Hey.
I had some problems at first with combofix. I had to uninstall every virus and malware software to be sure it would work. Also it seemed as if I clicked anywhere when combo was working it would freeze.
So I finally managed to get it to work by not touching anything while it was running. Combo found an infected Services.exe and succesfully replaced it. Everything seems to be working correctly now.
Thank you very much for the help. You saved me a ton of work as I don't have to do a total system reinstallation.
Oh, and here's the combofix log. It's in finnish, but I think you understand what you need from it. ;)
ComboFix 12-06-10.01 - Daemon 11.06.2012 0:47.1.3 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.358.1033.18.4094.2789 [GMT 3:00]
Sijainti: c:\users\Daemon\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\assembly\GAC_32\Desktop.ini
c:\windows\assembly\GAC_64\Desktop.ini
c:\windows\SysWow64\muzapp.exe
.
Saastunut kopio tiedostosta c:\windows\system32\Services.exe löytyi ja poistettiin
Puhdas kopio palautettiin paikasta - c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
.
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2012-05-10 to 2012-06-10 )))))))))))))))))
.
.
2012-06-11 06:08 . 2012-06-11 06:09 -------- d-----w- C:\FRST
2012-06-10 21:53 . 2012-06-10 21:53 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-06-10 21:53 . 2012-06-10 21:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-10 21:30 . 2012-06-10 21:30 -------- d-----w- c:\windows\18F97AF04F884494AFE25A5702E142CC.TMP
2012-06-10 21:24 . 2012-06-10 21:24 7021336 ----a-w- c:\users\UpdatusUser\AppData\Roaming\wruninstall.exe
2012-06-10 19:36 . 2012-06-10 19:36 -------- d-----w- c:\users\Daemon\AppData\Roaming\Process Hacker 2
2012-06-10 19:19 . 2012-06-10 19:19 -------- d-----w- C:\HDTVPlayer
2012-06-10 17:46 . 2012-06-10 17:46 -------- d-----w- c:\program files\Process Hacker 2
2012-06-10 17:32 . 2012-06-10 17:32 -------- d-----w- c:\users\Daemon\AppData\Local\SvchostViewer
2012-06-10 17:17 . 2012-06-10 17:17 -------- d-----w- c:\program files (x86)\DLLSuite
2012-06-10 14:50 . 2012-06-10 14:50 -------- d-----w- c:\users\Daemon\AppData\Local\lptmp288632729
2012-06-09 16:10 . 2012-06-09 16:10 -------- d-sh--w- c:\windows\SysWow64\%APPDATA%
2012-06-09 16:10 . 2012-06-09 16:10 -------- d-----w- c:\program files\Enigma Software Group
2012-06-09 16:09 . 2012-06-09 16:09 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2012-06-09 15:59 . 2012-06-09 16:48 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2012-06-09 15:59 . 2012-06-09 16:01 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2012-06-09 15:52 . 2012-06-09 15:52 388096 ----a-r- c:\users\Daemon\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-06-09 15:52 . 2012-06-09 15:52 -------- d-----w- c:\program files (x86)\Trend Micro
2012-06-09 09:58 . 2012-06-09 09:58 -------- d-----w- c:\users\Daemon\AppData\Roaming\Malwarebytes
2012-06-09 09:58 . 2012-06-09 15:44 -------- d-----w- c:\programdata\Malwarebytes
2012-06-09 07:51 . 2012-06-09 07:51 -------- d-----w- c:\program files (x86)\Kalypso
2012-06-06 14:51 . 2012-06-06 15:15 -------- d-----w- c:\programdata\RELOADED
2012-06-03 14:51 . 2012-06-09 07:53 -------- d-----w- c:\users\Daemon\AppData\Local\SKIDROW
2012-06-03 14:51 . 2012-06-03 14:51 -------- d-----w- c:\users\Daemon\AppData\Roaming\Sports Interactive
2012-06-03 14:51 . 2012-06-03 14:51 -------- d-----w- c:\users\Daemon\AppData\Local\Sports Interactive
2012-06-03 14:43 . 2012-06-03 14:43 -------- d-----w- c:\program files (x86)\SEGA
2012-06-02 05:52 . 2012-06-04 12:51 -------- d-----w- C:\yes
2012-05-28 13:30 . 2012-05-28 13:30 -------- d-----w- c:\windows\SysWow64\System32
