Så jeg skal ikke trykke på “fix”?
Her er loggen:
Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 25-07-2012 01
Ran by SYSTEM at 04-08-2012 10:40:07
Running from G:\
Windows Vista (TM) Home Premium Service Pack 1 (X86) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IAAnotif] “C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe” [178712 2007-10-03] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] RtHDVCpl.exe [x]
HKLM\...\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe [102400 2007-09-07] (Synaptics, Inc.)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [141848 2007-08-28] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [154136 2007-08-28] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [137752 2007-08-28] (Intel Corporation)
HKLM\...\Run: [RemoteControl] “C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe” [81920 2008-01-22] (Cyberlink Corp.)
HKLM\...\Run: [LanguageShortcut] “C:\Program Files\CyberLink\PowerDVD\Language\Language.exe” [62760 2007-10-11] ()
HKLM\...\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe [521776 2008-01-02] (Egis Incorporated)
HKLM\...\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe [858632 2008-01-07] (Dritek System Inc.)
HKLM\...\Run: [eRecoveryService] [x]
HKLM\...\Run: [WarReg_PopUp] C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe [303104 2008-01-28] (Acer Incorporated)
HKLM\...\Run: [GrooveMonitor] “C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe” [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [177440 2009-08-13] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] “C:\Program Files\QuickTime\QTTask.exe” -atboottime [417792 2009-11-10] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] “C:\Program Files\Itunes\iTunesHelper.exe” [141608 2010-02-15] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] “C:\Program Files\Common Files\Java\Java Update\jusched.exe” [248040 2010-02-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [EEventManager] C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe [665424 2008-12-04] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [54576 2008-12-08] (Hewlett-Packard)
HKLM\...\Run: [] [x]
HKLM\...\Run: [Communicator] “C:\Program Files\Microsoft Office Communicator\communicator.exe” /fromrunkey [5164120 2012-05-15] (Microsoft Corporation)
HKLM\...\Run: [Adobe Reader Speed Launcher] “C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe” [39792 2008-10-14] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] “C:\Program Files\Microsoft Security Client\msseces.exe” -hide -runkey [931200 2012-03-26] (Microsoft Corporation)
HKU\Penille\...\Run: [MsnMsgr] “C:\Program Files\Windows Live\Messenger\msnmsgr.exe” /background [3883856 2009-07-26] (Microsoft Corporation)
HKU\Penille\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-20] (Microsoft Corporation)
HKU\Penille\...\Run: [TomTomHOME.exe] “C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe” [247144 2010-05-07] (TomTom)
HKU\Penille\...\Run: [EPSON SX110 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIFBE.EXE /FU “C:\Windows\TEMP\E_SB9F2.tmp” /EF “HKCU” [199680 2008-09-26] (SEIKO EPSON CORPORATION)
HKU\Penille\...\Run: [cbsrkcmd] rundll32 “C:\Users\Penille\AppData\Local\Temp\ctfmalua.dll”,CreateProcessNotify [56320 2012-08-03] (FRISK Software International)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1 212.242.40.3 212.242.40.51
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Empowering Technology Launcher.lnk
ShortcutTarget: Empowering Technology Launcher.lnk -> C:\Acer\Empowering Technology\eAPLauncher.exe (Acer Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Opdateringsagent.lnk
ShortcutTarget: Opdateringsagent.lnk -> C:\Program Files\Connect it\AutoUpdateSrv.exe (No File)
================================ Services (Whitelisted) ==================
2 Apple Mobile Device; “C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe” [144672 2009-08-28] (Apple Inc.)
2 BBSvc; C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.exe [193616 2012-06-11] (Microsoft Corporation.)
3 BBUpdate; C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.exe [240208 2012-06-11] (Microsoft Corporation.)
2 BecHelperService; C:\Program Files\Connect it\BecHelperService.exe [1762176 2010-09-07] ()
2 eDataSecurity Service; “C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe” [506416 2008-01-02] (Egis Incorporated)
2 eLockService; C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe [24576 2007-10-01] (Acer Inc.)
2 eNet Service; C:\Acer\Empowering Technology\eNet\eNet Service.exe [131072 2007-12-20] (Acer Inc.)
2 eRecoveryService; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [57344 2007-09-10] (Acer Inc.)
2 eSettingsService; C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [24576 2007-12-19] ()
2 Eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [21504 2008-01-20] (Microsoft Corporation)
2 MobilityService; C:\Acer\Mobility Center\MobilityService.exe -p [110592 2007-11-27] ()
2 MsMpSvc; “C:\Program Files\Microsoft Security Client\MsMpEng.exe” [11552 2012-03-26] (Microsoft Corporation)
3 MSSQL$MSSMLBIZ; “C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe” -sMSSMLBIZ [29293408 2010-12-10] (Microsoft Corporation)
3 NisSrv; “C:\Program Files\Microsoft Security Client\NisSrv.exe” [214952 2012-03-26] (Microsoft Corporation)
2 WMIService; C:\Acer\Empowering Technology\ePower\ePowerSvc.exe [167936 2007-09-20] (acer)
========================== Drivers (Whitelisted) =============
3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [116736 2010-09-07] (Huawei Technologies Co., Ltd.)
