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 16:10 271360]
"egui"="C:\Program Files\ESET NOD32 Antivirus\egui.exe" [2007-12-21 09:21 1443072]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-08-02 10:49 1063752]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-07-13 05:48 77824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"ST Recovery Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 11:17 1241088]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-03-29 14:11:50 719664]
DVD Check.lnk - C:\Program Files\InterVideo\DVD Check\DVDCheck.exe [2008-02-26 14:20:56 192512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= divxa32.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{CBB55650-3ACC-44B0-BF77-50AF12C49968}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{7D9E6FD7-62C0-4403-91A5-C3264043B2D2}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{C879FB40-CA1B-4C5F-86CE-F5850E7949B5}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{CCA66E58-613D-4CC5-9F20-BE493B076708}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-30 14:23]
R1 epfwtdir;epfwtdir;C:\Windows\system32\DRIVERS\epfwtdir.sys [2007-12-21 09:21]
R2 ASBroker;Logon Session Broker;C:\Windows\System32\svchost.exe [2006-11-02 12:45]
R2 ASChannel;Local Communication Channel;C:\Windows\System32\svchost.exe [2006-11-02 12:45]
R2 BcmSqlStartupSvc;Business Contact Managerin SQL Server -käynnistyspalvelu;"C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe" [2008-01-16 11:16]
R2 pdfcDispatcher;PDF Document Manager;C:\Program Files\PDF Complete\pdfsvc.exe [2007-05-08 08:38]
R2 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\b57nd60x.sys [2007-02-26 17:52]
R3 btwaudio;Bluetooth-äänilaite;C:\Windows\system32\drivers\btwaudio.sys [2007-05-11 13:42]
R3 btwavdt;Bluetooth AVDT Service;C:\Windows\system32\drivers\btwavdt.sys [2007-05-11 13:42]
R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2007-05-11 13:42]
R3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-02-02 19:09]
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-12-13 13:49]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);"c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ []
S3 upperdev;upperdev;C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2007-11-29 10:39]
S3 V0090VID;Creative WebCam Vista Plus;C:\Windows\system32\DRIVERS\V0090Vid.sys [2005-04-14 01:00]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
Cognizance REG_MULTI_SZ ASBroker ASChannel
GPSvcGroup REG_MULTI_SZ GPSvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
msiexec /fums {990BA001-D69F-9DB2-56CE-88E0399B30FB} /qb
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by
Gmer,
http://www.gmer.net
Rootkit scan 2008-05-13 00:35:08
Windows 6.0.6000 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\Ati2evxx.exe
C:\Windows\System32\audiodg.exe
C:\Windows\System32\Ati2evxx.exe
C:\Program Files\Hewlett-Packard\IAM\Bin\asghost.exe
C:\Windows\System32\agrsmsvc.exe
C:\Program Files\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\System32\conime.exe
C:\Windows\SMINST\Scheduler.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\System32\wbem\WMIADAP.exe
.
**************************************************************************
.
Completion time: 2008-05-13 0:40:57 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-12 21:40:41
Järjestelmä ei löydä sanomaa numerolle 0x2379 ohjelman Application sanomatiedostossa.
J„rjestelm„ ei l”yd„ sanomaa numerolle 0x2379 ohjelman Application sanomatiedostossa.
248 --- E O F --- 2008-05-09 19:02:08