Efter jeg har kørt det du bad mig om lavede den en "ComboFix2.txt" hvor i der står følgende:
"Nordea-Elev" - 2007-07-10 7:16:17 - ComboFix 07-07-10.1 - Service Pack 2
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_NTMLSVC
-------\NtmlSvc
((((((((((((((((((((((((( Files Created from 2007-06-10 to 2007-07-10 )))))))))))))))))))))))))))))))
2007-07-10 07:15 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-10 00:38 6,369 ---hs---- C:\WINDOWS\system32\npstv.bak1
2007-07-10 00:37 266,336 --a------ C:\WINDOWS\system32\vtspn.dll.vir
2007-07-10 00:22 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2007-07-10 00:16 <DIR> d-------- C:\VundoFix Backups
2007-07-09 18:17 <DIR> d-------- C:\Program Files\Common Files\Application
2007-07-09 18:16 <DIR> d-------- C:\Program Files\SPYWAREfighter
2007-07-09 17:46 12,290,511 --------- C:\avg7qt.dat
2007-07-09 17:41 <DIR> d-------- C:\DOCUME~1\NORDEA~1\APPLIC~1\TrojanHunter
2007-07-09 07:34 <DIR> d-------- C:\Program Files\TrojanHunter 4.7
2007-07-08 19:20 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\ssdata
2007-07-08 19:01 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-07-08 17:54 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-07-08 06:40 31,254 --a------ C:\WINDOWS\system32\xxyxvtq.dll.vir
2007-07-08 06:03 <DIR> d-------- C:\DOCUME~1\NORDEA~1\APPLIC~1\WebStripper
2007-07-07 12:23 <DIR> d-------- C:\Program Files\Lavasoft
2007-07-07 12:23 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-07-07 12:22 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-07-06 03:53 <DIR> d-------- C:\Program Files\Common Files\DirectX
2007-07-06 03:46 <DIR> d-------- C:\Program Files\EA GAMES
2007-07-06 02:19 786,432 --ah----- C:\DOCUME~1\Guest\NTUSER.DAT
2007-07-04 11:28 7,552 --a------ C:\WINDOWS\system32\drivers\SONYPVU1.SYS
2007-07-02 09:59 <DIR> d-------- C:\DOCUME~1\NORDEA~1\APPLIC~1\HP
2007-06-23 15:14 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-07 10:13:25 -------- d-----w C:\Program Files\Google
2007-07-07 10:08:46 -------- d-----w C:\DOCUME~1\NORDEA~1\APPLIC~1\Lavasoft
2007-07-07 09:22:23 -------- d-----w C:\Program Files\IrfanView
2007-07-03 11:48:18 -------- d-----w C:\DOCUME~1\NORDEA~1\APPLIC~1\dvdcss
2007-07-02 21:53:06 -------- d-----w C:\DOCUME~1\NORDEA~1\APPLIC~1\Skype
2007-06-30 06:51:25 -------- d-----w C:\Program Files\Lx_cats
2007-06-23 14:01:43 -------- d-----w C:\DOCUME~1\NORDEA~1\APPLIC~1\Apple Computer
2007-06-23 13:21:10 -------- d-----w C:\DOCUME~1\NORDEA~1\APPLIC~1\Google
2007-06-08 09:52:50 947,096 ----a-w C:\WINDOWS\system32\_ISource30.dll
2007-06-07 18:50:01 4,385 ----a-w C:\WINDOWS\mozver.dat
2007-06-04 13:18:48 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 13:17:02 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 13:14:56 6,272 ----a-w C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-06-02 07:52:10 -------- d-----w C:\DOCUME~1\NORDEA~1\APPLIC~1\Azureus
2007-05-31 19:46:18 71,096 ----a-w C:\DOCUME~1\NORDEA~1\APPLIC~1\GDIPFONTCACHEV1.DAT
2007-05-23 22:08:51 -------- d-----w C:\Program Files\Nokia
2007-05-23 22:01:38 -------- d-----w C:\DOCUME~1\NORDEA~1\APPLIC~1\Nokia
2007-05-20 14:00:43 -------- d-----w C:\Program Files\LimeWire
2007-05-17 19:18:57 -------- d-----w C:\Program Files\QuickTime
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-16 20:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-16 20:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 20:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 20:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 20:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 20:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 20:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 20:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-13 13:19:52 7,680 ----a-w C:\WINDOWS\system32\lsdelete.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-12-18 05:16 59032 --a------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a------ C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FC93A6DF-F31C-44B1-A24A-C1723F723971}]
C:\WINDOWS\system32\nnnmj.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 14:00 C:\WINDOWS\system32\bthprops.cpl]
"BMMGAG"="C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2005-04-20 01:38]
"BMMLREF"="C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE" [2005-04-20 01:38]
"BMMMONWND"="C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll" [2005-04-20 01:38]
"BLOG"="C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2005-04-20 01:38]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-25 21:00]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 09:11]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2004-09-23 12:41]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2006-02-14 14:17]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-02-14 14:16]
"TPHOTKEY"="C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" []
"Lexmark 5200 series"="C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe" [2004-06-04 11:57]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-04-21 13:39]
"PDFCreatorClient"="C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe" [2003-08-08 18:30]
"TPKMAPHELPER"="C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" [2006-06-02 22:00]
"TP4EX"="tp4ex.exe" [2005-10-17 01:11 C:\WINDOWS\system32\TP4EX.exe]
"PRONoMgrWired"="C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe" [2003-08-06 16:08]
"EZEJMNAP"="C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2006-09-13 02:23]
"Tweak UI"="TWEAKUI.CPL" [2000-06-18 15:03 C:\WINDOWS\system32\tweakui.cpl]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-11 10:50 C:\WINDOWS\LOGI_MWX.EXE]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-05-20 15:46 C:\WINDOWS\KHALMNPR.Exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"NPDTRAY"="C:\PROGRA~1\ThinkPad\UTILIT~1\NPDTray.exe" [2006-07-21 02:54]
"THGuard"="C:\Program Files\TrojanHunter 4.7\THGuard.exe" [2007-06-23 00:19]
"spywarefighterguard"="C:\Program Files\SPYWAREfighter\spftray.exe" [2007-06-08 11:52]
"@"="" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00]
"TPKMAPMN"="C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe" []
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2003-09-01 20:52]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"PcSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Documents and Settings\Nordea-Elev\Desktop\DSC00240.jpg
FriendlyName=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
notifyf2.dll 2005-07-05 23:45 28672 C:\WINDOWS\system32\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
tphklock.dll 2005-11-30 20:16 24576 C:\WINDOWS\system32\tphklock.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winpge32]
winpge32.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
"C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
"C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
Logi_MwX.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechGalleryRepair]
C:\Program Files\Logitech\ImageStudio\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechImageStudioTray]
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMS]
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PcSync]
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ
Contents of the 'Scheduled Tasks' folder
2007-05-17 09:43:00 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-07-10 05:15:36 C:\WINDOWS\tasks\User_Feed_Synchronization-{F21A76AE-4D89-4A84-926B-625F4E085A11}.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-07-10 07:19:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-10 7:20:30 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-10 07:20
--- E O F ---