Thanks for insight once again. Here is the log as requested:
ComboFix 12-08-18.03 - Pasi 22.08.2012 16:37:28.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.358.1035.18.4094.3092 [GMT 3:00]
Sijainti: c:\users\Pasi\Desktop\username321.exe
Käytetyt komentorivivalitsimet :: c:\users\Pasi\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\programdata\HitmanPro
c:\programdata\HitmanPro\Banner.bin
c:\programdata\HitmanPro\Remnants.bin
.
Saastunut kopio tiedostosta c:\windows\SysWow64\kernel32.dll löytyi ja poistettiin
Puhdas kopio palautettiin paikasta - c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.21772_none_fc7f5397ba9be6d3\kernel32.dll
.
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2012-07-22 to 2012-08-22 )))))))))))))))))
.
.
2012-08-22 13:44 . 2012-08-22 13:44 -------- d-----w- c:\users\Tillu\AppData\Local\temp
2012-08-22 13:44 . 2012-08-22 13:44 -------- d-----w- c:\users\Tatu\AppData\Local\temp
2012-08-22 13:44 . 2012-08-22 13:44 -------- d-----w- c:\users\Rami\AppData\Local\temp
2012-08-22 13:44 . 2012-08-22 13:44 -------- d-----w- c:\users\Nelli\AppData\Local\temp
2012-08-22 13:44 . 2012-08-22 13:44 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-21 17:43 . 2012-08-21 17:43 -------- d-----w- c:\users\Rami\AppData\Roaming\Apple Computer
2012-08-21 15:56 . 2012-08-21 15:56 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2012-08-21 15:56 . 2012-08-21 15:56 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2012-08-21 15:56 . 2012-08-21 15:56 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2012-08-21 15:56 . 2012-08-21 15:56 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2012-08-21 15:56 . 2012-08-21 15:56 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2012-08-21 15:56 . 2012-08-21 15:56 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2012-08-21 15:56 . 2012-08-21 15:56 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2012-08-21 15:55 . 2012-08-21 15:56 -------- d-----w- c:\program files (x86)\QuickTime
2012-08-21 15:54 . 2012-08-21 15:54 -------- d-----w- c:\program files (x86)\Apple Software Update
2012-08-21 15:51 . 2012-08-21 15:51 -------- d-----w- c:\users\Pasi\AppData\Local\Apple Computer
2012-08-21 15:47 . 2012-08-21 15:47 -------- d-----w- c:\users\Pasi\AppData\Local\Apple
2012-08-21 13:19 . 2012-08-01 22:58 9309624 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{71597CCF-A7E6-4777-AFE1-FBE3D8793E9E}\mpengine.dll
2012-08-20 21:13 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-08-20 21:13 . 2012-05-04 11:00 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-08-20 20:59 . 2012-08-20 20:59 -------- d-----w- c:\program files (x86)\FileHippo.com
2012-08-20 16:15 . 2012-08-20 16:15 927800 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D325D83B-BEC2-42D2-83B7-9386BFFB382D}\gapaengine.dll
2012-08-20 16:15 . 2012-06-29 00:04 9133488 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-08-20 16:13 . 2012-08-20 16:13 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2012-08-20 16:13 . 2012-08-20 16:14 -------- d-----w- c:\program files\Microsoft Security Client
2012-08-19 16:52 . 2012-08-19 16:52 -------- d-----w- c:\windows\SysWow64\wbem\Performance
2012-08-19 16:50 . 2008-05-07 19:03 303616 ----a-w- C:\SetACL.exe
2012-08-19 16:49 . 2004-06-11 13:33 290304 ----a-w- C:\subinacl.exe
2012-08-19 16:48 . 2012-08-19 16:48 -------- d-----w- C:\RegBackup
2012-08-19 15:39 . 2012-08-19 16:57 181064 ----a-w- c:\windows\PSEXESVC.EXE
2012-08-19 15:24 . 2012-08-19 16:50 -------- d-----w- C:\Tweaking.com_Windows_Repair_Logs
2012-08-18 12:51 . 2012-08-18 12:51 -------- d-----w- c:\users\Rami\AppData\Roaming\Malwarebytes
2012-08-18 03:33 . 2012-06-29 10:04 9133488 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3916EADA-4C36-4E62-A701-3B3449AAE2B5}\mpengine.dll
2012-08-15 21:21 . 2012-06-29 03:51 887296 ----a-w- c:\program files\Internet Explorer\iedvtool.dll
2012-08-15 21:21 . 2012-06-29 03:50 499200 ----a-w- c:\program files\Internet Explorer\jsdbgui.dll
2012-08-15 21:21 . 2012-06-29 03:44 816640 ----a-w- c:\windows\system32\jscript.dll
2012-08-15 21:21 . 2012-06-29 00:10 678912 ----a-w- c:\program files (x86)\Internet Explorer\iedvtool.dll
