Det var så ComboFix (eller Agurk.exe, som den hedder hos mig):
ComboFix 11-09-12.02 - Nicole & Paw 12-09-2011 18:11:17.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.45.1030.18.2046.1436 [GMT 2:00]
Kører fra: c:\documents and settings\Nicole & Paw\Skrivebord\Agurk.exe
AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Firewall *Enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programmer\driver
c:\programmer\messenger\msmsgsin.exe
c:\windows\ehome\medctrro.exe
c:\windows\system32\mfc100deu.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Tjenester )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_SSHNAS
.
.
((((((((((((((((((((((((((((( Filer skabt fra 2011-08-12 til 2011-09-12 )))))))))))))))))))))))))))))))))))
.
.
2011-09-11 10:32 . 2011-09-11 10:32 -------- d-----w- c:\documents and settings\Nicole & Paw\Application Data\Malwarebytes
2011-09-11 10:32 . 2011-07-06 17:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-09-11 10:32 . 2011-09-11 10:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-09-11 10:32 . 2011-09-11 10:32 -------- d-----w- c:\programmer\Malwarebytes' Anti-Malware
2011-09-11 10:32 . 2011-07-06 17:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-09-11 10:14 . 2011-09-11 10:14 -------- d-----w- c:\programmer\CCleaner
2011-09-10 09:37 . 2011-09-10 09:55 -------- d-----w- c:\documents and settings\Nicole & Paw\Application Data\Uniblue
2011-09-10 09:37 . 2011-09-10 09:37 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
2011-09-10 09:37 . 2011-09-10 09:55 -------- d-----w- c:\programmer\Uniblue
2011-09-10 09:37 . 2011-09-10 09:37 -------- d-----w- c:\documents and settings\Nicole & Paw\Lokale indstillinger\Application Data\PackageAware
2011-09-10 08:28 . 2011-03-17 23:24 69120 ----a-w- c:\windows\system32\zlcomm.dll
2011-09-10 08:28 . 2011-03-17 23:24 104448 ----a-w- c:\windows\system32\zlcommdb.dll
2011-09-10 08:28 . 2011-09-10 08:28 -------- d-----w- c:\windows\system32\ZoneLabs
2011-09-10 08:28 . 2011-03-17 23:24 1238528 ----a-w- c:\windows\system32\zpeng25.dll
2011-09-10 08:28 . 2011-09-10 08:28 -------- d-----w- c:\programmer\Zone Labs
2011-09-10 08:27 . 2011-09-12 16:30 -------- d-----w- c:\windows\Internet Logs
2011-09-03 10:17 . 2011-09-03 10:17 602112 -c----w- c:\windows\system32\dllcache\crypt32.dll
2011-08-28 17:57 . 2011-08-28 17:57 -------- d-----w- c:\documents and settings\Nicole & Paw\Application Data\TrojanHunter
2011-08-28 10:07 . 2011-08-28 17:58 -------- d-----w- c:\programmer\TrojanHunter 5.3
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-03 10:17 . 2002-09-23 14:11 602112 ----a-w- c:\windows\system32\crypt32.dll
2011-08-23 16:40 . 2011-05-14 14:17 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-15 13:29 . 2001-10-09 11:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2001-10-09 11:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-06-24 14:10 . 2011-03-11 21:25 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:31 . 2001-10-09 11:00 916480 ----a-w- c:\windows\system32\wininet.dll
2011-06-23 18:31 . 2001-10-09 11:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-23 18:31 . 2001-10-09 11:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05 . 2011-03-12 09:46 385024 ----a-w- c:\windows\system32\html.iec
2011-06-20 17:44 . 2001-10-09 11:00 293376 ----a-w- c:\windows\system32\winsrv.dll
.
