Szia. A NoLop nem talált semmit,a Combfix pedig a következőket dobta:
ComboFix 08-01-09.2 - Én 2008-01-10 20:03:32.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1038.18.1450 [GMT 1:00]
Running from: E:\Letöltések\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-12-10 to 2008-01-10 )))))))))))))))))))))))))))))))
.
2008-01-10 19:55 . 2008-01-10 19:59 212 --a------ C:\delete.bat
2008-01-10 19:22 . 2008-01-10 19:22 <DIR> d-------- C:\Program Files\phonostar
2008-01-10 18:11 . 2008-01-10 18:11 <DIR> d-------- C:\Program Files\DAEMON Tools Lite
2008-01-09 22:04 . 2008-01-09 22:04 0 --a------ C:\WINDOWS\nsreg.dat
2008-01-09 21:24 . 2008-01-09 21:24 1,355 --a------ C:\WINDOWS\imsins.BAK
2008-01-09 16:18 . 2008-01-09 16:18 <DIR> d-------- C:\Program Files\CCleaner
2008-01-09 16:01 . 2008-01-09 16:01 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-09 15:58 . 2008-01-09 15:58 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-01-08 13:36 . 2008-01-08 13:37 250 --a------ C:\WINDOWS\gmer.ini
2008-01-06 19:19 . 2008-01-06 19:19 <DIR> d-------- C:\Program Files\Common Files\Sonic Shared
2008-01-06 19:18 . 2008-01-06 19:19 <DIR> d-------- C:\Program Files\Common Files\HP
2008-01-06 19:17 . 2008-01-06 19:17 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-01-06 19:11 . 2008-01-06 19:21 112,838 --a------ C:\WINDOWS\hpoins07.dat
2008-01-06 19:11 . 2005-05-24 03:48 21,124 --------- C:\WINDOWS\hpomdl07.dat
2008-01-06 19:01 . 2007-06-28 17:43 17,254 --a------ C:\WINDOWS\system32\nvwsapps.nvb
2008-01-06 19:00 . 2008-01-06 19:04 <DIR> d-------- C:\WINDOWS\NV36961884.TMP
2008-01-06 18:55 . 2008-01-06 18:55 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-06 18:52 . 2008-01-09 05:02 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-06 13:57 . 2008-01-10 11:42 <DIR> d-------- C:\Film
2008-01-05 10:42 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-05 10:36 . 2008-01-05 10:36 <DIR> d-------- C:\Program Files\ffdshow
2008-01-05 10:36 . 2007-01-01 00:00 60,273 --a------ C:\WINDOWS\system32\pthreadGC2.dll
2008-01-05 10:36 . 2008-01-04 15:32 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2008-01-05 10:36 . 2008-01-04 15:32 6,144 --a------ C:\WINDOWS\system32\ff_acm.acm
2008-01-05 10:36 . 2007-01-01 00:00 547 --a------ C:\WINDOWS\system32\ff_vfw.dll.manifest
2008-01-05 10:30 . 2008-01-05 10:31 <DIR> d-------- C:\WINDOWS\NV3992976.TMP
2008-01-04 18:45 . 2008-01-04 18:45 <DIR> d-------- C:\Program Files\Windows Defender
2008-01-04 18:39 . 2008-01-04 18:39 2,209 --a------ C:\WINDOWS\afp_debug.dat
2008-01-04 11:52 . 2008-01-04 11:54 <DIR> d-------- C:\WINDOWS\NV29882376.TMP
2007-12-21 18:59 . 2007-12-21 19:23 <DIR> d-------- C:\Program Files\Lavalys
2007-12-21 16:55 . 2007-12-21 16:57 <DIR> d-------- C:\WINDOWS\NV17524024.TMP
2007-12-21 09:34 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-12-21 09:34 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2007-12-21 09:34 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2007-12-21 09:34 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-21 09:34 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-21 09:34 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-21 09:34 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-21 09:34 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-20 21:43 . 2007-04-24 16:43 1,990 --a------ C:\WINDOWS\system32\drivers\net_m32.inf