2012-08-15 21:21 . 2012-06-29 00:10 387584 ----a-w- c:\program files (x86)\Internet Explorer\jsdbgui.dll
2012-08-15 21:21 . 2012-06-29 04:55 17809920 ----a-w- c:\windows\system32\mshtml.dll
2012-08-15 21:21 . 2012-06-29 04:09 10925568 ----a-w- c:\windows\system32\ieframe.dll
2012-08-15 07:32 . 2012-08-15 07:32 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-08-15 07:32 . 2012-08-15 07:32 -------- d-----w- c:\program files (x86)\Oracle
2012-08-15 07:31 . 2012-07-05 19:06 772544 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-08-11 18:54 . 2012-08-11 18:54 -------- d-----w- c:\users\Tatu\AppData\Roaming\Malwarebytes
2012-08-11 18:54 . 2012-08-11 18:54 -------- d-----w- c:\programdata\Malwarebytes
2012-08-11 18:54 . 2012-08-11 18:54 -------- d-----w- c:\program files (x86)\MBMA
2012-08-11 18:54 . 2012-07-03 10:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-05 16:43 . 2012-08-05 16:43 -------- d-----w- c:\users\Rami\AppData\Roaming\Wargaming.net
2012-07-30 21:52 . 2012-07-30 21:52 103904 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
2012-07-26 05:47 . 2012-07-26 05:47 -------- d-----w- c:\users\Pasi\AppData\Local\Macromedia
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-21 16:24 . 2012-04-02 07:52 696520 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-08-21 16:24 . 2011-05-16 09:03 73416 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-08-15 21:19 . 2009-12-21 12:12 62134624 ----a-w- c:\windows\system32\MRT.exe
2012-07-15 04:53 . 2012-07-15 04:53 4024320 ----a-w- c:\program files (x86)\GUTBF6F.tmp
2012-07-05 19:06 . 2010-05-04 19:40 687544 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-06-25 13:36 . 2012-06-25 13:36 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2012-06-25 13:36 . 2012-06-25 13:36 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-06-25 13:36 . 2012-06-25 13:36 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2012-06-25 13:36 . 2012-06-25 13:36 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2012-06-24 18:17 . 2012-06-24 18:17 164352 ----a-w- c:\windows\SysWow64\SpoonUninstall.exe
2012-06-13 09:24 . 2012-06-13 09:13 2829 ----a-w- c:\windows\War3Unin.pif
2012-06-13 09:24 . 2012-06-13 09:13 139264 ----a-w- c:\windows\War3Unin.exe
2012-06-09 05:43 . 2012-07-11 05:28 14172672 ----a-w- c:\windows\system32\shell32.dll
2012-06-06 06:06 . 2012-07-11 05:28 2004480 ----a-w- c:\windows\system32\msxml6.dll
2012-06-06 06:06 . 2012-07-11 05:28 1881600 ----a-w- c:\windows\system32\msxml3.dll
2012-06-06 06:02 . 2012-07-11 05:27 1133568 ----a-w- c:\windows\system32\cdosys.dll
2012-06-06 05:05 . 2012-07-11 05:28 1390080 ----a-w- c:\windows\SysWow64\msxml6.dll
2012-06-06 05:05 . 2012-07-11 05:28 1236992 ----a-w- c:\windows\SysWow64\msxml3.dll
2012-06-06 05:03 . 2012-07-11 05:27 805376 ----a-w- c:\windows\SysWow64\cdosys.dll
2012-06-02 22:19 . 2012-06-19 05:42 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-19 05:42 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-19 05:42 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-19 05:42 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-19 05:42 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-19 05:42 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-19 05:42 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 12:19 . 2012-06-19 05:42 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 12:15 . 2012-06-19 05:42 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-06-02 05:50 . 2012-07-11 05:27 458704 ----a-w- c:\windows\system32\drivers\cng.sys
2012-06-02 05:48 . 2012-07-11 05:27 95600 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-06-02 05:48 . 2012-07-11 05:27 151920 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-06-02 05:45 . 2012-07-11 05:27 340992 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 05:44 . 2012-07-11 05:27 307200 ----a-w- c:\windows\system32\ncrypt.dll
2012-06-02 04:40 . 2012-07-11 05:27 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2012-06-02 04:40 . 2012-07-11 05:27 225280 ----a-w- c:\windows\SysWow64\schannel.dll
2012-06-02 04:39 . 2012-07-11 05:27 219136 ----a-w- c:\windows\SysWow64\ncrypt.dll
