Combo Fix.n ajo raportti

Discussion in 'Virukset ja haittaohjelmat' started by pesix, Feb 1, 2010.

Thread Status:
Not open for further replies.
  1. pesix

    pesix Guest

    Voisko joku tsekata onko kaikki ok.

    ComboFix 10-01-31.06 - pasi 01.02.2010 19:03:13.7.2 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.358.1035.18.895.399 [GMT 2:00]
    Sijainti: c:\documents and settings\pasi\Työpöytä\ComboFix.exe
    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    .

    (((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Thumbs.db

    .
    ((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2010-01-01 to 2010-02-01 )))))))))))))))))
    .

    2010-01-26 17:27 . 2010-01-18 16:20 1260800 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
    2010-01-26 17:27 . 2010-01-18 16:20 3777280 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
    2010-01-12 12:07 . 2010-01-12 12:07 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\The_Pirate_Bay
    2010-01-12 12:07 . 2010-01-12 12:07 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
    2010-01-09 21:56 . 2010-01-09 21:57 -------- d-----w- c:\program files\QuickTime
    2010-01-09 21:56 . 2010-01-09 21:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
    2010-01-09 21:56 . 2010-01-09 21:56 -------- d-----w- c:\program files\Common Files\Apple
    2010-01-09 21:56 . 2010-01-09 21:56 -------- d-----w- c:\documents and settings\pasi\Local Settings\Application Data\Apple
    2010-01-09 21:56 . 2010-01-09 21:56 -------- d-----w- c:\program files\Apple Software Update
    2010-01-09 21:56 . 2010-01-09 21:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
    2010-01-09 21:55 . 2010-01-09 21:55 -------- d-----w- c:\documents and settings\pasi\Local Settings\Application Data\Apple Computer
    2010-01-07 21:17 . 2010-01-07 21:17 1924200 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player.exe
    2010-01-07 21:17 . 2010-01-08 15:59 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
    2010-01-03 11:46 . 2010-01-31 13:44 -------- d-----w- c:\documents and settings\pasi\Tracing
    2010-01-03 11:43 . 2010-01-03 11:43 -------- d-----w- c:\program files\Microsoft
    2010-01-03 11:43 . 2010-01-03 11:43 -------- d-----w- c:\program files\Windows Live SkyDrive

