No tässä olis nyt se ComboFix -raportti:
ComboFix 08-06-12.2 - Omistaja 2008-06-15 19:42:10.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1035.18.424 [GMT 3:00]
Running from: C:\Documents and Settings\Omistaja\Työpöytä\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
(((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Program Files\VirusHeat 4.3
C:\Program Files\VirusHeat 4.3\sdebug.log
C:\WINDOWS\BM7fa79b77.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\Fonts\CALIBRIB.TTF
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aigxwjnw.dll
C:\WINDOWS\system32\aqdhmhpv.dll
C:\WINDOWS\system32\ddwylojh.dll
C:\WINDOWS\system32\eilpujym.ini
C:\WINDOWS\system32\fffomcbj.dll
C:\WINDOWS\system32\hjolywdd.ini
C:\WINDOWS\system32\hrlkygij.dll
C:\WINDOWS\system32\jigyklrh.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mlfgqids.dll
C:\WINDOWS\system32\rxibfmpo.ini
C:\WINDOWS\system32\tbofovvy.ini
C:\WINDOWS\system32\urkmyybq.dll
C:\WINDOWS\system32\WyabcMoq.ini
C:\WINDOWS\system32\WyabcMoq.ini2
C:\WINDOWS\system32\xputftdr.dll
C:\WINDOWS\system32\yjtviucv.dll
C:\WINDOWS\system32\yvvofobt.dll
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-15 to 2008-06-15 )))))))))))))))))
.
2008-06-15 19:37 . 2008-06-15 19:37 <KANSIO> d-------- C:\WINDOWS\LastGood
2008-06-06 18:02 . 2008-06-06 18:02 8 --a------ C:\WINDOWS\system32\7c94ba65
2008-06-06 17:36 . 2008-01-01 19:45 <KANSIO> d--h----- C:\Documents and Settings\Järjestelmänvalvoja\Verkkoympäristö
2008-06-06 17:36 . 2008-01-01 19:45 <KANSIO> d--h----- C:\Documents and Settings\Järjestelmänvalvoja\Verkkoympäristö
2008-06-06 17:36 . 2008-01-01 18:02 <KANSIO> d-------- C:\Documents and Settings\Järjestelmänvalvoja\Työpöytä
2008-06-06 17:36 . 2008-01-01 18:02 <KANSIO> d-------- C:\Documents and Settings\Järjestelmänvalvoja\Työpöytä
2008-06-06 17:36 . 2008-01-01 19:45 <KANSIO> d--h----- C:\Documents and Settings\Järjestelmänvalvoja\Tulostinympäristö
2008-06-06 17:36 . 2008-01-01 19:45 <KANSIO> d--h----- C:\Documents and Settings\Järjestelmänvalvoja\Tulostinympäristö
2008-06-06 17:36 . 2008-01-01 19:45 <KANSIO> d-------- C:\Documents and Settings\Järjestelmänvalvoja\Suosikit
2008-06-06 17:36 . 2008-01-01 19:45 <KANSIO> d-------- C:\Documents and Settings\Järjestelmänvalvoja\Suosikit
2008-06-06 17:36 . 2008-01-01 17:55 <KANSIO> d--h----- C:\Documents and Settings\Järjestelmänvalvoja\Mallit
2008-06-06 17:36 . 2008-01-01 17:55 <KANSIO> d--h----- C:\Documents and Settings\Järjestelmänvalvoja\Mallit
2008-06-06 17:36 . 2008-01-01 19:45 <KANSIO> dr------- C:\Documents and Settings\Järjestelmänvalvoja\Käynnistä-valikko
2008-06-06 17:36 . 2008-01-01 19:45 <KANSIO> dr------- C:\Documents and Settings\Järjestelmänvalvoja\Käynnistä-valikko
2008-06-06 17:36 . 2008-06-06 18:27 <KANSIO> d-------- C:\Documents and Settings\Järjestelmänvalvoja
2008-06-03 12:50 . 2008-06-03 12:50 <KANSIO> d-------- C:\Documents and Settings\Omistaja\Application Data\TurvaPC
2008-06-03 12:45 . 2008-06-03 12:45 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\TurvaPC
2008-06-02 23:04 . 2008-06-02 23:04 7,680 --ahs---- C:\WINDOWS\Thumbs.db
2008-06-02 22:58 . 2008-06-02 22:58 244 --ah----- C:\sqmnoopt05.sqm
2008-06-02 22:58 . 2008-06-02 22:58 232 --ah----- C:\sqmdata05.sqm
2008-06-02 22:31 . 2008-06-02 22:58 97,116 --a------ C:\WINDOWS\DC5177176.zip
2008-06-02 21:17 . 2008-06-02 23:46 <KANSIO> d-------- C:\Program Files\Windows Installer Clean Up
2008-06-02 21:17 . 2008-06-02 21:17 <KANSIO> d-------- C:\Program Files\MSECACHE
2008-06-02 21:06 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-06-02 21:03 . 2008-06-02 21:03 <KANSIO> d-------- C:\Program Files\Common Files\Java
2008-06-01 17:08 . 2008-06-01 17:08 <KANSIO> d-------- C:\WINDOWS\Sun
2008-06-01 17:08 . 2008-06-02 21:06 <KANSIO> d-------- C:\Program Files\Java
2008-05-31 11:24 . 2008-05-31 11:24 0 --a------ C:\WINDOWS\system32\REN24.tmp
2008-05-31 11:24 . 2008-05-31 11:24 0 --a------ C:\WINDOWS\system32\REN23.tmp
2008-05-31 11:24 . 2008-05-31 11:24 0 --a------ C:\WINDOWS\system32\REN22.tmp
2008-05-31 10:51 . 2008-05-31 10:51 <KANSIO> d-------- C:\VivoxLogs
2008-05-30 16:41 . 2008-05-30 16:53 <KANSIO> d-------- C:\Documents and Settings\Omistaja\Application Data\OpenOffice.org2
2008-05-27 14:39 . 2008-05-27 14:39 <KANSIO> d--hs---- C:\WINDOWS\ftpcache
2008-05-25 09:08 . 2008-05-25 09:08 <KANSIO> d-------- C:\Documents and Settings\NetworkService\Application Data\Xfire
2008-05-21 12:00 . 2008-05-21 14:10 <KANSIO> d-------- C:\WINDOWS\system32\Adobe
2008-05-17 13:07 . 2008-05-17 13:07 118 --a------ C:\WINDOWS\system32\MRT.INI
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-15 16:31 --------- d-----w C:\Program Files\Norman
