Tällaista combofix pisti
"Arto" - 07-01-18 21:42:24 Service Pack 2
ComboFix 07-01-18 - Running from: "G:\"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\INSTALL.LOG
((((((((((((((((((((((((((((((( Files Created from 2006-12-18 to 2007-01-18 ))))))))))))))))))))))))))))))))))
2007-01-13 22:33 51,072 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ikhlayer.sys
2007-01-13 22:33 30,592 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ikhfile.sys
2007-01-13 22:33 <KANSIO> d-a------ C:\DOCUME~1\ALLUSE~1\Application Data\TEMP
2007-01-13 22:33 <KANSIO> d-------- C:\Program Files\Spyware Doctor
2007-01-13 22:33 <KANSIO> d-------- C:\DOCUME~1\Arto\Application Data\PC Tools
2007-01-09 22:56 <KANSIO> d-------- C:\WINDOWS\ie7updates
2007-01-01 21:51 <KANSIO> d-------- C:\DOCUME~1\Arto\Application Data\CyberLink
2007-01-01 21:51 <KANSIO> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\CyberLink
2007-01-01 21:09 16,384 --a------ C:\WINDOWS\SYSTEM32\lgfwunis.exe
2007-01-01 21:09 102,912 --a------ C:\WINDOWS\SYSTEM32\Vb6stkit.dll
2007-01-01 21:09 102,160 --a------ C:\WINDOWS\SYSTEM32\VB6KO.DLL
2007-01-01 21:09 <KANSIO> d-------- C:\Program Files\lg_fwupdate
2007-01-01 20:57 <KANSIO> d-------- C:\Program Files\Common Files\LightScribe
2007-01-01 20:55 476,320 --------- C:\WINDOWS\SYSTEM32\ImagXpr7.dll
2007-01-01 20:55 471,040 --------- C:\WINDOWS\SYSTEM32\ImagXRA7.dll
2007-01-01 20:55 364,544 --------- C:\WINDOWS\SYSTEM32\TwnLib4.dll
2007-01-01 20:55 262,144 --------- C:\WINDOWS\SYSTEM32\ImagXR7.dll
2007-01-01 20:55 155,648 --a------ C:\WINDOWS\SYSTEM32\NeroCheck.exe
2007-01-01 20:55 106,496 --a------ C:\WINDOWS\SYSTEM32\TwnLib20.dll
2007-01-01 20:55 1,568,768 --------- C:\WINDOWS\SYSTEM32\ImagX7.dll
2007-01-01 20:55 <KANSIO> d-------- C:\Program Files\Common Files\Ahead
2007-01-01 20:55 <KANSIO> d-------- C:\Program Files\Ahead
2007-01-01 20:50 40,960 --a------ C:\Program Files\Uninstall_CDS.exe
2007-01-01 20:50 <KANSIO> d-------- C:\Program Files\CyberLink DVD Solution
2007-01-01 20:50 <KANSIO> d-------- C:\Program Files\CyberLink
2007-01-01 20:50 <KANSIO> d-------- C:\MyWorks
2006-12-24 10:46 442,368 -ra------ C:\WINDOWS\SYSTEM32\vp6vfw.dll
2006-12-24 10:46 <KANSIO> d-------- C:\Program Files\EA GAMES
2006-12-19 21:21 <KANSIO> d-------- C:\WINDOWS\SxsCaPendDel
2006-12-19 21:21 <KANSIO> d-------- C:\Program Files\Windows Defender
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-01-18 18:00 -------- d-------- C:\Program Files\symantec antivirus
2007-01-13 21:01 -------- d-------- C:\Program Files\google
2007-01-13 20:13 -------- d--h----- C:\Program Files\installshield installation information
2006-12-13 16:46 -------- d-------- C:\Program Files\ponygirl2
2006-12-07 17:02 2174976 --a------ C:\WINDOWS\SYSTEM32\wmvcore.dll
2006-11-21 12:24 32768 --a------ C:\WINDOWS\SYSTEM32\snmp.exe