2012-06-02 04:34 . 2012-07-11 05:27 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2012-05-26 12:34 . 2012-05-26 12:34 2829 ----a-w- c:\windows\DiabUnin.pif
2012-05-26 12:34 . 2012-05-26 12:34 118784 ----a-w- c:\windows\DiabUnin.exe
.
.
(((((((((((((((((((((((((((((
SnapShot@2012-08-20_10.24.02 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-02-09 19:43 . 2012-02-09 19:43 61248 c:\windows\SysWOW64\OpenCL.dll
- 2009-07-14 04:54 . 2012-08-20 10:23 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2012-08-20 15:07 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2012-08-20 10:23 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-08-20 15:07 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-08-20 15:07 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-08-20 10:23 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-21 12:22 . 2012-08-22 05:18 48214 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-08-22 05:18 40364 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-01-10 16:10 . 2012-08-21 17:45 12498 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1415641805-828064493-1863220564-1007_UserData.bin
+ 2009-12-21 12:22 . 2012-08-20 15:44 16268 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1415641805-828064493-1863220564-1001_UserData.bin
+ 2009-08-10 12:29 . 2012-08-22 13:29 83350 c:\windows\system32\perfc00B.dat
+ 2012-02-09 19:43 . 2012-02-09 19:43 68928 c:\windows\system32\OpenCL.dll
+ 2009-07-14 05:30 . 2012-08-20 21:16 86016 c:\windows\system32\DriverStore\infpub.dat
- 2009-07-14 05:30 . 2012-08-16 05:25 86016 c:\windows\system32\DriverStore\infpub.dat
+ 2012-02-09 19:43 . 2012-02-09 19:43 68928 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\OpenCL64.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 61248 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\OpenCL.dll
+ 2012-03-20 17:44 . 2012-03-20 17:44 98688 c:\windows\system32\drivers\NisDrvWFP.sys
+ 2009-07-14 04:46 . 2012-08-22 05:22 92352 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2010-04-03 08:46 . 2011-10-28 09:36 90112 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\xlicons.exe
+ 2010-04-03 08:46 . 2012-08-21 15:24 90112 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\xlicons.exe
- 2010-04-03 08:46 . 2011-10-28 09:36 45056 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\wordicon.exe
+ 2010-04-03 08:46 . 2012-08-21 15:24 45056 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\wordicon.exe
- 2010-04-03 08:46 . 2011-10-28 09:36 22528 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\unbndico.exe
+ 2010-04-03 08:46 . 2012-08-21 15:24 22528 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\unbndico.exe
+ 2010-04-03 08:46 . 2012-08-21 15:24 30720 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\pptico.exe
- 2010-04-03 08:46 . 2011-10-28 09:36 30720 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\pptico.exe
- 2010-04-03 08:46 . 2011-10-28 09:36 16384 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\PEicons.exe
+ 2010-04-03 08:46 . 2012-08-21 15:24 16384 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\PEicons.exe
- 2010-04-03 08:46 . 2011-10-28 09:36 34304 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\misc.exe
+ 2010-04-03 08:46 . 2012-08-21 15:24 34304 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\misc.exe
+ 2010-04-03 08:46 . 2012-08-21 15:24 81920 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\fpicon.exe
- 2010-04-03 08:46 . 2011-10-28 09:36 81920 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\fpicon.exe
+ 2012-08-21 15:54 . 2012-08-21 15:54 27136 c:\windows\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}\AppleSoftwareUpdateIco.exe
+ 2011-01-10 00:23 . 2012-08-20 11:32 4116 c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2012-02-09 19:43 . 2012-02-09 19:43 4096 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvdetx.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 4096 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvdet.dll
