Tässä on combon loki:
ComboFix 08-06-16.5 - Admin 2008-06-18 19:02:08.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1035.18.271 [GMT 3:00]
Running from: C:\Documents and Settings\Admin\Työpöytä\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
(((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\ezibifope.reg
C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\niwym.ban
C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\xewicepyhi.vbs
C:\WINDOWS\g32.txt
C:\WINDOWS\system32\sn.txt
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASPIMGR
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-18 to 2008-06-18 )))))))))))))))))
.
2023-04-03 16:06 . 2023-04-03 16:06 135,168 --a------ C:\WINDOWS\system32\vbSendMail.dll
2008-06-18 17:31 . 2008-06-18 17:31 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-18 17:31 . 2008-06-18 17:31 <KANSIO> d-------- C:\Documents and Settings\Järjestelmänvalvoja\Application Data\Malwarebytes
2008-06-18 17:31 . 2008-06-18 17:31 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-18 17:31 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-18 17:31 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-18 16:52 . 2008-06-18 16:52 <KANSIO> d-------- C:\Program Files\SpywareGuard
2008-06-18 16:42 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-06-18 16:42 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-06-18 16:42 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-06-18 16:42 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-06-18 16:42 . 2008-06-15 15:28 81,920 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-06-18 16:42 . 2008-05-23 18:21 81,920 --a------ C:\WINDOWS\system32\404Fix.exe
2008-06-18 16:42 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-06-18 16:42 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-06-18 16:42 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-06-18 15:23 . 2008-06-18 15:23 <KANSIO> d-------- C:\backups
2008-06-18 15:20 . 2008-06-18 15:20 <KANSIO> d-------- C:\Documents and Settings\Järjestelmänvalvoja\temp
2008-06-18 15:20 . 2008-06-18 15:20 <KANSIO> d-------- C:\Documents and Settings\Järjestelmänvalvoja\temp
2008-06-18 15:20 . 2008-06-18 15:20 <KANSIO> d-------- C:\Documents and Settings\Järjestelmänvalvoja\Application Data\TeamViewer
2008-06-18 15:20 . 2008-06-18 13:28 396,288 --a------ C:\esan_kikka.exe
2008-06-18 15:05 . 2008-06-18 15:05 <KANSIO> d-------- C:\Program Files\SUPERAntiSpyware
2008-06-18 15:05 . 2008-06-18 15:05 <KANSIO> d-------- C:\Documents and Settings\Admin\Application Data\SUPERAntiSpyware.com
2008-06-18 14:58 . 2008-06-18 14:58 <KANSIO> d-------- C:\WINDOWS\system32\fi
2008-06-18 14:58 . 2008-06-18 14:58 <KANSIO> d-------- C:\WINDOWS\system32\bits
2008-06-18 14:58 . 2008-06-18 14:58 <KANSIO> d-------- C:\WINDOWS\l2schemas
2008-06-18 14:56 . 2008-06-18 14:56 <KANSIO> d-------- C:\WINDOWS\ServicePackFiles
2008-06-18 12:32 . 2004-07-17 22:55 129,045 --------- C:\WINDOWS\system32\drivers\cxthsfs2.cty
2008-06-18 12:11 . 2008-06-18 12:11 <KANSIO> d-------- C:\Program Files\Trend Micro
2008-06-18 12:11 . 2008-06-18 12:05 812,344 --a------ C:\HJTInstall.exe
2008-06-18 12:06 . 2008-06-18 12:06 <KANSIO> d-------- C:\Documents and Settings\Admin\temp
