Jamen den kommer så her:
ComboFix 08-06-20.4 - Louise 2008-06-25 20:21:21.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1030.18.209 [GMT 2:00]
Running from: C:\Documents and Settings\Louise\Skrivebord\ComboFix.exe
Command switches used :: C:\Documents and Settings\Louise\Skrivebord\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\WINDOWS\system32\cdjvjsse.dll
C:\WINDOWS\system32\dibadkxr.dll
C:\WINDOWS\system32\ebjdrdwc.dll
C:\WINDOWS\system32\gpoohqxb.dll
C:\WINDOWS\system32\jhqkkwdi.dll
C:\WINDOWS\system32\ldfjiffw.dll
C:\WINDOWS\system32\lldyjnya.dll
C:\WINDOWS\system32\MtRepair1.exe
C:\WINDOWS\system32\MtRepair2.exe
C:\WINDOWS\system32\syhcmrbk.dll
C:\WINDOWS\system32\ttclaedd.dll
C:\WINDOWS\system32\wgsdacqq.dll
C:\WINDOWS\system32\xniheekj.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Programmer\SurfingEnhancer
C:\Programmer\SurfingEnhancer\pcre3.dll
C:\Programmer\SurfingEnhancer\SurfingEnhancer.dat
C:\Programmer\SurfingEnhancer\uninstall.exe
C:\WINDOWS\system32\cdjvjsse.dll
C:\WINDOWS\system32\dibadkxr.dll
C:\WINDOWS\system32\ebjdrdwc.dll
C:\WINDOWS\system32\gpoohqxb.dll
C:\WINDOWS\system32\jhqkkwdi.dll
C:\WINDOWS\system32\ldfjiffw.dll
C:\WINDOWS\system32\lldyjnya.dll
C:\WINDOWS\system32\MtRepair1.exe
C:\WINDOWS\system32\MtRepair2.exe
C:\WINDOWS\system32\svcl32
C:\WINDOWS\system32\svcl32\license.txt
C:\WINDOWS\system32\svcl32\QuickStart.html
C:\WINDOWS\system32\svcl32\readme.txt
C:\WINDOWS\system32\svcl32\ResetSettings.bat
C:\WINDOWS\system32\svcl32\Serial.key
C:\WINDOWS\system32\svcl32\svcl32.chm
C:\WINDOWS\system32\svcl32\svcl32.dll
C:\WINDOWS\system32\svcl32\svcl32.exe
C:\WINDOWS\system32\svcl32\svcl32.txt
C:\WINDOWS\system32\svcl32\uninstall.exe
C:\WINDOWS\system32\wgsdacqq.dll
C:\WINDOWS\system32\xniheekj.dll
.
((((((((((((((((((((((((( Files Created from 2008-05-25 to 2008-06-25 )))))))))))))))))))))))))))))))
.
2008-06-25 17:59 . 2008-06-25 17:59 <DIR> d-------- C:\Programmer\CCleaner
2008-06-25 16:36 . 2008-06-25 16:36 <DIR> d-------- C:\Programmer\Malwarebytes' Anti-Malware
2008-06-25 16:36 . 2008-06-25 16:36 <DIR> d-------- C:\Documents and Settings\Louise\Application Data\Malwarebytes
2008-06-25 16:36 . 2008-06-25 16:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-25 16:36 . 2008-06-19 17:48 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-25 16:36 . 2008-06-19 17:47 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-25 14:40 . 2008-06-25 14:40 <DIR> d-------- C:\Programmer\SUPERAntiSpyware
2008-06-25 14:40 . 2008-06-25 14:40 <DIR> d-------- C:\Documents and Settings\Louise\Application Data\SUPERAntiSpyware.com
2008-06-25 14:40 . 2008-06-25 14:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-06-25 12:59 . 2008-06-25 12:59 <DIR> d-------- C:\Programmer\Lavasoft
2008-06-25 12:59 . <DIR> C:\Programmer\Fælles filer\Wise Installation Wizard
2008-06-10 21:58 . 2008-04-14 17:53 272,256 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-10 21:58 . 2008-04-14 17:53 272,256 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-05-26 18:01 . 2008-06-25 18:38 <DIR> d--h----- C:\Documents and Settings\NetworkService.NT AUTHORITY\Lokale indstillinger
2008-05-26 18:01 . 2008-05-26 18:01 <DIR> d--hs---- C:\Documents and Settings\NetworkService.NT AUTHORITY
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-25 10:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-22 15:30 --------- d-----w C:\Documents and Settings\Louise\Application Data\LimeWire
2008-05-16 09:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-08 12:28 202,752 ------w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:16 1,291,776 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:16 1,291,776 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2008-04-29 09:20 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 09:19 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 09:19 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
2008-04-23 23:20 3,591,680 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-04-22 07:39 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-22 07:38 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-04-22 07:38 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-04-20 05:07 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
.
((((((((((((((((((((((((((((( snapshot@2008-06-25_18.37.33.57 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-25 16:34:15 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-25 18:24:17 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-27 13:00 15360]
"MsnMsgr"="C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 12:34 5724184]
"SUPERAntiSpyware"="C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Programmer\Apoint\Apoint.exe" [2004-09-13 17:33 155648]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"ATIPTA"="C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-12-03 22:00 344064]
"IntelWireless"="C:\Programmer\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 15:59 385024]
"Dell QuickSet"="C:\Programmer\Dell\QuickSet\quickset.exe" [2005-03-04 12:26 606208]
"DVDLauncher"="C:\Programmer\r\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 17:19 53248]
"ISUSScheduler"="C:\Programmer\Fælles filer\InstallShield\UpdateService\issch.exe" [ ]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-15 16:54 579584]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [2006-10-25 18:58 282624]
"iTunesHelper"="C:\Programmer\iTunes\iTunesHelper.exe" [2006-10-30 09:36 256576]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-27 13:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-03-28 11:25 219136]
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\
Digital Line Detect.lnk - C:\Programmer\Digital Line Detect\DLG.exe [2005-06-27 09:55:28 24576]
Printkey2000.lnk - C:\Programmer\PrintKey2000\Printkey2000.exe [2008-03-27 15:59:55 869376]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 10:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Programmer\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 17:08 110592 C:\Programmer\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programmer\\Messenger\\msmsgs.exe"=
"C:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programmer\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Programmer\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Programmer\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Programmer\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Programmer\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Programmer\\LimeWire\\LimeWire.exe"=
"C:\\Programmer\\iTunes\\iTunes.exe"=
.
Contents of the 'Scheduled Tasks' folder
"2008-06-22 17:00:08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Programmer\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-25 20:25:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Programmer\Intel\Wireless\Bin\EvtEng.exe
C:\Programmer\Intel\Wireless\Bin\S24EvMon.exe
C:\Programmer\Intel\Wireless\Bin\WLKEEPER.exe
C:\Programmer\Intel\Wireless\Bin\ZCfgSvc.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Programmer\Lavasoft\Ad-Aware\aawservice.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\brss01a.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Programmer\Dell\NicConfigSvc\NicConfigSvc.exe
C:\Programmer\Intel\Wireless\Bin\RegSrvc.exe
C:\Programmer\Apoint\ApntEx.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-06-25 20:28:12 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-25 18:28:04
ComboFix2.txt 2008-06-25 16:38:00
Pre-Run: 3,464,179,712 byte ledig
Post-Run: 3,451,838,464 byte ledig
181 --- E O F --- 2008-06-10 23:09:51