Avatar billede hojben Novice
27. marts 2009 - 19:35 Der er 18 kommentarer og
1 løsning

Trojaner iflg AVG (AVG, som nu ik længere virker)

HJT-Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:31:26, on 27-03-2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Windows Live\Messenger\msnmsgr.exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmer\3\3Connect\AutoUpdateSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programmer\Mobile Partner\Mobile Partner.exe
C:\Programmer\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Bruger\Skrivebord\HiJackThis.exe

O2 - BHO: AcroIEHelperStub - {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Programmer\AVG\AVG8\avgssie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre6\bin\ssv.dll
O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {a057a204-bacc-4d26-9990-79a187e2698e} - C:\Programmer\AVG\AVG8\avgtoolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programmer\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Programmer\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmer\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmer\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programmer\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programmer\AVG\AVG8\avgtoolbar.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Opdateringsagent.lnk = ?
O16 - DPF: {9df01f00-08e7-4dbe-9070-94841463b3fe} (Util Class) - https://danid.dk/csp/authenticode/csp.exe
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F60F7C9A-BFD1-42C7-AD35-524C1033DF4E}: NameServer = 194.239.134.83 193.162.153.164
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmer\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Tjenesten Background Intelligent Transfer (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: getPlus(R) Helper (getplus(r) helper) - Unknown owner - C:\Programmer\NOS\bin\getPlus_HelperSvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmer\Java\jre6\bin\jqs.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmer\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Automatiske opdateringer (wuauserv) - Unknown owner - C:\WINDOWS\

--
End of file - 4672 bytes
Avatar billede f-arn Guru
27. marts 2009 - 19:37 #1
Hent "Malwarebytes' Anti-Malware" her: http://www.besttechie.net/tools/mbam-setup.exe
Installer og start programmet, opdater, lav "fuld systemskanning" under fanebladet "skanner".
Bagefter klik på "vis resultater", tryk på "Fjern det valgte" og send loggen herind sammen med en log fra DDS som du finder her: http://www.techsupportforum.com/sectools/sUBs/dds

eller her: http://download.bleepingcomputer.com/sUBs/dds.scr

eller her: http://www.forospyware.com/sUBs/dds


Den laver to logs,(DDS.txt og Attach.txt) gem dem på skrivebordet og kopier indholdet af DDS.txt  herind.
27. marts 2009 - 19:38 #2
Hent og instalér CCleaner http://www.ccleaner.com/ + http://www.spywarefri.dk/manualer/ccleaner-manual.htm
Under installationen får du tilbudt [Yahoo Toolbar]. Du kan sige ja eller *NEJ* til den.
Lad programmet foretage en oprydning...

--------

Hent Malwarebytes Anti-Malware herfra:
http://www.besttechie.net/tools/mbam-setup.exe
Eller herfra ->
http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html

Installer programmet - når det er gjort skal du lade programmet opdatere sig. Herefter åbner et vindue, hvor du skal flytte prikken til "Kør et fuldstændigt systemscan" - klik på Skan Knappen - lad programmet arbejde. Når det er færdig (det tager lidt tid afhængig af hvor meget du har på computeren).
Derefter - Tryk på "Vis resultater" knappen efter scanningen - og herefter tryk på "Fjern det valgte" - nu åbnes log'en og du skal gemme den et sted, hvor du kan finde den igen.
Kopier indholdet herind sammen med en frisk log fra HiJackThis...

...og her er omtalte HiJackThis ->
http://www.spywareinfo.dk/index.htm#/manualer/hijackthis.htm

Bemærk at HiJackThis.exe programmet skal gemmes i en dertil oprettet mappe og IKKE køres direkte fra nettet...

PS: Brug denne version af HJT -> http://www.trendsecure.com/portal/en-US/_download/HiJackThis.exe
27. marts 2009 - 19:39 #3
38 sekunder *S*
Avatar billede hojben Novice
27. marts 2009 - 19:44 #4
Først DSS.txt:


DDS (Ver_09-03-16.01) - NTFSx86 
Run by Bruger at 19:41:13.14 on 27-03-2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional  5.1.2600.3.1252.45.1030.18.511.169 [GMT 1:00]

AV: AVG Anti-Virus *On-access scanning disabled* (Outdated)

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
svchost.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Windows Live\Messenger\msnmsgr.exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmer\3\3Connect\AutoUpdateSrv.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wscntfy.exe
C:\Programmer\Mobile Partner\Mobile Partner.exe
C:\Programmer\Mozilla Firefox\firefox.exe
C:\Programmer\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Bruger\Skrivebord\dds.scr