2008-06-18 12:06 . 2008-06-18 12:06 <KANSIO> d-------- C:\Documents and Settings\Admin\Application Data\TeamViewer
2008-06-18 12:06 . 2008-06-18 12:01 6,467,096 --a------ C:\SUPERAntiSpyware.exe
2008-06-18 09:24 . 2008-06-18 09:24 19,920 --a------ C:\Documents and Settings\Järjestelmänvalvoja\Application Data\osinyryby.vbs
2008-06-18 09:24 . 2008-06-18 09:24 11,912 --a------ C:\Documents and Settings\All Users\Application Data\soxes.pif
2008-06-18 09:24 . 2008-06-18 09:24 11,650 --a------ C:\Documents and Settings\All Users\Application Data\vurazal.com
2008-06-18 08:40 . 2008-06-18 08:40 19,959 --a------ C:\Documents and Settings\Admin\Application Data\wobalokum.dll
2008-06-18 08:40 . 2008-06-18 08:40 19,302 --a------ C:\WINDOWS\evyvi.bat
2008-06-18 08:40 . 2008-06-18 08:40 19,272 --a------ C:\WINDOWS\system32\owik._dl
2008-06-18 08:40 . 2008-06-18 08:40 17,850 --a------ C:\Program Files\Common Files\ukobaryg.reg
2008-06-18 08:40 . 2008-06-18 08:40 17,504 --a------ C:\WINDOWS\system32\icufovy.dat
2008-06-18 08:40 . 2008-06-18 08:40 17,330 --a------ C:\WINDOWS\okadadir.bat
2008-06-18 08:40 . 2008-06-18 08:40 16,630 --a------ C:\WINDOWS\kijawax.pif
2008-06-18 08:40 . 2008-06-18 08:40 16,329 --a------ C:\WINDOWS\johujikycy.lib
2008-06-18 08:40 . 2008-06-18 08:40 14,898 --a------ C:\WINDOWS\qutuj._sy
2008-06-18 08:40 . 2008-06-18 08:40 12,899 --a------ C:\Documents and Settings\All Users\Application Data\zaqeguker.com
2008-06-18 08:40 . 2008-06-18 08:40 12,134 --a------ C:\WINDOWS\obysocu.com
2008-06-18 08:40 . 2008-06-18 08:40 10,464 --a------ C:\WINDOWS\qiqoni.pif
2008-06-18 08:40 . 2008-06-18 08:40 10,068 --a------ C:\Documents and Settings\All Users\Application Data\welyqeruzy.sys
2008-06-18 08:06 . 2008-06-18 08:14 <KANSIO> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-18 08:02 . 2008-06-18 08:02 <KANSIO> d-------- C:\Program Files\Common Files\Download Manager
2008-06-18 08:02 . 2005-09-23 07:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-06-18 07:47 . 2008-06-18 07:47 19,321 --a------ C:\WINDOWS\system32\vewehyzu.dll
2008-06-18 07:47 . 2008-06-18 07:47 18,524 --a------ C:\WINDOWS\vygenel.bin
2008-06-18 07:47 . 2008-06-18 07:47 18,044 --a------ C:\Documents and Settings\All Users\Application Data\yqody.vbs
2008-06-18 07:47 . 2008-06-18 07:47 16,929 --a------ C:\WINDOWS\tazufyva.reg
2008-06-18 07:47 . 2008-06-18 07:47 16,166 --a------ C:\WINDOWS\xajaj._sy
2008-06-18 07:47 . 2008-06-18 07:47 15,572 --a------ C:\Documents and Settings\Admin\Application Data\tanaqalisy.pif
2008-06-18 07:47 . 2008-06-18 07:47 15,317 --a------ C:\Documents and Settings\Admin\Application Data\gycelav.sys
2008-06-18 07:47 . 2008-06-18 07:47 15,013 --a------ C:\WINDOWS\system32\yquworu.dat
2008-06-18 07:47 . 2008-06-18 07:47 12,703 --a------ C:\WINDOWS\system32\upyqofa.vbs
2008-06-18 07:47 . 2008-06-18 07:47 12,594 --a------ C:\Program Files\Common Files\tolyjerod.reg
2008-06-18 07:47 . 2008-06-18 07:47 11,816 --a------ C:\WINDOWS\ubowixeloc.com
2008-06-18 07:47 . 2008-06-18 07:47 10,563 --a------ C:\Program Files\Common Files\nibo.com
2008-06-18 07:47 . 2008-06-18 07:47 10,555 --a------ C:\Documents and Settings\All Users\Application Data\mybicixena.bin
2008-06-18 07:47 . 2008-06-18 07:47 10,470 --a------ C:\Documents and Settings\All Users\Application Data\osoqelyno.dll