3 ew_hwusbdev; C:\Windows\System32\DRIVERS\ew_hwusbdev.sys [101504 2010-09-07] (Huawei Technologies Co., Ltd.)
3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [49664 2006-04-12] (HP)
3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2006-04-12] (HP)
3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21568 2006-04-12] (HP)
3 huawei_enumerator; C:\Windows\System32\DRIVERS\ew_jubusenum.sys [70656 2010-09-07] (Huawei Technologies Co., Ltd.)
3 k750bus; C:\Windows\System32\DRIVERS\k750bus.sys [55216 2005-02-11] (MCCI)
0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
3 s0017bus; C:\Windows\System32\DRIVERS\s0017bus.sys [90536 2008-10-17] (MCCI Corporation)
3 s0017mdfl; C:\Windows\System32\DRIVERS\s0017mdfl.sys [15016 2008-10-17] (MCCI Corporation)
3 s0017mdm; C:\Windows\System32\DRIVERS\s0017mdm.sys [122152 2008-10-17] (MCCI Corporation)
3 upperdev; C:\Windows\System32\DRIVERS\usbser_lowerflt.sys [8064 2008-05-02] (Windows (R) Codename Longhorn DDK provider)
3 UsbserFilt; C:\Windows\System32\DRIVERS\usbser_lowerfltj.sys [8064 2008-05-02] (Windows (R) Codename Longhorn DDK provider)
3 AVFSFilter; C:\Windows\System32\DRIVERS\avfsfilter.sys [x]
3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [x]
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-04 10:39 - 2012-08-04 10:39 - 00000000 ____D C:\FRST
2012-08-03 07:45 - 2012-08-03 07:45 - 09231560 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerInstaller.exe
2012-08-03 07:17 - 2012-08-03 07:18 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-03 06:57 - 2012-08-03 06:57 - 00000000 ____A C:\Windows\EEventManager.INI
2012-08-03 06:45 - 2012-08-03 07:19 - 00001912 ____A C:\Windows\epplauncher.mif
2012-08-03 06:31 - 2012-08-03 06:31 - 00000000 ____D C:\Users\Penille\AppData\Roaming\Fighters
2012-08-03 06:31 - 2012-08-03 06:31 - 00000000 ____D C:\Users\All Users\Common Toolkit Suite
2012-08-03 06:30 - 2012-08-03 06:34 - 00000000 ____D C:\Users\All Users\Fighters
2012-08-03 05:37 - 2012-08-03 05:37 - 00000000 ____D C:\Program Files\Enigma Software Group
2012-08-03 05:36 - 2012-08-03 06:30 - 00000000 ____D C:\Windows\CC1F6DA021D2425AB1B65B164A598450.TMP
2012-08-03 05:36 - 2012-08-03 05:36 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard
2012-08-03 05:27 - 2012-08-03 05:14 - 00407872 ____A C:\Users\Penille\Desktop\pkiller.exe
2012-08-03 04:10 - 2007-08-20 12:13 - 00172032 ____A (Intel Corporation) C:\Windows\System32\igfxres.dll
2012-08-03 03:55 - 2012-08-03 07:45 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-03 03:55 - 2012-08-03 07:45 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-03 03:55 - 2012-08-03 07:45 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-28 10:55 - 2012-08-02 02:30 - 03576578 ____H C:\Users\Penille\Desktop\~WRL0005.tmp
============ 3 Months Modified Files ========================
2012-08-03 12:23 - 2008-01-20 18:47 - 01407880 ____A C:\Windows\PFRO.log
2012-08-03 12:23 - 2006-11-02 05:01 - 00032590 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-08-03 12:23 - 2006-11-02 05:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-03 12:23 - 2006-11-02 04:47 - 00003216 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-03 12:23 - 2006-11-02 04:47 - 00003216 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-03 12:21 - 2008-01-20 18:24 - 00279040 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-03 12:16 - 2006-11-02 04:52 - 00158055 ____A C:\Windows\setupact.log
2012-08-03 12:14 - 2006-11-02 02:33 - 01384028 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-03 07:45 - 2012-08-03 07:45 - 09231560 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerInstaller.exe
2012-08-03 07:45 - 2012-08-03 03:55 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-08-03 07:45 - 2012-08-03 03:55 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-08-03 07:45 - 2012-08-03 03:55 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-03 07:19 - 2012-08-03 06:45 - 00001912 ____A C:\Windows\epplauncher.mif
