Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 7:44:54, on 7.6.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Billionton\Bluetooth-ohjelmisto\bin\btwdins.exe C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE C:\WINDOWS\runservice.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Raxco\PerfectDisk\PDSched.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Billionton\Bluetooth-ohjelmisto\BTTray.exe C:\WINDOWS\system32\devldr32.exe C:\PROGRA~1\BILLIO~1\BLUETO~1\BTSTAC~1.EXE C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\WINDOWS\explorer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: Adobe PDF Reader -linkkiavustaja - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user') O4 - S-1-5-18 Startup: No-IP DUC.lnk = C:\Program Files\No-IP\DUC20.exe (User 'SYSTEM') O4 - .DEFAULT Startup: No-IP DUC.lnk = C:\Program Files\No-IP\DUC20.exe (User 'Default user') O4 - Startup: No-IP DUC.lnk = C:\Program Files\No-IP\DUC20.exe O4 - Global Startup: BTTray.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Lähetä &Bluetooth-laitteeseen - C:\Program Files\Billionton\Bluetooth-ohjelmisto\btsendto_ie_ctx.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Billionton\Bluetooth-ohjelmisto\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Billionton\Bluetooth-ohjelmisto\btsendto_ie.htm O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by124w.bay124.mail.live.com/mail/resources/MsnPUpld.cab O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Autodata Limited License Service - Autodata Limited - C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Billionton\Bluetooth-ohjelmisto\bin\btwdins.exe O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe O23 - Service: NBService - Nero AG - D:\Program Files\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- End of file - 7892 bytes Ja combofixi logi: ComboFix 08-06-06.6 - Marko 2008-06-07 7:34:57.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.582 [GMT 3:00] Running from: C:\Documents and Settings\Marko\Työpöytä\ComboFix.exe * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . (((((((((((((((((((((((((((((((((((((( Muut poistot )))))))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\ups.exe . ((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-07 to 2008-06-07 ))))))))))))))))) . 2008-06-06 00:14 . 2008-06-06 13:12 2,232 --a------ C:\f.MSNFix 2008-06-05 19:30 . 2008-06-05 21:41 <KANSIO> d-------- C:\Program Files\Winamp Remote 2008-06-05 19:30 . 2008-06-06 07:21 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\OrbNetworks 2008-06-05 00:15 . 2008-06-05 00:15 290,110 --a------ C:\WINDOWS\ftp.exe 2008-06-04 18:09 . 2008-06-04 18:09 3,424 --a------ C:\is155400.exe 2008-06-04 17:51 . 2008-06-04 17:51 <KANSIO> d-------- C:\Program Files\Zittware 2008-06-04 17:50 . 2002-07-17 10:03 45,056 --a------ C:\WINDOWS\system32\WNASPI32.DLL 2008-06-04 17:50 . 2002-07-17 09:05 16,512 --a------ C:\WINDOWS\system32\drivers\ASPI32.SYS 2008-06-04 17:50 . 2002-07-17 16:22 5,600 --a------ C:\WINDOWS\system\winaspi.dll 2008-06-04 17:50 . 2002-07-17 16:22 4,672 --a------ C:\WINDOWS\system\wowpost.exe 2008-06-04 17:37 . 2008-06-04 17:37 <KANSIO> d-------- C:\Program Files\Bonjour 2008-06-04 17:37 . 2008-06-04 17:37 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Remote Speakers output 2008-06-04 14:31 . 2008-06-05 12:31 3,420 --a------ C:\bot.MSNFix 2008-06-04 12:56 . 2008-06-04 12:56 <KANSIO> d-------- C:\bt_cam_data 2008-06-04 11:24 . 2008-06-04 11:24 <KANSIO> d-------- C:\Documents and Settings\Marko\Application Data\ifolor 2008-06-04 11:23 . 2008-06-04 11:23 <KANSIO> d-------- C:\Program Files\ifolor 2008-06-04 11:23 . 2008-06-04 11:23 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\ifolor 2008-06-04 10:24 . 2008-06-04 13:31 3,423 --a------ C:\WINDOWS\is154890.exe 2008-06-03 08:28 . 