2008-06-12 10:57 . 2008-06-12 10:57 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-06-12 10:57 . 2008-06-12 10:57 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_silabser_01005.Wdf
2008-06-12 10:56 . 2008-06-12 10:56 <KANSIO> d-------- C:\Program Files\Silabs
2008-06-12 10:56 . 2007-11-02 14:40 1,419,232 --a------ C:\WINDOWS\system32\WdfCoinstaller01005.dll
2008-06-12 10:56 . 2007-11-02 14:40 61,440 --a------ C:\WINDOWS\system32\drivers\silabser.sys
2008-06-12 10:56 . 2007-11-02 14:40 17,920 --a------ C:\WINDOWS\system32\drivers\silabenm.sys
2008-06-12 10:54 . 2008-06-12 10:56 <KANSIO> d-------- C:\WINDOWS\system32\Silabs
2008-06-12 10:54 . 2008-06-12 10:54 <KANSIO> d-------- C:\SiLabs
2008-06-11 11:00 . 2008-04-14 18:59 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 11:00 . 2008-04-14 18:59 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 11:00 . 2008-05-08 17:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-06-10 06:50 . 2008-06-18 11:17 65,536 --a------ C:\WINDOWS\system32\msscntr32.exe_
2008-06-06 09:47 . 2008-06-18 16:44 2,998 --a------ C:\WINDOWS\system32\tmp.reg
2008-06-06 09:44 . 2005-11-04 18:04 <KANSIO> d--h----- C:\Documents and Settings\Järjestelmänvalvoja\Verkkoympäristö
2008-06-06 09:44 . 2005-11-04 18:04 <KANSIO> d--h----- C:\Documents and Settings\Järjestelmänvalvoja\Verkkoympäristö
2008-06-06 09:44 . 2008-06-18 17:50 <KANSIO> d-------- C:\Documents and Settings\Järjestelmänvalvoja\Työpöytä
2008-06-06 09:44 . 2008-06-18 17:50 <KANSIO> d-------- C:\Documents and Settings\Järjestelmänvalvoja\Työpöytä
2008-06-06 09:44 . 2005-11-04 18:04 <KANSIO> d--h----- C:\Documents and Settings\Järjestelmänvalvoja\Tulostinympäristö
2008-06-06 09:44 . 2005-11-04 18:04 <KANSIO> d--h----- C:\Documents and Settings\Järjestelmänvalvoja\Tulostinympäristö
2008-06-06 09:44 . 2005-11-04 18:04 <KANSIO> d-------- C:\Documents and Settings\Järjestelmänvalvoja\Suosikit
2008-06-06 09:44 . 2005-11-04 18:04 <KANSIO> d-------- C:\Documents and Settings\Järjestelmänvalvoja\Suosikit
2008-06-06 09:44 . 2005-11-04 16:10 <KANSIO> d--h----- C:\Documents and Settings\Järjestelmänvalvoja\Mallit
2008-06-06 09:44 . 2005-11-04 16:10 <KANSIO> d--h----- C:\Documents and Settings\Järjestelmänvalvoja\Mallit
2008-06-06 09:44 . 2005-11-04 18:04 <KANSIO> dr------- C:\Documents and Settings\Järjestelmänvalvoja\Käynnistä-valikko
2008-06-06 09:44 . 2005-11-04 18:04 <KANSIO> dr------- C:\Documents and Settings\Järjestelmänvalvoja\Käynnistä-valikko
2008-06-06 09:44 . 2008-06-18 16:41 <KANSIO> d-------- C:\Documents and Settings\Järjestelmänvalvoja
2008-06-06 09:10 . 2008-06-06 09:10 <KANSIO> d-------- C:\Program Files\Enigma Software Group
2008-06-04 17:50 . 2008-06-04 17:50 <KANSIO> d-------- C:\Program Files\Lavasoft
2008-06-04 17:50 . 2008-06-04 17:50 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-04 17:49 . 2008-06-18 15:04 <KANSIO> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-04 17:35 . 2008-06-04 17:35 <KANSIO> d-------- C:\Program Files\RealVNC
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-18 08:53 --------- d-----w C:\Program Files\AutoFuturPro
2008-06-18 06:24 19,766 ----a-w C:\WINDOWS\iladuqaho.pif
2008-06-18 06:24 18,546 ----a-w C:\WINDOWS\system32\ydybuca.sys
2008-06-18 06:24 17,928 ----a-w C:\WINDOWS\system32\oxedibek.sys