    .
    (((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-02-01 17:08 . 2008-05-08 09:06 -------- d-----w- c:\documents and settings\pasi\Application Data\DNA
    2010-02-01 16:41 . 2010-02-01 16:41 0 ----a-w- c:\documents and settings\pasi\MobilityManager.tmp
    2010-02-01 16:38 . 2008-05-08 09:06 -------- d-----w- c:\program files\DNA
    2010-01-31 21:37 . 2009-08-27 18:38 -------- d-----w- c:\documents and settings\pasi\Application Data\BitTorrent
    2010-01-30 20:07 . 2009-05-16 17:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
    2010-01-07 15:26 . 2009-11-14 17:41 -------- d-----w- c:\documents and settings\pasi\Application Data\Image Zone Express
    2010-01-03 11:44 . 2008-07-31 19:14 -------- d-----w- c:\program files\Windows Live
    2010-01-02 14:07 . 2010-01-02 14:07 -------- d-----w- c:\program files\Common Files\PCSuite
    2010-01-02 14:06 . 2010-01-02 14:06 -------- d-----w- c:\program files\Common Files\Nokia
    2010-01-02 14:06 . 2009-05-16 17:24 -------- d-----w- c:\program files\Nokia
    2010-01-02 14:06 . 2008-05-11 17:43 -------- d-----w- c:\documents and settings\pasi\Application Data\Nokia
    2010-01-02 14:05 . 2010-01-02 14:05 -------- d-----w- c:\program files\PC Connectivity Solution
    2010-01-02 14:00 . 2010-01-02 14:00 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\pcswpcsi.exe
    2010-01-02 14:00 . 2010-01-02 14:00 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstCCD.exe
    2010-01-02 14:00 . 2010-01-02 14:00 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
    2010-01-02 14:00 . 2010-01-02 14:00 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstPCS.exe
    2010-01-02 13:59 . 2010-01-02 14:02 34473536 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Nokia_PC_Suite_7_1_40_1_fin.exe
    2010-01-01 15:35 . 2010-01-01 15:35 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA
    2010-01-01 15:33 . 2010-01-01 15:33 -------- d-----w- c:\program files\CPUID
    2009-12-30 18:52 . 2009-12-30 17:18 -------- d-----w- c:\program files\Speccy
    2009-12-21 19:08 . 2008-05-07 18:46 916480 ----a-w- c:\windows\system32\wininet.dll
    2009-12-20 12:33 . 2009-11-03 20:41 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
    2009-12-20 10:36 . 2009-12-20 10:36 -------- d-----w- c:\program files\AusLogics Disk Defrag
    2009-12-19 23:10 . 2009-12-19 23:10 413696 ----a-w- c:\windows\system32\wrap_oal.dll
    2009-12-19 23:10 . 2009-12-19 23:10 110592 ----a-w- c:\windows\system32\OpenAL32.dll
    2009-12-19 23:10 . 2009-12-19 23:10 -------- d-----w- c:\program files\OpenAL
    2009-12-18 19:49 . 2009-12-18 19:38 -------- d-----w- c:\documents and settings\pasi\Application Data\SecondLife
    2009-12-18 19:38 . 2009-12-18 19:37 -------- d-----w- c:\program files\SecondLife
    2009-12-17 21:55 . 2009-12-17 21:55 -------- d-----w- c:\program files\directx
    2009-12-17 21:54 . 2009-12-17 21:54 0 ----a-w- c:\windows\DXT8E.tmp
    2009-12-17 21:54 . 2009-12-17 21:54 0 ----a-w- c:\windows\DXT8D.tmp
    2009-12-17 21:54 . 2009-12-17 21:54 0 ----a-w- c:\windows\DXT8C.tmp
    2009-12-17 21:54 . 2009-12-17 21:54 0 ----a-w- c:\windows\DXT8B.tmp
    2009-12-17 21:54 . 2009-12-17 21:54 0 ----a-w- c:\windows\DXT8A.tmp
    2009-12-17 21:54 . 2009-12-17 21:54 0 ----a-w- c:\windows\DXT89.tmp
    2009-12-17 21:54 . 2009-12-17 21:54 0 ----a-w- c:\windows\DXT88.tmp
    2009-12-17 15:53 . 2001-10-09 12:00 86038 ----a-w- c:\windows\system32\perfc00B.dat
    2009-12-17 15:53 . 2001-10-09 12:00 418658 ----a-w- c:\windows\system32\perfh00B.dat
    2009-11-21 15:58 . 2008-05-07 18:47 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
    2009-11-14 17:38 . 2009-11-14 17:10 127982 ----a-w- c:\windows\hpoins09.dat
    2009-11-09 17:42 . 2009-11-03 20:42 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
    2009-11-04 15:30 . 2009-11-04 15:30 152576 ----a-w- c:\documents and settings\pasi\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
    2009-11-03 20:42 . 2009-11-03 20:42 12464 ----a-w- c:\windows\system32\avgrsstx.dll
    2009-11-03 20:42 . 2009-11-03 20:42 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2009-11-03 20:41 . 2009-11-03 20:41 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
    .

