joo ok sorry tässä tää uudestaa......ComboFix 08-06-20.4 - kubla 2008-06-23 23:54:20.2 - NTFSx86
Running from: C:\Documents and Settings\kubla\Työpöytä\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-23 to 2008-06-23 )))))))))))))))))
.
2008-06-19 15:35 . 2008-06-19 16:43 <KANSIO> d-------- C:\Documents and Settings\kubla\Application Data\U3
2008-06-18 01:51 . 2008-06-18 01:51 <KANSIO> d-------- C:\Program Files\Trend Micro
2008-06-18 00:34 . 2008-06-18 00:34 <KANSIO> d-------- C:\Documents and Settings\kubla\Application Data\Malwarebytes
2008-06-18 00:34 . 2008-06-18 00:34 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-18 00:34 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-18 00:34 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-18 00:33 . 2008-06-18 00:34 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-17 23:01 . 2008-06-17 23:01 <KANSIO> d-------- C:\Program Files\ZoneAlarmSB
2008-06-17 23:00 . 2008-06-18 00:03 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-06-17 22:59 . 2008-06-17 22:59 <KANSIO> d-------- C:\Program Files\Zone Labs
2008-06-17 22:59 . 2004-04-27 05:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2008-06-17 22:59 . 2008-06-18 00:01 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-06-17 22:58 . 2008-06-18 00:43 <KANSIO> d-------- C:\WINDOWS\Internet Logs
2008-06-16 20:55 . 2008-06-16 20:55 <KANSIO> d-------- C:\Documents and Settings\kubla\Application Data\Ludia
2008-06-16 20:55 . 2008-06-16 20:55 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Ludia
2008-06-16 20:54 . 2008-06-16 20:54 <KANSIO> d-------- C:\WINDOWS\Hell's Kitchen
2008-06-16 20:54 . 2008-06-16 20:54 <KANSIO> d-------- C:\Program Files\Hell's Kitchen
2008-06-16 20:54 . 2008-06-18 02:26 <KANSIO> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-15 00:37 . 2008-06-15 00:37 <KANSIO> d-------- C:\Program Files\Microsoft Silverlight
2008-06-15 00:36 . 2008-06-15 00:36 <KANSIO> d-------- C:\Program Files\Windows Media Connect 2
2008-06-15 00:33 . 2008-06-22 23:16 <KANSIO> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-06-15 00:05 . 2008-06-15 00:05 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-06-14 23:55 . 2008-04-14 19:11 221,184 --a------ C:\WINDOWS\system32\setb0.tmp
2008-06-14 23:46 . 2008-06-14 23:46 <KANSIO> d-------- C:\WINDOWS\system32\fi
2008-06-14 23:46 . 2008-06-14 23:46 <KANSIO> d-------- C:\WINDOWS\system32\bits
2008-06-14 23:46 . 2008-06-14 23:46 <KANSIO> d-------- C:\WINDOWS\l2schemas
2008-06-14 23:29 . 2006-11-15 11:00 1,671,680 -----c--- C:\WINDOWS\system32\dllcache\setup_wm.exe
2008-06-14 23:28 . 2008-04-14 19:11 651,264 --------- C:\WINDOWS\system32\dot3ui.dll
2008-06-13 17:23 . 2008-06-13 17:23 0 --a------ C:\WINDOWS\tosOBEX.INI
2008-06-13 17:17 . 2008-06-13 17:18 <KANSIO> d-------- C:\Documents and Settings\kubla\Application Data\TOSHIBA
2008-06-13 17:12 . 2006-11-30 19:55 113,792 --a------ C:\WINDOWS\system32\drivers\tosrfbd.sys
2008-06-13 17:12 . 2006-10-05 16:07 73,600 --a------ C:\WINDOWS\system32\drivers\Tosrfhid.sys
2008-06-13 17:12 . 2006-11-22 16:09 53,504 --a------ C:\WINDOWS\system32\drivers\TosRfSnd.sys
2008-06-13 17:12 . 2006-10-28 00:29 40,960 --a------ C:\WINDOWS\system32\drivers\tosrfusb.sys
2008-06-13 17:12 . 2006-11-20 17:55 36,480 --a------ C:\WINDOWS\system32\drivers\tosrfbnp.sys
2008-06-13 17:12 . 2005-01-06 13:42 18,612 --a------ C:\WINDOWS\system32\drivers\tosrfnds.sys
2008-06-13 17:11 . 2008-06-13 17:11 <KANSIO> d-------- C:\Program Files\Toshiba