2006-11-18 12:52 -------- d-------- C:\Program Files\msxml 4.0
2006-11-08 07:06 679424 --a------ C:\WINDOWS\SYSTEM32\inetcomm.dll
2006-11-07 21:03 6049280 --------- C:\WINDOWS\SYSTEM32\ieframe.dll
2006-11-07 21:03 50688 --------- C:\WINDOWS\SYSTEM32\msfeedsbs.dll
2006-11-07 21:03 458752 --------- C:\WINDOWS\SYSTEM32\msfeeds.dll
2006-11-07 21:03 413696 --a------ C:\WINDOWS\SYSTEM32\vbscript.dll
2006-11-07 21:03 231424 --a------ C:\WINDOWS\SYSTEM32\webcheck.dll
2006-11-07 21:03 180736 --------- C:\WINDOWS\SYSTEM32\ieui.dll
2006-11-07 21:03 156160 --a------ C:\WINDOWS\SYSTEM32\msls31.dll
2006-11-07 03:27 382976 --a------ C:\WINDOWS\SYSTEM32\iedkcs32.dll
2006-11-07 03:27 229376 --a------ C:\WINDOWS\SYSTEM32\ieaksie.dll
2006-11-07 03:26 71680 --a------ C:\WINDOWS\SYSTEM32\admparse.dll
2006-11-07 03:26 55296 --a------ C:\WINDOWS\SYSTEM32\iesetup.dll
2006-11-07 03:26 54784 --a------ C:\WINDOWS\SYSTEM32\ie4uinit.exe
2006-11-07 03:26 43008 --a------ C:\WINDOWS\SYSTEM32\iernonce.dll
2006-11-07 03:26 152064 --a------ C:\WINDOWS\SYSTEM32\ieakeng.dll
2006-11-07 03:26 13312 --a------ C:\WINDOWS\SYSTEM32\ieudinit.exe
2006-11-07 03:26 123904 --a------ C:\WINDOWS\SYSTEM32\advpack.dll
2006-11-07 03:25 161792 --a------ C:\WINDOWS\SYSTEM32\ieakui.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\SYSTEM32\msxml4.dll
2006-10-20 03:39 713728 --a------ C:\WINDOWS\SYSTEM32\sxs.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"RemoteControl"="\"C:\\Program Files\\CyberLink DVD Solution\\PowerDVD\\PDVDServ.exe\""
"PCSuiteTrayApplication"="C:\\Program Files\\Nokia\\Nokia PC Suite 6\\LaunchApplication.exe -onlytray"
"nwiz"="nwiz.exe /install"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"LXBRKsk"="C:\\PROGRA~1\\LEXMAR~1\\LXBRKsk.exe"
"LGODDFU"="\"C:\\Program Files\\lg_fwupdate\\fwupdate.exe\""
"Lexmark 3100 Series"="\"C:\\Program Files\\Lexmark 3100 Series\\lxbrbmgr.exe\""
"DataLayer"="C:\\Program Files\\Common Files\\PCSuite\\DataLayer\\DataLayer.exe"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"AdaptecDirectCD"="\"C:\\Program Files\\Roxio\\Easy CD Creator 5\\DirectCD\\DirectCD.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
"PcSync"="C:\\Program Files\\Nokia\\Nokia PC Suite 6\\PcSync2.exe /NoDialog"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"system"="kdjmc.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"="183gxvtf96m.dll"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NVMCTRAY.DLL,NvTaskbarInit"
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NVMCTRAY.DLL,NvTaskbarInit"
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoFileUrl"=dword:00000001
"CDRAutoRun"=hex:00,00,00,00
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source REG_SZ
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\B11E7E5A91D1EE7A.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\XoftSpy.job
Completion time: 07-01-18 21:47:07
|