    ((((((((((((((((((((((((((((( SnapShot_2009-12-24_20.24.51 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2010-02-01 16:37 . 2010-02-01 16:37 16384 c:\windows\temp\Perflib_Perfdata_70c.dat
    + 2009-07-26 14:44 . 2009-07-26 14:44 48448 c:\windows\system32\sirenacm.dll
    + 2008-05-11 17:35 . 2009-10-06 09:52 91136 c:\windows\system32\nmwcdcls.dll
    - 2008-05-11 17:35 . 2009-02-09 05:37 91136 c:\windows\system32\nmwcdcls.dll
    - 2007-08-13 15:54 . 2009-10-29 07:43 55296 c:\windows\system32\msfeedsbs.dll
    + 2007-08-13 15:54 . 2009-12-21 19:08 55296 c:\windows\system32\msfeedsbs.dll
    + 2010-01-07 21:17 . 2010-01-07 21:17 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
    - 2009-02-11 08:03 . 2009-10-29 07:43 25600 c:\windows\system32\jsproxy.dll
    + 2009-02-11 08:03 . 2009-12-21 19:08 25600 c:\windows\system32\jsproxy.dll
    + 2001-10-09 12:00 . 2009-10-15 16:32 81920 c:\windows\system32\fontsub.dll
    - 2001-10-09 12:00 . 2009-06-16 14:39 81920 c:\windows\system32\fontsub.dll
    - 2009-06-26 20:52 . 2008-08-26 07:26 18816 c:\windows\system32\DRVSTORE\pccsmcfd_A3B3916E5D8138F59EE218321B27B044D3B18294\pccsmcfd.sys
    + 2010-01-02 14:05 . 2008-08-26 07:26 18816 c:\windows\system32\DRVSTORE\pccsmcfd_A3B3916E5D8138F59EE218321B27B044D3B18294\pccsmcfd.sys
    + 2010-01-02 14:04 . 2009-10-06 09:52 22016 c:\windows\system32\DRVSTORE\ccdcmbo_10FA6A921E353BE9BB700451FBD26A6E839F5860\ccdcmbo.sys
    + 2010-01-02 14:04 . 2009-10-06 09:52 91136 c:\windows\system32\DRVSTORE\ccdcmb_10FA6A921E353BE9BB700451FBD26A6E839F5860\nmwcdcls.dll
    + 2010-01-02 14:04 . 2009-10-06 09:52 17664 c:\windows\system32\DRVSTORE\ccdcmb_10FA6A921E353BE9BB700451FBD26A6E839F5860\ccdcmb.sys
    + 2010-01-02 14:05 . 2008-08-26 07:26 18816 c:\windows\system32\drivers\pccsmcfd.sys
    - 2009-06-26 20:52 . 2008-08-26 07:26 18816 c:\windows\system32\drivers\pccsmcfd.sys
    + 2010-01-01 15:33 . 2009-03-26 23:16 12672 c:\windows\system32\drivers\cpuz132_x32.sys
    + 2010-01-02 14:04 . 2009-10-06 09:52 22016 c:\windows\system32\drivers\ccdcmbo.sys
    - 2009-06-26 20:51 . 2009-02-09 05:37 22016 c:\windows\system32\drivers\ccdcmbo.sys
    - 2009-06-26 20:51 . 2009-02-09 05:37 17664 c:\windows\system32\drivers\ccdcmb.sys
    + 2010-01-02 14:04 . 2009-10-06 09:52 17664 c:\windows\system32\drivers\ccdcmb.sys
    + 2009-07-24 13:27 . 2009-12-21 19:08 12800 c:\windows\system32\dllcache\xpshims.dll
    - 2009-07-24 13:27 . 2009-10-29 07:43 12800 c:\windows\system32\dllcache\xpshims.dll
    + 2008-09-28 14:35 . 2009-12-21 19:08 55296 c:\windows\system32\dllcache\msfeedsbs.dll
    - 2008-09-28 14:35 . 2009-10-29 07:43 55296 c:\windows\system32\dllcache\msfeedsbs.dll
    - 2008-02-16 09:02 . 2009-10-29 07:43 25600 c:\windows\system32\dllcache\jsproxy.dll
    + 2008-02-16 09:02 . 2009-12-21 19:08 25600 c:\windows\system32\dllcache\jsproxy.dll
    - 2009-06-16 14:39 . 2009-06-16 14:39 81920 c:\windows\system32\dllcache\fontsub.dll
    + 2009-06-16 14:39 . 2009-10-15 16:32 81920 c:\windows\system32\dllcache\fontsub.dll
    + 2010-01-03 11:43 . 2010-01-03 11:43 27136 c:\windows\Installer\5931d6.msi
    + 2010-01-03 11:42 . 2010-01-03 11:42 83456 c:\windows\Installer\5931be.msi
    + 2010-01-03 11:42 . 2010-01-03 11:42 58880 c:\windows\Installer\5931b8.msi
    + 2010-01-03 11:43 . 2010-01-03 11:43 62304 c:\windows\Installer\{9C87F6BB-75E4-4F35-8353-F5E295264E98}\IconWlc.exe
    + 2010-01-02 14:07 . 2010-01-02 14:07 15086 c:\windows\Installer\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\ARPPRODUCTICON.exe