2008-06-13 17:11 . 2005-08-01 16:45 64,896 --a------ C:\WINDOWS\system32\drivers\tosrfcom.sys
2008-06-13 17:11 . 2006-10-10 19:33 41,600 --a------ C:\WINDOWS\system32\drivers\tosporte.sys
2008-06-13 17:08 . 2008-04-14 19:12 152,064 --a------ C:\WINDOWS\system32\irftp.exe
2008-06-13 17:08 . 2008-04-14 19:11 27,648 --a------ C:\WINDOWS\system32\irmon.dll
2008-06-13 17:08 . 2008-04-14 19:11 8,192 --a------ C:\WINDOWS\system32\wshirda.dll
2008-06-12 00:03 . 2008-06-12 00:03 <KANSIO> d-------- C:\Program Files\SATVOD
2008-06-12 00:03 . 2008-06-12 00:03 <KANSIO> d-------- C:\Documents and Settings\kubla\Application Data\MoviesApp
2008-06-11 21:57 . 2008-06-11 22:00 <KANSIO> d-------- C:\Documents and Settings\muut urpot\Application Data\Winamp
2008-06-11 21:56 . 2008-01-24 21:30 <KANSIO> d--h----- C:\Documents and Settings\muut urpot\Verkkoympäristö
2008-06-11 21:56 . 2008-01-24 21:30 <KANSIO> d-------- C:\Documents and Settings\muut urpot\Työpöytä
2008-06-11 21:56 . 2008-01-24 21:30 <KANSIO> d--h----- C:\Documents and Settings\muut urpot\Tulostinympäristö
2008-06-11 21:56 . 2008-06-11 21:56 <KANSIO> dr------- C:\Documents and Settings\muut urpot\Suosikit
2008-06-11 21:56 . 2008-06-11 21:56 <KANSIO> dr------- C:\Documents and Settings\muut urpot\Omat tiedostot
2008-06-11 21:56 . 2008-01-24 21:39 <KANSIO> d--h----- C:\Documents and Settings\muut urpot\Mallit
2008-06-11 21:56 . 2008-01-24 21:30 <KANSIO> dr------- C:\Documents and Settings\muut urpot\Käynnistä-valikko
2008-06-11 21:56 . 2008-06-11 21:56 <KANSIO> d-------- C:\Documents and Settings\muut urpot\Application Data\PC Suite
2008-06-11 21:56 . 2008-06-11 21:56 <KANSIO> d-------- C:\Documents and Settings\muut urpot\Application Data\ATI
2008-06-11 21:56 . 2008-06-11 21:56 <KANSIO> d-------- C:\Documents and Settings\muut urpot
2008-06-11 21:52 . 2008-06-11 21:52 <KANSIO> dr------- C:\Documents and Settings\Vieras\Omat tiedostot
2008-06-11 21:52 . 2008-06-11 21:52 <KANSIO> d-------- C:\Documents and Settings\Vieras\Application Data\ATI
2008-06-11 21:51 . 2008-01-24 21:30 <KANSIO> d--h----- C:\Documents and Settings\Vieras\Verkkoympäristö
2008-06-11 21:51 . 2008-01-24 21:30 <KANSIO> d-------- C:\Documents and Settings\Vieras\Työpöytä
2008-06-11 21:51 . 2008-01-24 21:30 <KANSIO> d--h----- C:\Documents and Settings\Vieras\Tulostinympäristö
2008-06-11 21:51 . 2008-06-11 21:52 <KANSIO> dr------- C:\Documents and Settings\Vieras\Suosikit
2008-06-11 21:51 . 2008-01-24 21:39 <KANSIO> d--h----- C:\Documents and Settings\Vieras\Mallit
2008-06-11 21:51 . 2008-01-24 21:30 <KANSIO> dr------- C:\Documents and Settings\Vieras\Käynnistä-valikko
2008-06-11 21:51 . 2008-06-11 21:51 <KANSIO> d-------- C:\Documents and Settings\Vieras\Application Data\PC Suite
2008-06-11 21:51 . 2008-06-11 21:52 <KANSIO> d-------- C:\Documents and Settings\Vieras
2008-06-11 13:03 . 2008-04-14 18:59 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 13:03 . 2008-05-08 17:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-28 15:28 . 2008-05-28 15:28 <KANSIO> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-05-27 15:56 . 2008-05-27 15:59 <KANSIO> d-------- C:\Program Files\PANZERS - Phase1
2008-05-27 11:22 . 2008-05-27 11:22 4,096 --a------ C:\WINDOWS\system32\crash
2008-05-27 11:11 . 2008-05-27 11:11 <KANSIO> d-------- C:\Documents and Settings\kubla\Application Data\ATI
2008-05-27 11:11 . 2008-05-27 11:11 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\ATI
2008-05-27 10:56 . 2008-05-12 10:49 593,920 --------- C:\WINDOWS\system32\ati2sgag.exe