- 2012-08-20 10:23 . 2012-08-20 10:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-08-22 13:45 . 2012-08-22 13:45 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-08-22 13:45 . 2012-08-22 13:45 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-08-20 10:23 . 2012-08-20 10:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-04-03 08:46 . 2012-08-21 15:24 3584 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\opwicon.exe
- 2010-04-03 08:46 . 2011-10-28 09:36 3584 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\opwicon.exe
+ 2010-04-03 08:46 . 2012-08-21 15:24 8192 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\mspicons.exe
- 2010-04-03 08:46 . 2011-10-28 09:36 8192 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\mspicons.exe
+ 2010-04-03 08:46 . 2012-08-21 15:24 2560 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\cagicon.exe
- 2010-04-03 08:46 . 2011-10-28 09:36 2560 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\cagicon.exe
+ 2000-06-02 15:48 . 2000-06-02 15:48 427520 c:\windows\SysWOW64\MPG4C32.DLL
+ 2012-08-21 16:21 . 2012-08-21 16:24 690888 c:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_4_402_265_Plugin.exe
+ 2012-04-02 07:52 . 2012-08-21 16:24 250568 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2012-08-15 07:31 . 2012-08-15 07:31 227824 c:\windows\SysWOW64\javaws.exe
+ 2009-12-26 20:51 . 2012-08-20 14:39 392492 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin
+ 2009-12-26 12:44 . 2012-08-22 12:42 691294 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
+ 2009-08-10 12:29 . 2012-08-22 13:29 443680 c:\windows\system32\perfh00B.dat
+ 2009-07-14 02:36 . 2012-08-22 13:29 618160 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-08-22 13:29 107440 c:\windows\system32\perfc009.dat
- 2009-12-21 12:07 . 2012-05-31 09:25 279656 c:\windows\system32\MpSigStub.exe
+ 2009-12-21 12:07 . 2012-01-31 12:44 279656 c:\windows\system32\MpSigStub.exe
+ 2012-08-21 16:21 . 2012-08-21 16:24 420552 c:\windows\system32\Macromed\Flash\FlashUtil64_11_4_402_265_Plugin.exe
+ 2009-07-14 04:45 . 2012-08-21 17:43 436496 c:\windows\system32\FNTCACHE.DAT
+ 2009-07-14 05:30 . 2012-08-20 21:16 143360 c:\windows\system32\DriverStore\infstrng.dat
- 2009-07-14 05:30 . 2012-08-16 05:25 143360 c:\windows\system32\DriverStore\infstrng.dat
- 2009-07-14 05:30 . 2012-08-16 05:25 143360 c:\windows\system32\DriverStore\infstor.dat
+ 2009-07-14 05:30 . 2012-08-20 21:16 143360 c:\windows\system32\DriverStore\infstor.dat
+ 2012-02-09 19:43 . 2012-02-09 19:43 962368 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvumdshimx.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 812352 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvumdshim.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 310592 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvml.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 260416 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvinitx.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 215360 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvinit.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 201024 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvidia-smi.exe
+ 2012-02-09 19:43 . 2012-02-09 19:43 202752 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvdxgiwrapx.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 182080 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvdxgiwrap.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 324516 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvdrsdb.bin
+ 2012-02-09 19:43 . 2012-02-09 19:43 301376 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvdecodemft32.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 364352 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvdecodemft.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 261120 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\Nvd3d9wrapx.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 236352 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\Nvd3d9wrap.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 224064 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\dbInstaller.exe
+ 2012-03-20 17:44 . 2012-03-20 17:44 203888 c:\windows\system32\drivers\MpFilter.sys
