ComboFix 08-05-19.4 - 2008-05-20 22:33:51.1 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6000.0.1252.1.1035.18.1222 [GMT 3:00]
Running from: C:\Users\\Desktop\ComboFix.exe
* Created a new restore point
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-04-20 to 2008-05-20 )))))))))))))))))
.
2008-05-19 20:03 . 2008-05-19 20:36 212 --a------ C:\delete.bat
2008-05-19 20:01 . 2008-05-19 20:01 <KANSIO> d-------- C:\_OTMoveIt
2008-05-19 18:20 . 2008-05-19 18:40 <KANSIO> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-05-19 18:20 . 2008-05-19 18:40 <KANSIO> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-05-19 18:20 . 2008-05-19 18:20 <KANSIO> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-17 11:43 . 2008-05-17 11:43 <KANSIO> d-------- C:\Users\All Users\Avg8
2008-05-17 11:43 . 2008-05-17 11:43 <KANSIO> d-------- C:\ProgramData\Avg8
2008-05-16 21:27 . 2008-05-16 21:27 <KANSIO> d-------- C:\Program Files\Trend Micro
2008-05-16 19:04 . 2008-05-16 19:33 <KANSIO> d-------- C:\Downloads
2008-05-16 19:04 . 2008-05-16 19:31 <KANSIO> d-------- C:\Bases
2008-05-16 19:01 . 2008-05-16 19:33 <KANSIO> d-------- C:\Kaspersky
2008-05-16 18:00 . 2008-05-16 18:00 <KANSIO> d-------- C:\Users\\AppData\Roaming\TrojanHunter
2008-05-16 17:22 . 2008-05-16 21:31 <KANSIO> d-------- C:\Program Files\TrojanHunter 5.0
2008-05-16 16:32 . 2008-05-16 16:32 <KANSIO> d-------- C:\Users\All Users\SUPERAntiSpyware.com
2008-05-16 16:32 . 2008-05-16 16:32 <KANSIO> d-------- C:\ProgramData\SUPERAntiSpyware.com
2008-05-16 16:31 . 2008-05-16 23:56 <KANSIO> d-------- C:\Users\\AppData\Roaming\SUPERAntiSpyware.com
2008-05-16 16:31 . 2008-05-16 23:56 <KANSIO> d-------- C:\Program Files\SUPERAntiSpyware
2008-05-16 16:12 . 2008-05-16 19:07 <KANSIO> d-------- C:\Program Files\The Cleaner Free
2008-05-16 00:07 . 2008-05-16 00:07 <KANSIO> d-------- C:\Users\All Users\TEMP
2008-05-16 00:07 . 2008-05-16 00:07 <KANSIO> d-------- C:\ProgramData\TEMP
2008-05-16 00:00 . 2008-05-16 00:00 <KANSIO> d-------- C:\Users\\AppData\Roaming\Simply
Super Software
2008-05-16 00:00 . 2008-05-16 00:00 <KANSIO> d-------- C:\Users\All Users\Simply
Super Software
2008-05-16 00:00 . 2008-05-16 00:00 <KANSIO> d-------- C:\ProgramData\Simply
Super Software
2008-05-16 00:00 . 2008-05-16 00:04 <KANSIO> d-------- C:\Program Files\Trojan Remover
2008-05-09 22:24 . 2008-05-09 22:24 <KANSIO> d-------- C:\Users\All Users\Adobe
2008-05-09 22:24 . 2008-05-09 22:24 <KANSIO> d-------- C:\Program Files\Common Files\Adobe
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-19 18:10 --------- d-----w C:\Program Files\SopCast
2008-05-19 17:18 --------- d-----w C:\Program Files\Norton 360
2008-05-18 11:11 --------- d-----w C:\ProgramData\Symantec
2008-05-16 23:03 --------- d-----w C:\ProgramData\Microsoft Help
2008-05-16 20:59 --------- d-----w C:\ProgramData\Lavasoft
2008-05-16 20:59 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-16 20:54 --------- d-----w C:\Program Files\PokerStars
2008-05-16 16:48 --------- d-----w C:\Program Files\Windows Mail
2008-05-16 08:23 --------- d-----w C:\Program Files\CCleaner
2008-05-15 13:22 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-13 18:25 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-09 12:32 --------- d-----w C:\Users\\AppData\Roaming\Malwarebytes
2008-04-09 12:32 --------- d-----w C:\ProgramData\Malwarebytes
2008-04-04 16:45 --------- d-----w C:\Program Files\Common Files\LightScribe
2008-04-04 16:45 --------- d-----w C:\Program Files\Atheros
2008-04-04 16:45 --------- d-----w C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
2008-04-04 16:45 --------- d-----w C:\Program Files\7-
Zip
2008-04-04 16:44 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-04-04 16:44 --------- d-----w C:\Users\AppData\Roaming\Stellarium