2008-06-03 08:28 96,950 --a------ C:\WINDOWS\mservice.MSNFix 2008-05-31 20:18 . 2008-06-03 18:32 86,548 --a------ C:\WINDOWS\service.MSNFix 2008-05-24 20:12 . 2008-05-24 20:12 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Azureus . (((((((((((((((((((((((((((((((((((( Find3M-raportti )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-06-03 09:49 --------- d-----w C:\Program Files\DAEMON Tools 2008-05-25 07:45 --------- d-----w C:\Documents and Settings\Marko\Application Data\Azureus 2008-05-24 18:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations 2008-05-24 17:12 --------- d-----w C:\Program Files\Azureus 2008-05-20 11:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help 2008-05-08 14:40 --------- d-----w C:\Program Files\Windows Live 2008-05-08 14:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller 2008-05-07 16:14 --------- d-----w C:\Program Files\Messenger Plus! Live 2008-05-07 16:09 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-05-07 16:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\flag ace stupid data 2008-05-06 13:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-05-06 13:46 --------- d-----w C:\Program Files\Spybot - Search & Destroy 2008-05-06 13:42 691,545 ----a-w C:\WINDOWS\unins000.exe 2008-04-17 06:12 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf 2008-04-17 06:11 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf 2008-04-17 06:10 --------- d-----w C:\Program Files\Nokia 2008-04-17 05:33 --------- d-----w C:\Program Files\Common Files\PCSuite 2008-04-17 05:33 --------- d-----w C:\Program Files\Common Files\Nokia 2008-04-17 05:32 --------- d-----w C:\Program Files\PC Connectivity Solution 2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll 2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll 2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys 2007-01-20 13:13 87,608 ----a-w C:\Documents and Settings\Marko\Application Data\ezpinst.exe 2007-01-20 13:13 47,360 ----a-w C:\Documents and Settings\Marko\Application Data\pcouffin.sys . (((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet ))))))))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184] "NvCplDaemon"="NvQTwk" [] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-14 16:12 15360] "Orb"="C:\Program Files\Winamp Remote\bin\OrbTray.exe" [2008-04-01 04:54 507904] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-16 02:19 79224] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22 7700480] "nwiz"="nwiz.exe" [2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2008-03-26 18:41 1232896] C:\Documents and Settings\Marko\K„ynnist„-valikko\Ohjelmat\K„ynnistys\ No-IP DUC.lnk - C:\Program Files\No-IP\DUC20.exe [2007-01-12 10:18:22 1172992] C:\Documents and Settings\Marko\K„ynnist„-valikko\Ohjelmat\K„ynnistys\ No-IP DUC.lnk - C:\Program Files\No-IP\DUC20.exe [2007-01-12 10:18:22 1172992] C:\Documents and Settings\Marko\K„ynnist„-valikko\Ohjelmat\K„ynnistys\ No-IP DUC.lnk - C:\Program Files\No-IP\DUC20.exe [2007-01-12 10:18:22 1172992] C:\Documents and Settings\All Users\K„ynnist„-valikko\Ohjelmat\K„ynnistys\ BTTray.lnk - C:\Program Files\Billionton\Bluetooth-ohjelmisto\BTTray.exe [2003-12-01 15:28:00 499779] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"= ctwdm32.dll "vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Azureus\\Azureus.exe"= "C:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"= "D:\\Program Files\\America's Army\\System\\ArmyOps.exe"= "D:\\Program Files\\Nero 7\\Nero Home\\NeroHome.exe"= "D:\\Program Files\\DC++\\DCPlusPlus.exe"= "D:\\Program Files\\RevConnect\\DCPlusPlus.exe"= "C:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"= "D:\\Downloads\\ynhub102\\ynhub102\\YnHub.exe"= "D:\\Program Files\\Nero 7\\Nero ShowTime\\ShowTime.exe"= "D:\\Program Files\\ApexDC++\\ApexDC.exe"= "D:\\Program