ComboFix 08-07-04.6 - Toni 2008-07-05 22:57:34.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1035.18.207 [GMT 3:00]
Running from: C:\Documents and Settings\Toni\Työpöytä\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
(((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Käynnistä-valikko\Ohjelmat\Käynnistys\.protected
C:\Documents and Settings\Toni\Application Data\rhcp2rj0e79p
C:\Documents and Settings\Toni\Käynnistä-valikko\Ohjelmat\Antivirus 2008 PRO
C:\Documents and Settings\Toni\Käynnistä-valikko\Ohjelmat\Antivirus 2008 PRO\antivirus-2008pro.lnk
C:\Documents and Settings\Toni\Käynnistä-valikko\Ohjelmat\Käynnistys\.protected
C:\Program Files\rhcp2rj0e79p
C:\WINDOWS\efbq.exe
C:\WINDOWS\gxvpsafm.dll
C:\WINDOWS\resources\AlrtDrv.dll
C:\WINDOWS\resources\SrvcVolume.dll
C:\WINDOWS\system32\931928
C:\WINDOWS\system32\931928\931928.dll
C:\WINDOWS\system32\auaytpok.ini
C:\WINDOWS\system32\cBsqppqn.dll
C:\WINDOWS\system32\cbXnonKe.dll
C:\WINDOWS\system32\config\systemprofile\Työpöytä\SystemDefender.lnk
C:\WINDOWS\system32\foigitin.dll
C:\WINDOWS\system32\kpfptxts.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\nqppqsBc.ini
C:\WINDOWS\system32\nqppqsBc.ini2
C:\WINDOWS\system32\pphct2rj0e79p.exe
C:\WINDOWS\system32\xggelkhs.ini
C:\WINDOWS\system32\yramfvao.ini
.
((((( Tiedostot, jotka on luotu seuraavalla aikav„lill„: 2008-06-05 to 2008-07-05 )))))))))))))))))
.
2008-07-05 22:07 . 2008-07-05 22:45 88,576 --------- C:\WINDOWS\system32\koptyaua.dll
2008-07-05 21:52 . 2008-07-05 22:45 88,576 --------- C:\WINDOWS\system32\shkleggx.dll
2008-07-05 21:47 . 2008-07-05 21:47 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-05 21:47 . 2008-07-05 21:47 <KANSIO> d-------- C:\Documents and Settings\Toni\Application Data\Malwarebytes
2008-07-05 21:47 . 2008-07-05 21:47 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-05 21:47 . 2008-06-28 14:16 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-07-05 21:47 . 2008-06-28 14:16 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-05 21:19 . 2008-07-05 21:19 <KANSIO> d-------- C:\Program Files\Trend Micro
2008-07-04 23:40 . 2008-07-04 23:40 <KANSIO> d-------- C:\Program Files\Lavasoft
2008-07-04 23:40 . 2008-07-04 23:43 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-04 23:39 . 2008-07-04 23:39 <KANSIO> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-04 22:29 . 2008-07-04 22:29 <KANSIO> d-------- C:\Program Files\Alwil Software
2008-06-30 05:48 . 2008-07-05 22:45 94,208 --a------ C:\WINDOWS\system32\42.tmp
2008-06-30 05:43 . 2008-06-30 05:43 138,752 --a------ C:\tmp1660931.dll
2008-06-30 05:43 . 2008-06-30 05:43 0 --a------ C:\system.dbf
2008-06-11 23:06 . 2008-06-14 20:59 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-14 17:59 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-30 16:04 --------- d-----w C:\Program Files\Nvc
2008-05-30 16:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\NPF
2008-05-30 16:01 5 ----a-w C:\NPF_USER.DAT
2008-05-14 17:45 988 ----a-w C:\Documents and Settings\Toni\Application Data\wklnhst.dat
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-06 06:58 --------- d-----w C:\Documents and Settings\Toni\Application Data\MSN6
.
(((((((((((((((((((((((((((((( Rekisterin k„ynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Huom* Tyhji„ arvoja ja laillisia oletusarvoja ei n„ytet„
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-15 02:12 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiS Windows KeyHook"="C:\WINDOWS\System32\keyhook.exe" [2004-09-02 14:44 249856]
"SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [2002-07-12 19:15 106496]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-11-11 12:37 32881]
"EPSON Stylus C46 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE" [2004-01-14 05:00 99840]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"EPSON Stylus C46 Series (Kopioi 1)"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE" [2004-01-14 05:00 99840]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SiSPower"="SiSPower.dll" [2004-09-02 14:47 49152 C:\WINDOWS\system32\SiSPower.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-09-15 02:12 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16]
R3 CONAN;CONAN;C:\WINDOWS\system32\drivers\o2mmb.sys [2004-02-12 02:18]
R3 MbxStby;MbxStby;C:\WINDOWS\system32\drivers\MbxStby.sys [2004-01-28 00:00]
R3 PRISM_A00;PRISM 802.11 Driver;C:\WINDOWS\system32\DRIVERS\PRISMA00.sys [2004-07-20 21:16]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{476fd160-0fc4-11dd-ae61-00030d1d557c}]
\Shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{476fd163-0fc4-11dd-ae61-00030d1d557c}]
\Shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c032160f-1ddd-11dd-ae6e-00030d1d557c}]
\Shell\AutoRun\command - E:\AutoRun.exe
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-updateMgr - C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKLM-Run-SMrhcp2rj0e79p - C:\Program Files\rhcp2rj0e79p\rhcp2rj0e79p.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by
Gmer,
http://www.gmer.net
Rootkit scan 2008-07-05 23:03:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\sistray.exe
.
**************************************************************************
.
Completion time: 2008-07-05 23:08:04 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-05 20:07:58
Pre-Run: 16,446,038,016 tavua vapaana
Post-Run: 16,609,914,880 tavua vapaana
128 --- E O F --- 2008-06-22 08:00:46