2012-05-24 13:11 . 2012-05-15 10:48 8139072 ----a-w- c:\windows\system32\nvcuda.dll
2012-05-24 13:11 . 2012-05-15 10:48 5982528 ----a-w- c:\windows\SysWow64\nvcuda.dll
2012-05-24 13:11 . 2012-05-15 10:48 2881856 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-05-24 13:11 . 2012-05-15 10:48 2681664 ----a-w- c:\windows\system32\nvcuvid.dll
2012-05-24 13:11 . 2012-05-15 10:48 25743168 ----a-w- c:\windows\system32\nvoglv64.dll
2012-05-24 13:11 . 2012-05-15 10:48 2524992 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2012-05-24 13:11 . 2012-05-15 10:48 25248064 ----a-w- c:\windows\system32\nvcompiler.dll
2012-05-24 13:11 . 2012-05-15 10:48 2445120 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2012-05-24 13:11 . 2012-05-15 10:48 19607872 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2012-05-24 13:11 . 2012-05-15 10:48 18044224 ----a-w- c:\windows\system32\nvd3dumx.dll
2012-05-24 13:11 . 2012-05-15 10:48 17551680 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2012-05-24 13:11 . 2012-05-15 10:48 14298944 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2012-05-24 12:48 . 2012-05-24 12:48 -------- d-----w- c:\program files\Microsoft Silverlight
2012-05-24 12:48 . 2012-05-24 12:48 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2012-05-23 13:51 . 2012-05-23 13:51 -------- d-----w- c:\users\Daemon\AppData\Roaming\f-secure
2012-05-23 13:51 . 2012-05-23 13:51 -------- d-----w- c:\programdata\F-Secure
2012-05-23 13:47 . 2012-05-23 13:47 -------- d-----w- c:\programdata\boost_interprocess
2012-05-20 11:54 . 2012-06-09 14:58 -------- d-----w- c:\program files (x86)\Cubemen
2012-05-17 08:03 . 2012-05-17 08:03 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2012-05-17 08:03 . 2012-05-17 08:03 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2012-05-17 08:03 . 2012-05-17 08:03 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2012-05-17 08:03 . 2012-05-17 08:03 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2012-05-17 08:03 . 2012-05-17 08:03 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2012-05-17 08:03 . 2012-05-17 08:03 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2012-05-17 08:03 . 2012-05-17 08:03 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2012-05-17 08:03 . 2012-05-17 08:03 -------- d-----w- c:\program files (x86)\QuickTime
2012-05-14 23:21 . 2012-05-14 23:21 423744 ----a-w- c:\windows\SysWow64\nvStreaming.exe
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-02 09:56 . 2012-03-28 08:17 15672 ----a-w- c:\windows\system32\drivers\SWDUMon.sys
2012-05-15 10:48 . 2012-03-23 15:35 8105280 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2012-05-15 10:48 . 2012-03-23 15:35 68928 ----a-w- c:\windows\system32\OpenCL.dll
2012-05-15 10:48 . 2012-03-23 15:35 61248 ----a-w- c:\windows\SysWow64\OpenCL.dll
2012-05-15 10:48 . 2012-03-23 15:35 1738048 ----a-w- c:\windows\system32\nvdispco64.dll
2012-05-15 10:48 . 2012-03-23 15:35 1468224 ----a-w- c:\windows\system32\nvgenco64.dll
2012-05-15 10:48 . 2012-03-23 15:35 2741568 ----a-w- c:\windows\system32\nvapi64.dll
2012-05-15 10:48 . 2012-03-23 15:35 2368832 ----a-w- c:\windows\SysWow64\nvapi.dll
2012-05-15 10:48 . 2009-07-13 21:59 10194752 ----a-w- c:\windows\system32\nvwgf2umx.dll
2012-05-15 10:48 . 2009-06-10 20:37 15322432 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2012-05-15 09:29 . 2012-03-23 15:36 889664 ----a-w- c:\windows\system32\nvvsvc.exe
2012-05-15 09:29 . 2012-03-23 15:36 63296 ----a-w- c:\windows\system32\nvshext.dll
2012-05-15 09:29 . 2012-03-23 15:36 118080 ----a-w- c:\windows\system32\nvmctray.dll
2012-05-15 09:29 . 2012-03-23 15:36 3149632 ----a-w- c:\windows\system32\nvsvc64.dll
