mserviceä ei vieläkään, muut kaksi fixasin
ComboFix 08-06-20.4 - OJ 2008-06-26 18:19:32.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.187 [GMT 3:00]
Running from: C:\Documents and Settings\OJ\Työpöytä\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
(((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
H:\autorun.inf
.
---- Previous Run -------
.
C:\WINDOWS\BM235979bc.xml
C:\WINDOWS\mservice.exe
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\fccccCVl.dll
C:\WINDOWS\system32\gcictxga.dll
C:\WINDOWS\system32\geBuVPjh.dll
C:\WINDOWS\system32\HRqssvut.ini
C:\WINDOWS\system32\HRqssvut.ini2
C:\WINDOWS\system32\ltwmcoow.ini
C:\WINDOWS\system32\mlJcCrOe.dll
C:\WINDOWS\system32\qoMfGVon.dll
C:\WINDOWS\system32\tuvssqRH.dll
C:\WINDOWS\system32\woocmwtl.dll
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-26 to 2008-06-26 )))))))))))))))))
.
2008-06-26 16:29 . 2008-06-26 16:29 0 --a------ C:\WINDOWS\BM235979bc.xml
2008-06-26 15:17 . 2008-06-26 16:54 474 ---hs---- C:\WINDOWS\system32\ltwmcoow.ini
2008-06-26 13:26 . 2008-06-26 13:26 106,496 --a------ C:\WINDOWS\system32\fcsacmvm.dll
2008-06-21 16:01 . 2008-06-21 16:01 <KANSIO> d-------- C:\Program Files\Java
2008-06-21 16:01 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-06-21 15:59 . 2008-06-21 15:59 <KANSIO> d-------- C:\Program Files\Common Files\Java
2008-06-17 13:28 . 2008-06-17 13:29 <KANSIO> d-------- C:\Program Files\Cardroom2
2008-06-16 12:47 . 2008-06-16 12:48 <KANSIO> d-------- C:\Program Files\GameShadow
2008-06-16 12:47 . 2007-04-04 18:55 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll
2008-06-16 12:46 . 2007-01-24 15:27 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll
2008-06-16 12:46 . 2006-12-08 12:02 251,672 --a------ C:\WINDOWS\system32\xactengine2_5.dll
2008-06-16 12:44 . 2008-06-16 12:44 <KANSIO> d-------- C:\Program Files\Eidos
2008-06-13 10:08 . 2008-06-13 10:08 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-06-13 07:05 . 2008-06-14 20:59 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-13 07:05 . 2008-06-14 20:59 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-12 14:46 . 2008-06-12 15:08 1,282 --a------ C:\WINDOWS\system32\tmp.reg
2008-06-12 13:03 . 2008-06-12 13:03 <KANSIO> d-------- C:\Documents and Settings\OJ\Application Data\Malwarebytes
2008-06-12 13:02 . 2008-06-12 13:02 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 13:02 . 2008-06-12 13:02 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 13:02 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 13:02 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-12 02:04 . 2008-06-12 02:04 <KANSIO> d-------- C:\Program Files\Trend Micro
2008-06-08 22:21 . 2008-06-08 22:21 18,587 --a------ C:\Documents and Settings\OJ\packed.exe
2008-06-05 00:15 . 2008-06-05 00:15 290,110 --a------ C:\WINDOWS\ftp.exe
2008-05-30 23:49 . 2008-03-06 21:32 23,904 --a------ C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-05-30 23:49 . 2008-03-06 21:32 10,537 --a------ C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-05-30 23:49 . 2008-03-06 21:32 706 --a------ C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-05-29 23:03 . 2008-05-29 23:03 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\pixelStorm
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-25 09:14 --------- d-----w C:\Documents and Settings\OJ\Application Data\uTorrent
2008-06-24 21:29 --------- d-----w C:\Documents and Settings\OJ\Application Data\LimeWire
2008-06-24 09:19 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-06-22 22:25 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-17 10:28 --------- d-----w C:\Program Files\B2BPOKER
2008-06-09 17:27 --------- d-----w C:\Program Files\mIRC
2008-06-01 23:00 --------- d-----w C:\Program Files\Opera
2008-05-30 20:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-05-30 20:42 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-05-30 20:42 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-05-30 20:42 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-05-30 20:42 10,671 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-05-30 20:42 --------- d-----w C:\Program Files\Symantec
2008-05-28 13:52 --------- d-----w C:\Documents and Settings\OJ\Application Data\OpenOffice.org2
2008-05-24 09:33 --------- d-----w C:\Program Files\Common Files\xing shared
2008-05-24 09:33 --------- d-----w C:\Program Files\Common Files\Real
2008-05-22 13:46 --------- d-----w C:\Program Files\Ubisoft
2008-05-10 17:09 --------- d-----w C:\Program Files\ESBC Moniveto
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:02 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-03-26 20:24 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2006-11-30 21:12 6,144 -csha-w C:\Program Files\Thumbs.db
.