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech Utility"="Logi_MwX.Exe" [2003-03-04 19968]
"nwiz"="c:\programmer\NVIDIA Corporation\nView\nwiz.exe" [2010-07-28 1753192]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-07-29 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-07-29 13923432]
"AVG_TRAY"="c:\programmer\AVG\AVG10\avgtray.exe" [2011-04-18 2334560]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 16270848]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"Smart File Advisor"="c:\programmer\Smart File Advisor\sfa.exe" [2011-03-02 280312]
"SunJavaUpdateSched"="c:\programmer\Fælles filer\Java\Java Update\jusched.exe" [2011-04-08 254696]
"Adobe ARM"="c:\programmer\Fælles filer\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"ZoneAlarm Client"="c:\programmer\Zone Labs\ZoneAlarm\zlclient.exe" [2011-03-17 1043968]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Menuen Start\Programmer\Start\
Gigaset WLAN Adapter Monitor.lnk - c:\programmer\Siemens\Gigaset USB Adapter 300\GUI.exe [2011-3-16 815104]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-03-21 18:56 1230704 ----a-w- c:\programmer\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-06-07 15:51 421160 ----a-w- c:\programmer\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 15:38 421888 ----a-w- c:\programmer\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\Opera\\opera.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\AVG\\AVG10\\avgmfapx.exe"=
"c:\\Programmer\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmer\\iTunes\\iTunes.exe"=
"c:\\Programmer\\AVG\\AVG10\\avgdiagex.exe"=
"c:\\Programmer\\AVG\\AVG10\\avgnsx.exe"=
"c:\\Programmer\\AVG\\AVG10\\avgemcx.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"13116:TCP"= 13116:TCP:BitComet 13116 TCP
"13116:UDP"= 13116:UDP:BitComet 13116 UDP
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [13-09-2010 16:27 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [07-09-2010 04:48 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [08-12-2010 05:12 248656]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [12-11-2010 14:19 297168]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [12-03-2011 09:55 13696]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [27-03-2011 12:22 218688]
R2 AVGIDSAgent;AVGIDSAgent;c:\programmer\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [18-04-2011 17:39 7398752]
R2 avgwd;AVG WatchDog;c:\programmer\AVG\AVG10\avgwdsvc.exe [08-02-2011 05:33 269520]
R2 NAUpdate;@c:\programmer\Nero\Update\NASvc.exe,-200;c:\programmer\Nero\Update\NASvc.exe [04-05-2010 12:07 503080]
R2 TomTomHOMEService;TomTomHOMEService;c:\programmer\TomTom HOME 2\TomTomHOMEService.exe [22-04-2011 14:21 92592]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [03-08-2010 16:23 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [03-08-2010 16:23 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [03-08-2010 16:23 27216]
R3 CBPSp50;CBPSp50 NDIS Protocol Driver;c:\windows\system32\drivers\CBPSp50.sys [11-03-2011 23:35 27072]
S1 ethfuagd;ethfuagd; [x]
S3 CBPMp50;CBPMp50 NDIS Protocol Driver;c:\windows\system32\Drivers\CBPMp50.sys --> c:\windows\system32\Drivers\CBPMp50.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [11-09-2011 12:32 41272]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 10:11 451872 ----a-w- c:\programmer\Fælles filer\LightScribe\LSRunOnce.exe
.
Indhold af mappen 'Planlagte Opgaver'
.
2011-06-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmer\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2011-09-12 c:\windows\Tasks\RegistryBooster.job
- c:\programmer\Uniblue\RegistryBooster\rbmonitor.exe [2011-09-10 09:48]
.
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://www.google.dk/uInternet Settings,ProxyOverride = *.local
.
- - - - TOMME GENVEJE FJERNET - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-09-12 18:31
Windows 5.1.2600 Service Pack 3 NTFS
.
scanner skjulte processer ...
.
scanner skjulte autostarter ...
.
scanner skjulte filer ...
.
scanning gennemført med succes
skjulte filer: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.netWindows 5.1.2600 Disk: MAXTOR_STM3320820AS rev.3.AAE -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
error: Read En enhed, som er sluttet til systemet, fungerer ikke.
kernel: MBR read successfully
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x89D5C31B
user & kernel MBR OK
.
**************************************************************************
.
--------------------- DLLs startet under kørende Processer ---------------------
.
- - - - - - - > 'explorer.exe'(1680)
c:\programmer\MouseWare\System\LgWndHk.dll
c:\programmer\Fælles filer\Logitech\Scrolling\LgMsgHk.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\progra~1\AVG\AVG10\avgchsvx.exe
c:\windows\system32\nvsvc32.exe
c:\programmer\Fælles filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\programmer\Bonjour\mDNSResponder.exe
c:\programmer\Canon\IJPLM\IJPLMSVC.EXE
c:\programmer\Java\jre6\bin\jqs.exe
c:\programmer\Fælles filer\LightScribe\LSSrvc.exe
c:\programmer\AVG\AVG10\avgnsx.exe
c:\programmer\AVG\AVG10\avgemcx.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\RTHDCPL.EXE
c:\programmer\MouseWare\system\em_exec.exe
c:\programmer\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
c:\windows\system32\wscntfy.exe
c:\windows\System32\ping.exe
c:\progra~1\AVG\AVG10\avgrsx.exe
c:\programmer\AVG\AVG10\avgcsrvx.exe
.
**************************************************************************
.
Gennemført tid: 2011-09-12 18:35:53 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2011-09-12 16:35
.
Pre-Kørsel: 71.236.440.064 byte ledig
Post-Kørsel: 71.198.621.696 byte ledig
.
- - End Of File - - 8B91742FC5D9EC45ED7248FA06E9B6AA