1. Tämä sivusto käyttää keksejä (cookie). Jatkamalla sivuston käyttämistä hyväksyt keksien käyttämisen. Lue lisää.

Windows XP:n automaattiset päivitykset eivät mene päälle? HJT

Viestiketju Virukset ja haittaohjelmat - HijackThis -logit -osiossa. Ketjun avasi Aksutus 14.07.2008.

  1. Aksutus

    Aksutus Member

    Liittynyt:
    14.07.2008
    Viestejä:
    19
    Kiitokset:
    0
    Pisteet:
    11
    Eli Windowsissa ei mene automaattiset päivitykset millään päälle. Mitä pitäisi tehdä?



    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:08:32, on 14.7.2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\WINDOWS\System32\wdfmgr.exe
    C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
    C:\Program Files\Nero\Nero 7\InCD\InCD.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\DAEMON Tools Lite\daemon.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\uTorrent\uTorrent.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\PROGRA~1\Mozilla Firefox\firefox.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Program Files\Winamp\winamp.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\Restore\rstrui.exe
    C:\Program Files\WinRAR\WinRAR.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\WINDOWS\System32\wbem\wmiprvse.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
    O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
    O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Microgaming\Poker\nordicbetMPP\MPPoker.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1205586996587
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1205587045665
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Application Driver Auto Removal Service (01) (appdrvrem01) - Protection Technology - C:\WINDOWS\System32\appdrvrem01.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

    --
    End of file - 7753 bytes
     
  2.  
  3. Aksutus

    Aksutus Member

    Liittynyt:
    14.07.2008
    Viestejä:
    19
    Kiitokset:
    0
    Pisteet:
    11
    Tein vielä tuon testin.


    Malwarebytes' Anti-Malware 1.20
    Tietokantaversio: 948
    Windows 5.1.2600 Service Pack 3

    9:05:15 14.7.2008
    mbam-log-7-14-2008 (09-05-15).txt

    Tarkistustyyppi: Täysi tarkistus (C:\|D:\|E:\|)
    Tarkistetut kohteet: 112589
    Kulunut aika: 34 minute(s), 38 second(s)

    Saastuneita muistiprosesseja: 0
    Saastuneita muistimoduuleja: 0
    Saastuneita rekisteriavaimia: 0
    Saastuneita rekisteriarvoja: 0
    Saastuneita rekisterikohteita: 0
    Saastuneita hakemistoja: 0
    Saastuneita tiedostoja: 0

    Saastuneita muistiprosesseja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita muistimoduuleja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita rekisteriavaimia:
    (Haitallisia kohteita ei löydetty)

    Saastuneita rekisteriarvoja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita rekisterikohteita:
    (Haitallisia kohteita ei löydetty)

    Saastuneita hakemistoja:
    (Haitallisia kohteita ei löydetty)

    Saastuneita tiedostoja:
    (Haitallisia kohteita ei löydetty)
     
  4. Aksutus

    Aksutus Member

    Liittynyt:
    14.07.2008
    Viestejä:
    19
    Kiitokset:
    0
    Pisteet:
    11
    Combofix testi:


    ComboFix 08-07-11.1 - Aksu 2008-07-14 11:17:06.2 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1035.18.1350 [GMT 3:00]
    Running from: C:\Documents and Settings\Aksu\Työpöytä\ComboFix.exe

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .
    The following files were disabled during the run:
    C:\Program Files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll


    ((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-06-14 to 2008-07-14 )))))))))))))))))
    .