((((((((((((((((((((((((((((( snapshot_2008-06-26_15.28.07.68 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-26 12:14:22 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-26 14:01:53 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8dcfe672-8033-45ac-8acc-d55b670a6072}]
2008-06-26 13:26 106496 --a------ C:\WINDOWS\system32\fcsacmvm.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-14 16:12 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 23:59 115816]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"206a4a20"="C:\WINDOWS\system32\woocmwtl.dll" [ ]
"BM235979bc"="C:\WINDOWS\system32\gcictxga.dll" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-14 16:12 15360]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2006-09-13 16:00 100032]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-11-09 18:15 1634304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"= 1 (0x1)
"AllowUnhashedWebView"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{BE7E4CE1-8CBA-44A6-956F-462A667D3286}"= C:\WINDOWS\system32\geBuVPjh.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.3iv2"= 3ivxVfWCodec.dll
"VIDC.HFYU"=
huffyuv.dll
"VIDC.VP31"= vp31vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
"C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"C:\\Program Files\\Soulseek\\slsk.exe"=
"C:\\Program Files\\Steam\\SteamApps\\a1e183f05652bdbca0e57d93311bbf60\\day of defeat source\\hl2.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"D:\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\Parbet.com Poker\\UA.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"C:\\Program Files\\Empire Interactive\\FlatOut2\\FlatOut2.exe"=
"C:\\Program Files\\B2BPOKER\\Staffpoker\\jre\\bin\\javaw.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"21618:TCP"= 21618:TCP:BitComet 21618 TCP
"21618:UDP"= 21618:UDP:BitComet 21618 UDP
R2 Automaattinen LiveUpdate-ajastustoiminto;Automaattinen LiveUpdate-ajastustoiminto;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2006-09-13 16:00]
R3 SMC55T;SMC EZ Card 10/100 (SMC1255TX-PF);C:\WINDOWS\system32\DRIVERS\SMC55T51.sys [2002-07-05 16:31]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8b217703-933f-11db-93a5-0004e2432a1b}]
\shell\play\Command - "C:\Program Files\Windows Media Player\wmplayer.exe" /prefetch:4 /device:DVD "%L"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9b1e83c2-7d3f-11db-937b-0004e2432a1b}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{28ABC5C0-4FCB-11CF-AAX5-81CX1C635612}]
C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\usb323.exe
.
'Ajoitetut tehtävät'-kansion sisältö
"2008-06-20 17:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Suorita täyd. järj.tarkistus - OJ.job"
- C:\PROGRA~1\NORTON~1\Navw32.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by
Gmer,
http://www.gmer.net
Rootkit scan 2008-06-26 18:24:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-26 18:30:05
ComboFix-quarantined-files.txt 2008-06-26 15:29:23
ComboFix2.txt 2008-06-12 14:42:12
ComboFix3.txt 2008-06-12 11:21:21
ComboFix4.txt 2008-06-12 09:13:58
Pre-Run: 3,404,099,584 tavua vapaana
Post-Run: 3,391,168,512 tavua vapaana
177 --- E O F --- 2008-06-21 00:21:11