Internet tahmaa

Discussion in 'Virukset ja haittaohjelmat - HijackThis -logit' started by Hubbbe, Dec 23, 2008.

  1. Hubbbe

    Hubbbe Member

    Joined:
    Jul 11, 2007
    Messages:
    55
    Likes Received:
    0
    Trophy Points:
    16
    Päivähdys tietokone gurut!
    Tässä olen taistellut viikon päivät nettiselainten ja siinä sivussa XP:n kanssa.

    Netti toimi kuin unelma, mutta asensin XP:n uudelleen ja luonnollisesti palomuurit ym muut tauhkat.
    mutta asennuksen jälkeen netti on toiminut toooodella hitaasti ilman mitään järjellistä selitystä.

    tässä hjt loki josta en paljoakaan ymmärrä:

    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Pidgin\pidgin.exe
    C:\Program Files\Opera 10 Preview\opera.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Jussi Huhtala\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
    O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted Zone: *.line6.net
    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1229193620203
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: M-Audio Series II MIDI Installer (MA_CMIDI_InstallerService) - Unknown owner - C:\Program Files\M-Audio\M-Audio Series II MIDI\MA_CMIDI_Inst.exe
    O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

    --
    End of file - 5191 bytes
     
  2. Hubbbe

    Hubbbe Member

    Joined:
    Jul 11, 2007
    Messages:
    55
    Likes Received:
    0
    Trophy Points:
    16
    Tässä combofix loki:

    ComboFix 08-12-23.01 - Jussi Huhtala 2008-12-23 22:32:37.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1035.18.3582.3102 [GMT 2:00]
    Sijainti: c:\documents and settings\Jussi Huhtala\Local Settings\Application Data\Opera\Opera 10 Preview\profile\cache4\temporary_download\ComboFix.exe
    * Uusi palautuspiste luotu
    .

    (((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\system32\pncrt.dll
    D:\install.exe

    .
    ((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-11-23 to 2008-12-23 )))))))))))))))))
    .