Files\\YnHub1.033\\YnHub1.033\\YnHub.exe"= "D:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "D:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "D:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "D:\\Program Files\\WASTE\\WASTE.exe"= "C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"= "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"= "C:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"= "D:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic.exe"= "D:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_online.exe"= "D:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_ds.exe"= "C:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"= "C:\\Program Files\\Skype\\Phone\\Skype.exe"= "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= R0 Defrag32b;Defrag32Boot;C:\WINDOWS\system32\drivers\Defrag32b.sys [2005-11-22 11:33] R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16] R2 Defrag32;Defrag32;C:\WINDOWS\system32\drivers\Defrag32.sys [2005-11-22 11:33] R2 LicCtrlService;LicCtrl Service;C:\WINDOWS\runservice.exe [2007-09-18 20:17] R2 PDSched;PDScheduler;"C:\Program Files\Raxco\PerfectDisk\PDSched.exe" [2005-11-29 11:16] S3 BTCAMDRV;Mobiola Web Camera driver;C:\WINDOWS\system32\DRIVERS\BTCamDrv.sys [2006-11-01 19:45] S3 MBLAUDRV;Mobiola Audio Service;C:\WINDOWS\system32\drivers\BTCamAudioDrv.sys [2007-07-31 14:27] S3 Nic_dprfsb;Nic_dprfsb;C:\WINDOWS\system32\drivers\dxg.sys [2004-08-03 23:00] S3 pccsmcfd;PCCS Mode Change Filter Driver;C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 15:53] S3 pctvvbi;PCTVVBI;C:\WINDOWS\system32\DRIVERS\pctvvbi.sys [2002-04-02 15:05] S3 SunkFilt6;Alcor Micro Corp - 6360;C:\WINDOWS\System32\Drivers\sunkfilt6.sys [] S3 SunkFilt62;Alcor Micro Corp - 6362;C:\WINDOWS\System32\Drivers\sunkfilt62.sys [2004-07-23 14:55] S3 TFBULK;Topfield USB client driver;C:\WINDOWS\system32\drivers\TfBulk.sys [2003-08-26 14:11] S3 upperdev;upperdev;C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2007-11-29 10:39] S3 UsbserFilt;UsbserFilt;C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2007-11-29 10:39] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{486642e0-7d96-11dc-828d-001060a71506}] \Shell\AutoRun\command - N:\InstallTomTomHOME.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{81958371-02d2-11dd-82bc-001d7d326040}] \Shell\AutoRun\command - H:\InstallTomTomHOME.exe *Newly Created Service* - CATCHME . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-06-07 07:36:12 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-06-07 7:37:04 ComboFix-quarantined-files.txt 2008-06-07 04:36:41 Pre-Run: 17,771,073,536 tavua vapaana Post-Run: 17,917,784,064 tavua vapaana 152 --- E O F --- 2008-05-20 11:01:20 Voisko joku auttaa tään pohjalta? Kiitos!
Avaa Muistio ja kopioi/liitä quoteboxin sisältö sinne: Tallenna se nimellä CFScript.txt Sitten raahaa CFScript ComboFix.exeen kuten alla. Käynnistä tietokone uudelleen pyydettäessä ja lähetä combofix.txt-tiedoston sisältö tänne.
ComboFix 08-06-06.6 - Marko 2008-06-09 12:26:02.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1035.18.551 [GMT 3:00] Running from: C:\Documents and Settings\Marko\Työpöytä\ComboFix.exe Command switches used :: C:\Documents and Settings\Marko\Työpöytä\CFScript.txt * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! FILE :: C:\bot.MSNFix C:\f.MSNFix C:\is155400.exe C:\WINDOWS\is154890.exe C:\WINDOWS\mservice.MSNFix C:\WINDOWS\service.MSNFix . (((((((((((((((((((((((((((((((((((((( Muut poistot )))))))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\bot.MSNFix C:\f.MSNFix C:\is155400.exe C:\WINDOWS\is154890.exe C:\WINDOWS\mservice.MSNFix C:\WINDOWS\service.MSNFix . ((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2008-05-09 to 2008-06-09 ))))))))))))))))) . 2008-06-07 07:43 . 2008-06-07 07:43 <KANSIO> d-------- C:\Program Files\Trend Micro 2008-06-05 19:30 . 