    + 2010-01-03 11:43 . 2010-01-03 11:43 80395 c:\windows\Installer\{85EB1E72-4FAA-40E4-A511-DF3A9A0A4CA8}\MsblIco.Exe
    + 2010-01-02 14:05 . 2010-01-02 14:05 10134 c:\windows\Installer\{6E0352EE-6F0D-4FBC-B1B8-4FF032C78BE0}\ARPPRODUCTICON.exe
    + 2010-01-09 21:56 . 2010-01-09 21:56 27136 c:\windows\Installer\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}\AppleSoftwareUpdateIco.exe
    + 2010-01-22 15:20 . 2009-10-29 07:43 12800 c:\windows\ie8updates\KB978207-IE8\xpshims.dll
    + 2010-01-22 15:20 . 2009-10-29 07:43 55296 c:\windows\ie8updates\KB978207-IE8\msfeedsbs.dll
    + 2010-01-22 15:20 . 2009-10-29 07:43 25600 c:\windows\ie8updates\KB978207-IE8\jsproxy.dll
    + 2009-12-24 23:11 . 2009-05-26 11:40 26488 c:\windows\$hf_mig$\KB955759\update\spcustom.dll
    + 2009-12-24 23:11 . 2009-05-26 11:40 17272 c:\windows\$hf_mig$\KB955759\spmsg.dll
    + 2010-01-02 14:04 . 2009-10-06 09:56 8320 c:\windows\system32\DRVSTORE\nmwcdnsuc_10FA6A921E353BE9BB700451FBD26A6E839F5860\nmwcdnsuc.sys
    + 2010-01-02 14:04 . 2009-10-06 09:52 7936 c:\windows\system32\DRVSTORE\ccdcmbm_10FA6A921E353BE9BB700451FBD26A6E839F5860\usbser_lowerflt.sys
    + 2010-01-02 14:04 . 2009-10-06 09:52 7936 c:\windows\system32\DRVSTORE\ccdcmbcj_10FA6A921E353BE9BB700451FBD26A6E839F5860\usbser_lowerfltj.sys
    + 2010-01-02 14:04 . 2009-10-06 09:52 7936 c:\windows\system32\drivers\usbser_lowerfltj.sys
    + 2010-01-02 14:04 . 2009-10-06 09:52 7936 c:\windows\system32\drivers\usbser_lowerflt.sys
    + 2010-01-02 14:04 . 2010-01-02 14:04 3262 c:\windows\Installer\{6869591A-7DD8-46D2-837F-57CBF7358955}\ARPPRODUCTICON.exe
    + 2009-07-10 10:52 . 2009-07-10 10:52 307048 c:\windows\WLXPGSS.SCR
    + 2001-10-09 12:00 . 2009-10-15 16:32 119808 c:\windows\system32\t2embed.dll
    - 2001-10-09 12:00 . 2009-06-16 14:39 119808 c:\windows\system32\t2embed.dll
    + 2001-10-09 12:00 . 2009-12-21 19:08 206848 c:\windows\system32\occache.dll
    - 2001-10-09 12:00 . 2009-10-29 07:43 206848 c:\windows\system32\occache.dll
    + 2010-01-02 14:04 . 2009-10-06 09:52 660480 c:\windows\system32\nmwcdcocls.dll
    - 2007-08-13 15:54 . 2009-10-29 07:43 594432 c:\windows\system32\msfeeds.dll
    + 2007-08-13 15:54 . 2009-12-21 19:08 594432 c:\windows\system32\msfeeds.dll
    + 2009-10-28 03:40 . 2009-10-28 03:40 257440 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
    + 2009-11-03 00:24 . 2009-11-03 00:24 257440 c:\windows\system32\Macromed\Flash\FlashUtil10d.exe
    - 2008-05-07 18:46 . 2009-10-29 07:43 184320 c:\windows\system32\iepeers.dll
    + 2008-05-07 18:46 . 2009-12-21 19:08 184320 c:\windows\system32\iepeers.dll
    + 2008-05-07 18:46 . 2009-12-21 19:08 387584 c:\windows\system32\iedkcs32.dll
    - 2008-05-07 18:46 . 2009-10-29 07:43 387584 c:\windows\system32\iedkcs32.dll
    + 2008-05-07 18:46 . 2009-12-21 13:19 173056 c:\windows\system32\ie4uinit.exe
    - 2008-05-07 18:46 . 2009-10-28 14:40 173056 c:\windows\system32\ie4uinit.exe
    - 2009-06-26 20:52 . 2009-05-11 10:30 547840 c:\windows\system32\DRVSTORE\pccswpddri_1C34ED6F4888FC93BE68C7A31A24834F522D3CBF\PCCSWpdDriver.dll
    + 2010-01-02 14:05 . 2009-05-11 10:30 547840 c:\windows\system32\DRVSTORE\pccswpddri_1C34ED6F4888FC93BE68C7A31A24834F522D3CBF\PCCSWpdDriver.dll
    + 2010-01-02 14:04 . 2009-10-06 09:56 136704 c:\windows\system32\DRVSTORE\nmwcdnsu_10FA6A921E353BE9BB700451FBD26A6E839F5860\nmwcdnsu.sys