    2008-12-23 10:05 . 2008-12-23 10:05 <KANSIO> d-------- c:\program files\Malwarebytes' Anti-Malware
    2008-12-23 10:05 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
    2008-12-23 10:05 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
    2008-12-23 10:03 . 2008-12-23 10:03 <KANSIO> d-------- c:\documents and settings\Jussi Huhtala\Application Data\Malwarebytes
    2008-12-23 10:03 . 2008-12-23 10:03 <KANSIO> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
    2008-12-23 09:55 . 2008-12-23 09:55 <KANSIO> d-------- c:\program files\Trend Micro
    2008-12-22 19:09 . 2008-12-22 19:09 <KANSIO> d-------- c:\program files\Java
    2008-12-22 19:09 . 2008-12-22 19:09 410,984 --a------ c:\windows\system32\deploytk.dll
    2008-12-22 19:09 . 2008-12-22 19:09 73,728 --a------ c:\windows\system32\javacpl.cpl
    2008-12-22 09:31 . 2008-12-22 09:31 <KANSIO> d-------- c:\documents and settings\Jussi Huhtala\Application Data\OpenOffice.org
    2008-12-22 09:30 . 2008-12-22 09:30 <KANSIO> d-------- c:\program files\OpenOffice.org 3
    2008-12-21 18:44 . 2008-04-14 09:11 159,232 --a------ c:\windows\system32\ptpusd.dll
    2008-12-21 18:44 . 2008-04-13 11:45 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
    2008-12-21 18:44 . 2008-04-13 11:45 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys
    2008-12-21 18:44 . 2001-10-05 16:31 5,632 --a------ c:\windows\system32\ptpusb.dll
    2008-12-21 13:28 . 2008-12-21 13:28 <KANSIO> dr-h----- c:\documents and settings\Jussi Huhtala\Application Data\SecuROM
    2008-12-21 13:28 . 2008-12-21 13:28 <KANSIO> d-------- c:\documents and settings\Jussi Huhtala\Application Data\Red Alert 3
    2008-12-21 13:18 . 2008-12-21 13:18 <KANSIO> d-------- C:\ProgramData
    2008-12-21 12:48 . 2008-12-21 13:23 <KANSIO> d-------- c:\program files\Electronic Arts
    2008-12-20 19:07 . 2008-12-20 19:07 <KANSIO> d-------- c:\program files\Antares Audio Technologies
    2008-12-20 17:58 . 2008-12-20 17:58 <KANSIO> d-------- c:\program files\FileZilla FTP Client
    2008-12-20 17:58 . 2008-12-21 12:02 <KANSIO> d-------- c:\documents and settings\Jussi Huhtala\Application Data\FileZilla
    2008-12-20 14:53 . 2008-12-23 09:34 <KANSIO> d-------- C:\Temp
    2008-12-20 14:53 . 2008-12-20 14:53 <KANSIO> d-------- c:\documents and settings\Jussi Huhtala\Application Data\Syntrillium
    2008-12-20 14:51 . 2008-12-20 15:01 <KANSIO> d-------- c:\program files\coolpro2
    2008-12-19 23:59 . 2008-12-19 23:59 <KANSIO> d-------- c:\program files\MSXML 4.0
    2008-12-19 21:56 . 2008-12-19 21:56 <KANSIO> d-------- c:\documents and settings\Jussi Huhtala\Application Data\Steinberg
    2008-12-19 21:52 . 2008-12-20 19:07 <KANSIO> d-------- c:\program files\Steinberg
    2008-12-19 21:51 . 2008-12-19 21:51 <KANSIO> d-------- c:\program files\Syncrosoft
    2008-12-19 21:51 . 2005-10-17 09:35 704,512 --a------ c:\windows\system32\SYNSOACC.dll
    2008-12-19 21:51 . 2004-05-10 15:58 147,456 --a------ c:\windows\system32\SynsoLChk.dll
    2008-12-19 21:51 . 2003-07-31 20:28 147,425 --a------ c:\windows\system32\SYNSOACC-Aide.chm
    2008-12-19 21:51 . 2003-05-26 15:29 120,468 --a------ c:\windows\system32\SYNSOACC-Hilfe.chm
    2008-12-19 21:51 . 2003-05-26 15:29 114,279 --a------ c:\windows\system32\SYNSOACC-Help.chm
    2008-12-19 21:51 . 2002-11-25 08:36 45,056 --a------ c:\windows\system32\Synsopos.exe
    2008-12-19 21:51 . 2005-05-09 20:08 33,792 --a------ c:\windows\system32\drivers\cledx.sys
    2008-12-19 21:51 . 2002-11-25 05:46 16,896 --a------ c:\windows\system32\drivers\synasUSB.sys
    2008-12-19 19:27 . 2008-12-19 19:27 <KANSIO> d-------- c:\program files\CCleaner
    2008-12-19 18:15 . 2008-12-19 18:21 <KANSIO> d-------- c:\windows\system32\NtmsData
    2008-12-19 17:46 . 2008-12-19 18:21 <KANSIO> d-------- c:\documents and settings\Jussi Huhtala\Application Data\Hamachi
    2008-12-19 17:46 . 2008-12-19 17:46 25,280 --a------ c:\windows\system32\drivers\hamachi.sys
    2008-12-19 09:03 . 2008-12-19 09:03 <KANSIO> d-------- c:\program files\ffdshow
