Tässäpä tämä: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 23:21:33, on 21.8.2008 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18000) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Alwil Software\Avast4\ashDisp.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Microsoft IntelliType Pro\itype.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Windows\System32\rundll32.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\BitComet\BitComet.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Windows\ehome\ehtray.exe C:\Program Files\DAEMON Tools Lite\daemon.exe C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Stardock\ObjectDock\ObjectDock.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Last.fm\LastFM.exe C:\Program Files\RivaTuner v2.07\RivaTuner.exe C:\Windows\system32\conime.exe C:\Program Files\Opera\opera.exe C:\Program Files\Winamp\winamp.exe C:\Windows\system32\SearchFilterHost.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe" O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Paikallinen palvelu') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'Paikallinen palvelu') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Verkkopalvelu') O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe O4 - Startup: Winamp.lnk = C:\Program Files\Winamp\winamp.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file) O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll/206 (file missing) O13 - Gopher Prefix: O17 - HKLM\System\CCS\Services\Tcpip\..\{D43A299D-7C9A-41B4-8B20-F052C4F23EBB}: NameServer = 62.240.64.97,62.216.99.250 O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Bonjour-palvelu (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: iPod-palvelu (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\Windows\system32\sfrem01.exe -- End of file - 7200 bytes Jos joku kehtaa katsoa tän niin olen kiitollinen
scannaa hjt:llä merkkaa paina Fix checked O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file) =============== Lataa Malwarebytes' Anti-Malware työpöydällesi. 1. Tuplaklikkaa mbam-setup.exe ja seuraa ohjeita asentaaksesi ohjelman. 2. Lopuksi varmistu, että seuraavat on valittu: Update Malwarebytes', Anti-Malwareja Launch Malwarebytes' Anti-Malware ja sen jälkeen klikkaaFinish. 3. Jos päivitys löytyy. ohjelma lataa ja asentaa uusimman version. 4. Kun ohjelma on latautunut, valitse Perform full scan ja klikkaa Scan. 5. Kun skanni on valmis, klikkaa OK ja sitten Show Results nähdäksesi tulokset. 6. Varmistu, että kaikki on merkitty ja klikkaa Remove Selected. 7. Tämän jälkeen loki avautuu muistioon. Tallenna se paikkaan, josta löydät sen helposti. Loki löytyy myös täältä: C:\Documents and Settings\Käyttäjänimi\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-päiväys.txt 8. Lähetä lokin sisältö seuraavassa viestissäsi.
Tässäpä tämä: Malwarebytes' Anti-Malware 1.25 Tietokantaversio: 1076 Windows 6.0.6001 Service Pack 1 16:29:55 22.8.2008 mbam-log-08-22-2008 (16-29-55).txt Tarkistustyyppi: Täysi tarkistus (B:\|C:\|) Tarkistetut kohteet: 193029 Kulunut aika: 1 hour(s), 7 minute(s), 31 second(s) Saastuneita muistiprosesseja: 0 Saastuneita muistimoduuleja: 0 Saastuneita rekisteriavaimia: 1 Saastuneita rekisteriarvoja: 0 Saastuneita rekisterikohteita: 0 Saastuneita hakemistoja: 0 Saastuneita tiedostoja: 1 Saastuneita muistiprosesseja: (Haitallisia kohteita ei löydetty) Saastuneita muistimoduuleja: (Haitallisia kohteita ei löydetty) Saastuneita rekisteriavaimia: HKEY_CLASSES_ROOT\Typelib\{86a44ef9-78fc-4e18-a564-b18f806f7f56} (Trojan.MultiDefender) -> Quarantined and deleted successfully. Saastuneita rekisteriarvoja: (Haitallisia kohteita ei löydetty) Saastuneita rekisterikohteita: (Haitallisia kohteita ei löydetty) Saastuneita hakemistoja: (Haitallisia kohteita ei löydetty) Saastuneita tiedostoja: B:\GALA-NET\Rappelz Epic3\Launcher.