Jeg kan se i hjælp, at men ikke kan vedhæfte filer, så jeg sender loggen her:
ComboFix 08-07-15.4 - Benny 2008-07-17 12:30:04.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1030.18.2061 [GMT 2:00]
Running from: C:\Users\Benny\Desktop\ComboFix.exe
Command switches used :: /snapshot
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
C:\Windows\system32\MSINET.oca
——- BITS: Possible infected sites——-
hxxp://ftp.hp.com
.
((((((((((((((((((((((((( Files Created from 2008-06-17 to 2008-07-17 )))))))))))))))))))))))))))))))
.
2008-07-16 14:55 . 2008-07-16 14:55 <DIR> d————C:\Users\Benny\AppData\Roaming\Download Manager
2008-07-14 18:34 . 2008-07-14 18:34 <DIR> d————C:\Users\Benny\AppData\Roaming\SUPERAntiSpyware.com
2008-07-14 18:34 . 2008-07-14 18:34 <DIR> d————C:\Users\All Users\SUPERAntiSpyware.com
2008-07-14 18:34 . 2008-07-14 18:34 <DIR> d————C:\ProgramData\SUPERAntiSpyware.com
2008-07-14 18:34 . 2008-07-14 18:34 <DIR> d————C:\Program Files\SUPERAntiSpyware
2008-07-09 06:59 . 2008-07-09 06:59 <DIR> d————C:\Users\Benny\AppData\Roaming\Uniblue
2008-07-09 00:07 . 2008-06-26 03:45 12,240,896—a———C:\Windows\System32\NlsLexicons0007.dll
2008-07-09 00:07 . 2008-06-26 03:45 2,644,480—a———C:\Windows\System32\NlsLexicons0009.dll
2008-07-09 00:07 . 2008-06-26 05:29 801,280—a———C:\Windows\System32\NaturalLanguage6.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-17 10:29 786,432—sha-w C:\Users\Gæst\ntuser.dat
2008-07-17 10:29 786,432—sha-w C:\Users\Gæst\ntuser.dat
2008-07-17 10:24————- d——-w C:\ProgramData\BullGuard
2008-07-17 10:17————- d—-a-w C:\ProgramData\TEMP
2008-07-14 16:34————- d——-w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-08 22:16————- d——-w C:\Program Files\Windows Mail
2008-07-08 22:11————- d——-w C:\ProgramData\Microsoft Help
2008-07-02 19:25————- d—h—w C:\Program Files\InstallShield Installation Information
2008-07-02 19:25————- d——-w C:\Program Files\pinnacle
2008-07-02 19:22————- d——-w C:\ProgramData\Pinnacle
2008-06-30 17:21 342——a-w C:\Users\Benny\AppData\Roaming\wklnhst.dat
2008-06-16 05:20————- d——-w C:\Users\Benny\AppData\Roaming\ICAClient
2008-06-16 04:46————- d——-w C:\Program Files\Citrix
2008-05-19 20:10————- d——-w C:\Program Files\Microsoft Silverlight
2008-05-15 21:03 262,144——a-w C:\ntuser.dat
2008-05-10 03:35 564,736——a-w C:\Windows\System32\emdmgmt.dll
2008-05-08 21:59 90,112——a-w C:\Windows\System32\wshext.dll
2008-05-08 21:59 430,080——a-w C:\Windows\System32\vbscript.dll
2008-05-08 21:59 180,224——a-w C:\Windows\System32\scrobj.dll
2008-05-08 21:59 172,032——a-w C:\Windows\System32\scrrun.dll
2008-05-08 21:59 155,648——a-w C:\Windows\System32\wscript.exe
2008-05-08 21:58 135,168——a-w C:\Windows\System32\cscript.exe
2008-04-26 08:25 3,600,952——a-w C:\Windows\System32\ntkrnlpa.exe
2008-04-26 08:25 3,549,240——a-w C:\Windows\System32\ntoskrnl.exe
2008-04-26 08:08 1,314,816——a-w C:\Windows\System32\quartz.dll
2008-04-25 04:35 826,880——a-w C:\Windows\System32\wininet.dll
2008-04-23 04:42 428,544——a-w C:\Windows\System32\EncDec.dll
2008-04-23 04:42 293,376——a-w C:\Windows\System32\psisdecd.dll
2008-04-18 19:14 174—sha-w C:\Program Files\desktop.ini
2008-04-18 18:45 82,432——a-w C:\Windows\System32\axaltocm.dll
2008-04-18 18:45 101,888——a-w C:\Windows\System32\ifxcardm.dll
2008-03-30 18:57 22—sha-w C:\Windows\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ehTray.exe”=“C:\Windows\ehome\ehTray.exe” [2008-01-19 09:33 125952]