2008-05-27 10:46 . 2008-04-14 19:11 32,768 --a------ C:\WINDOWS\system32\ativtmxx.dll
2008-05-27 10:45 . 2008-04-14 19:12 23,040 --a------ C:\WINDOWS\system32\ativmvxx.ax
2008-05-27 10:45 . 2008-05-27 10:45 10 --a------ C:\WINDOWS\WININIT.INI
2008-05-27 10:20 . 2008-05-27 10:31 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-05-27 09:28 . 2008-05-27 09:56 <KANSIO> d-------- C:\Program Files\Empire Interactive
2008-05-27 08:53 . 2008-05-27 08:53 <KANSIO> d-------- C:\Program Files\Yamicsoft
2008-05-27 00:07 . 2008-05-27 00:10 <KANSIO> d-------- C:\WINDOWS\system32\XPSViewer
2008-05-27 00:07 . 2008-05-27 00:07 <KANSIO> d-------- C:\Program Files\MSBuild
2008-05-27 00:06 . 2008-05-27 00:06 <KANSIO> d-------- C:\Program Files\Reference Assemblies
2008-05-27 00:06 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-05-27 00:05 . 2008-05-27 00:05 <KANSIO> d-------- C:\Program Files\MSXML 6.0
2008-05-26 12:02 . 2008-05-26 12:02 <KANSIO> d-------- C:\Documents and Settings\kubla\usernotes
2008-05-25 11:44 . 2008-05-25 11:44 <KANSIO> d-------- C:\Program Files\Google
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-23 20:54 --------- d-----w C:\Documents and Settings\kubla\Application Data\uTorrent
2008-06-23 10:08 --------- d-----w C:\Program Files\RevConnect
2008-06-22 20:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-06-17 18:41 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-06-16 08:25 --------- d-----w C:\Program Files\Ubisoft
2008-06-16 08:22 --------- d-----w C:\Program Files\PowerArchiver
2008-06-13 17:11 --------- d-----w C:\Program Files\Pocket Tanks Deluxe
2008-05-30 19:30 --------- d-----w C:\Program Files\SweetIM
2008-05-27 08:09 --------- d-----w C:\Program Files\ATI Technologies
2008-05-22 18:44 --------- d-----w C:\Documents and Settings\kubla\Application Data\PC Suite
2008-05-20 07:15 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-20 07:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-20 07:13 --------- d-----w C:\Program Files\Lavasoft
2008-05-13 18:43 --------- d-----w C:\Program Files\Winamp
2008-05-13 18:43 --------- d-----w C:\Documents and Settings\kubla\Application Data\Winamp
2008-05-12 16:30 3,007,488 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-05-12 15:56 397,312 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-05-12 15:54 305,152 ------w C:\WINDOWS\system32\ati2dvag.dll
2008-05-12 15:53 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2008-05-12 15:45 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2008-05-12 15:45 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-05-12 15:45 180,224 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2008-05-12 15:45 139,264 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2008-05-12 15:44 139,264 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2008-05-12 15:43 540,672 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2008-05-12 15:43 10,153,984 ----a-w C:\WINDOWS\system32\atioglx2.dll
2008-05-12 15:41 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-05-12 15:32 3,203,168 ------w C:\WINDOWS\system32\ati3duag.dll
2008-05-12 15:22 1,999,616 ------w C:\WINDOWS\system32\ativvaxx.dll
2008-05-12 15:09 47,104 ----a-w C:\WINDOWS\system32\amdpcom32.dll
2008-05-12 15:05 5,439,488 ----a-w C:\WINDOWS\system32\atioglxx.dll
2008-05-12 15:05 327,680 ----a-w C:\WINDOWS\system32\atikvmag.dll
2008-05-12 15:03 19,968 ----a-w C:\WINDOWS\system32\atiadlxx.dll