    + 2010-01-02 14:04 . 2009-10-06 09:52 660480 c:\windows\system32\DRVSTORE\ccdcmb_10FA6A921E353BE9BB700451FBD26A6E839F5860\nmwcdcocls.dll
    + 2008-02-16 09:02 . 2009-12-21 19:08 916480 c:\windows\system32\dllcache\wininet.dll
    - 2008-02-16 09:02 . 2009-10-29 07:43 916480 c:\windows\system32\dllcache\wininet.dll
    + 2009-06-16 14:39 . 2009-10-15 16:32 119808 c:\windows\system32\dllcache\t2embed.dll
    - 2009-06-16 14:39 . 2009-06-16 14:39 119808 c:\windows\system32\dllcache\t2embed.dll
    + 2007-08-13 15:44 . 2009-12-21 19:08 206848 c:\windows\system32\dllcache\occache.dll
    - 2007-08-13 15:44 . 2009-10-29 07:43 206848 c:\windows\system32\dllcache\occache.dll
    - 2008-09-28 14:35 . 2009-10-29 07:43 594432 c:\windows\system32\dllcache\msfeeds.dll
    + 2008-09-28 14:35 . 2009-12-21 19:08 594432 c:\windows\system32\dllcache\msfeeds.dll
    - 2009-07-24 13:27 . 2009-10-29 07:43 246272 c:\windows\system32\dllcache\ieproxy.dll
    + 2009-07-24 13:27 . 2009-12-21 19:08 246272 c:\windows\system32\dllcache\ieproxy.dll
    + 2008-02-16 09:02 . 2009-12-21 19:08 184320 c:\windows\system32\dllcache\iepeers.dll
    - 2008-02-16 09:02 . 2009-10-29 07:43 184320 c:\windows\system32\dllcache\iepeers.dll
    - 2007-08-13 15:39 . 2009-10-29 07:43 387584 c:\windows\system32\dllcache\iedkcs32.dll
    + 2007-08-13 15:39 . 2009-12-21 19:08 387584 c:\windows\system32\dllcache\iedkcs32.dll
    + 2007-08-13 15:39 . 2009-12-21 13:19 173056 c:\windows\system32\dllcache\ie4uinit.exe
    - 2007-08-13 15:39 . 2009-10-28 14:40 173056 c:\windows\system32\dllcache\ie4uinit.exe
    + 2009-12-24 20:36 . 2009-11-21 15:58 471552 c:\windows\system32\dllcache\aclayers.dll
    + 2010-01-02 14:07 . 2010-01-02 14:07 858624 c:\windows\Installer\d3653.msi
    + 2010-01-02 14:05 . 2010-01-02 14:05 496128 c:\windows\Installer\d35b0.msi
    + 2010-01-02 14:04 . 2010-01-02 14:04 331776 c:\windows\Installer\d357a.msi
    + 2010-01-02 14:03 . 2010-01-02 14:03 215552 c:\windows\Installer\d355e.msi
    + 2010-01-03 11:45 . 2010-01-03 11:45 778752 c:\windows\Installer\593218.msi
    + 2010-01-03 11:44 . 2010-01-03 11:44 482816 c:\windows\Installer\5931eb.msi
    + 2010-01-03 11:43 . 2010-01-03 11:43 430080 c:\windows\Installer\5931e5.msi
    + 2010-01-03 11:43 . 2010-01-03 11:43 155648 c:\windows\Installer\5931dc.msi
    + 2010-01-03 11:43 . 2010-01-03 11:43 140288 c:\windows\Installer\5931d0.msi
    + 2010-01-03 11:43 . 2010-01-03 11:43 202752 c:\windows\Installer\5931ca.msi
    + 2010-01-03 11:43 . 2010-01-03 11:43 152576 c:\windows\Installer\5931c4.msi
    + 2010-01-03 11:42 . 2010-01-03 11:42 107008 c:\windows\Installer\5931b2.msi
    + 2010-01-09 21:56 . 2010-01-09 21:56 796672 c:\windows\Installer\2cd9d64.msi
    + 2010-01-03 11:45 . 2010-01-03 11:45 132096 c:\windows\Installer\{AC499BEE-256D-46F5-9B3B-458B65DFDD03}\WLXPhotoGalleryIcon.exe
    + 2010-01-22 15:20 . 2009-10-29 07:43 916480 c:\windows\ie8updates\KB978207-IE8\wininet.dll
    + 2010-01-22 15:20 . 2009-05-26 11:40 392056 c:\windows\ie8updates\KB978207-IE8\spuninst\updspapi.dll
    + 2010-01-22 15:20 . 2008-07-08 13:03 232824 c:\windows\ie8updates\KB978207-IE8\spuninst\spuninst.exe
    + 2010-01-22 15:20 . 2009-10-29 07:43 206848 c:\windows\ie8updates\KB978207-IE8\occache.dll
    + 2010-01-22 15:20 . 2009-10-29 07:43 594432 c:\windows\ie8updates\KB978207-IE8\msfeeds.dll
    + 2010-01-22 15:20 . 2009-10-29 07:43 246272 c:\windows\ie8updates\KB978207-IE8\ieproxy.dll
    + 2010-01-22 15:20 . 2009-10-29 07:43 184320 c:\windows\ie8updates\KB978207-IE8\iepeers.dll