2012-05-15 09:28 . 2012-03-23 15:36 6151488 ----a-w- c:\windows\system32\nvcpl.dll
2012-05-06 11:59 . 2012-03-23 19:30 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2012-05-06 11:59 . 2012-03-23 19:30 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-05-06 11:59 . 2012-03-23 19:30 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2012-05-06 11:59 . 2012-03-23 19:30 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2012-05-05 18:57 . 2012-04-01 08:11 419488 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-05-05 18:57 . 2012-03-23 15:46 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-05 18:57 . 2012-04-01 08:57 8744608 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-04-18 17:56 . 2012-04-18 17:56 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2012-04-18 17:56 . 2012-04-18 17:56 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
2012-03-31 06:05 . 2012-05-09 16:08 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-03-31 04:39 . 2012-05-09 16:08 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-03-31 04:39 . 2012-05-09 16:08 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-03-31 03:10 . 2012-05-09 16:08 3146240 ----a-w- c:\windows\system32\win32k.sys
2012-03-30 11:35 . 2012-05-09 16:08 1918320 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-03-28 19:11 . 2012-04-29 08:23 4659712 ----a-w- c:\windows\SysWow64\Redemption.dll
2012-03-28 19:11 . 2012-03-28 19:11 90112 ----a-w- c:\windows\MAMCityDownload.ocx
2012-03-28 19:11 . 2012-03-28 19:11 325552 ----a-w- c:\windows\MASetupCaller.dll
2012-03-28 19:11 . 2012-03-28 19:11 30568 ----a-w- c:\windows\MusiccityDownload.exe
2012-03-28 19:11 . 2012-03-28 19:11 974848 ----a-w- c:\windows\SysWow64\cis-2.4.dll
2012-03-28 19:11 . 2012-03-28 19:11 81920 ----a-w- c:\windows\SysWow64\issacapi_bs-2.3.dll
2012-03-28 19:11 . 2012-03-28 19:11 65536 ----a-w- c:\windows\SysWow64\issacapi_pe-2.3.dll
2012-03-28 19:11 . 2012-03-28 19:11 57344 ----a-w- c:\windows\SysWow64\MTXSYNCICON.dll
2012-03-28 19:11 . 2012-03-28 19:11 57344 ----a-w- c:\windows\SysWow64\MK_Lyric.dll
2012-03-28 19:11 . 2012-03-28 19:11 57344 ----a-w- c:\windows\SysWow64\issacapi_se-2.3.dll
2012-03-28 19:11 . 2012-03-28 19:11 569344 ----a-w- c:\windows\SysWow64\muzdecode.ax
2012-03-28 19:11 . 2012-03-28 19:11 491520 ----a-w- c:\windows\SysWow64\muzapp.dll
2012-03-28 19:11 . 2012-03-28 19:11 49152 ----a-w- c:\windows\SysWow64\MaJGUILib.dll
2012-03-28 19:11 . 2012-03-28 19:11 45320 ----a-w- c:\windows\SysWow64\MAMACExtract.dll
2012-03-28 19:11 . 2012-03-28 19:11 45056 ----a-w- c:\windows\SysWow64\MaXMLProto.dll
2012-03-28 19:11 . 2012-03-28 19:11 45056 ----a-w- c:\windows\SysWow64\MACXMLProto.dll
2012-03-28 19:11 . 2012-03-28 19:11 40960 ----a-w- c:\windows\SysWow64\MTTELECHIP.dll
2012-03-28 19:11 . 2012-03-28 19:11 352256 ----a-w- c:\windows\SysWow64\MSLUR71.dll
2012-03-28 19:11 . 2012-03-28 19:11 258048 ----a-w- c:\windows\SysWow64\muzoggsp.ax
2012-03-28 19:11 . 2012-03-28 19:11 245760 ----a-w- c:\windows\SysWow64\MSCLib.dll
2012-03-28 19:11 . 2012-03-28 19:11 24576 ----a-w- c:\windows\SysWow64\MASetupCleaner.exe
2012-03-28 19:11 . 2012-03-28 19:11 200704 ----a-w- c:\windows\SysWow64\muzwmts.dll
2012-03-28 19:11 . 2012-03-28 19:11 155648 ----a-w- c:\windows\SysWow64\MSFLib.dll
2012-03-28 19:11 . 2012-03-28 19:11 143360 ----a-w- c:\windows\SysWow64\3DAudio.ax
2012-03-28 19:11 . 2012-03-28 19:11 135168 ----a-w- c:\windows\SysWow64\muzaf1.dll
2012-03-28 19:11 . 2012-03-28 19:11 131072 ----a-w- c:\windows\SysWow64\muzmpgsp.ax
2012-03-28 19:11 . 2012-03-28 19:11 122880 ----a-w- c:\windows\SysWow64\muzeffect.ax
2012-03-28 19:11 . 2012-03-28 19:11 118784 ----a-w- c:\windows\SysWow64\MaDRM.dll