“WMPNSCFG”=“C:\Program Files\Windows Media Player\WMPNSCFG.exe” [2008-01-19 09:33 202240]
“SUPERAntiSpyware”=“C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe” [2008-05-28 10:33 1506544]
“Sidebar”=“C:\Program Files\Windows Sidebar\sidebar.exe” [2008-01-19 09:33 1233920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“hpsysdrv”=“c:\hp\support\hpsysdrv.exe” [2007-04-18 17:01 65536]
“KBD”=“C:\HP\KBD\KbdStub.EXE” [2006-12-08 18:16 65536]
“SunJavaUpdateReg”=“C:\Windows\system32\jureg.exe” [2008-02-22 05:25 54672]
“HP Software Update”=“c:\Program Files\HP\HP Software Update\HPWuSchd2.exe” [2007-05-08 17:24 54840]
“GrooveMonitor”=“C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe” [2007-08-24 08:00 33648]
“PinnacleDriverCheck”=“C:\Windows\system32\\PSDrvCheck.exe” [2004-03-11 01:26 406016]
“Adobe Reader Speed Launcher”=“C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe” [2008-01-11 23:16 39792]
“OsdMaestro”=“C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe” [2007-02-15 13:59 118784]
“StartCCC”=“C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” [2008-01-21 12:17 61440]
“BullGuard”=“C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe” [2008-07-02 17:36 308552]
“SpySweeper”=“C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe” [2008-01-04 21:56 5367664]
“RtHDVCpl”=“RtHDVCpl.exe” [2008-01-15 11:26 4874240 C:\Windows\RtHDVCpl.exe]
C:\Users\Sonja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Mobile Connect.lnk - C:\Program Files\Huawei technologies\Mobile Connect\Mobile Connect.exe [2008-03-03 01:16:45 921600]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“EnableUIADesktopToggle”= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
“{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}”= “C:\Program Files\SUPERAntiSpyware\SASSEH.DLL” [2008-05-13 10:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“vidc.i420”= vdrcodec.dll
“msacm.l3codecp”= l3codecp.acm
“VIDC.MJPG”= Pvmjpg30.dll
“VIDC.PIM1”= pclepim1.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
“DisableMonitoring”=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
“DisableMonitoring”=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
“DisableMonitoring”=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1159194974-4179016457-1645135426-1000]
“EnableNotificationsRef”=dword:00000002
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
“{645711F2-45D2-4064-A674-DBD2D8E533DC}”= c:\Program Files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
“{E69C0106-5361-4A1E-86B7-04B7C8F88335}”= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
“{C05472B3-526F-42BB-B9FC-D29202127070}”= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
“{E74D6426-752C-4817-96E0-C266F7F3D800}”= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
“{1A5357A0-12E2-473A-BE78-26BF8AE17537}”= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
“{C25CDB05-92CA-4E5F-86BF-EB3DC5A7A6E6}”= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
“{19D8EDB1-E915-4AD7-AEDF-DBBC3FE340F1}”= UDP:C:\Program Files\pinnacle\Studio 10\programs\RM.exe:Render Manager
“{BB35AB1E-DC32-4B56-90F6-E4F11B42F4DB}”= TCP:C:\Program Files\pinnacle\Studio 10\programs\RM.exe:Render Manager
“{DB4B5BD0-2E0F-478E-9F9A-53FBFDC2A347}”= UDP:C:\Program Files\pinnacle\Studio 10\programs\Studio.exe:Studio
