Jees. :) ComboFix:
----------------------------------------------------------------------
ComboFix 08-06-20.4 - HP_Omistaja 2008-07-01 0:22:50.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.358.1035.18.202 [GMT 3:00]
Running from: C:\Documents and Settings\HP_Omistaja\Työpöytä\ComboFix.exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\msvrc20.dll
D:\Autorun.inf
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-28 to 2008-06-30 )))))))))))))))))
.
2008-06-30 20:52 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-06-30 20:51 . 2008-06-30 20:51 <KANSIO> d-------- C:\Program Files\Common Files\Java
2008-06-30 16:58 . 2008-06-30 16:58 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-30 16:58 . 2008-06-30 16:58 <KANSIO> d-------- C:\Documents and Settings\HP_Omistaja\Application Data\Malwarebytes
2008-06-30 16:58 . 2008-06-30 16:58 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-30 16:58 . 2008-06-28 14:16 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-30 16:58 . 2008-06-28 14:16 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-30 02:18 . 2008-06-30 02:19 <KANSIO> d-------- C:\Program Files\VST Plug-Ins
2008-06-27 08:36 . 2008-06-27 08:36 <KANSIO> d-------- C:\Program Files\Trend Micro
2008-06-27 08:35 . 2008-06-27 08:35 <KANSIO> d-------- C:\Program Files\hijackthis_v2.0.2
2008-06-27 08:34 . 2008-06-27 08:34 499,568 --a------ C:\Program Files\hijackthis_v2.0.2.zip
2008-06-27 02:12 . 2008-06-27 02:12 <KANSIO> d-------- C:\Program Files\Opera 9
2008-06-18 06:15 . 2008-06-18 06:15 7,330,552 --a------ C:\Program Files\Firefox Setup 3.0.exe
2008-06-17 01:38 . 2008-06-17 01:40 8,926,832 --a------ C:\Program Files\Opera_950_in_Setup.exe
2008-06-11 00:55 . 2008-06-14 20:59 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 00:55 . 2008-06-14 20:59 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-03 05:55 . 2008-06-03 05:55 <KANSIO> d-------- C:\Program Files\hjsplit_v2.3
2008-06-03 05:54 . 2008-06-03 05:54 304,957 --a------ C:\Program Files\hjsplit_v2.3.zip
2008-05-11 04:15 . 2008-06-22 20:15 6,553,344 --a------ C:\Program Files\AWCSetup.exe
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-30 19:16 --------- d-----w C:\Documents and Settings\HP_Omistaja\Application Data\uTorrent
2008-06-30 17:52 --------- d-----w C:\Program Files\Java
2008-06-29 23:06 571,339 ----a-w C:\Program Files\mgTriggerGate_v0.17_vst.rar
2008-06-29 18:26 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-29 16:28 --------- d-----w C:\Program Files\Ad-Aware SE Professional
2008-06-27 04:47 --------- d-----w C:\Documents and Settings\HP_Omistaja\Application Data\MegauploadToolbar
2008-06-25 02:53 --------- d-----w C:\Program Files\rpg2003
2008-06-24 20:19 --------- d-----w C:\Program Files\LDC++
2008-06-12 11:27 120,848 ----a-w C:\Documents and Settings\HP_Omistaja\Application Data\GDIPFONTCACHEV1.DAT
2008-06-11 21:02 --------- d-----w C:\Program Files\BSPlayer
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:15 1,288,192 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
2008-04-29 00:38 --------- d-----w C:\Program Files\Goldwave
2008-04-17 10:52 18,432 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\dllcache\mswstr10.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\dllcache\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
2008-02-13 08:44 22,974,393 ----a-w C:\Program Files\Inkscape-0.45.1-1.win32.exe
2008-01-31 12:25 6,270,357 ----a-w C:\Program Files\AWCSetup.rar
2007-12-05 08:21 1,919,432 ----a-w C:\Program Files\daemon410-x86.exe
2007-11-21 17:29 3,499,729 ----a-w C:\Program Files\ffdshow_rev610_20061201_clsid.exe
2007-11-20 15:26 6,585,000 ----a-w C:\Program Files\Opera_9.24_International_Setup.exe