2008-06-13 07:46 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-06-06 15:00 --------- d-----w C:\Program Files\Norton Security Scan
2008-06-03 06:06 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-06-03 06:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-06-02 20:28 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-31 09:38 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-30 14:00 --------- d-----w C:\Program Files\Microsoft Works
2008-05-30 14:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-27 10:27 --------- d-----w C:\Program Files\PicLensIE
2008-05-24 20:37 --------- d-----w C:\Program Files\WarRock
2008-05-09 12:18 40,960 ----a-w C:\WINDOWS\Gorillaz Albumsaver.dll
2008-05-09 12:18 265,388 ----a-w C:\WINDOWS\Gorillaz Albumsaver.scr
2008-05-09 12:18 1,581,226 ----a-w C:\WINDOWS\Gorillaz Albumsaver.exe
2008-05-06 19:19 --------- d-----w C:\Documents and Settings\Omistaja\Application Data\Skype
2008-05-06 13:19 --------- d-----w C:\Documents and Settings\Omistaja\Application Data\skypePM
2008-05-04 16:40 --------- d-----w C:\Documents and Settings\Omistaja\Application Data\LimeWire
2008-05-01 13:22 --------- d-----w C:\Program Files\EA GAMES
2008-04-26 12:21 --------- d-----w C:\Program Files\Maxis
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
2008-02-17 17:36 21,769,888 ----a-w C:\Documents and Settings\sanrox\Nokia_PC_Suite_6_84_10_3_fin_web.exe
2008-01-06 13:29 0 ----a-w C:\Documents and Settings\Omistaja\Application Data\wklnhst.dat
2008-01-04 16:11 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((( snapshot@2008-06-15_19.38.52.01 )))))))))))))))))))))))))))))))))))))))))
.
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{387039A9-5C4B-432A-B7D7-915460856985}]
C:\WINDOWS\system32\qoMcbayW.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-15 15:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-01-04 16:34 171448]
"MsnMsgr"="C:\Documents and Settings\Omistaja\Työpöytä\msnmsgr.exe" [2007-10-18 12:34 5724184]
"WinBejSetup.exe"="C:\DOWNLO~1\WINBEJ~1.exe" [ ]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2007-12-10 11:12 695808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 16:21 61952 C:\WINDOWS\system32\HdAShCut.exe]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-07-19 12:09 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-07-19 12:06 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-07-19 12:10 114688]
"SoundMan"="SOUNDMAN.EXE" [2005-09-21 11:24 86016 C:\WINDOWS\SoundMan.exe]
"AlcWzrd"="ALCWZRD.EXE" [2005-09-21 16:32 2807808 C:\WINDOWS\alcwzrd.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-04-15 09:48 708697]
"Norman ZANDA"="C:\Program Files\Norman\Npm\bin\ZLH.exe" [2007-08-09 15:40 183352]
"SMSERIAL"="sm56hlpr.exe" [2005-08-12 12:09 552960 C:\WINDOWS\sm56hlpr.exe]
"Creative WebCam Tray"="C:\Program Files\Creative\Shared Files\CAMTRAY.EXE" [2003-06-26 04:02 184320]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album
Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 12:09 63712]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"Windows svchost"="service.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-15 15:00 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 18:35 1294336]
C:\Documents and Settings\All Users\K„ynnist„-valikko\Ohjelmat\K„ynnistys\
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2008-01-04 16:46:47 184320]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqRLDwwV]
rqRLDwwV.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Nexon\\MapleStory\\MapleStory.exe"=
"C:\\Program Files\\Activision\\Rome - Total War\\RomeTW.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 Ndiskio;Ndiskio;C:\Program Files\Norman\Nse\bin\NDISKIO.SYS [2007-01-02 11:55]
R3 NvcMFlt;NvcMFlt;C:\WINDOWS\system32\DRIVERS\nvcw32mf.sys [2008-02-11 15:56]
R3 nvcoas;Norman Virus Control on-access component;C:\Program Files\Norman\Nvc\bin\nvcoas.exe [2007-12-12 12:45]
R3 NVCScheduler;Norman Virus Control Scheduler;C:\Program Files\Norman\Nvc\BIN\NVCSCHED.EXE [2007-05-23 14:23]
S3 EraserUtilDrv10741;EraserUtilDrv10741;C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10741.sys []
.
'Ajoitetut tehtävät'-kansion sisältö
"2008-03-24 06:48:22 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-06 15:26:51 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2008-06-15 16:40:00 C:\WINDOWS\Tasks\Tarkistetaan Windows Live -työkalurivin päivitykset.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by
Gmer,
http://www.gmer.net
Rootkit scan 2008-06-15 19:43:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-15 19:45:05
ComboFix-quarantined-files.txt 2008-06-15 16:44:22
Pre-Run: 95,534,538,752 tavua vapaana
Post-Run: 95,526,080,512 tavua vapaana
186 --- E O F --- 2008-05-28 07:17:22