    2008-12-19 09:03 . 2008-06-08 22:58 60,273 --a------ c:\windows\system32\pthreadGC2.dll
    2008-12-19 09:03 . 2008-12-08 12:53 57,344 --a------ c:\windows\system32\ff_vfw.dll
    2008-12-19 09:03 . 2008-12-08 12:53 50,688 --a------ c:\windows\system32\ff_acm.acm
    2008-12-19 09:03 . 2007-07-10 17:10 547 --a------ c:\windows\system32\ff_vfw.dll.manifest
    2008-12-19 07:59 . 2008-12-20 22:06 69 --a------ c:\windows\NeroDigital.ini
    2008-12-18 23:00 . 2008-12-18 23:02 <KANSIO> d-------- c:\documents and settings\Jussi Huhtala\Application Data\Nero
    2008-12-18 22:50 . 2008-12-18 22:50 4,767 --a------ c:\windows\Irremote.ini
    2008-12-18 22:49 . 2008-12-18 22:49 <KANSIO> d-------- c:\program files\Windows Sidebar
    2008-12-18 22:41 . 2008-12-18 22:49 <KANSIO> d-------- c:\program files\Nero
    2008-12-18 22:41 . 2008-12-18 22:58 <KANSIO> d-------- c:\program files\Common Files\Nero
    2008-12-18 22:41 . 2008-12-18 22:45 <KANSIO> d-------- c:\documents and settings\All Users\Application Data\Nero
    2008-12-17 16:53 . 2008-12-17 16:54 <KANSIO> d-------- C:\Fraps
    2008-12-17 16:53 . 2008-12-17 16:54 <KANSIO> d-a------ c:\documents and settings\All Users\Application Data\TEMP
    2008-12-17 08:02 . 2008-12-17 08:02 <KANSIO> d-------- c:\program files\Empire Interactive
    2008-12-16 17:27 . 2008-12-16 17:27 <KANSIO> d-------- c:\windows\system32\LogFiles
    2008-12-16 17:27 . 2008-12-16 17:27 103,736 --a------ c:\windows\system32\PnkBstrB.exe
    2008-12-16 17:27 . 2008-12-16 17:27 66,872 --a------ c:\windows\system32\PnkBstrA.exe
    2008-12-16 17:27 . 2008-12-16 17:27 22,328 --a------ c:\windows\system32\drivers\PnkBstrK.sys
    2008-12-16 17:27 . 2008-12-16 17:27 22,328 --a------ c:\documents and settings\Jussi Huhtala\Application Data\PnkBstrK.sys
    2008-12-16 17:27 . 2008-12-16 17:27 319 --a------ c:\windows\game.ini
    2008-12-16 17:03 . 2008-12-23 12:31 <KANSIO> d-------- c:\program files\DNA
    2008-12-16 17:03 . 2008-12-16 17:03 <KANSIO> d-------- c:\program files\BitTorrent
    2008-12-16 17:03 . 2008-12-23 22:32 <KANSIO> d-------- c:\documents and settings\Jussi Huhtala\Application Data\DNA
    2008-12-16 17:03 . 2008-12-21 16:43 <KANSIO> d-------- c:\documents and settings\Jussi Huhtala\Application Data\BitTorrent
    2008-12-14 21:00 . 2008-12-14 21:03 <KANSIO> d-------- c:\program files\honestech Burn DVD 3.2 Trial
    2008-12-14 15:00 . 2008-08-14 15:25 2,191,488 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
    2008-12-14 15:00 . 2008-08-14 15:25 2,147,840 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
    2008-12-14 15:00 . 2008-08-14 15:25 2,068,352 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
    2008-12-14 15:00 . 2008-08-14 15:24 2,026,496 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
    2008-12-14 15:00 . 2008-06-14 19:34 272,128 -----c--- c:\windows\system32\dllcache\bthport.sys
    2008-12-14 14:59 . 2008-08-14 12:04 138,496 -----c--- c:\windows\system32\dllcache\afd.sys
    2008-12-14 14:58 . 2008-09-08 12:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
    2008-12-14 14:57 . 2008-12-12 19:03 3,088,896 -----c--- c:\windows\system32\dllcache\mshtml.dll
    2008-12-14 14:57 . 2008-10-16 03:01 1,498,624 -----c--- c:\windows\system32\dllcache\shdocvw.dll
    2008-12-14 14:57 . 2008-10-16 03:01 666,112 -----c--- c:\windows\system32\dllcache\wininet.dll
    2008-12-14 14:57 . 2008-10-16 03:01 619,008 -----c--- c:\windows\system32\dllcache\urlmon.dll
    2008-12-14 14:53 . 2008-09-15 17:27 1,846,656 -----c--- c:\windows\system32\dllcache\win32k.sys
    2008-12-14 14:42 . 2008-05-08 16:02 203,136 -----c--- c:\windows\system32\dllcache\rmcast.sys
    2008-12-14 14:41 . 2008-10-24 13:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
    2008-12-14 14:40 . 2008-05-01 16:35 331,776 -----c--- c:\windows\system32\dllcache\msadce.dll
    2008-12-14 14:39 . 2008-04-11 21:05 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
    2008-12-14 14:33 . 2008-10-15 18:37 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
