Omistaja - 06-12-07 17:24:44,95 Service Pack 2
ComboFix 06.11.27W - Running from: "C:\Documents and Settings\Omistaja\Ty?p?yt?"
((((((((((((((((((((((((((((((( Files Created from 2006-11-07 to 2006-12-07 ))))))))))))))))))))))))))))))))))
2006-12-05 11:35 <KANSIO> d-------- C:\Downloads
2006-12-05 11:35 <KANSIO> d-------- C:\Bases
2006-12-01 12:31 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Samsung
2006-12-01 12:25 80,272 -ra------ C:\WINDOWS\system32\drivers\sscdbus.sys
2006-12-01 12:25 137,884 -ra------ C:\WINDOWS\system32\drivers\sscdmdm.sys
2006-12-01 12:25 11,877 -ra------ C:\WINDOWS\system32\drivers\sscdcmnt.sys
2006-12-01 12:25 11,877 -ra------ C:\WINDOWS\system32\drivers\sscdcm.sys
2006-12-01 12:25 11,188 -ra------ C:\WINDOWS\system32\drivers\sscdwhnt.sys
2006-12-01 12:25 11,188 -ra------ C:\WINDOWS\system32\drivers\sscdwh.sys
2006-12-01 12:25 10,864 -ra------ C:\WINDOWS\system32\drivers\sscdmdfl.sys
2006-11-30 16:22 <KANSIO> d-------- C:\Documents and Settings\Omistaja\Application Data\Apple Computer
2006-11-30 16:21 <KANSIO> d-------- C:\Documents and Settings\Omistaja\Application Data\ConvertTemp
2006-11-30 16:17 <KANSIO> d-------- C:\Documents and Settings\Omistaja\Application Data\Samsung
2006-11-30 07:40 <KANSIO> d-------- C:\Program Files\MSXML 4.0
2006-11-30 07:40 <KANSIO> d-------- C:\4180c0c0331758c11361
2006-11-29 16:30 77,824 --a------ C:\WINDOWS\system32\fun_mp4_dec.dll
2006-11-29 16:30 684,032 --a------ C:\WINDOWS\system32\fun_mp4_enc.dll
2006-11-29 16:30 2,729,472 --a------ C:\WINDOWS\system32\fun_avcodec.dll
2006-11-29 16:30 <KANSIO> d-------- C:\WINDOWS\system32\Samsung PC Studio Codecs
2006-11-29 16:01 <KANSIO> d-------- C:\WINDOWS\system32\Samsung_USB_Drivers
2006-11-29 16:01 <KANSIO> d-------- C:\Program Files\Samsung
2006-11-29 14:40 <KANSIO> d-------- C:\Documents and Settings\Omistaja\Application Data\Adobe
2006-11-23 18:54 <KANSIO> d-------- C:\Kaspersky
2006-11-19 18:12 <KANSIO> d-------- C:\Documents and Settings\All Users\Application Data\Google
2006-11-17 12:49 <KANSIO> d-------- C:\Program Files\eMule
2006-11-14 19:11 <KANSIO> d--hs---- C:\found.001
2006-11-13 15:11 <KANSIO> d-------- C:\Program Files\MaxMusic
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-12-04 16:00 -------- d-------- C:\Program Files\hijack this
2006-12-04 15:46 -------- d-------- C:\Program Files\DC++
2006-12-01 13:27 -------- d---s---- C:\Documents and Settings\Omistaja\Application Data\Microsoft
2006-12-01 12:32 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-11-30 16:14 -------- d-------- C:\Program Files\BitComet
2006-11-28 18:35 -------- d-------- C:\Program Files\Google
2006-11-28 14:40 -------- d-------- C:\Program Files\QuickTime
2006-11-28 14:06 -------- d-------- C:\Program Files\Apple Software Update
2006-11-19 17:56 -------- d-------- C:\Program Files\Internet Explorer
2006-11-19 17:51 -------- d-------- C:\Program Files\Java
2006-11-09 16:11 -------- d-------- C:\Program Files\Paint Shop Pro 6
2006-11-04 15:55 -------- d-------- C:\Documents and Settings\Omistaja\Application Data\Template
2006-11-04 15:54 0 --a------ C:\Documents and Settings\Omistaja\Application Data\wklnhst.dat
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
2006-10-13 14:37 142336 --a------ C:\WINDOWS\system32\nwprovau.dll
2006-09-13 07:03 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"ares"="\"C:\\Program Files\\Ares\\Ares.exe\" -h"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe\""
"SoundMan"="SOUNDMAN.EXE"
"ATIPTA"="C:\\ATI-CPanel\\atiptaxx.exe"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"F-Secure Manager"="\"C:\\Program Files\\Sonera Tietoturva\\Common\\FSM32.EXE\" /splash"
"F-Secure TNB"="\"C:\\Program Files\\Sonera Tietoturva\\TNB\\TNBUtil.exe\" /CHECKALL /WAITFORSW"
"F-Secure Startup Wizard"="\"C:\\Program Files\\Sonera Tietoturva\\FSGUI\\FSSW.EXE\" /reboot"
"News Service"="\"C:\\Program Files\\Sonera Tietoturva\\FSGUI\\ispnews.exe\""
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Nykyinen kotisivu"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,23,00,00,00,7c,00,00,00,72,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
Completion time: 06-12-07 17:25:59.89
C:\ComboFix.txt ... 06-12-07 17:25
|