2008-04-04 16:44 --------- d-----w C:\ProgramData\Symantec Temporary Files
2008-04-04 16:44 --------- d-----w C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
2008-04-04 16:44 --------- d-----w C:\Program Files\Microsoft Works
2008-04-04 16:44 --------- d-----w C:\Program Files\Launch Manager
2008-04-04 16:44 --------- d-----w C:\Program Files\K-Lite
Codec Pack
2008-03-28 15:09 --------- d-----w C:\Program Files\Windows Live
2008-03-28 14:24 --------- d-----w C:\ProgramData\WLInstaller
2008-03-28 14:01 --------- d-----w C:\Users\Okko\AppData\Roaming\Lavasoft
2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll
2008-02-29 04:16 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll
2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2007-11-27 11:08 22,328 ----a-w C:\Users\\AppData\Roaming\PnkBstrK.sys
2007-08-29 15:12 174 --sha-w C:\Program Files\desktop.ini
2007-08-28 18:36 4,129,768 ----a-w C:\Users\\DCPlusPlus-0.699.exe
2007-11-21 14:28 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-11-21 14:28 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-11-21 14:28 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
------- Sigcheck -------
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 15:30 249856]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"VMCL"="C:\Program Files\vodafone\vmclite\DongleEnumerator.exe" [2007-04-16 13:56 131072]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 15:33 201728]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 15:34 125440]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-16 09:45 815104]
"RtHDVCpl"="RtHDVCpl.exe" [2006-12-01 08:37 4186112 C:\Windows\RtHDVCpl.exe]
"FerrariWP"="C:\Acer\WallPaper\FerrariWP\FerrariWP.exe" [2007-01-18 17:45 31528]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-07 00:04 464168]
"Acer Tour"="" []
"eDSMSNfix"="C:\Acer\Empowering Technology\eDSMSNfix.exe" [2007-02-08 20:40 13312]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 15:30 81920]
"LManager"="C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE" [2006-12-07 06:27 483328]
"WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 21:48 57344]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-10-31 01:06 304664]
"LVCOMSX"="C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-11-28 18:38 244512]
"AcerOrbicamRibbon"="C:\Program Files\Acer\OrbiCam10\OrbiCam.exe" [2006-11-28 18:43 754712]
"eRecoveryService"="" []
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 00:59 115816]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 18:38 583048]
"Windows Mobile-based device management"="%windir%\WindowsMobile\wmdSync.exe" [ ]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-08-29 17:56 1006264]
"WinampAgent"="D:\\Ohjelmat\Winamp\winampa.exe" [2004-12-20 21:41 33792]
"VirtualCloneDrive"="C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2006-04-29 16:21 94208]
"PlayMovie"="C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe" [2007-01-22 21:20 125032]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Acer VCM.lnk - C:\Program Files\Acer\Acer VCM\AcerVCM.exe [2007-08-06 19:03:08 1187840]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-12-07 12:46:46 719664]
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-04-14 20:25:03 528384]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{B7DD177E-67E6-4998-9B5C-3B53AAB2681B}"= C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Acer Arcade Deluxe.exe:Acer Arcade Deluxe
"{451D5E98-A0B0-4A6E-AD94-AC814DFCD109}"= C:\Program Files\Acer Arcade Deluxe\DVDivine\DVDivine.exe:DVDivine
"{F8046918-51CB-48A6-BB54-B7BE2819FD46}"= C:\Program Files\Acer Arcade Deluxe\VideoMagician\MagicDirector.exe:CyberLink MagicDirector
"{7276772B-AC89-41EB-A242-E959A23D5757}"= C:\Program Files\Acer Arcade Deluxe\DV Wizard\PowerDV.exe:CyberLink PowerDV