2008-06-18 06:24 17,896 ----a-w C:\WINDOWS\fuko.bin
2008-06-18 06:24 16,561 ----a-w C:\Program Files\Common Files\idyrujyq._sy
2008-06-18 06:24 13,644 ----a-w C:\WINDOWS\qilexoman.exe
2008-06-18 06:24 12,934 ----a-w C:\WINDOWS\nyjobaxybu.sys
2008-06-18 06:24 11,650 ----a-w C:\Documents and Settings\All Users\Application Data\vurazal.com
2008-06-18 05:40 10,154 ----a-w C:\Program Files\Common Files\cysyrowydy.ban
2008-06-18 04:47 11,630 ----a-w C:\Program Files\Common Files\tycopeneke._dl
2008-06-12 07:54 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-08 14:02 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:12 1,288,704 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-21 07:46 --------- d-----w C:\Documents and Settings\Admin\Application Data\U3
2008-04-14 16:27 1,804 ----a-w C:\WINDOWS\system32\dcache.bin
2008-04-14 16:15 331,264 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 16:11 997,888 ----a-w C:\WINDOWS\system32\msgina.dll
2008-04-14 16:10 9,344 ----a-w C:\WINDOWS\system32\framebuf.dll
2008-04-14 16:09 3,072 ----a-w C:\WINDOWS\system32\dpnlobby.dll
2008-04-14 16:09 3,072 ----a-w C:\WINDOWS\system32\dpnaddr.dll
2008-04-14 16:09 285,696 ----a-w C:\WINDOWS\system32\atmfd.dll
2008-04-14 16:09 16,896 ----a-w C:\WINDOWS\system32\cfgmgr32.dll
2008-04-14 15:49 2,147,840 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-14 15:49 2,026,496 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-14 15:48 4,096 ----a-w C:\WINDOWS\system32\dsprpres.dll
2008-04-14 15:46 79,872 ----a-w C:\WINDOWS\system32\msxml6r.dll
2008-04-14 15:45 80,384 ------w C:\WINDOWS\system32\msshavmsg.dll
2008-04-14 15:44 48,640 ----a-w C:\WINDOWS\system32\inetres.dll
2008-04-14 15:43 556,032 ----a-w C:\WINDOWS\system32\shdoclc.dll
2008-04-14 15:41 9,728 ----a-w C:\WINDOWS\system32\gpkrsrc.dll
2008-04-14 15:41 1,845,888 ----a-w C:\WINDOWS\system32\win32k.sys
2008-04-14 15:40 65,536 ----a-w C:\WINDOWS\system32\browselc.dll
2008-04-14 06:12 11,264 ----a-w C:\WINDOWS\system32\spnpinst.exe
2008-04-14 06:11 992,256 ----a-w C:\WINDOWS\system32\setupapi.dll
2008-04-14 06:11 423,936 ----a-w C:\WINDOWS\system32\licdll.dll
2008-04-13 18:44 17,664 ----a-w C:\WINDOWS\system32\watchdog.sys
2008-04-13 18:43 9,728 ------w C:\WINDOWS\system32\comsdupd.exe
2008-04-13 18:43 12,800 ----a-w C:\WINDOWS\system32\spiisupd.exe
2008-04-13 18:40 440,832 ----a-w C:\WINDOWS\system32\xpob2res.dll
2008-04-13 18:36 2,921,984 ----a-w C:\WINDOWS\system32\xpsp2res.dll
2008-04-13 18:35 186,368 ----a-w C:\WINDOWS\system32\xpsp1res.dll
2008-04-13 18:31 7,424 ----a-w C:\WINDOWS\system32\kd1394.dll
2008-04-13 18:30 61,440 ----a-w C:\WINDOWS\system32\msvcrt40.dll
2008-04-13 17:37 208,384 ----a-w C:\WINDOWS\system32\rsaenh.dll
2008-04-13 17:37 138,752 ----a-w C:\WINDOWS\system32\dssenh.dll
2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\odbcp32r.dll
2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\mscpx32r.dll
2008-04-13 17:21 733,696 ----a-w C:\WINDOWS\system32\qedwipes.dll
2008-04-13 16:48 1,647,616 ----a-w C:\WINDOWS\system32\winbrand.dll
2008-04-13 16:45 216,064 ----a-w C:\WINDOWS\system32\moricons.dll
2008-04-13 16:23 48,128 ----a-w C:\WINDOWS\system32\msprivs.dll
2008-04-13 15:39 884,736 ----a-w C:\WINDOWS\system32\msimsg.dll