    2008-07-14 08:21 . 2008-07-14 08:21 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-07-14 08:21 . 2008-07-14 08:21 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-07-14 08:21 . 2008-07-14 08:21 <KANSIO> d-------- C:\Documents and Settings\Aksu\Application Data\Malwarebytes
    2008-07-14 08:21 . 2008-07-07 17:35 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
    2008-07-14 08:21 . 2008-07-07 17:35 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
    2008-07-14 08:08 . 2008-07-14 08:08 <KANSIO> d-------- C:\Program Files\Trend Micro
    2008-07-14 07:58 . 2008-07-14 07:58 <KANSIO> d-------- C:\Program Files\Enigma Software Group
    2008-07-12 13:24 . 2008-04-14 08:45 2,957,312 -----c--- C:\WINDOWS\system32\dllcache\wmploc.dll
    2008-07-12 13:23 . 2008-04-13 11:40 10,240 --------- C:\WINDOWS\system32\drivers\sffp_mmc.sys
    2008-07-12 13:22 . 2006-12-28 12:01 19,569 --a------ C:\WINDOWS\005367_.tmp
    2008-07-12 12:11 . 2008-07-12 12:11 <KANSIO> d-------- C:\Program Files\CCleaner
    2008-07-12 12:10 . 2008-07-12 12:10 <KANSIO> d-------- C:\Program Files\SUPERAntiSpyware
    2008-07-12 12:10 . 2008-07-12 12:10 <KANSIO> d-------- C:\Program Files\Common Files\Wise Installation Wizard
    2008-07-12 12:10 . 2008-07-12 12:10 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
    2008-07-12 12:10 . 2008-07-12 12:10 <KANSIO> d-------- C:\Documents and Settings\Aksu\Application Data\SUPERAntiSpyware.com
    2008-07-07 19:37 . 2008-07-07 19:37 3,468,904 --a------ C:\WINDOWS\system32\drivers\appdrv01.sys
    2008-07-07 19:37 . 2008-07-07 19:37 304,528 --a------ C:\WINDOWS\system32\appdrvrem01.exe
    2008-07-07 16:38 . 2008-07-07 17:54 <KANSIO> d-------- C:\Documents and Settings\Aksu\Application Data\Pro Cycling Manager 2008
    2008-07-07 16:37 . 2008-07-10 13:16 <KANSIO> d-------- C:\Program Files\Cyanide
    2008-06-18 23:24 . 2008-06-18 23:24 38 --a------ C:\WINDOWS\avisplitter.INI
    2008-06-18 16:09 . 2008-06-18 16:09 1,024 --a------ C:\.rnd
    2008-06-17 16:57 . 2008-06-17 16:57 <KANSIO> d-------- C:\WINDOWS\Hell's Kitchen
    2008-06-17 16:57 . 2008-07-03 08:58 <KANSIO> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
    2008-06-17 16:57 . 2008-06-17 16:57 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Ludia
    2008-06-17 16:57 . 2008-06-17 16:57 <KANSIO> d-------- C:\Documents and Settings\Aksu\Application Data\Ludia
    2008-06-16 00:55 . 2008-04-14 18:59 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
    2008-06-16 00:55 . 2008-05-08 17:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys

    .
    (((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-07-14 08:17 --------- d-----w C:\Documents and Settings\Aksu\Application Data\uTorrent
    2008-07-12 09:29 --------- d-----w C:\Program Files\DAEMON Tools Lite
    2008-07-12 08:04 --------- d-----w C:\Program Files\Winamp
    2008-07-12 08:04 --------- d-----w C:\Documents and Settings\Aksu\Application Data\Winamp
    2008-06-29 19:12 --------- d-----w C:\Documents and Settings\Aksu\Application Data\dvdcss
    2008-06-06 08:43 413,696 ----a-w C:\WINDOWS\system32\wrap_oal.dll
    2008-06-06 08:43 110,592 ----a-w C:\WINDOWS\system32\OpenAL32.dll
    2008-06-06 08:43 --------- d-----w C:\Program Files\OpenAL
    2008-06-06 07:55 --------- d-----w C:\Documents and Settings\Aksu\Application Data\Microgaming
    2008-05-26 19:46 --------- d-----w C:\Documents and Settings\Aksu\Application Data\Skype
    2008-05-26 18:56 --------- d-----w C:\Documents and Settings\Aksu\Application Data\skypePM
    2008-05-20 18:50 --------- d-----w C:\Program Files\Skype
    2008-05-20 17:57 --------- d-----w C:\Program Files\Common Files\Skype
    2008-05-20 17:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
    2008-05-20 16:31 --------- d-----w C:\Documents and Settings\Aksu\Application Data\Media Player Classic
    2008-05-20 09:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\ATI
    2008-05-20 07:41 --------- d-----w C:\Program Files\ATI Technologies
    2008-05-20 06:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-05-19 20:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Trymedia
    2008-05-14 19:59 --------- d-----w C:\Program Files\K-Lite Codec Pack
    2008-05-07 05:12 1,288,704 ----a-w C:\WINDOWS\system32\quartz.dll
    2008-04-23 06:46 21,840 ----a-w C:\WINDOWS\system32\SIntfNT.dll
    2008-04-23 06:46 17,212 ----a-w C:\WINDOWS\system32\SIntf32.dll
    2008-04-23 06:46 12,067 ----a-w C:\WINDOWS\system32\SIntf16.dll
    2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
    2008-04-14 06:27 1,804 ----a-w C:\WINDOWS\system32\dcache.bin
    2008-04-14 06:15 331,264 ----a-w C:\WINDOWS\system32\netsetup.exe
    2008-04-14 06:13 92,424 ----a-w C:\WINDOWS\system32\rdpdd.dll
    2008-04-14 06:13 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll
    2008-04-14 06:13 12,168 ----a-w C:\WINDOWS\system32\tsddd.dll
    2008-04-14 06:11 997,888 ----a-w C:\WINDOWS\system32\msgina.dll
    2008-04-14 06:10 9,344 ----a-w C:\WINDOWS\system32\framebuf.dll
    2008-04-14 06:09 3,072 ----a-w C:\WINDOWS\system32\dpnlobby.dll
    2008-04-14 06:09 3,072 ----a-w C:\WINDOWS\system32\dpnaddr.dll
    2008-04-14 06:09 285,696 ----a-w C:\WINDOWS\system32\atmfd.dll
    2008-04-14 06:09 16,896 ----a-w C:\WINDOWS\system32\cfgmgr32.dll
    2008-04-14 05:49 2,147,840 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
    2008-04-14 05:49 2,026,496 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
    2008-04-14 05:48 4,096 ----a-w C:\WINDOWS\system32\dsprpres.dll
    2008-04-14 05:46 79,872 ------w C:\WINDOWS\system32\msxml6r.dll
    2008-04-14 05:45 80,384 ------w C:\WINDOWS\system32\msshavmsg.dll
    2008-04-14 05:45 2,957,312 ----a-w C:\WINDOWS\system32\wmploc.dll
    2008-04-14 05:44 48,640 ----a-w C:\WINDOWS\system32\inetres.dll
    2008-04-14 05:43 556,032 ----a-w C:\WINDOWS\system32\shdoclc.dll
    2008-04-14 05:42 171,520 ------w C:\WINDOWS\system32\wmerror.dll
    2008-04-14 05:41 9,728 ----a-w C:\WINDOWS\system32\gpkrsrc.dll
    2008-04-14 05:41 1,845,888 ----a-w C:\WINDOWS\system32\win32k.sys
    2008-04-14 05:40 65,536 ----a-w C:\WINDOWS\system32\browselc.dll
    2008-04-14 05:38 7,680 ----a-w C:\WINDOWS\system32\asferror.dll
    2008-04-14 05:38 103,424 ----a-w C:\WINDOWS\system32\dpcdll.dll
    .