“{AE2FEA30-FFC3-4E1D-8255-5AC121FD93C2}”= TCP:C:\Program Files\pinnacle\Studio 10\programs\Studio.exe:Studio
“{9A2E9245-16CF-424F-951B-9BBED1160051}”= UDP:C:\Program Files\pinnacle\Studio 10\programs\PMSRegisterFile.exe:PMSRegisterFile
“{A5C25486-394E-4DCC-B288-E1276E0AEC41}”= TCP:C:\Program Files\pinnacle\Studio 10\programs\PMSRegisterFile.exe:PMSRegisterFile
“{3D36A9D1-F32D-4A5B-B5E8-D499F92BF75D}”= UDP:C:\Program Files\pinnacle\Studio 10\programs\umi.exe:umi
“{11614322-D9F0-46A2-8179-ED1363F7B3FF}”= TCP:C:\Program Files\pinnacle\Studio 10\programs\umi.exe:umi
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
“EnableFirewall”= 0 (0x0)
R1 afw;BullGuard Firewall Driver;C:\Windows\system32\DRIVERS\afw.sys [2007-10-29 10:08]
R2 BdFileSpy;BullGuard File Monitor Driver;C:\Windows\system32\drivers\BdFileSpy.sys [2008-04-10 19:13]
R2 BsFileScan;BullGuard File Scan Service;C:\Windows\System32\svchost.exe [2008-01-19 09:33]
R2 BsFire;BullGuard Firewall Service;C:\Windows\System32\svchost.exe [2008-01-19 09:33]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2008-02-26 00:53]
R3 Reconn;BullGuard Email Monitor;C:\Program Files\BullGuard Ltd\BullGuard\Reconn.sys [2007-10-29 10:08]
R3 USB28xxBGA;PCTV 320e Device;C:\Windows\system32\DRIVERS\emBDA.sys [2007-08-07 14:39]
R3 USB28xxOEM;USB 28xx OEM Filter;C:\Windows\system32\DRIVERS\emOEM.sys [2007-08-07 14:39]
S3 ECDMVDZUNKCV;ECDMVDZUNKCV;C:\Users\Benny\AppData\Local\Temp\ECDMVDZUNKCV.exe []
S3 SA;SA;C:\Users\Benny\AppData\Local\Temp\SA.exe []
S3 SXIBIAJQ;SXIBIAJQ;C:\Users\Benny\AppData\Local\Temp\SXIBIAJQ.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
BullGuard REG_MULTI_SZ BgMainSvc BsFileScan BsMailProxy BsFire
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\shell\AutoRun\command - K:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
\shell\AutoRun\command - L:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{39a02216-e940-11dc-ad8e-001e9008345d}]
\shell\AutoRun\command - J:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{39a02218-e940-11dc-ad8e-001e9008345d}]
\shell\AutoRun\command - J:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{76c0cd37-f5d2-11dc-b774-001e9008345d}]
\shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd3d646f-fa88-11dc-ae85-001e9008345d}]
\shell\AutoRun\command - K:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f1d0b52b-e8ad-11dc-9d9e-001e9008345d}]
\shell\AutoRun\command - J:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f1d0b544-e8ad-11dc-9d9e-001e9008345d}]
\shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f965444b-f3a6-11dc-8319-001e9008345d}]
\shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fe58269b-f2cc-11dc-a500-806e6f6e6963}]
\shell\AutoRun\command - F:\AutoRun.exe
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Uniblue RegistryBooster 2 - c:\program files\uniblue\registrybooster 2\StartRegistryBooster.exe
HKLM-Run-HP Health Check Scheduler - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
HKLM-Run-RegistryMechanic - (no file)
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-17 12:33:57
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-17 12:35:01
ComboFix-quarantined-files.txt 2008-07-17 10:34:55
ComboFix2.txt 2008-04-12 18:22:04
Pre-Run: 284,060,798,976 byte ledig
Post-Run: 303,364,259,840 byte ledig
178—- E O F—- 2008-07-11 05:40:10