Tusind tak for dine svar indtil videre. Har fulgt dine instrukser og her er log filen:
ComboFix 10-03-02.08 - telefon 03-03-2010 15:09:11.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.45.1030.18.510.238 [GMT 1:00]
Kører fra: c:\documents and settings\telefon\Skrivebord\ComboFix.exe
advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\telefon\Application Data\02000000a4698aa3C.manifest
c:\documents and settings\telefon\Application Data\02000000a4698aa3O.manifest
c:\documents and settings\telefon\Application Data\02000000a4698aa3P.manifest
c:\documents and settings\telefon\Application Data\02000000a4698aa3R.manifest
c:\documents and settings\telefon\Application Data\02000000a4698aa3S.manifest
c:\windows\system32\nfr.assembly
c:\windows\system32\nfr.gpref
C:\xcrashdump.dat
.
((((((((((((((((((((((((((((( Filer skabt fra 2010-02-03 til 2010-03-03 )))))))))))))))))))))))))))))))))))
.
2010-03-03 13:04 . 2010-03-03 13:57 -------- d-----w- c:\programmer\Malwarebytes' Anti-Malware
2010-03-03 09:51 . 2010-03-03 09:51 388096 ----a-r- c:\documents and settings\telefon\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-03-03 09:51 . 2010-03-03 09:51 -------- d-----w- c:\programmer\TrendMicro
2010-03-01 10:52 . 2010-03-01 10:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-03-01 10:45 . 2010-03-03 13:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-11 12:11 . 2010-03-03 14:06 -------- d-----w- c:\documents and settings\telefon\Application Data\U3
2010-02-10 20:17 . 2009-09-24 22:13 131072 ----a-w- c:\windows\system32\DellSPMsg.dll
2010-02-10 19:52 . 2010-02-10 19:52 -------- d-----w- C:\Broadcom
2010-02-10 15:30 . 2010-02-10 15:30 -------- d-----w- c:\programmer\Intel
2010-02-10 15:30 . 2009-08-18 12:44 53248 ----a-w- c:\windows\system32\CSVer.dll
2010-02-10 15:29 . 2010-02-10 15:29 -------- d-----w- C:\Intel
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-01 10:52 . 2009-02-26 10:45 -------- d-----w- c:\programmer\Alwil Software
2010-03-01 09:52 . 2010-03-01 09:52 24952 ----a-w- c:\documents and settings\Administrator\Lokale indstillinger\Application Data\GDIPFONTCACHEV1.DAT
2010-02-18 14:49 . 2007-07-21 15:39 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-02-10 14:18 . 2004-08-27 12:00 79160 ----a-w- c:\windows\system32\perfc006.dat
2010-02-10 14:18 . 2004-08-27 12:00 450658 ----a-w- c:\windows\system32\perfh006.dat
2010-02-10 13:40 . 2007-04-08 15:44 -------- d-----w- c:\programmer\Google
2010-02-10 13:36 . 2009-08-20 11:25 -------- d-----w- c:\programmer\Fælles filer\Real
2010-02-10 13:32 . 2009-10-11 20:54 -------- d-----w- c:\programmer\Unity
2010-02-10 13:31 . 2009-03-18 13:09 -------- d-----w- c:\programmer\MP3 To Wave Maker Plus
2010-02-10 13:30 . 2008-01-12 12:28 -------- d-----w- c:\programmer\DivX
2009-12-31 16:50 . 2004-08-27 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:08 . 2004-08-27 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-17 07:41 . 2006-10-10 11:58 344576 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:09 . 2004-08-27 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-09 10:10 . 2004-08-27 12:00 2147840 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-12-09 10:10 . 2004-08-26 17:50 2026496 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2004-08-27 12:00 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-03 18:51 . 2009-12-03 18:47 5562672 ----a-w- c:\documents and settings\telefon\Application Data\TVU Networks\AutoUpgrade\TVUPlayer2.4.9.1.exe
2009-12-03 18:47 . 2006-11-06 10:59 24952 ----a-w- c:\documents and settings\telefon\Lokale indstillinger\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\programmer\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"updateMgr"="c:\programmer\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2008-04-14 143872]
"SunJavaUpdateSched"="c:\programmer\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\telefon\Menuen Start\Programmer\Start\
rout.bat [2006-11-15 56]
c:\documents and settings\All Users\Menuen Start\Programmer\Start\
Adobe Reader Hurtigstart.lnk - c:\programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisablePersonalDirChange"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Alcatel\\A4400 Call Center Supervisor\\ccs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmer\\Windows Live\\Sync\\WindowsLiveSync.exe"=
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [11-03-2009 10:47 54752]
S2 gupdate;Google Update Service (gupdate);c:\programmer\Google\Update\GoogleUpdate.exe [07-12-2009 11:06 135664]
S3 fsssvc;Windows Live-tjenesten Family Safety;c:\programmer\Windows Live\Family Safety\fsssvc.exe [05-08-2009 22:48 704864]
.
Indhold af mappen 'Planlagte Opgaver'
2010-03-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmer\Google\Update\GoogleUpdate.exe [2009-12-07 10:06]
2010-03-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmer\Google\Update\GoogleUpdate.exe [2009-12-07 10:06]
.
.
------- Yderligere scanning -------
.
uStart Page =
hxxp://portal/uInternet Settings,ProxyServer = http=localhost:7070
uInternet Settings,ProxyOverride = *.local;<local>
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki ... - c:\programmer\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} -
hxxp://dkbn.dk/imageuploader/ImageUploader5.cabFF - ProfilePath - c:\documents and settings\telefon\Application Data\Mozilla\Firefox\Profiles\5f8az9m3.default\
FF - prefs.js: browser.startup.homepage -
FF - prefs.js: network.proxy.http - localhost
FF - prefs.js: network.proxy.http_port - 7070
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\programmer\Google\Update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: c:\programmer\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\programmer\Windows Live\Photo Gallery\NPWLPG.dll
.
- - - - TOMME GENVEJE FJERNET - - - -
Notify-54daba63382 - c:\windows\system32\__c008539E.dat
Notify-NavLogon - (no file)
MSConfigStartUp-googletalk - c:\programmer\Google\Google Talk\googletalk.exe
AddRemove-CCsupervision - c:\program files\Alcatel\A4400 Call Center Supervisor\Uninst.isu
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-03-03 15:14
Windows 5.1.2600 Service Pack 3 NTFS
scanner skjulte processer ...
scanner skjulte autostarter ...
scanner skjulte filer ...
scanning gennemført med succes
skjulte filer: 0
**************************************************************************
.
Gennemført tid: 2010-03-03 15:16:06
ComboFix-quarantined-files.txt 2010-03-03 14:16
Pre-Kørsel: 60.731.846.656 byte ledig
Post-Kørsel: 61.076.246.528 byte ledig
- - End Of File - - C8AAB09B3D8681235E0B1BBCE4A08CB0