2008-05-12 15:03 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2008-05-12 15:02 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2008-05-12 15:02 241,664 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2008-05-12 14:57 548,864 ------w C:\WINDOWS\system32\ati2cqag.dll
2008-05-12 12:33 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-11 08:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\MGS
2008-05-11 08:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microgaming
2008-05-09 18:03 --------- d-----w C:\Program Files\Any Video Converter
2008-05-08 14:02 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 08:44 --------- d-----w C:\Program Files\ProPilkki2
2008-05-07 05:12 1,288,704 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-06 12:23 --------- d-----w C:\Program Files\IObit
2008-04-29 08:20 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 08:19 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 08:19 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
2008-04-27 12:35 --------- d-----w C:\Documents and Settings\kubla\Application Data\fretsonfire
2008-04-27 12:34 --------- d-----w C:\Program Files\Frets on Fire
2008-04-24 12:46 --------- d-----w C:\Documents and Settings\kubla\Application Data\Nokia Multimedia Player
2008-04-24 12:40 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-04-24 12:40 --------- d-----w C:\Program Files\Common Files\Nokia
2008-04-24 12:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 16:27 1,804 ----a-w C:\WINDOWS\system32\dcache.bin
2008-04-14 16:15 331,264 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 16:11 997,888 ----a-w C:\WINDOWS\system32\msgina.dll
2008-04-14 16:10 9,344 ----a-w C:\WINDOWS\system32\framebuf.dll
2008-04-14 16:09 3,072 ----a-w C:\WINDOWS\system32\dpnlobby.dll
2008-04-14 16:09 3,072 ----a-w C:\WINDOWS\system32\dpnaddr.dll
2008-04-14 16:09 285,696 ----a-w C:\WINDOWS\system32\atmfd.dll
2008-04-14 16:09 24,064 ----a-w C:\WINDOWS\system32\pidgen.dll
2008-04-14 16:09 16,896 ----a-w C:\WINDOWS\system32\cfgmgr32.dll
2008-04-14 15:49 2,147,840 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-14 15:49 2,026,496 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-14 15:48 4,096 ----a-w C:\WINDOWS\system32\dsprpres.dll
2008-04-14 15:46 79,872 ----a-w C:\WINDOWS\system32\msxml6r.dll
2008-04-14 15:45 80,384 ------w C:\WINDOWS\system32\msshavmsg.dll
2008-04-14 15:44 48,640 ----a-w C:\WINDOWS\system32\inetres.dll
2008-04-14 15:43 556,032 ----a-w C:\WINDOWS\system32\shdoclc.dll
2008-04-14 15:41 9,728 ----a-w C:\WINDOWS\system32\gpkrsrc.dll
2008-04-14 15:41 1,845,888 ----a-w C:\WINDOWS\system32\win32k.sys
2008-04-14 15:40 65,536 ----a-w C:\WINDOWS\system32\browselc.dll
2008-04-14 06:12 11,264 ------w C:\WINDOWS\system32\spnpinst.exe
2008-04-14 06:11 992,256 ----a-w C:\WINDOWS\system32\setupapi.dll
2008-04-14 06:11 423,936 ----a-w C:\WINDOWS\system32\licdll.dll
2008-04-13 18:44 17,664 ----a-w C:\WINDOWS\system32\watchdog.sys
2008-04-13 18:43 9,728 ------w C:\WINDOWS\system32\comsdupd.exe
2008-04-13 18:43 12,800 ----a-w C:\WINDOWS\system32\spiisupd.exe
2008-04-13 18:40 440,832 ------w C:\WINDOWS\system32\xpob2res.dll
2008-04-13 18:36 2,921,984 ----a-w C:\WINDOWS\system32\xpsp2res.dll
2008-04-13 18:35 186,368 ----a-w C:\WINDOWS\system32\xpsp1res.dll
2008-04-13 18:31 7,424 ----a-w C:\WINDOWS\system32\kd1394.dll
2008-04-13 18:30 61,440 ----a-w C:\WINDOWS\system32\msvcrt40.dll
2008-04-13 17:37 208,384 ----a-w C:\WINDOWS\system32\rsaenh.dll
2008-04-13 17:37 138,752 ----a-w C:\WINDOWS\system32\dssenh.dll
