Hjælp til fjernelse af Cleanup Antivirus

Hej alle sammen

Som overskriften siger så har jeg fået denne trælse virus ind på min pc. Har googlet mig frem og tilbage men uden at blive klogere på det. Udfra det fandt jeg frem til nogle tråde her på jeres forum men uden held at blive klogere blot mere forvirret

Jeg har brugt ComboFix som jeg kunne se at andre anbefalede og her er hvad der kom ud af den:

ComboFix 12-02-17.02 - HPG61420SO 17-02-2012  15:02:45.1.2 - x64
Microsoft Windows 7 Home Premium  6.1.7601.1.1252.45.1030.18.3003.1345 [GMT 1:00]
Kører fra: c:\users\HPG61420SO\Desktop\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
c:\users\Palle\Desktop\Security Protection.lnk
(((((((((((((((((((((((((((((  Filer skabt fra 2012-01-17 til 2012-02-17  )))))))))))))))))))))))))))))))))))
2012-02-17 14:24 . 2012-02-17 14:24    --------    d-----w-    c:\users\Palle\AppData\Local\temp
2012-02-17 14:23 . 2012-02-17 14:23    --------    d-----w-    c:\users\Default\AppData\Local\temp
2012-02-17 13:26 . 2012-02-17 13:26    110080    ----a-r-    c:\users\HPG61420SO\AppData\Roaming\Microsoft\Installer\{5B210B8A-B66E-4702-B44D-0D6F388D29EB}\IconF7A21AF7.exe
2012-02-17 13:26 . 2012-02-17 13:26    110080    ----a-r-    c:\users\HPG61420SO\AppData\Roaming\Microsoft\Installer\{5B210B8A-B66E-4702-B44D-0D6F388D29EB}\IconD7F16134.exe
2012-02-17 13:26 . 2012-02-17 13:26    110080    ----a-r-    c:\users\HPG61420SO\AppData\Roaming\Microsoft\Installer\{5B210B8A-B66E-4702-B44D-0D6F388D29EB}\Icon1226A4C5.exe
2012-02-17 13:26 . 2012-02-17 13:26    --------    d-----w-    C:\sh4ldr
2012-02-17 13:26 . 2012-02-17 13:26    --------    d-----w-    c:\program files\Enigma Software Group
2012-02-17 13:25 . 2012-02-17 13:26    --------    d-----w-    c:\windows\5B210B8AB66E4702B44D0D6F388D29EB.TMP
2012-02-17 13:25 . 2012-02-17 13:25    --------    d-----w-    c:\program files (x86)\Common Files\Wise Installation Wizard
2012-02-17 13:17 . 2012-02-17 13:17    69000    ----a-w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{48BD11D6-CEBE-4FD2-92A2-1C8ED0AD1B68}\offreg.dll
2012-02-17 12:58 . 2012-01-05 20:15    8602168    ----a-w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{48BD11D6-CEBE-4FD2-92A2-1C8ED0AD1B68}\mpengine.dll
2012-02-17 12:57 . 2012-02-17 12:57    --------    d-----w-    c:\program files (x86)\Microsoft Security Client
2012-02-17 12:56 . 2012-02-17 12:57    --------    d-----w-    c:\program files\Microsoft Security Client
2012-02-17 11:28 . 2012-02-17 11:28    --------    d-----w-    c:\users\HPG61420SO\AppData\Roaming\HP Support Assistant
2012-02-17 10:47 . 2012-02-17 10:47    --------    d-----w-    c:\users\HPG61420SO\AppData\Roaming\Malwarebytes
2012-02-17 10:46 . 2012-02-17 10:46    --------    d-----w-    c:\programdata\Malwarebytes
2012-02-17 10:17 . 2012-02-17 10:17    --------    d-----w-    c:\program files (x86)\Loaris
2012-02-17 09:42 . 2012-02-17 10:04    --------    d-----w-    c:\program files (x86)\GridinSoft Trojan Killer
2012-02-17 09:39 . 2012-02-17 09:39    69000    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{F0AEA5BD-FD7F-40BB-A287-0B9EA12BCD11}\offreg.dll
2012-02-17 09:38 . 2012-02-17 09:38    --------    d-----w-    c:\programdata\PC Tools
2012-02-17 09:38 . 2012-02-17 09:38    --------    d-----w-    c:\users\HPG61420SO\AppData\Roaming\TestApp
2012-02-17 08:11 . 2012-02-17 11:07    --------    d-----w-    c:\program files (x86)\Spybot - Search & Destroy
2012-02-17 08:11 . 2012-02-17 09:44    --------    d-----w-    c:\programdata\Spybot - Search & Destroy
2012-02-17 07:24 . 2012-01-06 05:15    8602168    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{F0AEA5BD-FD7F-40BB-A287-0B9EA12BCD11}\mpengine.dll
2012-02-15 15:02 . 2012-02-15 15:02    --------    d-----w-    c:\program files (x86)\Hp
2012-02-15 15:01 . 2012-02-15 15:01    --------    d-----w-    c:\windows\Hewlett-Packard
2012-02-15 14:44 . 2012-01-04 10:44    509952    ----a-w-    c:\windows\system32\ntshrui.dll
2012-02-15 14:44 . 2012-01-04 08:58    442880    ----a-w-    c:\windows\SysWow64\ntshrui.dll
2012-02-15 14:44 . 2012-02-15 14:44    --------    d-----w-    c:\program files (x86)\Common Files\Java
2012-02-15 14:41 . 2011-12-30 06:26    515584    ----a-w-    c:\windows\system32\timedate.cpl
2012-02-15 14:41 . 2011-12-30 05:27    478720    ----a-w-    c:\windows\SysWow64\timedate.cpl
2012-02-15 14:41 . 2012-01-14 04:06    3145728    ----a-w-    c:\windows\system32\win32k.sys
2012-02-15 14:41 . 2011-12-28 03:59    498688    ----a-w-    c:\windows\system32\drivers\afd.sys
2012-02-15 14:41 . 2011-12-16 08:46    634880    ----a-w-    c:\windows\system32\msvcrt.dll
2012-02-15 14:41 . 2011-12-16 07:52    690688    ----a-w-    c:\windows\SysWow64\msvcrt.dll
2012-02-15 14:39 . 2011-11-28 18:01    256960    ----a-w-    c:\windows\system32\aswBoot.exe
2012-02-15 14:39 . 2011-11-28 17:54    591192    ----a-w-    c:\windows\system32\drivers\aswSnx.sys
