ComboFix 08-05-21.2 - rinki ja susinki 2008-05-22 18:49:56.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1035.18.637 [GMT 3:00]
Running from: C:\Documents and Settings\rinki ja susinki\Työpöytä\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
(((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
----- BITS: Possible
infected sites -----
hxxp://sync.avustaja.sonera.fi
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-04-22 to 2008-05-22 )))))))))))))))))
.
2008-05-22 13:35 . 2008-05-22 13:35 <KANSIO> d-------- C:\Program Files\Trend Micro
2008-05-22 12:37 . 2008-05-22 12:37 268 --ah----- C:\sqmdata13.sqm
2008-05-22 12:37 . 2008-05-22 12:37 244 --ah----- C:\sqmnoopt13.sqm
2008-05-22 12:10 . 2008-05-22 12:10 268 --ah----- C:\sqmdata12.sqm
2008-05-22 12:10 . 2008-05-22 12:10 244 --ah----- C:\sqmnoopt12.sqm
2008-05-22 03:32 . 2008-05-22 03:32 268 --ah----- C:\sqmdata11.sqm
2008-05-22 03:32 . 2008-05-22 03:32 244 --ah----- C:\sqmnoopt11.sqm
2008-05-22 01:51 . 2008-05-22 01:51 268 --ah----- C:\sqmdata10.sqm
2008-05-22 01:51 . 2008-05-22 01:51 244 --ah----- C:\sqmnoopt10.sqm
2008-05-21 22:33 . 2008-05-21 22:33 268 --ah----- C:\sqmdata09.sqm
2008-05-21 22:33 . 2008-05-21 22:33 244 --ah----- C:\sqmnoopt09.sqm
2008-05-21 04:07 . 2008-05-21 04:07 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-05-21 01:33 . 2008-05-21 01:33 <KANSIO> d-------- C:\Program Files\Yahoo!
2008-05-21 01:33 . 2008-05-21 01:33 <KANSIO> d-------- C:\Program Files\CCleaner
2008-05-07 19:20 . 2008-05-07 19:20 268 --ah----- C:\sqmdata08.sqm
2008-05-07 19:20 . 2008-05-07 19:20 244 --ah----- C:\sqmnoopt08.sqm
2008-05-07 12:44 . 2008-05-07 12:44 268 --ah----- C:\sqmdata07.sqm
2008-05-07 12:44 . 2008-05-07 12:44 244 --ah----- C:\sqmnoopt07.sqm
2008-05-06 23:40 . 2008-05-06 23:40 268 --ah----- C:\sqmdata06.sqm
2008-05-06 23:40 . 2008-05-06 23:40 244 --ah----- C:\sqmnoopt06.sqm
2008-05-06 17:34 . 2008-05-06 17:34 268 --ah----- C:\sqmdata05.sqm
2008-05-06 17:34 . 2008-05-06 17:34 244 --ah----- C:\sqmnoopt05.sqm
2008-05-06 00:18 . 2008-05-06 00:18 268 --ah----- C:\sqmdata04.sqm
2008-05-06 00:18 . 2008-05-06 00:18 244 --ah----- C:\sqmnoopt04.sqm
2008-04-25 20:09 . 2008-04-25 20:09 <KANSIO> d-------- C:\Program Files\AVSMedia
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-21 01:10 --------- d-----w C:\Documents and Settings\rinki ja susinki\Application Data\uTorrent
2008-05-20 18:07 15,322 ----a-w C:\Documents and Settings\rinki ja susinki\Application Data\wklnhst.dat
2008-05-20 14:31 --------- d-----w C:\Program Files\Sonera
2008-04-26 16:54 --------- d-----w C:\Program Files\Windows Live
2008-04-14 14:09 --------- d-----w C:\Program Files\Common Files\AVSMedia
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-18 04:49 2,402,320 ----a-w C:\WLinstaller.exe
2008-03-01 13:01 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-12 18:29 57,656 ----a-w C:\Documents and Settings\rinki ja susinki\Application Data\GDIPFONTCACHEV1.DAT
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 15:00 15360]