2008-06-05 21:41 <KANSIO> d-------- C:\Program Files\Winamp Remote 2008-06-05 19:30 . 2008-06-06 07:21 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\OrbNetworks 2008-06-05 00:15 . 2008-06-05 00:15 290,110 --a------ C:\WINDOWS\ftp.exe 2008-06-04 17:51 . 2008-06-04 17:51 <KANSIO> d-------- C:\Program Files\Zittware 2008-06-04 17:50 . 2002-07-17 10:03 45,056 --a------ C:\WINDOWS\system32\WNASPI32.DLL 2008-06-04 17:50 . 2002-07-17 09:05 16,512 --a------ C:\WINDOWS\system32\drivers\ASPI32.SYS 2008-06-04 17:50 . 2002-07-17 16:22 5,600 --a------ C:\WINDOWS\system\winaspi.dll 2008-06-04 17:50 . 2002-07-17 16:22 4,672 --a------ C:\WINDOWS\system\wowpost.exe 2008-06-04 17:37 . 2008-06-04 17:37 <KANSIO> d-------- C:\Program Files\Bonjour 2008-06-04 17:37 . 2008-06-04 17:37 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Remote Speakers output 2008-06-04 12:56 . 2008-06-04 12:56 <KANSIO> d-------- C:\bt_cam_data 2008-06-04 11:24 . 2008-06-04 11:24 <KANSIO> d-------- C:\Documents and Settings\Marko\Application Data\ifolor 2008-06-04 11:23 . 2008-06-04 11:23 <KANSIO> d-------- C:\Program Files\ifolor 2008-06-04 11:23 . 2008-06-04 11:23 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\ifolor 2008-05-24 20:12 . 2008-05-24 20:12 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Azureus . (((((((((((((((((((((((((((((((((((( Find3M-raportti )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-06-03 09:49 --------- d-----w C:\Program Files\DAEMON Tools 2008-05-25 07:45 --------- d-----w C:\Documents and Settings\Marko\Application Data\Azureus 2008-05-24 18:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations 2008-05-24 17:12 --------- d-----w C:\Program Files\Azureus 2008-05-20 11:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help 2008-05-08 14:40 --------- d-----w C:\Program Files\Windows Live 2008-05-08 14:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller 2008-05-07 16:14 --------- d-----w C:\Program Files\Messenger Plus! Live 2008-05-07 16:09 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-05-07 16:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\flag ace stupid data 2008-05-06 13:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-05-06 13:46 --------- d-----w C:\Program Files\Spybot - Search & Destroy 2008-05-06 13:42 691,545 ----a-w C:\WINDOWS\unins000.exe 2008-04-17 06:12 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf 2008-04-17 06:11 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf 2008-04-17 06:10 --------- d-----w C:\Program Files\Nokia 2008-04-17 05:33 --------- d-----w C:\Program Files\Common Files\PCSuite 2008-04-17 05:33 --------- d-----w C:\Program Files\Common Files\Nokia 2008-04-17 05:32 --------- d-----w C:\Program Files\PC Connectivity Solution 2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll 2008-03-25 04:51 166,688 ----a-w C:\WINDOWS\system32\msjint40.dll 2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys 2007-01-20 13:13 87,608 ----a-w C:\Documents and Settings\Marko\Application Data\ezpinst.exe 2007-01-20 13:13 47,360 ----a-w C:\Documents and Settings\Marko\Application Data\pcouffin.sys . (((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet ))))))))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184] "NvCplDaemon"="NvQTwk" [] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-14 16:12 15360] "Orb"="C:\Program Files\Winamp Remote\bin\OrbTray.exe" [2008-04-01 04:54 507904] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-16 02:19 79224] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22 7700480] "nwiz"="nwiz.exe" [2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2008-03-26 18:41 1232896] C:\Documents and Settings\Marko\K„ynnist„-valikko\Ohjelmat\K„ynnistys\ No-IP DUC.lnk - C:\Program Files\No-IP\DUC20.exe [2007-01-12 10:18:22 1172992] C:\Documents and