her er den, jeg ved ikke om det var combofix der fixede den, :)
jeg gætte på det var det fordi jeg prøvede ikke den antispyware pro eller hvad den hedde, og den ene virkede slet ikke. og hijacklog virkede heller ikke, så jeg gætte på combofix! :)
ComboFix 08-01-23.1C - Ejer 2008-01-26 13:20:09.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1030.18.450 [GMT 1:00]
Running from: C:\Documents and Settings\Ejer\Skrivebord\Downloads\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
----- BITS: Possible infected sites -----
hxxp://dl.google.com.
((((((((((((((((((((((((( Files Created from 2007-12-26 to 2008-01-26 )))))))))))))))))))))))))))))))
.
2008-01-26 13:19 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-24 15:19 . 2008-01-24 15:19 <DIR> d-------- C:\Programmer\iPod
2008-01-23 16:24 . 2008-01-23 16:24 <DIR> dr-h----- C:\MSOCache
2008-01-21 16:57 . 2008-01-21 16:58 <DIR> d-------- C:\Programmer\ConTEXT
2008-01-16 20:44 . 2008-01-16 20:44 <DIR> d-------- C:\WINDOWS\ShellNew
2008-01-16 20:44 . <DIR> C:\Programmer\Fælles filer\Designer
2008-01-16 20:44 . 2008-01-16 20:44 376 --a------ C:\WINDOWS\ODBC.INI
2008-01-13 21:36 . 2008-01-13 21:36 244 --ah----- C:\sqmnoopt01.sqm
2008-01-13 21:36 . 2008-01-13 21:36 232 --ah----- C:\sqmdata01.sqm
2008-01-13 16:11 . 2008-01-13 16:11 <DIR> d-------- C:\Programmer\Skype
2008-01-13 16:11 . <DIR> C:\Programmer\Fælles filer\Skype
2008-01-11 19:56 . 2008-01-11 19:56 948 --a------ C:\index.php
2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-01-07 20:44 . 2008-01-07 20:44 <DIR> d-------- C:\Programmer\Robster Productions
2008-01-05 17:25 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2008-01-05 17:25 . 2004-08-03 23:07 59,264 --a--c--- C:\WINDOWS\system32\dllcache\usbaudio.sys
2008-01-02 08:54 . 2008-01-02 08:54 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-01-01 20:41 . 2008-01-01 20:41 <DIR> d-------- C:\Programmer\vso
2008-01-01 20:41 . 2008-01-01 20:41 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2008-01-01 20:22 . 2008-01-01 21:04 <DIR> d-------- C:\MyWorks
2008-01-01 20:11 . 2008-01-01 20:11 <DIR> d-------- C:\Programmer\Digital Photo Navigator 1.5
2008-01-01 13:51 . 2008-01-01 13:51 0 --a------ C:\WINDOWS\muveeapp.INI
2008-01-01 12:41 . 2008-01-01 12:41 <DIR> d-------- C:\Programmer\muvee Technologies
2008-01-01 12:41 . <DIR> C:\Programmer\Fælles filer\muvee Technologies
2008-01-01 12:27 . 2008-01-01 12:27 <DIR> d-------- C:\Programmer\X10 Hardware
2008-01-01 12:27 . 2008-01-01 12:27 <DIR> d-------- C:\Programmer\Common Files
2008-01-01 12:27 . 1999-06-25 09:56 127,184 --a------ C:\WINDOWS\Unwise.exe
2008-01-01 12:26 . 2006-06-04 15:48 198,144 --------- C:\WINDOWS\system32\_psisdecd.dll
2008-01-01 12:26 . 2006-02-09 19:02 44,544 --a------ C:\WINDOWS\system32\msxml4a.dll
2008-01-01 12:25 . 2008-01-01 20:25 <DIR> d-------- C:\Programmer\CyberLink
2008-01-01 12:24 . 2008-01-01 14:03 <DIR> d-------- C:\Programmer\Home Cinema
2008-01-01 12:01 . 2008-01-01 12:01 <DIR> d-------- C:\Programmer\Microsoft Works Suite 2006
2008-01-01 11:54 . 2008-01-01 11:54 <DIR> d-------- C:\Programmer\AL-Software
2008-01-01 11:50 . 2008-01-01 11:50 <DIR> d-------- C:\Programmer\Saint Paint
2008-01-01 11:50 . 2008-01-01 11:50 213,504 --a------ C:\WINDOWS\system32\SpoonUninstall.exe
2008-01-01 11:50 . 2008-01-01 11:50 28,898 --a------ C:\WINDOWS\system32\SpoonUninstall-Saint Paint Studio.bmp
2008-01-01 11:50 . 2008-01-01 11:53 3,959 --a------ C:\WINDOWS\SaintPaint.INI
2008-01-01 11:50 . 2008-01-01 11:50 1,064 --a------ C:\WINDOWS\system32\SpoonUninstall-Saint Paint Studio.dat
2008-01-01 11:45 . 2008-01-01 11:45 1,682 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2008-01-01 11:45 . 2008-01-01 11:45 56 -r-hs---- C:\WINDOWS\system32\F8A69C88CD.sys
2008-01-01 11:43 . 2008-01-01 11:45 10,356 --a------ C:\temp.avs
2008-01-01 11:43 . 2008-01-01 11:45 55 --a------ C:\WINDOWS\param.ini
2008-01-01 11:38 . 2008-01-01 11:38 <DIR> d-------- C:\Programmer\Photo Movie Creator
2008-01-01 11:38 . 2004-02-23 21:41 719,872 --a------ C:\WINDOWS\system32\devil.dll
2008-01-01 11:38 . 2005-10-08 01:14 308,224 --a------ C:\WINDOWS\system32\avisynth.dll
2008-01-01 11:38 . 2006-05-11 09:43 163,496 --a------ C:\WINDOWS\system32\help.chm
2008-01-01 11:38 . 2006-05-11 09:53 78 --a------ C:\WINDOWS\system32\Home Page.url
2007-12-29 20:10 . <DIR> C:\Programmer\Fælles filer\xing shared
2007-12-27 20:49 . 2007-12-27 20:49 <DIR> d-------- C:\WINDOWS\.jagex_cache_32
2007-12-26 11:20 . <DIR> C:\Programmer\Fælles filer\Real