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Siinäpä se: C:\Program Files\RivaTuner v2.07\RivaTuner.exe C:\Program Files\Windows Mail\WinMail.exe C:\Windows\system32\SearchFilterHost.exe C:\Program Files\Opera\Opera.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fi/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe" O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Paikallinen palvelu') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'Paikallinen palvelu') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Verkkopalvelu') O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe O4 - Startup: Winamp.lnk = C:\Program Files\Winamp\winamp.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file) O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll/206 (file missing) O13 - Gopher Prefix: O17 - HKLM\System\CCS\Services\Tcpip\..\{D43A299D-7C9A-41B4-8B20-F052C4F23EBB}: NameServer = 62.240.64.97,62.216.99.250 O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Bonjour-palvelu (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: iPod-palvelu (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\Windows\system32\sfrem01.exe -- End of file - 6906 bytes Edit: O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file) ei jostain syystä hävinny fixauksella.
1.Lataa combofix.exe työpöydällesi yhdestä linkistä: combofix1 combofix2 2. Tuplaklikkaa combofix.exe tiedostoa ja seuraa ohjeistuksia. 3. Kun työkalu on valmis, se tuottaa lokin. Lähetä tämä loki viesti ketjuusi. Huom! Älä klikkaile combofixin ikkunaa käytön aikana. Tämä saattaa aiheuttaa ohjelman jumiutumisen.
ComboFix 08-08-21.02 - Pave 2008-08-22 19:36:06.1 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1035.18.1139 [GMT 3:00] Running from: C:\Users\Pave\Desktop\ComboFix.exe * Created a new restore point . ((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-07-22 to 2008-08-22 ))))))))))))))))) . 2008-08-22 15:19 . 2008-08-22 15:19 <KANSIO> d-------- C:\Users\Pave\AppData\Roaming\Malwarebytes 2008-08-22 15:19 . 2008-08-22 15:19 <KANSIO> d-------- C:\Users\All Users\Malwarebytes 2008-08-22 15:19 . 2008-08-22 15:19 <KANSIO> d-------- C:\ProgramData\Malwarebytes 2008-08-22 15:19 . 2008-08-22 15:19 <KANSIO> d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-08-22 15:19 . 2008-08-17 15:01 38,472 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys 2008-08-22 15:19 . 2008-08-17 15:01 17,144 --a------ C:\Windows\System32\drivers\mbam.sys 2008-08-21 22:58 . 2008-08-21 22:58 <KANSIO> d-------- C:\Users\Pave\AppData\Roaming\GrabPro 2008-08-21 22:57 . 2008-08-21 23:06 <KANSIO> d-------- C:\Users\Pave\AppData\Roaming\Orbit 2008-08-17 23:37 . 2008-08-17 23:44 <KANSIO> d-------- C:\Program Files\Audacity 2008-08-13 16:00 . 2008-07-16 04:32 2,048 --a------ C:\Windows\System32\tzres.dll 2008-08-13 15:50 . 2008-06-27 04:55 1,383,424 --a------ C:\Windows\System32\mshtml.tlb 2008-08-13 15:50 . 2008-06-27 07:15 827,392 --a------ C:\Windows\System32\wininet.dll 2008-08-13 15:50 . 2008-04-10 08:12 738,304 --a------ C:\Windows\System32\inetcomm.dll 2008-08-13 15:50 . 2008-06-19 06:31 361,984 --a------ C:\Windows\System32\IPSECSVC.DLL 2008-08-13 15:50 . 2008-04-18 08:48 269,312 --a------ C:\Windows\System32\es.dll 2008-08-09 12:44 . 2008-08-09 12:44 1,043,415 --a------ C:\Windows\Nintendo Zelda.scr 2008-08-09 12:44 . 