2012-03-28 19:11 . 2012-03-28 19:11 110592 ----a-w- c:\windows\SysWow64\muzmp4sp.ax
2012-03-28 19:11 . 2012-04-29 08:22 821824 ----a-w- c:\windows\SysWow64\dgderapi.dll
2012-03-28 08:49 . 2012-03-28 08:49 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2012-03-28 08:49 . 2012-03-28 08:49 460624 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2012-03-24 10:23 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2012-03-24 10:23 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2012-03-23 19:57 . 2012-03-23 17:35 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-03-23 18:55 . 2011-03-28 16:36 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-03-23 18:31 . 2012-03-23 18:31 53248 ----a-r- c:\users\Daemon\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2012-03-23 15:44 . 2012-03-23 15:44 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-03-23 15:44 . 2012-03-23 15:44 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-03-23 15:44 . 2012-03-23 15:44 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2012-03-23 15:44 . 2012-03-23 15:44 85504 ----a-w- c:\windows\system32\iesetup.dll
2012-03-23 15:44 . 2012-03-23 15:44 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2012-03-23 15:44 . 2012-03-23 15:44 76800 ----a-w- c:\windows\system32\tdc.ocx
2012-03-23 15:44 . 2012-03-23 15:44 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-03-23 15:44 . 2012-03-23 15:44 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2012-03-23 15:44 . 2012-03-23 15:44 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2012-03-23 15:44 . 2012-03-23 15:44 603648 ----a-w- c:\windows\system32\vbscript.dll
2012-03-23 15:44 . 2012-03-23 15:44 49664 ----a-w- c:\windows\system32\imgutil.dll
2012-03-23 15:44 . 2012-03-23 15:44 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2012-03-23 15:44 . 2012-03-23 15:44 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-03-23 15:44 . 2012-03-23 15:44 448512 ----a-w- c:\windows\system32\html.iec
2012-03-23 15:44 . 2012-03-23 15:44 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2012-03-23 15:44 . 2012-03-23 15:44 367104 ----a-w- c:\windows\SysWow64\html.iec
2012-03-23 15:44 . 2012-03-23 15:44 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2012-03-23 15:44 . 2012-03-23 15:44 30720 ----a-w- c:\windows\system32\licmgr10.dll
2012-03-23 15:44 . 2012-03-23 15:44 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2012-03-23 15:44 . 2012-03-23 15:44 222208 ----a-w- c:\windows\system32\msls31.dll
2012-03-23 15:44 . 2012-03-23 15:44 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2012-03-23 15:44 . 2012-03-23 15:44 165888 ----a-w- c:\windows\system32\iexpress.exe
2012-03-23 15:44 . 2012-03-23 15:44 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2012-03-23 15:44 . 2012-03-23 15:44 160256 ----a-w- c:\windows\system32\wextract.exe
2012-03-23 15:44 . 2012-03-23 15:44 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2012-03-23 15:44 . 2012-03-23 15:44 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2012-03-23 15:44 . 2012-03-23 15:44 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2012-03-23 15:44 . 2012-03-23 15:44 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-03-23 15:44 . 2012-03-23 15:44 12288 ----a-w- c:\windows\system32\mshta.exe
2012-03-23 15:44 . 2012-03-23 15:44 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2012-03-23 15:44 . 2012-03-23 15:44 114176 ----a-w- c:\windows\system32\admparse.dll
2012-03-23 15:44 . 2012-03-23 15:44 111616 ----a-w- c:\windows\system32\iesysprep.dll
2012-03-23 15:44 . 2012-03-23 15:44 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2012-03-23 15:44 . 2012-03-23 15:44 101888 ----a-w- c:\windows\SysWow64\admparse.dll
.