2012-08-03 07:19 - 2008-08-15 17:58 - 01075531 ____A C:\Windows\WindowsUpdate.log
2012-08-03 06:57 - 2012-08-03 06:57 - 00000000 ____A C:\Windows\EEventManager.INI
2012-08-03 06:47 - 2006-11-02 04:47 - 00371256 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-03 06:43 - 2008-08-29 11:20 - 00001356 ____A C:\Users\Penille\AppData\Local\d3d9caps.dat
2012-08-03 05:19 - 2008-08-15 12:25 - 00096768 ____A C:\Users\Penille\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-08-03 05:14 - 2012-08-03 05:27 - 00407872 ____A C:\Users\Penille\Desktop\pkiller.exe
2012-08-03 03:54 - 2012-05-19 11:04 - 00000439 ____A C:\Windows\System32\Drivers\etc\hosts.ics
2012-08-02 02:30 - 2012-07-28 10:55 - 03576578 ____H C:\Users\Penille\Desktop\~WRL0005.tmp
2012-07-28 06:57 - 2006-11-02 02:23 - 00000219 ____A C:\Windows\win.ini
2012-07-28 06:50 - 2006-11-02 02:24 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
ZeroAccess:
C:\Windows\Installer\{681c730e-5659-3b37-cbe3-6ed72c7eda84}
C:\Windows\Installer\{681c730e-5659-3b37-cbe3-6ed72c7eda84}\@
C:\Windows\Installer\{681c730e-5659-3b37-cbe3-6ed72c7eda84}\L
C:\Windows\Installer\{681c730e-5659-3b37-cbe3-6ed72c7eda84}\n
C:\Windows\Installer\{681c730e-5659-3b37-cbe3-6ed72c7eda84}\U
C:\Windows\Installer\{681c730e-5659-3b37-cbe3-6ed72c7eda84}\U\00000001.@
C:\Windows\Installer\{681c730e-5659-3b37-cbe3-6ed72c7eda84}\U\80000000.@
C:\Windows\Installer\{681c730e-5659-3b37-cbe3-6ed72c7eda84}\U\800000cb.@
ZeroAccess:
C:\Users\Penille\AppData\Local\{681c730e-5659-3b37-cbe3-6ed72c7eda84}
C:\Users\Penille\AppData\Local\{681c730e-5659-3b37-cbe3-6ed72c7eda84}\@
C:\Users\Penille\AppData\Local\{681c730e-5659-3b37-cbe3-6ed72c7eda84}\L
C:\Users\Penille\AppData\Local\{681c730e-5659-3b37-cbe3-6ed72c7eda84}\n
C:\Users\Penille\AppData\Local\{681c730e-5659-3b37-cbe3-6ed72c7eda84}\U
C:\Users\Penille\AppData\Local\{681c730e-5659-3b37-cbe3-6ed72c7eda84}\U\00000001.@
C:\Users\Penille\AppData\Local\{681c730e-5659-3b37-cbe3-6ed72c7eda84}\U\80000000.@
C:\Users\Penille\AppData\Local\{681c730e-5659-3b37-cbe3-6ed72c7eda84}\U\800000cb.@
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 5DC3C54FC22BBB6F66C290C7C0384DF9 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: “%1” %* => OK
========================= Memory info ======================
Percentage of memory in use: 20%
Total physical RAM: 2037.68 MB
Available physical RAM: 1611.82 MB
Total Pagefile: 1805.91 MB
Available Pagefile: 1675 MB
Total Virtual: 2047.88 MB
Available Virtual: 1974.31 MB
======================= Partitions =========================
1 Drive c: (ACER) (Fixed) (Total:144.17 GB) (Free:54.3 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (DATA) (Fixed) (Total:144.15 GB) (Free:136.59 GB) NTFS
4 Drive f: (PQSERVICE) (Fixed) (Total:9.76 GB) (Free:3.13 GB) FAT32
5 Drive g: () (Removable) (Total:3.73 GB) (Free:1.66 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
————————————- ———- —- —-
Disk 0 Online 298 GB 0 B
Disk 1 Online 3832 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
——————- ———————————- ———-
Partition 1 OEM 10 GB 1024 KB
Partition 2 Primary 144 GB 10 GB
Partition 3 Primary 144 GB 154 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
——————- —————- ——- ————————- ————- ————
* Volume 4 F PQSERVICE FAT32 Partition 10 GB Healthy Hidden
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
——————- —————- ——- ————————- ————- ————
* Volume 1 C ACER NTFS Partition 144 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
——————- —————- ——- ————————- ————- ————
* Volume 2 D DATA NTFS Partition 144 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
——————- ———————————- ———-
Partition 1 Primary 3832 MB 64 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
——————- —————- ——- ————————- ————- ————
* Volume 3 G FAT32 Removable 3832 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-08-03 07:19
======================= End Of Log ==========================