Hjælp til fjernelse af Cleanup Antivirus
Hej alle sammenSom overskriften siger så har jeg fået denne trælse virus ind på min pc. Har googlet mig frem og tilbage men uden at blive klogere på det. Udfra det fandt jeg frem til nogle tråde her på jeres forum men uden held at blive klogere blot mere forvirret
Jeg har brugt ComboFix som jeg kunne se at andre anbefalede og her er hvad der kom ud af den:
ComboFix 12-02-17.02 - HPG61420SO 17-02-2012 15:02:45.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.45.1030.18.3003.1345 [GMT 1:00]
Kører fra: c:\users\HPG61420SO\Desktop\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Andet, der er slettet )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.dll
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\cb.exe
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\CLSV.exe
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\CLSV.tmp
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\delfile.dll
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\delfile.drv
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\dudl.tmp
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\eb.exe
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\eb.sys
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\energy.drv
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\energy.sys
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\exec.exe
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\exec.tmp
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\fix.dll
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\FW.drv
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\gid.dll
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\gid.tmp
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\grid.dll
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\hymt.exe
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\hymt.sys
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\kernel32.drv
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\pal.exe
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\PE.dll
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\PE.drv
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\PE.tmp
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\ppal.exe
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.drv
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\sld.drv
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\sld.sys
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\SM.sys
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\snl2w.dll
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\std.dll
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\std.drv
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\tjd.exe
c:\users\HPG61420SO\AppData\Roaming\Microsoft\Windows\Recent\tjd.sys
c:\users\Palle\Desktop\Security Protection.lnk
c:\users\Palle\Documents\~WRL2885.tmp
c:\users\Palle\Taskmgr.exe
c:\windows\system32\GroupPolicy\Machine\Registry.pol
.
.
((((((((((((((((((((((((((((( Filer skabt fra 2012-01-17 til 2012-02-17 )))))))))))))))))))))))))))))))))))
.
.
2012-02-17 14:24 . 2012-02-17 14:24 -------- d-----w- c:\users\Palle\AppData\Local\temp
2012-02-17 14:23 . 2012-02-17 14:23 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-02-17 13:26 . 2012-02-17 13:26 110080 ----a-r- c:\users\HPG61420SO\AppData\Roaming\Microsoft\Installer\{5B210B8A-B66E-4702-B44D-0D6F388D29EB}\IconF7A21AF7.exe
2012-02-17 13:26 . 2012-02-17 13:26 110080 ----a-r- c:\users\HPG61420SO\AppData\Roaming\Microsoft\Installer\{5B210B8A-B66E-4702-B44D-0D6F388D29EB}\IconD7F16134.exe
2012-02-17 13:26 . 2012-02-17 13:26 110080 ----a-r- c:\users\HPG61420SO\AppData\Roaming\Microsoft\Installer\{5B210B8A-B66E-4702-B44D-0D6F388D29EB}\Icon1226A4C5.exe
2012-02-17 13:26 . 2012-02-17 13:26 -------- d-----w- C:\sh4ldr
2012-02-17 13:26 . 2012-02-17 13:26 -------- d-----w- c:\program files\Enigma Software Group
2012-02-17 13:25 . 2012-02-17 13:26 -------- d-----w- c:\windows\5B210B8AB66E4702B44D0D6F388D29EB.TMP
2012-02-17 13:25 . 2012-02-17 13:25 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2012-02-17 13:17 . 2012-02-17 13:17 69000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{48BD11D6-CEBE-4FD2-92A2-1C8ED0AD1B68}\offreg.dll
2012-02-17 12:58 . 2012-01-05 20:15 8602168 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{48BD11D6-CEBE-4FD2-92A2-1C8ED0AD1B68}\mpengine.dll
2012-02-17 12:57 . 2012-02-17 12:57 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2012-02-17 12:56 . 2012-02-17 12:57 -------- d-----w- c:\program files\Microsoft Security Client
2012-02-17 11:28 . 2012-02-17 11:28 -------- d-----w- c:\users\HPG61420SO\AppData\Roaming\HP Support Assistant
2012-02-17 10:47 . 2012-02-17 10:47 -------- d-----w- c:\users\HPG61420SO\AppData\Roaming\Malwarebytes
2012-02-17 10:46 . 2012-02-17 10:46 -------- d-----w- c:\programdata\Malwarebytes
2012-02-17 10:17 . 2012-02-17 10:17 -------- d-----w- c:\program files (x86)\Loaris
2012-02-17 09:42 . 2012-02-17 10:04 -------- d-----w- c:\program files (x86)\GridinSoft Trojan Killer
2012-02-17 09:39 . 2012-02-17 09:39 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F0AEA5BD-FD7F-40BB-A287-0B9EA12BCD11}\offreg.dll
2012-02-17 09:38 . 2012-02-17 09:38 -------- d-----w- c:\programdata\PC Tools
2012-02-17 09:38 . 2012-02-17 09:38 -------- d-----w- c:\users\HPG61420SO\AppData\Roaming\TestApp
2012-02-17 08:11 . 2012-02-17 11:07 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2012-02-17 08:11 . 2012-02-17 09:44 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2012-02-17 07:24 . 2012-01-06 05:15 8602168 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F0AEA5BD-FD7F-40BB-A287-0B9EA12BCD11}\mpengine.dll