2007-12-20 21:28 . 2007-12-21 08:14 <DIR> d-------- C:\Program Files\Common Files\Panda Software
2007-12-19 01:10 . 2007-12-20 18:23 <DIR> d-------- C:\WINDOWS\system32\ebay
2007-12-17 09:43 . 2007-12-21 09:28 <DIR> d-------- C:\Program Files\PC Tools Internet Security
2007-12-17 00:38 . 2007-12-17 00:38 <DIR> d-------- C:\WINDOWS\Sun
2007-12-13 20:39 . 2007-12-13 20:39 <DIR> d-------- C:\Program Files\Fifa Master
2007-12-11 09:18 . 2007-12-12 20:27 <DIR> d-------- C:\WINDOWS\system32\hu-hu
2007-12-10 11:10 . 2007-12-10 11:10 34 --a------ C:\WINDOWS\system32\oeminfo.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-10 18:30 196,608 ----a-w C:\WINDOWS\system32\drivers\nStandard.bin
2008-01-10 17:05 715,248 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-01-08 17:54 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-06 18:17 --------- d-----w C:\Program Files\HP
2008-01-06 17:41 --------- d-----w C:\Program Files\Google
2008-01-04 18:14 --------- d-----w C:\Program Files\Your Uninstaller 2008
2008-01-04 18:14 --------- d-----w C:\Program Files\LimeWire
2008-01-04 17:46 --------- d-----w C:\Program Files\Windows Live
2008-01-03 15:10 --------- d-----w C:\Program Files\Opera
2007-12-22 08:48 --------- d-----w C:\Program Files\ashampoo
2007-12-20 20:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-20 19:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-09 22:51 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-12-08 18:21 --------- d-----w C:\Program Files\ArtMoney
2007-12-07 17:55 --------- d-----w C:\Program Files\GameHouse
2007-12-06 14:38 --------- d-----w C:\Program Files\Auto Power-on
2007-12-05 07:24 --------- d-----w C:\Program Files\realtech VR
2007-12-02 11:23 --------- d-----w C:\Program Files\CyberLink
2007-12-02 11:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2007-11-29 11:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\River Past G5
2007-11-29 10:52 164,787 ----a-w C:\WINDOWS\Screen Recorder Pro Uninstaller.exe
2007-11-29 10:52 --------- d-----w C:\Program Files\River Past
2007-11-29 10:52 --------- d-----w C:\Program Files\Common Files\River Past
2007-11-29 00:50 127,034 ------r C:\WINDOWS\bwUnin-8.1.1.50-8876480SL.exe
2007-11-28 18:38 --------- d-----w C:\Program Files\BlazeVideo
2007-11-28 16:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2007-11-27 23:31 --------- d-----w C:\Program Files\MSXML 6.0
2007-11-27 19:26 --------- d-----w C:\Program Files\DaDaDev
2007-11-27 15:39 --------- d-----w C:\Program Files\MSBuild
2007-11-27 15:36 --------- d-----w C:\Program Files\Reference Assemblies
2007-11-26 00:13 --------- d-----w C:\Program Files\Picasa2
2007-11-25 14:54 --------- d-----w C:\Program Files\ProxyShell
2007-11-25 11:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\ashampoo
2007-11-25 03:28 --------- d-----w C:\Program Files\EuroPrice Világatlasz
2007-11-24 21:25 --------- d-----w C:\Program Files\SystemRequirementsLab