    + 2010-01-22 15:20 . 2009-10-29 07:43 387584 c:\windows\ie8updates\KB978207-IE8\iedkcs32.dll
    + 2010-01-22 15:20 . 2009-10-28 14:40 173056 c:\windows\ie8updates\KB978207-IE8\ie4uinit.exe
    + 2009-12-24 23:11 . 2009-05-26 15:10 392056 c:\windows\$NtUninstallKB955759$\spuninst\updspapi.dll
    + 2009-12-24 23:11 . 2009-05-26 11:40 232824 c:\windows\$NtUninstallKB955759$\spuninst\spuninst.exe
    + 2009-12-24 23:11 . 2008-04-14 16:11 451072 c:\windows\$NtUninstallKB955759$\aclayers.dll
    + 2009-12-24 23:11 . 2009-05-26 15:10 392056 c:\windows\$hf_mig$\KB955759\update\updspapi.dll
    + 2009-12-24 23:11 . 2009-05-26 11:40 757112 c:\windows\$hf_mig$\KB955759\update\update.exe
    + 2009-12-24 23:11 . 2009-05-26 11:40 232824 c:\windows\$hf_mig$\KB955759\spuninst.exe
    + 2009-12-24 20:36 . 2009-11-21 15:46 471552 c:\windows\$hf_mig$\KB955759\SP3QFE\aclayers.dll
    + 2010-01-02 14:04 . 2009-10-06 09:55 1112288 c:\windows\system32\wdfcoinstaller01007.dll
    - 2009-06-26 20:51 . 2009-02-09 05:32 1112288 c:\windows\system32\wdfcoinstaller01007.dll
    + 2008-05-07 18:46 . 2009-12-21 19:08 1208832 c:\windows\system32\urlmon.dll
    - 2008-05-07 18:46 . 2009-10-29 07:43 1208832 c:\windows\system32\urlmon.dll
    + 2008-05-07 18:46 . 2009-12-21 19:08 5942784 c:\windows\system32\mshtml.dll
    + 2009-10-28 03:40 . 2009-10-28 03:40 3885984 c:\windows\system32\Macromed\Flash\NPSWF32.dll
    + 2007-08-13 15:34 . 2009-12-21 19:08 1985536 c:\windows\system32\iertutil.dll
    - 2007-08-13 15:34 . 2009-10-29 07:43 1985536 c:\windows\system32\iertutil.dll
    - 2009-06-26 20:52 . 2009-05-11 09:47 1302600 c:\windows\system32\DRVSTORE\pccswpddri_1C34ED6F4888FC93BE68C7A31A24834F522D3CBF\WUDFUpdate_01007.dll
    + 2010-01-02 14:05 . 2009-05-11 09:47 1302600 c:\windows\system32\DRVSTORE\pccswpddri_1C34ED6F4888FC93BE68C7A31A24834F522D3CBF\WUDFUpdate_01007.dll
    + 2010-01-02 14:04 . 2009-10-06 09:55 1112288 c:\windows\system32\DRVSTORE\ccdcmb_10FA6A921E353BE9BB700451FBD26A6E839F5860\wdfcoinstaller01007.dll
    - 2008-02-16 09:02 . 2009-10-29 07:43 1208832 c:\windows\system32\dllcache\urlmon.dll
    + 2008-02-16 09:02 . 2009-12-21 19:08 1208832 c:\windows\system32\dllcache\urlmon.dll
    + 2008-02-16 22:32 . 2009-12-21 19:08 5942784 c:\windows\system32\dllcache\mshtml.dll
    + 2008-09-28 14:35 . 2009-12-21 19:08 1985536 c:\windows\system32\dllcache\iertutil.dll
    - 2008-09-28 14:35 . 2009-10-29 07:43 1985536 c:\windows\system32\dllcache\iertutil.dll
    + 2010-01-09 21:57 . 2010-01-09 21:57 9473024 c:\windows\Installer\2cd9d68.msi
    + 2010-01-09 21:56 . 2010-01-09 21:56 1549312 c:\windows\Installer\2cd9d5e.msi
    + 2010-01-22 15:20 . 2009-10-29 07:43 1208832 c:\windows\ie8updates\KB978207-IE8\urlmon.dll
    + 2010-01-22 15:20 . 2009-10-29 07:43 5940736 c:\windows\ie8updates\KB978207-IE8\mshtml.dll
    + 2010-01-22 15:20 . 2009-10-29 07:43 1985536 c:\windows\ie8updates\KB978207-IE8\iertutil.dll
    + 2008-05-12 06:12 . 2010-01-05 00:17 29634504 c:\windows\system32\MRT.exe
    + 2007-08-13 15:54 . 2009-12-21 19:08 11070464 c:\windows\system32\ieframe.dll
    + 2008-09-28 14:35 . 2009-12-21 19:08 11070464 c:\windows\system32\dllcache\ieframe.dll
    + 2010-01-22 15:20 . 2009-10-29 07:43 11069952 c:\windows\ie8updates\KB978207-IE8\ieframe.dll
    .
    -- Snapshot nollattu tähän hetkeen --
    .
    (((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{a33fa729-d155-4b23-842b-2c665ecabdb6}"= "c:\program files\The_Pirate_Bay\tbThe0.dll" [2009-11-15 2166296]