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"KiesPDLR"="c:\program files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-05-04 21392]
"KiesHelper"="c:\program files (x86)\Samsung\Kies\KiesHelper.exe" [2012-05-04 955792]
"SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2012-03-08 4280184]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoEncryptOnMove"= 0 (0x0)
"NoResolveTrack"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoEncryptOnMove"= 0 (0x0)
"NoResolveTrack"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"DisableLocalMachineRun"= 0 (0x0)
"DisableLocalMachineRunOnce"= 0 (0x0)
"DisableCurrentUserRun"= 0 (0x0)
"DisableCurrentUserRunOnce"= 0 (0x0)
"NoFile"= 0 (0x0)
"HideClock"= 0 (0x0)
"NoDevMgrUpdate"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoEncryptOnMove"= 0 (0x0)
"NoResolveTrack"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"KiesTrayAgent"=c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe
"WRSVC"="c:\program files\Webroot\WRSA.exe" -ul
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-05 257696]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [x]
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [x]
R3 SWDUMon;SWDUMon;c:\windows\system32\DRIVERS\SWDUMon.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 XENfiltv;XENfiltv;c:\windows\system32\drivers\XENfiltv.sys [x]
R4 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
R4 gupdate;Google Päivitä-palvelu (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-27 116648]
R4 gupdatem;Google Päivitä-palvelu (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-27 116648]
R4 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15 1262400]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-05-14 382272]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2012-02-09 2143552]
S3 HCW85BDA;Hauppauge WinTV 885 Video Capture;c:\windows\system32\drivers\HCW85BDA.sys [x]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
S3 RTCore64;RTCore64;c:\program files (x86)\MSI Afterburner\RTCore64.sys [2010-05-27 14648]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [2012-02-09 11856]
.
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0ed5ad06-750b-11e1-8b64-0022152566e2}]
\shell\AutoRun\command - K:\setup.exe
.
'Ajoitetut tehtävät'-kansion sisältö
.
2012-06-10 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 18:57]
.
2012-06-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-27 11:58]
.
2012-06-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-27 11:58]
.
2012-04-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-920578845-3360453427-151566150-1001Core.job
- c:\users\Daemon\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-23 15:04]
.
2012-04-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-920578845-3360453427-151566150-1001UA.job
- c:\users\Daemon\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-23 15:04]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Täydentävä tarkistus -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = http=localhost:8118
TCP: Interfaces\{813A4C3B-BA26-45F3-A22A-0F1B0E2769C7}: NameServer = 192.89.123.231,193.210.19.190
.
.
------- Tiedostokytkennät -------
.
inifile=%SystemRoot%\SysWow64\NOTEPAD.EXE %1
JSEFile="%SystemRoot%\System32\WScript.exe" "%1" %*
txtfile=%SystemRoot%\SysWow64\NOTEPAD.EXE %1
.
- - - - POISTETUT JÄMÄRIVIT - - - -
.
Toolbar-{95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
Wow6432Node-HKLM-Run-vProt - c:\program files (x86)\AVG Secure Search\vprot.exe
Notify-LBTWlgn - (no file)
.
.
.
--------------------- LUKITUT REKISTERIAVAIMET ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Muut prosessit ------------------------
.
c:\program files (x86)\MSI Afterburner\MSIAfterburner.exe
.
**************************************************************************
.
Valmistumisajankohta: 2012-06-11 00:59:59 - kone käynnistettiin uudelleen
ComboFix-quarantined-files.txt 2012-06-10 21:59
.
Ennen ajoa: 399 709 798 400 bytes free
Ajon jälkeen: 399 744 270 336 bytes free
.
- - End Of File - - 50812DFEA75EC4744AB56C83F902E8AF