2007-11-19 14:34 4,669,596 ----a-w C:\Program Files\Ace Utilities.rar
2007-11-19 14:17 17,167,872 ----a-w C:\Program Files\Install_WLMessenger.msi
2007-11-18 22:13 1,043,036 ----a-w C:\Program Files\PowerISO38.exe
2007-10-27 17:07 824,476 ----a-w C:\Program Files\pkrinstall.exe
2007-10-03 19:38 1,164,456 ----a-w C:\Program Files\install_flash_player.exe
2007-09-03 20:12 6,498,440 ----a-w C:\Program Files\Opera_9.23_International_Setup.exe
2007-08-29 14:07 2,820,423 ----a-w C:\Program Files\COLDownloadManager-Windows.exe
2007-08-11 11:34 9,197 ----a-w C:\Program Files\Z-Windows98Patch.zip
2007-08-11 11:34 825,469 ----a-w C:\Program Files\ZDemoPart4-Windows.zip
2007-08-11 11:34 1,173,528 ----a-w C:\Program Files\ZDemoPart2.zip
2007-08-11 11:34 1,095,923 ----a-w C:\Program Files\ZDemoPart3.zip
2007-08-11 11:33 1,553,363 ----a-w C:\Program Files\ZDemoPart1-English.zip
2007-07-30 14:48 12,767,609 ----a-w C:\Program Files\Z (1996)(Bitmap Brothers).zip
2007-07-26 21:22 13,858,056 ----a-w C:\Program Files\RealPlayer11BETA.exe
2007-07-02 19:10 208,897 ----a-w C:\Program Files\NetInstallPAFPoker.exe
2007-04-29 08:09 17,176,744 ----a-w C:\Program Files\antivir_workstation_win7u_en_h.exe
2007-03-07 16:57 6,718,976 ----a-w C:\Program Files\winamp533_full_emusic-7plus.exe
2007-03-04 10:10 173,730 ----a-w C:\Program Files\Sidplay2.exe
2007-03-02 17:45 86,115,351 ----a-w C:\Program Files\Dofus.exe
2007-02-21 00:03 13,444,614 ----a-w C:\Program Files\quicktimealt177.exe
2007-02-20 23:58 8,991,852 ----a-w C:\Program Files\QuickTimeInstaller.exe
2007-02-07 21:22 345,049 ----a-w C:\Program Files\Copy of toaster.exe1
2007-02-07 18:27 6,653,000 ----a-w C:\Program Files\winamp532_full_emusic-7plus.exe
2007-01-16 16:11 5,083,078 ----a-w C:\Program Files\pokerihuonesetup.exe
2007-01-14 15:42 251,656 ----a-w C:\Program Files\jre-1_5_0_10-windows-i586-p-iftw.exe
2006-11-01 10:59 3,483,338 ----a-w C:\Program Files\ffdshow_rev420_2006-10-20.zip
2006-09-17 11:57 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2006-08-08 14:43 663,398 ----a-w C:\Program Files\General-CleanTool.zip
2006-07-11 17:17 8,661,936 ----a-w C:\Program Files\winamp524_full_bundle_emusic-7plus.exe
2006-06-09 12:35 3,039,776 ----a-w C:\Program Files\SFTPMSI.exe
2006-06-04 22:59 520,350 ----a-w C:\Program Files\SAmp320.exe
2006-06-04 15:28 2,726,712 ----a-w C:\Program Files\LastfmWindows-1.1.4.exe
2006-06-04 15:26 159,122 ----a-w C:\Program Files\audioscrobbler.wa.1.1.10.exe
2006-03-14 22:12 291,911 ----a-w C:\Program Files\ft209.zip
2006-03-05 14:07 510,696 ----a-w C:\Program Files\GenuineCheck.exe
2006-02-24 14:59 1,351,680 ----a-w C:\Program Files\mirc617.exe
2006-02-14 21:07 4,831,717 ----a-w C:\Program Files\Renoise1_5_2_Demo.exe
2006-02-01 21:52 1,535,035 ----a-w C:\Program Files\regclean_cic.exe
2006-01-12 17:48 419,592 ----a-w C:\Program Files\CleanSetup.exe
2005-11-28 19:57 11,817,800 ----a-w C:\Program Files\GoogleEarthSetup.exe
2005-11-24 19:10 733,501 ----a-w C:\Program Files\SetupEasyCleaner.exe
2005-11-21 16:13 196,065 ----a-w C:\Program Files\wa5_coloreditor_2_0_2.exe
2005-11-16 22:55 3,821,411 ----a-w C:\Program Files\ow32fifi850.exe
2005-11-16 22:50 4,096 ----a-w C:\Documents and Settings\HP_Omistaja\log.dat
2005-11-13 18:32 2,668,740 ----a-w C:\Program Files\LastfmWindows-1.0.4.exe
2005-10-28 16:36 7,855,104 ----a-w C:\Program Files\avwinsfx.exe
2007-04-01 14:05 56 --sh--r C:\WINDOWS\system32\99E29121A6.sys
2007-04-01 14:05 3,766 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 12:55 5674352]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-15 15:00 15360]
"SuperCleaner"="C:\Program Files\Super Cleaner\SuperCleaner.exe" [2006-10-31 20:24 565248]
"NCLaunch"="C:\WINDOWS\NCLAUNCH.EXe" [2005-12-24 15:30 40960]