    [HKEY_CLASSES_ROOT\clsid\{a33fa729-d155-4b23-842b-2c665ecabdb6}]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a33fa729-d155-4b23-842b-2c665ecabdb6}]
    2009-11-15 21:39 2166296 ----a-w- c:\program files\The_Pirate_Bay\tbThe0.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{a33fa729-d155-4b23-842b-2c665ecabdb6}"= "c:\program files\The_Pirate_Bay\tbThe0.dll" [2009-11-15 2166296]

    [HKEY_CLASSES_ROOT\clsid\{a33fa729-d155-4b23-842b-2c665ecabdb6}]

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{A33FA729-D155-4B23-842B-2C665ECABDB6}"= "c:\program files\The_Pirate_Bay\tbThe0.dll" [2009-11-15 2166296]

    [HKEY_CLASSES_ROOT\clsid\{a33fa729-d155-4b23-842b-2c665ecabdb6}]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 136136]
    "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2007-12-13 1688872]
    "BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-13 323392]
    "PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-11-11 1451520]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2006-10-31 7634944]
    "nwiz"="nwiz.exe" [2006-10-31 1622016]
    "NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2006-10-31 86016]
    "SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
    "PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2007-04-09 200704]
    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
    "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-08-27 185896]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
    "RTHDCPL"="RTHDCPL.EXE" [2006-08-01 16049664]
    "AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-01-01 2033432]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-10 417792]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

    c:\documents and settings\All Users\K„ynnist„-valikko\Ohjelmat\K„ynnistys\
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
    Software Director Scheduler.lnk - c:\program files\Common Files\Cloanto\Software Director\softdir.exe [2009-9-5 289096]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-11-03 20:42 12464 ----a-w- c:\windows\system32\avgrsstx.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Käynnistä-valikko^Ohjelmat^Käynnistys^HP Digital Imaging Monitor.lnk]
    path=c:\documents and settings\All Users\Käynnistä-valikko\Ohjelmat\Käynnistys\HP Digital Imaging Monitor.lnk
    backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Käynnistä-valikko^Ohjelmat^Käynnistys^InterVideo WinCinema Manager.lnk]
    path=c:\documents and settings\All Users\Käynnistä-valikko\Ohjelmat\Käynnistys\InterVideo WinCinema Manager.lnk
    backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Käynnistä-valikko^Ohjelmat^Käynnistys^Microsoft Office.lnk]
    path=c:\documents and settings\All Users\Käynnistä-valikko\Ohjelmat\Käynnistys\Microsoft Office.lnk
    backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Käynnistä-valikko^Ohjelmat^Käynnistys^WinZip Quick Pick.lnk]
    path=c:\documents and settings\All Users\Käynnistä-valikko\Ohjelmat\Käynnistys\WinZip Quick Pick.lnk
    backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
    2008-12-20 05:50 2656528 ----a-w- c:\program files\Logitech\QuickCam\Quickcam.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsgCenterExe]
    2008-08-27 16:53 69632 ----a-w- c:\program files\Common Files\Real\Update_OB\RealOneMessageCenter.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
    2009-04-10 17:29 37888 ----a-w- c:\program files\Winamp\winampa.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\DNA\\btdna.exe"=
    "c:\\Program Files\\DC++\\DCPlusPlus.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\BitTorrent\\bittorrent.exe"=
    "c:\\Program Files\\AC3Filter\\ac3config.exe"=
    "c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
    "c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=