2012-02-15 14:02 . 2012-02-15 14:02    --------    d-----w-    c:\users\HPG61420SO\AppData\Local\FILSH_Media_GmbH
2012-02-11 16:35 . 2012-02-11 16:35    --------    d-----w-    c:\users\Palle\AppData\Local\PackageAware
2012-01-21 13:02 . 2012-01-21 13:02    --------    d-----w-    c:\program files\iPod
2012-01-21 13:02 . 2012-01-21 13:03    --------    d-----w-    c:\program files\iTunes
2012-01-21 13:02 . 2012-01-21 13:03    --------    d-----w-    c:\program files (x86)\iTunes
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
2012-02-17 07:23 . 2011-10-21 18:00    414368    ----a-w-    c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-15 14:43 . 2010-07-10 14:21    472808    ----a-w-    c:\windows\SysWow64\deployJava1.dll
2012-01-31 12:44 . 2010-05-29 13:22    279656    ------w-    c:\windows\system32\MpSigStub.exe
2011-11-28 18:01 . 2010-07-10 14:18    41184    ----a-w-    c:\windows\avastSS.scr
2011-11-28 18:01 . 2010-07-10 14:18    199816    ----a-w-    c:\windows\SysWow64\aswBoot.exe
2011-11-28 17:53 . 2010-07-10 14:18    304472    ----a-w-    c:\windows\system32\drivers\aswSP.sys
2011-11-28 17:52 . 2010-07-10 14:18    42328    ----a-w-    c:\windows\system32\drivers\aswRdr.sys
2011-11-28 17:52 . 2010-07-10 14:18    58712    ----a-w-    c:\windows\system32\drivers\aswTdi.sys
2011-11-28 17:52 . 2010-07-10 14:18    66904    ----a-w-    c:\windows\system32\drivers\aswMonFlt.sys
2011-11-28 17:51 . 2010-07-10 14:18    24408    ----a-w-    c:\windows\system32\drivers\aswFsBlk.sys
2011-11-27 13:57 . 2011-11-27 13:57    158056    ----a-w-    c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10139.bin
2011-11-19 14:58 . 2012-01-11 15:21    77312    ----a-w-    c:\windows\system32\packager.dll
(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
*Bemærk* tomme linier & lovlige standard linier vises ikke 
"WirelessAssistant"="c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2009-07-23 498744]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
Security Packages    REG_MULTI_SZ      kerberos msv1_0 schannel wdigest tspkg pku2u livessp
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2009-07-14 27136]
R3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-09-02 225280]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Tjenesten Windows Aktivering;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe [2009-03-02 89600]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [x]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
--- Andre Services/Drivers i Hukommelsen ---
*NewlyCreated* - WS2IFSL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 21:24    451872    ----a-w-    c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
Indhold af mappen 'Planlagte Opgaver'
2012-02-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3068793190-3891165355-258360892-1000Core.job
- c:\users\HPG61420SO\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-17 14:42]
2012-02-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3068793190-3891165355-258360892-1000UA.job
- c:\users\HPG61420SO\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-17 14:42]
2012-02-17 c:\windows\Tasks\HPCeeScheduleForHPG61420SO.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2009-10-07 12:22]
2012-02-17 c:\windows\Tasks\RegistryBooster.job
- c:\program files (x86)\Uniblue\RegistryBooster\rbmonitor.exe [2011-01-14 12:36]
--------- x86-64 -----------
2011-11-28 18:01    134384    ----a-w-    c:\program files\Alwil Software\Avast5\ashShA64.dll
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-16 171520]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
------- Yderligere scanning -------
uStart Page = https://www.lectio.dk/lectio/253/default.aspx/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer =
BHO-{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - c:\progra~2\BEARSH~1\MediaBar\ToolBar\bsdtxmltbpi.dll
Toolbar-{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - c:\progra~2\BEARSH~1\MediaBar\ToolBar\bsdtxmltbpi.dll
Toolbar-10 - (no file)
Wow6432Node-HKCU-Run-RegistryBooster - c:\program files (x86)\Uniblue\RegistryBooster\launcher.exe
Toolbar-10 - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-EasyBits Magic Desktop - c:\windows\system32\ezMDUninstall.exe
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
@Denied: (A 2) (Everyone)
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx, 1"
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx, 1"
@Denied: (A 2) (Everyone)
@Denied: (Full) (Everyone)
------------------------ Andre kørende processer ------------------------
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\CyberLink\Shared files\RichVideo.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
Gennemført tid: 2012-02-17  15:34:24 - maskinen blev genstartet
ComboFix-quarantined-files.txt  2012-02-17 14:34
Pre-Kørsel: 98.969.497.600 byte ledig
Post-Kørsel: 101.305.430.016 byte ledig
- - End Of File - - DC4ED6AC8385254B7D853F6B1ABA2113