    2008-12-14 14:32 . 2008-09-04 19:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
    2008-12-14 14:08 . 2008-12-22 22:51 <KANSIO> d-------- c:\documents and settings\Jussi Huhtala\Application Data\gtk-2.0
    2008-12-14 14:07 . 2008-12-23 22:33 <KANSIO> d-------- c:\documents and settings\Jussi Huhtala\Application Data\.purple
    2008-12-14 14:06 . 2008-12-14 14:06 <KANSIO> d-------- c:\program files\Pidgin
    2008-12-14 14:06 . 2008-12-14 14:06 <KANSIO> d-------- c:\program files\Common Files\GTK
    2008-12-14 13:48 . 2008-12-14 13:48 <KANSIO> d-------- c:\program files\Bethesda Softworks
    2008-12-14 13:48 . 2008-12-14 13:48 <KANSIO> d-------- c:\documents and settings\All Users\Application Data\Fallout3
    2008-12-14 13:46 . 2008-12-14 13:46 <KANSIO> d-------- c:\program files\MSBuild
    2008-12-14 13:44 . 2008-12-14 13:44 <KANSIO> d-------- c:\windows\system32\XPSViewer
    2008-12-14 13:43 . 2008-12-14 13:43 <KANSIO> d-------- c:\program files\Reference Assemblies
    2008-12-14 13:43 . 2006-06-29 13:07 14,048 --------- c:\windows\system32\spmsg2.dll
    2008-12-14 13:41 . 2008-12-14 13:41 <KANSIO> d-------- c:\windows\system32\xlive
    2008-12-14 13:12 . 2008-12-14 13:12 <KANSIO> d-------- c:\windows\Logs
    2008-12-14 13:07 . 2008-12-16 17:22 <KANSIO> d-------- c:\program files\Activision
    2008-12-14 13:01 . 2008-12-14 13:01 <KANSIO> d--hs---- c:\windows\ftpcache
    2008-12-14 12:38 . 2008-12-14 12:38 368,640 --a------ c:\windows\system32\ReWire.dll
    2008-12-14 12:38 . 2008-12-14 12:38 233,472 --a------ c:\windows\system32\REX Shared Library.dll
    2008-12-14 12:36 . 2008-12-14 12:36 <KANSIO> d-------- c:\program files\Propellerhead
    2008-12-14 12:35 . 2008-12-14 12:35 <KANSIO> d-------- c:\documents and settings\Jussi Huhtala\Application Data\DAEMON Tools Pro
    2008-12-14 12:35 . 2008-12-14 12:35 <KANSIO> d-------- c:\documents and settings\Jussi Huhtala\Application Data\DAEMON Tools
    2008-12-14 12:34 . 2008-12-14 12:34 <KANSIO> d-------- c:\program files\DAEMON Tools Lite
    2008-12-14 12:34 . 2008-12-14 12:34 <KANSIO> d-------- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
    2008-12-14 12:29 . 2008-12-14 12:36 <KANSIO> d-------- c:\documents and settings\Jussi Huhtala\Application Data\DAEMON Tools Lite
    2008-12-14 12:29 . 2008-12-14 12:29 717,296 --a------ c:\windows\system32\drivers\sptd.sys
    2008-12-14 12:05 . 2008-12-14 12:05 32 --a------ c:\windows\GearBox.ini
    2008-12-14 11:57 . 2008-12-14 11:57 <KANSIO> d-------- c:\program files\Common Files\Digidesign
    2008-12-14 11:47 . 2008-12-14 11:47 <KANSIO> d-------- c:\program files\M-Audio
    2008-12-14 11:46 . 2008-12-21 13:18 <KANSIO> d-------- c:\program files\Common Files\InstallShield
    2008-12-14 11:38 . 2008-04-13 11:45 172,416 --a------ c:\windows\system32\drivers\kmixer.sys
    2008-12-14 11:37 . 2008-12-14 11:57 <KANSIO> d-------- c:\documents and settings\All Users\Application Data\Line 6
    2008-12-14 11:37 . 2008-04-14 09:12 129,536 --a------ c:\windows\system32\ksproxy.ax
    2008-12-14 11:37 . 2008-04-14 09:12 129,536 --a--c--- c:\windows\system32\dllcache\ksproxy.ax
    2008-12-14 11:37 . 2008-04-13 11:45 60,160 --a------ c:\windows\system32\drivers\drmk.sys
    2008-12-14 11:37 . 2008-04-13 11:45 60,160 --a--c--- c:\windows\system32\dllcache\drmk.sys
    2008-12-14 11:36 . 2008-12-14 11:37 <KANSIO> d----c--- c:\windows\system32\DRVSTORE
    2008-12-14 11:36 . 2008-10-24 00:51 530,560 --a------ c:\windows\system32\drivers\L6TPortB.sys
    2008-12-14 11:36 . 2008-10-24 00:51 167,936 --a------ c:\windows\system32\l6tpux2.dll
    2008-12-14 11:27 . 2008-12-14 12:06 <KANSIO> d-------- c:\documents and settings\Jussi Huhtala\Application Data\Line 6
    2008-12-14 11:26 . 2008-12-14 12:05 <KANSIO> d-------- c:\program files\Line6
    2008-12-13 23:22 . 2008-12-13 23:22 <KANSIO> d-------- c:\windows\system32\AGEIA
    2008-12-13 23:22 . 2008-12-13 23:22 <KANSIO> d-------- c:\program files\AGEIA Technologies