+ 2009-07-14 05:01 . 2012-08-22 13:44 434952 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2012-05-22 16:20 . 2012-08-21 22:15 868904 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1415641805-828064493-1863220564-1007-12288.dat
+ 2008-04-11 07:11 . 2008-04-11 07:11 233472 c:\windows\Installer\1ae3779.msi
+ 2012-08-20 16:14 . 2012-08-20 16:14 109563 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\SCEP.exe
+ 2012-08-20 16:14 . 2012-08-20 16:14 123352 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\MSE.exe
+ 2012-08-20 16:14 . 2012-08-20 16:14 109563 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\INTUNE.exe
+ 2012-08-20 16:14 . 2012-08-20 16:14 109563 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\FEP.exe
+ 2012-08-20 16:14 . 2012-08-20 16:14 109563 c:\windows\Installer\{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}\EPP.exe
- 2010-04-03 08:46 . 2011-10-28 09:36 114688 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\outicon.exe
+ 2010-04-03 08:46 . 2012-08-21 15:24 114688 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\outicon.exe
- 2010-04-03 08:46 . 2011-10-28 09:36 167936 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\accicons.exe
+ 2010-04-03 08:46 . 2012-08-21 15:24 167936 c:\windows\Installer\{9028040B-6000-11D3-8CFE-0050048383C9}\accicons.exe
+ 2012-02-09 19:43 . 2012-02-09 19:43 7713088 c:\windows\SysWOW64\nvwgf2um.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 2517312 c:\windows\SysWOW64\nvcuvid.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 2437440 c:\windows\SysWOW64\nvcuvenc.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 5892928 c:\windows\SysWOW64\nvcuda.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 2301248 c:\windows\SysWOW64\nvapi.dll
+ 2012-08-21 16:21 . 2012-08-21 16:24 9813704 c:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll
+ 2012-08-21 16:21 . 2012-08-21 16:24 1807560 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe
+ 2011-08-09 22:48 . 2011-07-16 04:49 1114112 c:\windows\SysWOW64\kernel32.dll
- 2011-08-09 22:48 . 2011-07-16 04:24 1114112 c:\windows\SysWOW64\kernel32.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 9717568 c:\windows\system32\nvwgf2umx.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 1466176 c:\windows\system32\nvgenco64.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 1737536 c:\windows\system32\nvdispco64.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 2672448 c:\windows\system32\nvcuvid.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 2872640 c:\windows\system32\nvcuvenc.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 8008000 c:\windows\system32\nvcuda.dll
+ 2009-10-26 18:35 . 2012-02-09 19:43 2660160 c:\windows\system32\nvapi64.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 9717568 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvwgf2umx.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 7713088 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvwgf2um.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 1466176 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvgenco64.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 1737536 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvdispco64.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 2517312 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvcuvid32.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 2672448 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvcuvid.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 2872640 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvcuvenc64.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 2437440 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvcuvenc.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 5892928 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvcuda32.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 8008000 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvcuda.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 2660160 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvapi64.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 2301248 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvapi.dll