2008-08-09 12:44 12 --a------ C:\Windows\screenmx.ini 2008-08-04 18:06 . 2008-08-04 18:07 <KANSIO> d-------- C:\Program Files\iTunes 2008-08-04 18:06 . 2008-08-04 18:06 <KANSIO> d-------- C:\Program Files\iPod 2008-08-03 13:14 . 2008-08-03 13:14 <KANSIO> d-------- C:\Users\Pave\AppData\Roaming\GeoVid 2008-08-03 13:14 . 2008-08-03 13:14 <KANSIO> d-------- C:\Program Files\Common Files\GeoVid 2008-08-03 13:14 . 2004-08-18 16:00 1,712,128 --a------ C:\Windows\System32\gdiplus.dll 2008-08-03 13:14 . 2003-03-19 09:12 1,047,552 --a------ C:\Windows\System32\mfc71u.dll 2008-08-03 13:14 . 2003-03-19 07:05 89,088 --a------ C:\Windows\System32\atl71.dll 2008-08-03 13:14 . 2007-06-28 19:55 77,824 --a------ C:\Windows\System32\xvid.ax 2008-08-03 13:14 . 2005-06-07 16:11 60,416 --a------ C:\Windows\System32\dsetup.dll 2008-08-01 14:28 . 2008-08-01 14:28 <KANSIO> d-------- C:\Program Files\Common Files\Wise Installation Wizard 2008-07-22 20:32 . 2008-07-22 20:32 32,000 --a------ C:\Windows\System32\drivers\usbaapl.sys . (((((((((((((((((((((((((((((((((((( Find3M-raportti )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-08-20 17:32 --------- d-----w C:\Program Files\World of Warcraft 2008-08-19 18:01 --------- d-----w C:\Program Files\Microsoft Silverlight 2008-08-17 13:13 --------- d-----w C:\Program Files\Counter-Strike Source 2008-08-13 13:05 --------- d-----w C:\ProgramData\NVIDIA 2008-08-13 13:02 --------- d-----w C:\Program Files\Windows Mail 2008-08-10 20:49 --------- d-----w C:\Users\Pave\AppData\Roaming\Winamp 2008-08-04 09:00 --------- d-----w C:\Program Files\Java 2008-08-01 11:29 --------- d-----w C:\Program Files\Lavasoft 2008-08-01 11:25 --------- d-----w C:\ProgramData\Lavasoft 2008-07-31 15:27 --------- d-----w C:\Program Files\Stardock 2008-07-21 10:03 --------- d-----w C:\Program Files\Common Files\Blizzard Entertainment 2008-07-19 14:36 51,280 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys 2008-07-10 12:40 --------- d-----w C:\ProgramData\WLInstaller 2008-07-10 12:40 --------- d-----w C:\Program Files\Windows Live 2008-07-08 11:23 --------- d-----w C:\Program Files\Opera 2008-07-03 20:52 --------- d---a-w C:\ProgramData\TEMP 2008-07-03 20:52 --------- d-----w C:\Program Files\SpywareBlaster 2008-07-02 12:08 --------- d-----w C:\Program Files\Common Files\Java 2008-07-02 10:01 --------- d-----w C:\Program Files\Common Files\InstallShield 2008-07-02 09:42 --------- d-----w C:\Users\Pave\AppData\Roaming\iSproggler 2008-07-01 12:54 --------- d-----w C:\Program Files\Apple Software Update 2008-07-01 12:53 --------- d-----w C:\Program Files\U-ABIT 2008-07-01 12:52 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-07-01 12:44 --------- d-----w C:\Users\Pave\AppData\Roaming\InstallShield 2008-07-01 11:16 --------- d-----w C:\Program Files\Winamp 2008-07-01 10:54 --------- d-----w C:\Program Files\Last.fm 2008-07-01 10:46 --------- d-----w C:\ProgramData\Last.fm 2008-07-01 10:42 --------- d-----w C:\Users\Pave\AppData\Roaming\Winamp(134) 2008-07-01 09:14 --------- d-----w C:\Program Files\Apple Software Update(105) 2008-06-26 03:29 801,280 ----a-w C:\Windows\System32\NaturalLanguage6.dll 2008-06-26 01:45 2,644,480 ----a-w C:\Windows\System32\NlsLexicons0009.dll 2008-06-26 01:45 12,240,896 ----a-w C:\Windows\System32\NlsLexicons0007.dll 2008-06-25 09:23 --------- d-----w C:\Users\Pave\AppData\Roaming\Apple Computer 2008-06-25 09:23 --------- d-----w C:\ProgramData\Apple Computer 2008-06-25 09:23 --------- d-----w C:\Program Files\Bonjour 2008-06-25 09:22 --------- d-----w C:\Program Files\QuickTime 2008-06-25 09:21 --------- d-----w C:\ProgramData\Apple 