"{13DFF211-7316-4C38-8F1C-E5D4A44F40B2}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{5BEA8EC1-28B2-40AB-A18F-30D08F829BCC}"= C:\Program Files\Acer Arcade Deluxe\Play Movie\PlayMovie.exe:CyberLink PlayMovie
"{A644C70B-D2DE-4995-A9A5-53910A22AC42}"= C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe:CyberLink PlayMovie Resident Program
"{E7C65FDB-C529-44DE-A735-C141249B52F7}"= UDP:C:\Program Files\Norton 360\MainStub.exe:Norton 360
"{314AAC77-8CA0-4D3C-ACAB-755348E76693}"= TCP:C:\Program Files\Norton 360\MainStub.exe:Norton 360
"{E3845F17-DB9A-4456-9DDD-65057865BB6D}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{6E7D7C8E-9CB7-47B9-B728-A333B71C8EFB}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{D3C74757-2732-48C3-813F-81E25515D401}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{251B96F6-3D8F-447D-9ED4-996F0B536C61}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{5E4573C9-F354-42B8-93BF-54BEC524D8A7}"= UDP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"{99B887FB-10D4-4209-9390-E34CFBDC021C}"= TCP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"{1E5C5251-5899-4CC7-B7A2-B58A4266B516}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{B55E3FCC-ED83-44B7-9406-55261559BC62}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{B518A02D-24BF-42D2-972F-A6EFC8A6F1E3}"= UDP:C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{B68EFD8F-CEB7-4DAC-8D32-35239CC30BE7}"= TCP:C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{B743E461-31E7-440D-8A67-CFDA2E47B6BF}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{CE3D1806-55AF-4B28-BE98-4412F8CE4909}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{4D6BFE44-308E-4371-9990-C3E6CAE7088A}"= UDP:C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe
"{8A53E153-EBAE-49D5-8FDB-12342D3D010E}"= UDP:C:\Program Files\AVG\AVG8\avgnsx.exe:avgnsx.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Acer\\Empowering Technology\\eDataSecurity\\eDSfsu.exe"= C:\Acer\Empowering Technology\eDataSecurity\eDSfsu.exe:*:Enabled:eDSfsu
"C:\\Acer\\Empowering Technology\\eDataSecurity\\encryption.exe"= C:\Acer\Empowering Technology\eDataSecurity\encryption.exe:*:Enabled:encryption
"C:\\Acer\\Empowering Technology\\eDataSecurity\\decryption.exe"= C:\Acer\Empowering Technology\eDataSecurity\decryption.exe:*:Enabled:decryption
R0 PSDFilter;PSDFilter;C:\Windows\system32\DRIVERS\psdfilter.sys [2007-02-07 00:04]
R0 PSDNServ;PSDNSERVER;C:\Windows\system32\drivers\PSDNServ.sys [2007-02-07 00:04]
R0 psdvdisk;psdvdisk;C:\Windows\system32\drivers\psdvdisk.sys [2007-02-07 00:04]
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080508.002\IDSvix86.sys [2008-02-13 19:18]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};C:\Program Files\Acer Arcade Deluxe\Play Movie\
000.fcl [2006-11-02 16:51]
R2 Automaattinen LiveUpdate-ajastustoiminto;Automaattinen LiveUpdate-ajastustoiminto;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-09-26 13:53]
R2 eDataSecurity Service;eDSService.exe;"C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe" [2007-02-07 00:04]
R2 eNet Service;eNet Service;C:\Acer\Empowering Technology\eNet\eNet Service.exe [2006-12-28 20:07]
R2 eSettingsService;eSettings Service;C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [2007-01-02 16:46]
R2 MobilityService;MobilityService;C:\Acer\Mobility Center\MobilityService.exe [2006-11-24 12:57]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);"C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ []
R2 RapiMgr;Windows Mobile -laitteen liitettävyys;C:\Windows\system32\svchost.exe [2006-11-02 12:45]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R2 SQLWriter;SQL Server VSS Writer;"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]
R2 WcesComm;Windows Mobile 2003 -laitteen liitettävyys;C:\Windows\system32\svchost.exe [2006-11-02 12:45]