    ((((((((((((((((((((((((((((( snapshot@2008-07-12_14.23.21.70 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2008-07-12 11:20:45 2,048 --s-a-w C:\WINDOWS\bootstat.dat
    + 2008-07-14 04:19:45 2,048 --s-a-w C:\WINDOWS\bootstat.dat
    + 2006-09-11 08:56:00 526,184 ------w C:\WINDOWS\system32\XceedCry.dll
    + 2006-12-21 12:18:00 497,496 ------w C:\WINDOWS\system32\XceedZip.dll
    + 2008-07-14 04:19:50 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_594.dat
    .
    (((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 09:12 15360]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 20:03 152872]
    "DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-03-14 14:55 486856]
    "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
    "uTorrent"="C:\Program Files\uTorrent\uTorrent.exe" [2008-03-15 16:52 219952]
    "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 16:57 153136]
    "SecurDisc"="C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe" [2007-06-25 09:47 1629480]
    "InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [2007-06-25 09:47 1057064]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
    "GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
    "StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 12:17 61440]
    "RTHDCPL"="RTHDCPL.EXE" [2007-01-30 13:54 16116224 C:\WINDOWS\RTHDCPL.exe]
    "SkyTel"="SkyTel.EXE" [2006-05-16 13:04 2879488 C:\WINDOWS\SkyTel.exe]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 09:12 15360]

    C:\Documents and Settings\All Users\K„ynnist„-valikko\Ohjelmat\K„ynnistys\
    ZDWLan Utility.lnk - C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe [2008-03-15 14:45:14 487424]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "msacm.avis"= ff_acm.acm
    "VIDC.YV12"= yv12vfw.dll

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\Messenger\\msmsgs.exe"=
    "C:\\Program Files\\uTorrent\\uTorrent.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
    "C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
    "C:\\WINDOWS\\system32\\dpvsetup.exe"=
    "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "D:\\Pelit\\Pro Cycling Manager - Season 2008\\PCM.exe"=
    "D:\\Pelit\\Pro Cycling Manager - Season 2008\\Autorun\\Exe\\Autorun.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "C:\\WINDOWS\\system32\\usmt\\migwiz.exe"=

    R1 appdrv01;Application Driver (01);C:\WINDOWS\system32\Drivers\appdrv01.sys [2008-07-07 19:37]
    R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20]
    R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16]
    R3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2006-08-24 14:44]
    S2 appdrvrem01;Application Driver Auto Removal Service (01);C:\WINDOWS\System32\appdrvrem01.exe svc []
    S3 BRGSp50;BRGSp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\BRGSp50.sys [2005-06-08 19:44]

    *Newly Created Service* - CATCHME
    *Newly Created Service* - EAPHOST
    *Newly Created Service* - MCHINJDRV

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    "C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
    .
    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-07-14 11:17:57
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    PROCESS: C:\WINDOWS\system32\winlogon.exe
    -> C:\Program Files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll

    PROCESS: C:\WINDOWS\system32\lsass.exe
    -> C:\Program Files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
    .
    Completion time: 2008-07-14 11:18:29
    ComboFix-quarantined-files.txt 2008-07-14 08:18:19
    ComboFix2.txt 2008-07-12 11:24:26

    Pre-Run: 8,544,968,704 tavua vapaana
    Post-Run: 8,533,495,808 tavua vapaana

    179 --- E O F --- 2008-06-16 00:13:08

     
  5. Aksutus

    Aksutus Member

    Liittynyt:
    14.07.2008
    Viestejä:
    19
    Kiitokset:
    0
    Pisteet:
    11
    Voiko joku auttaa?
     

Jaa tämä sivu