+ 2009-07-14 04:45 . 2012-08-21 17:44 7130306 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
- 2009-07-14 04:45 . 2012-08-16 05:29 7130306 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2009-12-21 12:18 . 2012-08-22 13:44 1583296 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2010-12-21 00:49 . 2012-08-22 13:44 6897428 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1415641805-828064493-1863220564-1007-8192.dat
+ 2011-01-16 09:53 . 2012-08-21 16:27 6022968 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1415641805-828064493-1863220564-1001-8192.dat
+ 2012-06-20 09:16 . 2012-08-21 16:27 1420584 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1415641805-828064493-1863220564-1001-12288.dat
+ 2012-03-26 16:21 . 2012-03-26 16:21 7622656 c:\windows\Installer\1cee3a.msi
+ 2012-01-25 01:52 . 2012-01-25 01:52 2323456 c:\windows\Installer\1ae37a9.msi
+ 2012-02-09 19:43 . 2012-02-09 19:43 19443520 c:\windows\SysWOW64\nvoglv32.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 15009600 c:\windows\SysWOW64\nvd3dum.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 17543488 c:\windows\SysWOW64\nvcompiler.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 25541952 c:\windows\system32\nvoglv64.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 17642816 c:\windows\system32\nvd3dumx.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 25222976 c:\windows\system32\nvcompiler.dll
+ 2012-08-21 16:21 . 2012-08-21 16:24 12812488 c:\windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 25541952 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvoglv64.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 19443520 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvoglv32.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 13624128 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvlddmkm.sys
+ 2012-02-09 19:43 . 2012-02-09 19:43 17642816 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvd3dumx.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 15009600 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvd3dum.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 71579376 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\NvCplSetupInt.exe
+ 2012-02-09 19:43 . 2012-02-09 19:43 17543488 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvcompiler32.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 25222976 c:\windows\system32\DriverStore\FileRepository\nv_disp.inf_amd64_neutral_d895694e10f22a11\nvcompiler.dll
+ 2012-02-09 19:43 . 2012-02-09 19:43 13624128 c:\windows\system32\drivers\nvlddmkm.sys
+ 2012-04-18 19:28 . 2012-04-18 19:28 26820096 c:\windows\Installer\1ae3b6d.msi
+ 2012-04-18 14:50 . 2012-04-18 14:50 20396032 c:\windows\Installer\1ae3888.msi
+ 2004-02-24 14:18 . 2004-02-24 14:18 57439292 c:\windows\Installer\1ae3772.msp
.
-- Snapshot nollattu tähän hetkeen --
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-12-21 39408]
"FileHippo.com"="c:\program files (x86)\FileHippo.com\UpdateChecker.exe" [2012-03-26 306688]
"Spotify Web Helper"="d:\spotify\Data\SpotifyWebHelper.exe" [2012-08-04 1193176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl9"="c:\program files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" [2009-04-27 87336]
"PDVD9LanguageShortcut"="c:\program files (x86)\CyberLink\PowerDVD9\Language\Language.exe" [2009-04-27 50472]
"BDRegion"="c:\program files (x86)\Cyberlink\Shared Files\brs.exe" [2009-05-07 75048]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-11 919008]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-18 421888]
.
c:\users\Nelli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\startup\
LaunchCenter.lnk - c:\program files (x86)\Fujitsu\LaunchCenter\LaunchCenter.exe [2009-8-31 2351104]
.
c:\users\Rami\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\startup\
LaunchCenter.lnk - c:\program files (x86)\Fujitsu\LaunchCenter\LaunchCenter.exe [2009-8-31 2351104]
.
c:\users\Tatu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\startup\
Adobe Gamma.lnk - c:\program files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
.