2008-06-25 09:21 --------- d-----w C:\Program Files\Common Files\Apple 2008-05-27 05:21 1,582,592 ----a-w C:\Windows\System32\tquery.dll 2008-05-27 05:21 1,418,240 ----a-w C:\Windows\System32\mssrch.dll 2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\SearchFilterHost.exe 2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\mssitlb.dll 2008-05-27 05:17 754,176 ----a-w C:\Windows\System32\propsys.dll 2008-05-27 05:17 60,416 ----a-w C:\Windows\System32\msscntrs.dll 2008-05-27 05:17 6,103,040 ----a-w C:\Windows\System32\chtbrkr.dll 2008-05-27 05:17 34,816 ----a-w C:\Windows\System32\msscb.dll 2008-05-27 05:17 32,768 ----a-w C:\Windows\System32\mssprxy.dll 2008-05-27 05:17 313,344 ----a-w C:\Windows\System32\thawbrkr.dll 2008-05-27 05:17 301,568 ----a-w C:\Windows\System32\srchadmin.dll 2008-05-27 05:17 194,560 ----a-w C:\Windows\System32\offfilt.dll 2008-05-27 05:17 143,872 ----a-w C:\Windows\System32\korwbrkr.dll 2008-05-27 05:17 11,776 ----a-w C:\Windows\System32\msshooks.dll 2008-05-27 05:17 1,671,680 ----a-w C:\Windows\System32\chsbrkr.dll 2008-05-27 04:59 18,904 ----a-w C:\Windows\System32\StructuredQuerySchemaTrivial.bin 2008-05-27 04:59 106,605 ----a-w C:\Windows\System32\StructuredQuerySchema.bin 2008-05-22 13:17 2,560 ----a-w C:\Windows\_MSRSTRT.EXE 2008-05-18 09:40 60,528 ----a-w C:\Users\Pave\AppData\Roaming\GDIPFONTCACHEV1.DAT 2008-04-20 15:59 174 --sha-w C:\Program Files\desktop.ini 2008-03-04 15:51 22,328 ----a-w C:\Users\Pave\AppData\Roaming\PnkBstrK.sys 2008-03-04 13:53 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat 2008-03-04 13:53 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat 2008-03-04 13:53 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat . (((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet ))))))))))))))))))))))))))))))))))))))))))))) . . *Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 10:33 1233920] "BitComet"="C:\Program Files\BitComet\BitComet.exe" [2008-02-01 10:20 2194744] "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2008-07-10 15:50 5724184] "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 10:33 125952] "DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 12:39 486856] "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 10:33 202240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 17:38 78008] "itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-11-21 18:08 813912] "WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-04-01 21:49 36352] "IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 12:01 1037736] "AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 20:42 116040] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 10:47 289064] "NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-11-06 21:00 86016] "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-11-06 21:00 8530464] "NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-11-06 21:00 81920] "RtHDVCpl"="RtHDVCpl.exe" [2006-11-09 05:57 3784704 C:\Windows\RtHDVCpl.exe] C:\Users\Pave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2008-03-05 16:36:33 3581680] Winamp.lnk - C:\Program Files\Winamp\winamp.exe [2008-04-01 21:50:32 1307648] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 13:01:04 83360] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.divxa32"= msaud32_divx.acm "vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{BDE4A07F-7120-43BF-A184-8A8552494BF1}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) "TCP Query User{5181A381-E7EB-4A01-A6ED-C2F8542A8670}C:\\program files\\opera\\opera.exe"= UDP:C:\program files\opera\opera.exe:Opera Internet