Hvad skal jeg gøre nu?

Havde overvejet om at geninstallere windows, vil det hjælpe?

På forhånd mange tak

mvh. elvis
Velkommen til E. ...

Du ser ud til at have både
instaleret ?
Kan ikke anbefales at have flere aktive Sikkerhedsprogrammer samtidig!!! (Ligesom det med at have flere 'kærester' *S*)
Èn af dem skal du afinstall helt!


* RegistryBooster (Jeg tror ikke en dyt på den!!!)


COMBOFIX har allerede nappet en del 'snavs' !


Hent og instalér CCleaner www.ccleaner.com/ + www.spywarefri.dk/manualer/manual-for-installation-og-brug-af-ccleaner/
Lad programmet foretage en oprydning...



Hent Malwarebytes Anti-Malware herfra:

Installer programmet - når det er gjort skal du lade programmet opdatere sig. Herefter åbner et vindue, hvor du skal flytte prikken til "Kør et fuldstændigt systemscan" - klik på Skan Knappen - lad programmet arbejde. Når det er færdig (det tager lidt tid afhængig af hvor meget du har på computeren).
Derefter - Tryk på "Vis resultater" knappen efter scanningen - og herefter tryk på "Fjern det valgte" - nu åbnes log'en og du skal gemme den et sted, hvor du kan finde den igen.
Kopier indholdet herind sammen med en frisk log fra HiJackThis...

...og her er omtalte HiJackThis ->

Bemærk at HiJackThis.exe programmet skal gemmes i en dertil oprettet mappe og IKKE køres direkte fra nettet...

PS: Brug denne version af HJT -> www.trendsecure.com/portal/en-US/_download/HiJackThis.exe

Mht.: Vista/Win7 - HøjreMusseTast - "Kør som Administrator..."