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2007-12-21 08:31 20 ---h--w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
2007-12-21 08:31 20 ---h--w C:\Documents and Settings\All Users\Application Data\PKP_DLds.DAT
2007-10-04 07:48 2,437,456 ----a-w C:\WINDOWS\inf\SET3B.tmp
2005-03-31 20:17 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 19:12 15360]
"H/PC Connection Agent"="C:\PROGRA~1\MICROS~2\wcescomm.exe" [2005-11-15 22:38 1200128]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-15 11:40 204288]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-06 19:23 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 18:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-05-03 13:43 90112 C:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2005-05-04 05:01 2805248 C:\WINDOWS\ALCWZRD.EXE]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-02-15 09:28 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-02-15 09:28 118784]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 14:03 36975]
"RemoteControl"="C:\Program Files\CyberLink
DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-08 18:35 32768]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-01-13 16:19 180269]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-07-10 10:31 282624]
"KTSInit"="C:\Programme\Bosch\ESItronic\KTS500\ph_test.exe" [2006-08-04 09:17 1081856]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"WinVNC"="C:\Program Files\RealVNC\WinVNC\WinVNC.exe" [2003-03-05 13:49 335872]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 19:12 15360]
C:\Documents and Settings\J„rjestelm„nvalvoja\K„ynnist„-valikko\Ohjelmat\K„ynnistys\
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 19:05:35 360448]
C:\Documents and Settings\Admin\K„ynnist„-valikko\Ohjelmat\K„ynnistys\
Bosch-diagnoosiohjelmisto.lnk - C:\BOSCH_PR\RBTSKMAN\RBTSKMAN.EXE [2008-03-07 12:33:34 585232]
C:\Documents and Settings\All Users\K„ynnist„-valikko\Ohjelmat\K„ynnistys\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 20:05:56 65588]
NkbMonitor.exe.lnk - C:\Program Files\Nikon\PictureProject\NkbMonitor.exe [2007-06-01 09:12:28 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 10:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\AutoFuturPro\\AutoFuturPro.exe"=
"C:\\Program Files\\AutoFuturPro\\noudahin.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R2 autod;autod;C:\WINDOWS\system32\Autoserv.exe [2007-10-09 19:11]
R2 cis1284;cis1284;C:\WINDOWS\system32\drivers\cis1284.sys [2002-01-21 13:03]
R3 silabenm;Silicon Labs CP210x
USB to UART Bridge Serial Port Enumerator Driver;C:\WINDOWS\system32\DRIVERS\silabenm.sys [2007-11-02 14:40]
R3 silabser;Silicon Labs CP210x USB to UART Bridge Driver;C:\WINDOWS\system32\DRIVERS\silabser.sys [2007-11-02 14:40]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL \Explore_this_CD\index.htm
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3ae1cc79-4d43-11da-8d21-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by
Gmer,
http://www.gmer.net
Rootkit scan 2008-06-18 19:04:10
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-18 19:07:19
ComboFix-quarantined-files.txt 2008-06-18 16:07:16
Pre-Run: 17,408,958,464 tavua vapaana
Post-Run: 17,394,511,872 tavua vapaana
260 --- E O F --- 2008-06-13 19:00:41