Browser "UDP Query User{B6539A50-319B-468F-998F-A7EDBBD0B1E6}C:\\program files\\opera\\opera.exe"= TCP:C:\program files\opera\opera.exe:Opera Internet Browser "{C73909CF-E1A0-4DFE-A55B-9945C832AE92}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32 "{DEA935D1-099B-4C21-A721-8160CA3D9424}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32 "{F5CE0CF9-F419-4A35-BD41-12D99B6BE3A4}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32 "{60417F37-3B47-4266-BC48-9AFF1CAE4A8C}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32 "{CBAEFE41-1C45-40E7-8B57-EABC2C12EE54}"= UDP:C:\Windows\System32\PnkBstrA.exenkBstrA "{31B03D26-90C0-42D0-B5F1-485E1A679ED4}"= TCP:C:\Windows\System32\PnkBstrA.exenkBstrA "{AD5B69B1-17AE-41FC-ABE3-1D645987358E}"= UDP:C:\Windows\System32\PnkBstrB.exenkBstrB "{07787747-1747-495E-AEF5-08F5E7C7EC8E}"= TCP:C:\Windows\System32\PnkBstrB.exenkBstrB "TCP Query User{38D4CE2F-F1A3-4751-AAA4-E835145EAF5A}C:\\program files\\gamespy\\comrade\\comrade.exe"= UDP:C:\program files\gamespy\comrade\comrade.exe:Comrade "UDP Query User{FFCE2939-C1A7-4F6A-9450-A576DC15CCF2}C:\\program files\\gamespy\\comrade\\comrade.exe"= TCP:C:\program files\gamespy\comrade\comrade.exe:Comrade "TCP Query User{E36DA09A-C756-4438-AEBD-5D22DAC891AB}C:\\program files\\the all-seeing eye\\eye.exe"= UDP:C:\program files\the all-seeing eye\eye.exe:Yahoo! All-Seeing Eye "UDP Query User{DE1DE2AF-71BF-449F-B3BC-3925675CFF79}C:\\program files\\the all-seeing eye\\eye.exe"= TCP:C:\program files\the all-seeing eye\eye.exe:Yahoo! All-Seeing Eye "TCP Query User{71FD2EEA-5B75-4490-B20A-E9F5E49C4693}C:\\program files\\counter-strike source\\hl2.exe"= UDP:C:\program files\counter-strike source\hl2.exe:hl2 "UDP Query User{2B3FD90B-79E3-4133-BEB8-A4F7E14622ED}C:\\program files\\counter-strike source\\hl2.exe"= TCP:C:\program files\counter-strike source\hl2.exe:hl2 "TCP Query User{9638C56D-2704-4BEB-853D-DA7E74B85001}C:\\program files\\bitcomet\\bitcomet.exe"= UDP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client "UDP Query User{73BCB3EA-76DA-445F-8582-91ABF7F81B0F}C:\\program files\\bitcomet\\bitcomet.exe"= TCP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client "TCP Query User{BD5E6F57-2E64-4957-AE97-1B2CCFF783CC}C:\\program files\\empire interactive\\flatout 2\\flatout2.exe"= UDP:C:\program files\empire interactive\flatout 2\flatout2.exe:FlatOut2 "UDP Query User{F1CEFE71-B81F-4439-A463-B25D76A46A0D}C:\\program files\\empire interactive\\flatout 2\\flatout2.exe"= TCP:C:\program files\empire interactive\flatout 2\flatout2.exe:FlatOut2 "TCP Query User{ED74B741-7930-4CA7-B804-010EF486DFF1}B:\\lataukset\\the.all.seeing.eye.v2.6.0.winall.cracked-emporio\\eye.exe"= UDP:B:\lataukset\the.all.seeing.eye.v2.6.0.winall.cracked-emporio\eye.exe:Yahoo! All-Seeing Eye "UDP Query User{B415B408-8571-43EF-A27D-0DADE9DE3F78}B:\\lataukset\\the.all.seeing.eye.v2.6.0.winall.cracked-emporio\\eye.exe"= TCP:B:\lataukset\the.all.seeing.eye.v2.6.0.winall.cracked-emporio\eye.exe:Yahoo! All-Seeing Eye "TCP Query User{1293FE34-6FB9-45C8-A214-CC16A57860F4}C:\\users\\pave\\desktop\\eye.exe"= UDP:C:\users\pave\desktop\eye.exe:eye.exe "UDP Query User{09FEC1D5-532E-41EB-A6CE-40E6C112D6B8}C:\\users\\pave\\desktop\\eye.exe"= TCP:C:\users\pave\desktop\eye.exe:eye.exe "TCP Query User{0AFF66D7-95FE-4AA4-8AF0-B176C7957C94}C:\\users\\pave\\desktop\\the all-seeing eye\\eye.exe"= UDP:C:\users\pave\desktop\the all-seeing eye\eye.exe:eye.exe "UDP Query User{ED0FC608-38E6-496D-BF5B-7A78E612C134}C:\\users\\pave\\desktop\\the all-seeing eye\\eye.exe"= TCP:C:\users\pave\desktop\the all-seeing eye\eye.exe:eye.exe "TCP Query User{B3A67A88-489E-41DB-A64A-0DDE34D597B8}C:\\program files\\half-life 2 deathmatch\\hl2.exe"= UDP:C:\program files\half-life 2 deathmatch\hl2.exe:hl2 "UDP Query User{3627A2F0-2E3C-4F38-8E1A-F5CAE64F9D9C}C:\\program files\\half-life 2 deathmatch\\hl2.exe"= TCP:C:\program files\half-life 2 deathmatch\hl2.exe:hl2 "TCP Query User{180127DC-2C52-4F88-9313-55B69FF180BE}C:\\program files\\steam\\steamapps\\haudankaivajasi\\half-life 2 deathmatch\\hl2.exe"= UDP:C:\program files\steam\steamapps\haudankaivajasi\half-life 2 deathmatch\hl2.exe:hl2 "UDP Query User{0C3D030D-B0B6-4577-A800-675F285443B2}C:\\program files\\steam\\steamapps\\haudankaivajasi\\half-life 2 deathmatch\\hl2.exe"= TCP:C:\program files\steam\steamapps\haudankaivajasi\half-life 2 deathmatch\hl2.exe:hl2 "{D59DEBF8-2C49-437E-B491-7BC755C1AF19}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour "{F4E4B501-5457-436B-9306-61395EAA7C94}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour "{3C51EADC-1272-4AEA-8EF5-0679A507B573}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) "{18430F58-ADC6-48A5-8233-F2C10445E1A8}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) "{5FFAC532-6FD6-40A1-A90F-391FC9985E5B}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes "{6839C73F-23B6-4852-AE25-8EE974726E10}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes "TCP Query User{D421F4BA-1AA4-4DCC-91FD-BC85191F56AB}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer "UDP Query User{7E571EAF-AF87-4E4A-93C5-708CCE79131D}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer "TCP Query User{74122801-33BA-4193-996B-F38831D1E4E7}C:\\uusi kansio\\orbitdownloader\\orbitnet.exe"= UDP:C:\uusi kansio\orbitdownloader\orbitnet.exe2P service of Orbit Downloader "UDP Query User{A670C0B8-2FC7-4521-81A4-ED8268A24CFE}C:\\uusi kansio\\orbitdownloader\\orbitnet.exe"= TCP:C:\uusi kansio\orbitdownloader\orbitnet.exe2P service of Orbit Downloader R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);C:\Windows\system32\drivers\sfdrv01a.sys [2006-07-05 15:46] R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-07-19 17:35] R1 uGuru;uGuru;C:\Windows\system32\Drivers\uGuru.sys [2006-10-02 04:10] R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 17:37] R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-07-19 17:36] R2 NMSAccessU;NMSAccessU;C:\Program Files\CDBurnerXP\NMSAccessU.exe [2007-10-12 09:34] *Newly Created Service* - CATCHME *Newly Created Service* - PROCEXP90 . - - - - ORPHANS REMOVED - - - - Notify-WBSrv - C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll . ------- Supplementary Scan ------- . R0 -: HKCU-Main,Start Page = hxxp://www.google.fi/ R1 -: HKCU-Internet Settings,ProxyOverride = *.local O8 -: &D&ownload &with BitComet - C:\Program Files\BitComet\BitComet.exe/AddLink.htm O8 -: &D&ownload all video with BitComet - C:\Program Files\BitComet\BitComet.exe/AddVideo.htm O8 -: &D&ownload all with BitComet - C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm O9 -: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll/206 O17 -: HKLM\CCS\Interface\{D43A299D-7C9A-41B4-8B20-F052C4F23EBB}: NameServer = 62.240.64.97,62.216.99.250 . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-08-22 19:38:41 Windows 6.0.6001 Service Pack 1 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\Windows\Explorer.exe -> C:\Program Files\Stardock\ObjectDock\DockShellHook.dll . Completion time: 2008-08-22 19:40:10 ComboFix-quarantined-files.txt 2008-08-22 16:39:47 Pre-Run: 91,349,852,160 tavua vapaana Post-Run: 91,326,808,064 tavua vapaana 217 --- E O F --- 2008-08-20 15:23:57