2007-11-24 14:48 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-24 14:48 --------- d-----w C:\Program Files\AGEIA Technologies
2007-11-23 19:37 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-11-23 19:35 --------- d-----w C:\Program Files\MSXML 4.0
2007-11-23 10:46 --------- d-----w C:\Program Files\Mv2Player
2007-11-22 17:53 --------- d-----w C:\Program Files\File Recover
2007-11-22 17:06 --------- d-----w C:\Program Files\Smart Projects
2007-11-22 09:27 --------- d-----w C:\Program Files\MBMAKA+
2007-11-22 07:58 --------- d-----w C:\Program Files\Java
2007-11-22 07:58 --------- d-----w C:\Program Files\Common Files\Java
2007-11-22 07:50 --------- d-----w C:\Program Files\Logitech
2007-11-22 07:49 --------- d-----w C:\Program Files\Common Files\Logitech
2007-11-22 07:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2007-11-22 07:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sonic
2007-11-22 07:39 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2007-11-21 16:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\MumboJumbo
2007-11-21 15:48 --------- d-----w C:\Program Files\Nero
2007-11-21 15:48 --------- d-----w C:\Program Files\Common Files\Ahead
2007-11-20 23:58 --------- d-----w C:\Program Files\QuickTime
2007-11-20 23:58 --------- d-----w C:\Program Files\Apple Software Update
2007-11-20 23:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-11-20 23:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-11-20 21:22 --------- d-----w C:\Program Files\Macrogaming
2007-11-20 18:52 --------- d-----w C:\Program Files\uTorrent
2007-11-20 17:31 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2007-11-20 17:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-11-20 17:24 --------- d-----w C:\Program Files\Winamp
2007-11-20 15:43 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-11-20 15:42 --------- d-----w C:\Program Files\Skype
2007-11-20 15:42 --------- d-----w C:\Program Files\Common Files\Skype
2007-11-20 15:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2007-11-20 15:41 --------- d-----w C:\Program Files\Common Files\Adobe
2007-11-20 15:11 --------- d-----w C:\Program Files\Common Files\snpstd
2007-11-20 15:06 --------- d-----w C:\Program Files\Alwil Software
2007-11-19 21:00 --------- d-----w C:\Program Files\Webteh
2007-11-19 20:44 --------- d-----w C:\Program Files\TGTSoft
2007-11-19 18:45 --------- d-----w C:\Program Files\Saitek
2007-11-19 18:45 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-11-19 16:33 60,416 ----a-w C:\WINDOWS\ALCFDRTM.EXE
2007-11-19 15:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2007-11-19 13:56 --------- d-----w C:\Program Files\Ahead
2007-11-19 13:49 --------- d-----w C:\Program Files\My Company Name
2007-11-19 13:46 --------- d-----w C:\Program Files\ASUS
2007-11-19 13:39 --------- d-----w C:\Program Files\DIFX
2007-11-19 13:38 --------- d-----w C:\Program Files\Realtek AC97
2007-11-19 13:12 --------- d-----w C:\Program Files\microsoft frontpage
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2005-05-11 22:36 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll
.
((((((((((((((((((((((((((((( snapshot_2008-01-07_21.26.22.01 )))))))))))))))))))))))))))))))))))))))))
.