    .
    (((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-12-21 11:23 --------- d--h--w c:\program files\InstallShield Installation Information
    2008-12-14 10:39 --------- d-----w c:\documents and settings\Jussi Huhtala\Application Data\Propellerhead Software
    2008-12-13 18:31 --------- d-----w c:\program files\SystemRequirementsLab
    2008-12-13 18:15 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
    2008-12-13 18:14 71,656,960 ----a-w C:\180.48_geforce_winxp_32bit_english_whql.exe
    2008-12-13 18:04 --------- d-----w c:\program files\Opera 10 Preview
    2008-12-13 17:58 --------- d-----w c:\program files\Realtek
    2008-12-13 17:58 --------- d-----w c:\documents and settings\Jussi Huhtala\Application Data\InstallShield
    2008-12-13 17:43 --------- d-----w c:\program files\Mobile Partner
    2008-12-13 16:41 --------- d-----w c:\documents and settings\Jussi Huhtala\Application Data\MSN6
    2008-12-13 16:39 --------- d-----w c:\documents and settings\All Users\Application Data\MSN6
    2008-12-13 16:28 --------- d-----w c:\program files\Alwil Software
    2008-12-13 16:27 --------- d-----w c:\program files\Sunbelt Software
    2008-12-13 16:22 558,142 ----a-w c:\windows\java\Packages\LB9RNRRJ.ZIP
    2008-12-13 16:22 155,995 ----a-w c:\windows\java\Packages\93Z37HFV.ZIP
    2008-12-13 16:22 --------- d-----w c:\program files\microsoft frontpage
    2008-11-12 11:45 453,152 ----a-w c:\windows\system32\NVUNINST.EXE
    2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
    2008-10-23 12:38 286,720 ----a-w c:\windows\system32\gdi32.dll
    2008-10-16 12:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
    2008-10-16 12:12 561,688 ----a-w c:\windows\system32\wuapi.dll
    2008-10-16 12:12 323,608 ----a-w c:\windows\system32\wucltui.dll
    2008-10-16 12:12 202,776 ----a-w c:\windows\system32\wuweb.dll
    2008-10-16 12:09 92,696 ----a-w c:\windows\system32\cdm.dll
    2008-10-16 12:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
    2008-10-16 12:09 43,544 ----a-w c:\windows\system32\wups2.dll
    2008-10-16 12:08 34,328 ----a-w c:\windows\system32\wups.dll
    2008-10-16 01:01 666,112 ----a-w c:\windows\system32\wininet.dll
    2008-10-13 07:56 70,936 ----a-w c:\windows\system32\PhysXLoader.dll
    2008-10-03 10:03 247,326 ----a-w c:\windows\system32\strmdll.dll
    2008-10-02 23:46 81,920 ----a-w c:\windows\system32\frapsvid.dll
    2008-09-30 14:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
    .