2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\odbcp32r.dll
2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\mscpx32r.dll
2008-04-13 17:21 733,696 ----a-w C:\WINDOWS\system32\qedwipes.dll
2008-04-13 16:48 1,647,616 ----a-w C:\WINDOWS\system32\winbrand.dll
2008-04-13 16:45 216,064 ----a-w C:\WINDOWS\system32\moricons.dll
2008-04-13 16:23 48,128 ----a-w C:\WINDOWS\system32\msprivs.dll
2008-04-13 15:39 884,736 ----a-w C:\WINDOWS\system32\msimsg.dll
2008-03-31 12:59 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-01-28 20:46 22,328 ----a-w C:\Documents and Settings\kubla\Application Data\PnkBstrK.sys
2004-10-01 13:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((( snapshot@2008-06-23_20.14.04.67 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-23 17:06:52 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-23 17:24:59 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-23 17:25:05 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_6c8.dat
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe" [2008-03-26 18:41 1232896]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2008-04-16 12:53 1079808]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 19:12 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-04-01 21:49 36352]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 18:05 81920]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 12:17 61440]
"BluetoothAuthenticationAgent"="bthprops.cpl,,BluetoothAuthenticationAgent" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 19:12 15360]
C:\Documents and Settings\All Users\K„ynnist„-valikko\Ohjelmat\K„ynnistys\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth
Toshiba Stack\TosBtMng.exe [2007-01-18 14:48:42 2752512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2005-09-08 12:06 94208 C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Comrade.exe]
C:\Program Files\GameSpy\Comrade\Comrade.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-14 19:12 1695232 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 12:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2006-03-18 05:24 184320 C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"PowerBar"="C:\Program Files\CyberLink
DVD Solution\Multimedia Launcher\PowerBar.exe" /AtBootTime
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\RevConnect\\DCPlusPlus.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\EA GAMES\\MOHAA\\moh_Breakthrough.exe"=
"C:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"C:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"C:\\Program Files\\ProPilkki2\\ProPilkki2.exe"=
"C:\\UnrealTournament\\System\\UnrealTournament.exe"=
"D:\\imutukset\\Pocket Tanks Deluxe 1.3\\pockettanks.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\B2BPOKER\\Pokerihuone\\jre\\bin\\javaw.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"D:\\imutukset\\worms\\Worms\\WA.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16]
S3 SetupNTGLM7X;SetupNTGLM7X;E:\NTGLM7X.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{28c382dc-3dfc-11dd-b7ef-00508de72078}]
\Shell\AutoRun\command - H:\LaunchU3.exe -a
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by
Gmer,
http://www.gmer.net
Rootkit scan 2008-06-23 23:58:00
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-24 0:00:18
ComboFix-quarantined-files.txt 2008-06-23 20:59:45
ComboFix2.txt 2008-06-23 17:14:41
Pre-Run: 17,409,376,256 tavua vapaana
Post-Run: 17,393,582,080 tavua vapaana
286 --- E O F --- 2008-06-16 00:00:57