    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3.11.2009 22:42 333192]
    R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3.11.2009 22:42 360584]
    R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [3.11.2009 22:41 285392]
    R2 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [1.1.2010 17:33 12672]
    R2 FMMService;FMMService;c:\progra~1\MOBILI~1\FMMSER~1.EXE [12.6.2009 13:11 40960]
    R3 FlrnUSB;Leadtek USB Network Interface;c:\windows\system32\drivers\LtkUSB.sys [12.6.2009 13:11 41907]
    S3 speccy;speccy;\??\c:\docume~1\pasi\LOCALS~1\Temp\1628684616570212003235650396speccy.sys --> c:\docume~1\pasi\LOCALS~1\Temp\1628684616570212003235650396speccy.sys [?]
    S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [8.5.2008 10:22 685816]
    .
    'Ajoitetut tehtävät'-kansion sisältö

    2010-01-12 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
    .
    .
    ------- Täydentävä tarkistus -------
    .
    uStart Page = hxxp://www.mtv3.fi/
    IE: Vie Microsoft E&xceliin - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
    DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab
    FF - ProfilePath - c:\documents and settings\pasi\Application Data\Mozilla\Firefox\Profiles\9lq1uz7a.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.mtv3.fi/
    FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
    .
    - - - - POISTETUT JÄMÄRIVIT - - - -

    WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-02-01 19:11
    Windows 5.1.2600 Service Pack 3 NTFS

    tarkistaa piilotettuja prosesseja ...

    tarkistaa piilotettuja käynnistysarvoja ...

    tarkistaa piilotettuja tiedostoja ...

    tarkistus on valmis
    piilotetut tiedostot: 0

    **************************************************************************
    .
    --------------------- LUKITUT REKISTERIAVAIMET ---------------------

    [HKEY_USERS\S-1-5-21-602162358-1957994488-839522115-1003\Software\SecuROM\License information*]
    "datasecu"=hex:08,3e,09,f4,f9,77,fa,80,36,33,98,03,26,84,bf,15,c4,f8,b2,92,0b,
    62,ff,a6,4c,0a,55,78,f0,75,fc,dd,b7,4a,c6,e1,3a,87,a4,85,ff,02,8f,ff,83,3c,\
    "rkeysecu"=hex:e5,f3,9a,1e,5a,c2,e2,67,5c,62,4e,85,1c,14,a6,6e

    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\¹mÓw*]
    "AB79C053C7D38EE4AB9A00CB3B5D2472"="C?\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\PUBPLACE.HTT"

    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\463ae326-3297-65a9-f0a2-d6d8e61ec25]
    @Denied: (Full) (AuthenticatedUsers)
    @Denied: (Full) (Administrators)
    "1xqy3iybidxey"=hex:33,34,65,36,61,63,38,33,2d,64,37,37,36,2d,34,66,30,39,2d,
    62,34,36,33,2d,32,61,65,64,63,39,37,38,61,64,33,33
    "17zk8nx8rmerz"=hex:65,00,00,00,f8,00,00,00,f8,b5,70,f7,70,65,73,69,78,00,00,
    00,00,00,00,00,00,00,00,00,83,ac,e6,34,76,d7,09,4f,b4,63,2a,ed,c9,78,ad,33,\
    .
    Valmistumisajankohta: 2010-02-01 19:15:46
    ComboFix-quarantined-files.txt 2010-02-01 17:15
    ComboFix2.txt 2009-12-24 20:26
    ComboFix3.txt 2009-10-24 19:49
    ComboFix4.txt 2009-08-16 09:44
    ComboFix5.txt 2010-02-01 17:01

    Ennen ajoa: 64 147 632 128 tavua vapaana
    Ajon jälkeen: 64 292 380 672 tavua vapaana

    Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
    - - End Of File - - 85B8C47D53135CFB32C0EA0654AFDAEA
     
  2. lolacco

    lolacco Regular member

    Joined:
    Jul 2, 2009
    Messages:
    636
    Likes Received:
    0
    Trophy Points:
    26
    Pistä tuo HJT-loki osastolle, siellä osaavat auttaa paremmin.
     
  3. Quiote

    Quiote Moderator Staff Member

    Joined:
    Dec 20, 2005
    Messages:
    2,215
    Likes Received:
    0
    Trophy Points:
    46
    Väärin. Oikea tapa on raportoida ketju joko aloittajat tai muun käyttäjän toimesta ja odottaa ketjun siirtoa moderaattoreilta. Ei siis aloitella niitä uusia ketjuja turhaan.
     
Thread Status:
Not open for further replies.

Share This Page