    (((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "Google Update"="c:\documents and settings\Jussi Huhtala\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-12-14 133104]
    "BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-16 342848]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13672448]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-11-12 86016]
    "H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-10-23 385024]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-22 136600]
    "nwiz"="nwiz.exe" [2008-11-12 c:\windows\system32\nwiz.exe]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "midi1"= ma_cmidn.dll
    "msacm.avis"= ff_acm.acm

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
    "c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
    "c:\\Program Files\\DNA\\btdna.exe"=
    "c:\\Program Files\\BitTorrent\\bittorrent.exe"=
    "c:\\WINDOWS\\system32\\PnkBstrA.exe"=
    "c:\\WINDOWS\\system32\\PnkBstrB.exe"=
    "c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
    "c:\\Program Files\\NetMeeting\\conf.exe"=
    "c:\\Program Files\\Empire Interactive\\FlatOut Ultimate Carnage\\Fouc.exe"=

    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-13 111184]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-13 20560]
    R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-24 935208]
    R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\DRIVERS\cledx.sys [2008-12-19 33792]
    R3 L6TPortB;Service - Line 6 TonePort UX2;c:\windows\system32\Drivers\L6TPortB.sys [2008-12-14 530560]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{03e64dec-cdf2-11dd-88b9-001d7d9b19fd}]
    \Shell\AutoRun\command - E:\AutoRun.exe

    *Newly Created Service* - PROCEXP90
    .
    'Ajoitetut tehtävät'-kansion sisältö

    2008-12-23 c:\windows\Tasks\GoogleUpdateTaskUser.job
    - c:\documents and settings\Jussi Huhtala\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-14 20:06]
    .
    .
    ------- Täydentävä tarkistus -------
    .
    Trusted Zone: *.line6.net

    O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
    c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd

    O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

    c:\windows\Downloaded Program Files\sysreqlab_srl.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E}
    hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
    c:\windows\Downloaded Program Files\sysreqlab.osd
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-12-23 22:33:36
    Windows 5.1.2600 Service Pack 3 NTFS

    tarkistaa piilotettuja prosesseja ...

    tarkistaa piilotettuja käynnistysarvoja ...

    tarkistaa piilotettuja tiedostoja ...

    tarkistus on valmis
    piilotetut tiedostot: 0

    **************************************************************************
    .
    Valmistumisajankohta: 2008-12-23 22:34:02
    ComboFix-quarantined-files.txt 2008-12-23 20:33:58

    Ennen ajoa: 232 871 567 360 tavua vapaana
    Ajon jälkeen: 232,859,897,856 tavua vapaana

    WindowsXP-KB310994-SP2-Home-BootDisk-FIN.EXE
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

    254 --- E O F --- 2008-12-20 23:18:07
     
  3. Hubbbe

    Hubbbe Member

    Joined:
    Jul 11, 2007
    Messages:
    55
    Likes Received:
    0
    Trophy Points:
    16
  4. Hubbbe

    Hubbbe Member

    Joined:
    Jul 11, 2007
    Messages:
    55
    Likes Received:
    0
    Trophy Points:
    16
    tässä vielä javara loki:

    JavaRa 1.12 Removal Log.

    Report follows after line.

    ------------------------------------

    The JavaRa removal process was started on Tue Dec 23 22:37:41 2008

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

    ------------------------------------

    Finished reporting.


    Jos joku näistä jotain ymmärtää, niin helppaisitko?
    Ottaa pannuun kun g-aymailikaan ei lähde.

     

Share This Page