Settings\Marko\K„ynnist„-valikko\Ohjelmat\K„ynnistys\ No-IP DUC.lnk - C:\Program Files\No-IP\DUC20.exe [2007-01-12 10:18:22 1172992] C:\Documents and Settings\Marko\K„ynnist„-valikko\Ohjelmat\K„ynnistys\ No-IP DUC.lnk - C:\Program Files\No-IP\DUC20.exe [2007-01-12 10:18:22 1172992] C:\Documents and Settings\All Users\K„ynnist„-valikko\Ohjelmat\K„ynnistys\ BTTray.lnk - C:\Program Files\Billionton\Bluetooth-ohjelmisto\BTTray.exe [2003-12-01 15:28:00 499779] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"= ctwdm32.dll "vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Azureus\\Azureus.exe"= "C:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"= "D:\\Program Files\\America's Army\\System\\ArmyOps.exe"= "D:\\Program Files\\Nero 7\\Nero Home\\NeroHome.exe"= "D:\\Program Files\\DC++\\DCPlusPlus.exe"= "D:\\Program Files\\RevConnect\\DCPlusPlus.exe"= "C:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"= "D:\\Downloads\\ynhub102\\ynhub102\\YnHub.exe"= "D:\\Program Files\\Nero 7\\Nero ShowTime\\ShowTime.exe"= "D:\\Program Files\\ApexDC++\\ApexDC.exe"= "D:\\Program Files\\YnHub1.033\\YnHub1.033\\YnHub.exe"= "D:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "D:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "D:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "D:\\Program Files\\WASTE\\WASTE.exe"= "C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"= "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"= "C:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"= "D:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic.exe"= "D:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_online.exe"= "D:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_ds.exe"= "C:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"= "C:\\Program Files\\Skype\\Phone\\Skype.exe"= "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= R0 Defrag32b;Defrag32Boot;C:\WINDOWS\system32\drivers\Defrag32b.sys [2005-11-22 11:33] R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16] R2 Defrag32;Defrag32;C:\WINDOWS\system32\drivers\Defrag32.sys [2005-11-22 11:33] R2 LicCtrlService;LicCtrl Service;C:\WINDOWS\runservice.exe [2007-09-18 20:17] R2 PDSched;PDScheduler;"C:\Program Files\Raxco\PerfectDisk\PDSched.exe" [2005-11-29 11:16] S3 BTCAMDRV;Mobiola Web Camera driver;C:\WINDOWS\system32\DRIVERS\BTCamDrv.sys [2006-11-01 19:45] S3 MBLAUDRV;Mobiola Audio Service;C:\WINDOWS\system32\drivers\BTCamAudioDrv.sys [2007-07-31 14:27] S3 Nic_dprfsb;Nic_dprfsb;C:\WINDOWS\system32\drivers\dxg.sys [2004-08-03 23:00] S3 pccsmcfd;PCCS Mode Change Filter Driver;C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 15:53] S3 pctvvbi;PCTVVBI;C:\WINDOWS\system32\DRIVERS\pctvvbi.sys [2002-04-02 15:05] S3 SunkFilt6;Alcor Micro Corp - 6360;C:\WINDOWS\System32\Drivers\sunkfilt6.sys [] S3 SunkFilt62;Alcor Micro Corp - 6362;C:\WINDOWS\System32\Drivers\sunkfilt62.sys [2004-07-23 14:55] S3 TFBULK;Topfield USB client driver;C:\WINDOWS\system32\drivers\TfBulk.sys [2003-08-26 14:11] S3 upperdev;upperdev;C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2007-11-29 10:39] S3 UsbserFilt;UsbserFilt;C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2007-11-29 10:39] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{486642e0-7d96-11dc-828d-001060a71506}] \Shell\AutoRun\command - N:\InstallTomTomHOME.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{81958371-02d2-11dd-82bc-001d7d326040}] \Shell\AutoRun\command - H:\InstallTomTomHOME.exe *Newly Created Service* - CATCHME . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-06-09 12:27:06 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-06-09 12:27:51 ComboFix-quarantined-files.txt 2008-06-09 09:27:35 ComboFix2.txt 2008-06-07 04:37:05 Pre-Run: 17,849,802,752 tavua vapaana Post-Run: 17,837,158,400 tavua vapaana 161 --- E O F --- 2008-05-20 11:01:20