"Steam"="D:\HalfLife\Steam.exe" [2008-03-28 10:06 1271032]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"F-Secure Manager"="D:\Elisa\Common\FSM32.exe" [2007-04-26 20:12 183208]
"F-Secure TNB"="D:\Elisa\FSGUI\TNBUtil.exe" [2007-04-26 20:10 740208]
"News Service"="D:\Elisa\FSGUI\ispnews.exe" [2005-05-31 15:45 356352]
"zBrowser Launcher"="C:\Program Files\Logitech\iTouch\iTouch.exe" [2004-03-18 10:33 892928]
"Logitech Utility"="Logi_MwX.Exe" [2002-11-08 13:50 19968 C:\WINDOWS\LOGI_MWX.EXE]
"EPSON Stylus C46 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.exe" [2004-01-14 05:00 99840]
"RemoteControl"="D:\PDVDServ.exe" [2003-10-31 19:42 32768]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-10 03:11 50688]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"QuickTime Task"="D:\QuickTime\qttask.exe" [2007-06-29 06:24 286720]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-09 06:37 185632]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-14 10:00 267064]
"Sonera"="C:\Program Files\Sonera\InternetAvustaja\bin\sprtcmd.exe" [2007-08-19 11:47 197880]
"CnxTrApp"="C:\Program Files\TeleWell\ADSL
USB Router\CnxTrApp.dll" [ ]
"ASUS Probe"="C:\Program Files\ASUS\Probe\AsusProb.exe" [2002-12-06 17:07 617984]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 02:41 81920]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 15:00 15360]
C:\Documents and Settings\All Users\K„ynnist„-valikko\Ohjelmat\K„ynnistys\
Color Calibration.lnk - C:\Program Files\SEC\MagicTune 2.5\GammaTray.exe [2007-07-13 19:06:19 36864]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 12:01:04 83360]
NaturalColorLoad.lnk - C:\Program Files\SEC\Natural Color\NaturalColorLoad.exe [2007-07-13 19:05:43 155715]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-04-11 11:10:00 394856]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R0 FSFW;F-Secure Firewall Driver;C:\WINDOWS\system32\drivers\fsdfw.sys [2007-04-26 20:09]
R1 F-Secure HIPS;F-Secure HIPS;D:\Elisa\HIPS\fshs.sys [2007-04-26 20:11]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;D:\Elisa\Anti-Virus\minifilter\fsgk.sys [2007-04-26 20:07]
R3 LCcfltr;Logitech USB Filter Driver;C:\WINDOWS\system32\Drivers\LCcFltr.Sys [2004-03-03 10:50]
S4 F-Secure Filter;F-Secure File System Filter;D:\Elisa\Anti-Virus\Win2K\FSfilter.sys [2007-04-26 20:08]
S4 F-Secure Recognizer;F-Secure File System Recognizer;D:\Elisa\Anti-Virus\Win2K\FSrec.sys [2007-04-26 20:08]
*Newly Created Service* - CATCHME
.
'Ajoitetut tehtävät'-kansion sisältö
"2008-04-24 05:57:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-22 00:05:13 C:\WINDOWS\Tasks\Scheduled scanning task.job"
- D:\Elisa\ANTI-V~1\fsav.exeE /HARD /POLICY /SCHED /NOBREAK /REPORT=D:\Elisa\ANTI-V~1\report.txt
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by
Gmer,
http://www.gmer.net
Rootkit scan 2008-05-22 18:53:30
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-22 18:54:43
ComboFix-quarantined-files.txt 2008-05-22 15:54:37
Pre-Run: 5,819,158,528 tavua vapaana
Post-Run: 6,636,777,472 tavua vapaana
130 --- E O F --- 2008-05-16 20:03:41