c:\users\Tillu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\startup\
LaunchCenter.lnk - c:\program files (x86)\Fujitsu\LaunchCenter\LaunchCenter.exe [2009-8-31 2351104]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files (x86)\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
LaunchCenter.lnk - c:\program files (x86)\Fujitsu\LaunchCenter\LaunchCenter.exe [2009-8-31 2351104]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google-päivityspalvelu (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-04 135664]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\IswSvc.exe
R3 GGSAFERDriver;GGSAFER Driver;d:\garena plus\Room\safedrv.sys
R3 gupdatem;Google Päivitä-palvelu (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-04 135664]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-06 113120]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-20 98688]
R3 NisSrv;Microsoftin verkon tarkastus;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
R3 nmwcdcx64;Nokia USB Generic;c:\windows\system32\drivers\ccdcmbox64.sys [2011-08-17 27136]
R3 nmwcdnsucx64;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsucx64.sys [2010-02-26 12288]
R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys [2010-02-26 173056]
R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\ccdcmbx64.sys [2011-08-17 19968]
R3 PVUSB;CESG502 64bit USB Driver;c:\windows\system32\DRIVERS\CESG64.sys [2007-02-19 63808]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 WatAdminSvc;Windowsin aktivointitekniikoiden palvelu;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-08 1255736]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-06-22 828912]
S2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2009/12/21 13:59];c:\program files (x86)\CyberLink\PowerDVD9\000.fcl [2009-05-07 19:05 146928]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2010-09-07 155752]
S3 SNXPCAMD;SUNIX Mulit-I/O Card Driver;c:\windows\system32\DRIVERS\snxpcamd.sys [2009-06-25 62464]
S3 SNXPPAMD;SUNIX Parallel Port Driver;c:\windows\system32\DRIVERS\snxppamd.sys [2009-06-25 133632]
.
.
'Ajoitetut tehtävät'-kansion sisältö
.
2012-08-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-04 22:26]
.
2012-08-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-04 22:26]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-08-05 8060960]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [BU]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
.
------- Täydentävä tarkistus -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.fi/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Vie Microsoft E&xceliin - c:\progra~2\MICROS~1\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.100.1
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://85.23.161.214/activex/AMC.cab
FF - ProfilePath - c:\users\Pasi\AppData\Roaming\Mozilla\Firefox\Profiles\nhgo6yp4.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
www.google.fiFF - prefs.js: keyword.URL - hxxp://fi.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p=
FF - prefs.js: network.proxy.type - 0
.
- - - - POISTETUT JÄMÄRIVIT - - - -
.
Toolbar-Locked - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\{B154377D-700F-42cc-9474-23858FBDF4BD}]
"ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD9\000.fcl"
.
--------------------- LUKITUT REKISTERIAVAIMET ---------------------
.
[HKEY_USERS\S-1-5-21-1415641805-828064493-1863220564-1001\Software\SecuROM\License information*]
"datasecu"=hex:a3,28,a5,42,11,dc,ea,07,1b,e2,c0,54,36,40,91,f1,6a,ef,e9,af,09,
63,b6,84,28,0d,7f,de,64,b6,49,ec,71,b2,66,3e,18,4e,2c,22,05,39,90,1c,f3,14,\
"rkeysecu"=hex:5e,09,10,d5,26,c0,fd,18,81,87,5e,10,89,e3,38,fe
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Muut prosessit ------------------------
.
c:\program files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\CyberLink\Shared files\RichVideo.exe
c:\program files (x86)\Fujitsu\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe
.
**************************************************************************
.
Valmistumisajankohta: 2012-08-22 16:49:48 - kone käynnistettiin uudelleen
ComboFix-quarantined-files.txt 2012-08-22 13:49
ComboFix2.txt 2012-08-20 11:28
.
Ennen ajoa: 353 693 020 160 tavua vapaana
Ajon jälkeen: 353 133 223 936 tavua vapaana
.
- - End Of File - - 9B4C18945D7489747621C451B1188565