2012-02-15 15:02 . 2012-02-15 15:02 -------- d-----w- c:\program files (x86)\Hp
2012-02-15 15:01 . 2012-02-15 15:01 -------- d-----w- c:\windows\Hewlett-Packard
2012-02-15 14:44 . 2012-01-04 10:44 509952 ----a-w- c:\windows\system32\ntshrui.dll
2012-02-15 14:44 . 2012-01-04 08:58 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll
2012-02-15 14:44 . 2012-02-15 14:44 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-02-15 14:41 . 2011-12-30 06:26 515584 ----a-w- c:\windows\system32\timedate.cpl
2012-02-15 14:41 . 2011-12-30 05:27 478720 ----a-w- c:\windows\SysWow64\timedate.cpl
2012-02-15 14:41 . 2012-01-14 04:06 3145728 ----a-w- c:\windows\system32\win32k.sys
2012-02-15 14:41 . 2011-12-28 03:59 498688 ----a-w- c:\windows\system32\drivers\afd.sys
2012-02-15 14:41 . 2011-12-16 08:46 634880 ----a-w- c:\windows\system32\msvcrt.dll
2012-02-15 14:41 . 2011-12-16 07:52 690688 ----a-w- c:\windows\SysWow64\msvcrt.dll
2012-02-15 14:39 . 2011-11-28 18:01 256960 ----a-w- c:\windows\system32\aswBoot.exe
2012-02-15 14:39 . 2011-11-28 17:54 591192 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-02-15 14:02 . 2012-02-15 14:02 -------- d-----w- c:\users\HPG61420SO\AppData\Local\FILSH_Media_GmbH
2012-02-11 16:35 . 2012-02-11 16:35 -------- d-----w- c:\users\Palle\AppData\Local\PackageAware
2012-01-21 13:02 . 2012-01-21 13:02 -------- d-----w- c:\program files\iPod
2012-01-21 13:02 . 2012-01-21 13:03 -------- d-----w- c:\program files\iTunes
2012-01-21 13:02 . 2012-01-21 13:03 -------- d-----w- c:\program files (x86)\iTunes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-17 07:23 . 2011-10-21 18:00 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-15 14:43 . 2010-07-10 14:21 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-01-31 12:44 . 2010-05-29 13:22 279656 ------w- c:\windows\system32\MpSigStub.exe
2011-11-28 18:01 . 2010-07-10 14:18 41184 ----a-w- c:\windows\avastSS.scr
2011-11-28 18:01 . 2010-07-10 14:18 199816 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-11-28 17:53 . 2010-07-10 14:18 304472 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-11-28 17:52 . 2010-07-10 14:18 42328 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-11-28 17:52 . 2010-07-10 14:18 58712 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-11-28 17:52 . 2010-07-10 14:18 66904 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-11-28 17:51 . 2010-07-10 14:18 24408 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-11-27 13:57 . 2011-11-27 13:57 158056 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10139.bin
2011-11-19 14:58 . 2012-01-11 15:21 77312 ----a-w- c:\windows\system32\packager.dll
.
.
((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"WirelessAssistant"="c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2009-07-23 498744]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
.
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2009-07-14 27136]
R3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-09-02 225280]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Tjenesten Windows Aktivering;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe [2009-03-02 89600]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [x]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
--- Andre Services/Drivers i Hukommelsen ---
.
*NewlyCreated* - WS2IFSL
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 21:24 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Indhold af mappen 'Planlagte Opgaver'
.
2012-02-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3068793190-3891165355-258360892-1000Core.job
- c:\users\HPG61420SO\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-17 14:42]
.
2012-02-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3068793190-3891165355-258360892-1000UA.job
- c:\users\HPG61420SO\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-17 14:42]
.
2012-02-17 c:\windows\Tasks\HPCeeScheduleForHPG61420SO.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2009-10-07 12:22]
.
2012-02-17 c:\windows\Tasks\RegistryBooster.job
- c:\program files (x86)\Uniblue\RegistryBooster\rbmonitor.exe [2011-01-14 12:36]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 134384 ----a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-16 171520]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
.
------- Yderligere scanning -------
.
uStart Page = https://www.lectio.dk/lectio/253/default.aspx/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
.
- - - - TOMME GENVEJE FJERNET - - - -
.
BHO-{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - c:\progra~2\BEARSH~1\MediaBar\ToolBar\bsdtxmltbpi.dll
Toolbar-{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - c:\progra~2\BEARSH~1\MediaBar\ToolBar\bsdtxmltbpi.dll
Toolbar-10 - (no file)
Wow6432Node-HKCU-Run-RegistryBooster - c:\program files (x86)\Uniblue\RegistryBooster\launcher.exe
Toolbar-10 - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-EasyBits Magic Desktop - c:\windows\system32\ezMDUninstall.exe
.
.
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11f_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11f_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Andre kørende processer ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\CyberLink\Shared files\RichVideo.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
.
**************************************************************************
.
Gennemført tid: 2012-02-17 15:34:24 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2012-02-17 14:34
.
Pre-Kørsel: 98.969.497.600 byte ledig
Post-Kørsel: 101.305.430.016 byte ledig
.
- - End Of File - - DC4ED6AC8385254B7D853F6B1ABA2113
Hvad skal jeg gøre nu?
Havde overvejet om at geninstallere windows, vil det hjælpe?
På forhånd mange tak
mvh. elvis