"STYLEXP"="C:\Program Files\TGTSoft\StyleXP\StyleXP.exe" [2006-05-24 21:31 1372160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 19:04 52736]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-07-20 21:07 7110656]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 20:06 88363 C:\WINDOWS\AGRSMMSG.exe]
"HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [2004-06-07 22:29 659456]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 22:02 61440]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-10-14 00:04 278528]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 23:43 233472]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-15 00:54 253952]
"Reminder"="C:\Windows\Creator\Remind_XP.exe" [2004-12-14 02:23 663552]
"CamMonitor"="C:\Program Files\HP\Digital Imaging\\Unload\hpqcmon.exe" [2002-10-07 00:23 90112]
"Share-to-Web Namespace Daemon"="C:\Program Files\HP\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 10:42 69632]
"F-Secure Manager"="C:\Program Files\F-Secure\Common\FSM32.EXE" [2004-09-09 12:03 118832]
"F-Secure TNB"="C:\Program Files\F-Secure\TNB\TNBUtil.exe" [2004-05-27 11:57 684032]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 17:32 221184]
C:\WINDOWS\system32\config\systemprofile\K„ynnist„-valikko\Ohjelmat\K„ynnistys\
AutoTBar.exe [2003-09-30 22:30:04 57344]
C:\WINDOWS\system32\config\systemprofile\K„ynnist„-valikko\Ohjelmat\K„ynnistys\
AutoTBar.exe [2003-09-30 22:30:04 57344]
C:\Documents and Settings\All Users\K„ynnist„-valikko\Ohjelmat\K„ynnistys\
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2005-01-01 20:56:49 114688]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.xvid"=
xvid.dll
"vidc.X264"= x264vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\F-Secure\\BackWeb\\7681197\\program\\F-Secure Automatic Update.exe"=
"C:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe"=
"C:\\Program Files\\LDC++\\LDCPlusPlus.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
R0 FSFW;F-Secure Firewall Driver;C:\WINDOWS\system32\drivers\fsdfw.sys [2004-11-10 15:58]
R2 BackWeb Plug-in - 7681197;F-Secure Automatic Update;C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE [2005-10-29 15:30]
R2 F-Secure Filter;F-Secure File System Filter;C:\Program Files\F-Secure\Anti-Virus\Win2K\FSfilter.sys [2004-09-10 19:14]
R2 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\F-Secure\Anti-Virus\Win2K\FSgk.sys [2004-09-10 19:14]
R2 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\F-Secure\Anti-Virus\Win2K\FSrec.sys [2003-02-06 15:32]
R3 PRISM_A00;Wireless PCI 802.11b/g adapter WN4201B Driver;C:\WINDOWS\system32\DRIVERS\PCTELSAP.SYS [2004-11-30 21:54]
S3 k600bus;Sony Ericsson 600i driver (WDM);C:\WINDOWS\system32\DRIVERS\k600bus.sys [2005-05-11 14:12]
S3 k600mdfl;Sony Ericsson 600i
USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k600mdfl.sys [2005-05-11 14:12]
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\k600mdm.sys [2005-05-11 14:12]
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\k600mgmt.sys [2005-05-11 14:12]
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\k600obex.sys [2005-05-11 14:12]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{648f6965-ff1a-11dc-b1cf-00110908de3d}]
\Shell\AutoRun\command - K:\AutoTransfer.exe
*Newly Created Service* - CATCHME
.
'Ajoitetut tehtävät'-kansion sisältö
"2008-06-30 16:05:02 C:\WINDOWS\Tasks\WebReg .job"
- C:\Program Files\HP\Digital Imaging\Bin\hpqwrg.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by
Gmer,
http://www.gmer.net
Rootkit scan 2008-07-01 00:27:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-01 0:38:59
ComboFix-quarantined-files.txt 2008-06-30 21:38:38
Pre-Run: 2,412,322,816 tavua vapaana
Post-Run: 2,419,716,096 tavua vapaana
210 --- E O F --- 2008-06-20 12:26:34