2007-12-26 10:39 . 2007-12-26 10:39 <DIR> d-------- C:\Programmer\KURU
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-26 11:46 --------- d-----w C:\Programmer\Steam
2008-01-24 14:19 --------- d-----w C:\Programmer\iTunes
2008-01-24 14:18 --------- d-----w C:\Programmer\QuickTime
2008-01-23 15:25 --------- d-----w C:\Programmer\Fælles filer\Microsoft Shared
2008-01-22 16:36 --------- d-----w C:\Programmer\Folder Lock
2008-01-20 20:16 --------- d-----w C:\Programmer\Fælles filer
2008-01-09 12:48 --------- d-----w C:\Programmer\BitComet
2008-01-03 11:14 --------- d-----w C:\Programmer\Google
2008-01-01 19:25 --------- d--h--w C:\Programmer\InstallShield Installation Information
2008-01-01 10:45 --------- d-----w C:\Programmer\DivX
2007-12-22 14:43 --------- d-----w C:\Programmer\Gabest
2007-12-18 22:07 --------- d-----w C:\Programmer\Chessmaster Challenge
2007-12-15 14:24 --------- d-----w C:\Programmer\Valve Hammer Editor
2007-12-14 15:35 --------- d-----w C:\Programmer\AMX Mod X
2007-12-12 17:16 35,363 ----a-w C:\WINDOWS\system32\windrvNT.sys
2007-12-06 20:19 --------- d-----w C:\Programmer\Fælles filer\Blizzard Entertainment
2007-12-02 18:54 79,920 ----a-w C:\WINDOWS\system32\FLKill.exe
2007-11-07 09:28 723,456 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-31 16:15 73,728 ----a-w C:\WINDOWS\ALCFDRTM.EXE
2007-10-29 22:44 1,291,776 ----a-w C:\WINDOWS\system32\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 13:00 15360]
"Steam"="c:\programmer\steam\steam.exe" [2007-11-30 11:50 1266936]
"LaunchList"="C:\Programmer\Pinnacle\Studio 11\LaunchList2.exe" [ ]
"Veoh"="C:\Programmer\Veoh Networks\Veoh\VeohClient.exe" [2007-12-03 13:21 3461120]
"SpybotSD TeaTimer"="C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"swg"="C:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-01-02 18:27 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-21 10:59 579072]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-10-10 20:49 7286784]
"nwiz"="nwiz.exe" [2005-10-10 20:49 1519616 C:\WINDOWS\system32\nwiz.exe]
"CmUCRRun"="C:\WINDOWS\system32\CmUCReye.exe" [2006-06-22 18:17 237568]
"RTHDCPL"="RTHDCPL.EXE" [2005-08-18 15:20 14820864 C:\WINDOWS\RTHDCPL.EXE]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"HP Software Update"="C:\Programmer\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 22:12 49152]
"BigDogPath323VMSnap"="C:\WINDOWS\VMSnap23.exe" [2006-07-20 04:37 90112]
"BigDogPath323Domino"="C:\WINDOWS\Domino.exe" [2006-06-28 02:54 49152]
"Google Desktop Search"="C:\Programmer\Google\Google Desktop Search\GoogleDesktop.exe" [2007-10-25 20:07 1838592]
"UVS11 Preload"="C:\Programmer\Ulead Systems\Ulead VideoStudio 11\uvPL.exe" [2007-04-12 13:23 341488]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"EverioService"="C:\Programmer\CyberLink\PCM4Everio\EverioService.exe" [2006-11-22 21:10 151552]
"TkBellExe"="C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe" [ ]
"QuickTime Task"="C:\Programmer\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Programmer\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-27 13:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-25 12:35 219136]
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
HP Digital Imaging Monitor.lnk - C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 22:23:26 282624]
Microsoft Office.lnk - C:\Programmer\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
R2 mi-raysat_3dsMax2008_32;mental ray 3.6 Satellite for Autodesk 3ds Max 2008 32-bit 32-bit;"C:\Programmer\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe" [2007-09-24 17:05]
R3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-12-06 11:16]
R3 CMISTOR;CMIUCR.SYS CM220 Card Reader Driver;C:\WINDOWS\system32\DRIVERS\cmiucr.SYS [2006-06-24 00:39]
S3 USBAAPL;Apple Mobile USB Driver;C:\WINDOWS\system32\Drivers\usbaapl.sys [2007-10-31 14:09]
S3 vmfilter323;323 filter service, Normal;C:\WINDOWS\system32\drivers\vmfilter323.sys [2006-08-08 11:25]
S3 ZSMC326;Vimicro USB2.0 PC Camera(VC0323);C:\WINDOWS\system32\Drivers\usbvm323.sys [2006-08-21 16:40]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RECYCLER\systems.com
\Shell\read\command - explorer.exe
\Shell\start\command - RECYCLER\systems.com
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-26 13:24:04
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
disk error: C:\WINDOWS\
**************************************************************************
.
Completion time: 2008-01-26 13:25:23
ComboFix-quarantined-files.txt 2008-01-26 12:24:26
.
2008-01-22 20:20:39 --- E O F ---