R2 WMIService;ePower Service;C:\Acer\Empowering Technology\ePower\ePowerSvc.exe [2007-01-02 09:33]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-11-28 11:44]
R3 athr;Atheros Extensible Wireless
LAN device driver;C:\Windows\system32\DRIVERS\athr.sys [2006-11-10 09:38]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\b57nd60x.sys [2006-11-02 10:30]
R3 btusbflt;Bluetooth
USB Filter;C:\Windows\system32\drivers\btusbflt.sys [2006-10-13 08:45]
R3 btwaudio;Bluetooth-äänilaite;C:\Windows\system32\drivers\btwaudio.sys [2006-12-05 11:07]
R3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys [2006-12-05 11:05]
R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2006-12-05 11:09]
R3 lv321av;Logitech USB PC Camera (VC0321);C:\Windows\system32\DRIVERS\lv321av.sys [2006-11-28 13:36]
R3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-01-08 07:16]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2007-01-10 01:32]
S3 TfBulk;TfBulk;C:\Windows\system32\DRIVERS\TfBulk.sys [2007-05-31 22:11]
S3 WSVD;WSVD;C:\Windows\system32\drivers\WSVD.sys [2006-09-19 16:47]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\shell\AutoRun\command - F:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{211b9f33-cea4-11dc-9322-00197edf806e}]
\shell\AutoRun\command - F:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{211b9f34-cea4-11dc-9322-00197edf806e}]
\shell\AutoRun\command - F:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2681e6e3-bad1-11dc-915a-00197edf806e}]
\shell\AutoRun\command - F:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d39e684-d26a-11dc-9cd3-001b2423bb7f}]
\shell\AutoRun\command - F:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d39e685-d26a-11dc-9cd3-001b2423bb7f}]
\shell\AutoRun\command - F:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3a1d1cb8-a366-11dc-8f14-00197edf806e}]
\shell\AutoRun\command - F:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3a1d1cb9-a366-11dc-8f14-00197edf806e}]
\shell\AutoRun\command - F:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b472c038-c522-11dc-bff3-00197edf806e}]
\shell\AutoRun\command - H:\AutoRunLauncher.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d4def51d-a1c6-11dc-b66a-00197edf806e}]
\shell\AutoRun\command - F:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d4def51e-a1c6-11dc-b66a-00197edf806e}]
\shell\AutoRun\command - F:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dbbc36a4-a1cb-11dc-9eb8-00197edf806e}]
\shell\AutoRun\command - F:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dbbc36a5-a1cb-11dc-9eb8-00197edf806e}]
\shell\AutoRun\command - F:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e91c0e89-5d0f-11dc-a349-00197edf806e}]
\shell\AutoRun\command - F:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e91c0e8a-5d0f-11dc-a349-00197edf806e}]
\shell\AutoRun\command - F:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{edef986a-556e-11dc-a444-00197edf806e}]
\shell\AutoRun\command - F:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{edef9875-556e-11dc-a444-00197edf806e}]
\shell\AutoRun\command - F:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{edef9ce4-556e-11dc-a444-00197edf806e}]
\shell\AutoRun\command - F:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{edef9ce5-556e-11dc-a444-00197edf806e}]
\shell\AutoRun\command - F:\VMC_PBStarter.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
msiexec /fums {264387C0-5B9A-F85A-CAF2-FDBA49EC9D35} /qb
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by
Gmer,
http://www.gmer.net
Rootkit scan 2008-05-20 22:36:13
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-20 22:37:03
ComboFix-quarantined-files.txt 2008-05-20 19:36:56
Pre-Run: 32,352,854,016 tavua vapaana
Post-Run: 32,462,680,064 tavua vapaana
259 --- E O F --- 2008-05-16 23:04:05