+ 2000-08-31 07:00:00 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2008-01-10 19:03:22 622,592 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-10 19:03:22 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-10 19:03:22 602,112 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
+ 2008-01-10 19:03:22 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-10 19:03:22 5,197,824 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
+ 2008-01-10 19:03:22 258,048 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2000-08-31 07:00:00 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2008-01-05 05:57:26 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-01-09 15:01:28 5,165,056 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000001\NTUSER.DAT
+ 2008-01-09 15:01:28 258,048 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000002\UsrClass.dat
+ 2008-01-05 05:57:26 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-01-09 15:01:22 5,165,056 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\
00000001\NTUSER.DAT
+ 2008-01-09 15:01:22 258,048 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\
00000002\UsrClass.dat
+ 2008-01-08 12:36:12 585,791 ----a-w C:\WINDOWS\gmer.dll
+ 2007-06-29 08:38:18 581,632 ----a-w C:\WINDOWS\gmer.exe
- 2006-08-17 12:29:58 725,504 -c--a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
+ 2007-11-07 09:29:26 725,504 -c--a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
- 2006-04-20 11:51:50 359,808 -c--a-w C:\WINDOWS\system32\dllcache\tcpip.sys
+ 2007-10-30 17:20:55 360,064 -c--a-w C:\WINDOWS\system32\dllcache\tcpip.sys
+ 2008-01-08 12:36:12 70,001 ----a-w C:\WINDOWS\system32\drivers\gmer.sys
- 2006-04-20 11:51:50 359,808 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
+ 2007-10-30 17:20:55 360,064 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
- 2006-08-17 12:29:58 725,504 ----a-w C:\WINDOWS\system32\lsasrv.dll
+ 2007-11-07 09:29:26 725,504 ----a-w C:\WINDOWS\system32\lsasrv.dll
- 2007-12-02 14:00:06 18,684,536 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2008-01-02 18:21:36 17,642,616 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2008-01-10 19:06:20 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_618.dat
+ 2008-01-10 19:08:20 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_e34.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:47 15360]
"STYLEXP"="C:\Program Files\TGTSoft\StyleXP\StyleXP.exe" [2006-05-24 19:31 1372160]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-11-12 15:48 21760296]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-11-29 01:55 67128]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2007-12-29 10:43 486856]
"PhonostarTimer"="C:\Program Files\phonostar\ps_timer.exe" [2007-12-05 16:14 126976]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2006-06-20 22:42 577536 C:\WINDOWS\soundman.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-28 17:43 8466432]
"nwiz"="nwiz.exe" [2007-06-28 17:43 1626112 C:\WINDOWS\system32\nwiz.exe]
"ASUSGamerOSD"="C:\Program Files\ASUS\GamerOSD\GamerOSD.exe" [2007-07-12 10:03 380928]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"SaiSmart"="C:\Program Files\Saitek\Software\SaiSmart.exe" [2004-01-28 09:19 98304]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"snpstd"="C:\WINDOWS\vsnpstd.exe" [2003-12-31 17:39 40960]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"BDRegion"="C:\Program Files\Cyberlink\Shared Files\brs.exe" [2007-11-16 19:20 91432]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-10-28 09:35 72736]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2007-10-11 12:06 62760]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-28 17:43 81920]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 15:47 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\WINDOWS\\system32\\LogonUi.exe"
R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\
000.fcl [2007-11-03 00:12]
R3 asusgsb;ASUS Virtual Video Capture Device Driver;C:\WINDOWS\system32\drivers\asusgsb.sys [2007-07-12 10:03]
R3 SaiH0109;SaiH0109;C:\WINDOWS\system32\DRIVERS\SaiH0109.sys [2004-01-30 14:19]
R3 SaiU0109;SaiU0109;C:\WINDOWS\system32\DRIVERS\SaiU0109.sys [2004-01-30 14:19]
R3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D32.sys [2007-07-12 10:03]
S0 lohmobri;lohmobri;C:\WINDOWS\system32\drivers\ercdejss.sys []
S2 PCAutoPowerOnService;Auto Power-on & Shut-down Service;C:\Program Files\Auto Power-on\PCAutoPowerOnService.exe [2006-02-08 14:12]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [2007-10-17 00:00]
S3 NETIMFLT;PANDA NDIS IM Filter Miniport;C:\WINDOWS\system32\DRIVERS\netimflt.sys []
S3 SIWIO;SIW low-level I/O driver;C:\WINDOWS\TEMP\SiwIo.sys []
.
Contents of the 'Scheduled Tasks' folder
"2008-01-10 19:09:20 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-10 20:07:10
Windows 5.1.2600 Szervizcsomag 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-10 20:10:44 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-10 19:10:42
ComboFix2.txt 2008-01-07 20:26:45
ComboFix3.txt 2008-01-05 11:22:51
ComboFix4.txt 2008-01-05 09:45:11
.
2008-01-09 20:25:05 --- E O F ---
Akkor tudod mi a hiba?Ciao