============== Pseudo HJT Report ===============

mSearchAssistant = hxxp://www.google.com/ie
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\programmer\fælles filer\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\programmer\avg\avg8\avgssie.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\programmer\java\jre6\bin\ssv.dll
BHO: Hjælp til tilmelding til Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\programmer\fælles filer\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\programmer\avg\avg8\avgtoolbar.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\programmer\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\programmer\google\googletoolbarnotifier\5.0.926.3450\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\programmer\google\google toolbar\component\fastsearch_219B3E1547538286.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\programmer\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\programmer\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\programmer\google\google toolbar\GoogleToolbar.dll
TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\programmer\avg\avg8\avgtoolbar.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [msnmsgr] "c:\programmer\windows live\messenger\msnmsgr.exe" /background
uRun: [swg] c:\programmer\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRunOnce: [Malwarebytes' Anti-Malware] c:\programmer\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\docume~1\alluse~1\menuen~1\progra~1\start\opdate~1.lnk - c:\programmer\3\3connect\AutoUpdateSrv.exe
Trusted Zone: danid.dk
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {9df01f00-08e7-4dbe-9070-94841463b3fe} - hxxps://danid.dk/csp/authenticode/csp.exe
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: {F60F7C9A-BFD1-42C7-AD35-524C1033DF4E} = 194.239.134.83 193.162.153.164
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\programmer\avg\avg8\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\bruger\applic~1\mozilla\firefox\profiles\i0rvbkky.default\
FF - component: c:\programmer\avg\avg8\firefox\components\avgssff.dll
FF - component: c:\programmer\avg\avg8\toolbarff\components\vmAVGConnector.dll
FF - component: c:\programmer\nokia\nokia pc suite 7\bkmrksync\components\BkMrkExt.dll

============= SERVICES / DRIVERS ===============

R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-3-11 298264]
R2 mdvrmng;Mobile IP Route Manager;c:\windows\system32\drivers\mdvrmng.sys [2009-3-27 10240]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-3-27 38496]
S1 avgldx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys --> c:\windows\system32\drivers\avgldx86.sys [?]
S1 avgmfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys --> c:\windows\system32\drivers\avgmfx86.sys [?]
S1 avgtdix;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys --> c:\windows\system32\drivers\avgtdix.sys [?]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-3-11 908056]
S2 giwosi;giwosi;c:\windows\system32\svchost.exe -k netsvcs [2008-4-15 14336]
S3 dae8206;dae8206;c:\windows\system32\drivers\dae8206.sys --> c:\windows\system32\drivers\dae8206.sys [?]
S3 fbs068e;fbs068e;c:\windows\system32\drivers\fbs068e.sys --> c:\windows\system32\drivers\fbs068e.sys [?]
S3 getplus(r) helper;getPlus(R) Helper;c:\programmer\nos\bin\getplus_helpersvc.exe --> c:\programmer\nos\bin\getPlus_HelperSvc.exe [?]
S3 iei5c4e;iei5c4e;c:\windows\system32\drivers\iei5c4e.sys --> c:\windows\system32\drivers\iei5c4e.sys [?]
S3 lil5cde;lil5cde;c:\windows\system32\drivers\lil5cde.sys --> c:\windows\system32\drivers\lil5cde.sys [?]
S3 njgf60c;njgf60c;c:\windows\system32\drivers\njgf60c.sys --> c:\windows\system32\drivers\njgf60c.sys [?]
S3 OZSCR;O2Micro SmartCardBus Smartcard Reader;c:\windows\system32\drivers\ozscr.sys --> c:\windows\system32\drivers\ozscr.sys [?]
S4 ICF;ICF;c:\windows\system32\svchost.exe:ext.exe --> c:\windows\system32\svchost.exe:ext.exe [?]
UnknownUnknown idr15a8;idr15a8; [x]

=============== Created Last 30 ================

2009-03-27 19:39    <DIR>    --d-h---    c:\windows\PIF
2009-03-27 19:38    <DIR>    --d-----    c:\docume~1\bruger\applic~1\Malwarebytes
2009-03-27 19:38    15,504    a-------    c:\windows\system32\drivers\mbam.sys
2009-03-27 19:38    38,496    a-------    c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-27 19:38    <DIR>    --d-----    c:\programmer\Malwarebytes' Anti-Malware
2009-03-27 19:38    <DIR>    --d-----    c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-03-27 18:02    <DIR>    --d-----    c:\docume~1\bruger\applic~1\Birdstep Technology
2009-03-27 18:01    10,240    --------    c:\windows\system32\drivers\mdvrmng.sys
2009-03-27 18:00    102,016    a-------    c:\windows\system32\drivers\ewusbmdm.sys
2009-03-27 18:00    100,992    a-------    c:\windows\system32\drivers\ewusbnet.sys
2009-03-27 18:00    24,448    a-------    c:\windows\system32\drivers\ewdcsc.sys
2009-03-27 18:00    <DIR>    --d-----    c:\windows\LastGood.Tmp
2009-03-27 17:59    <DIR>    --d-----    c:\programmer\3
2009-03-27 17:51    22,304    a-------    c:\windows\system32\drivers\qkjafb0.sys
2009-03-27 17:50    22,304    a-------    c:\windows\system32\drivers\smkd0d2.sys
2009-03-27 17:49    22,304    a-------    c:\windows\system32\drivers\tsm4c30.sys
2009-03-27 17:48    22,304    a-------    c:\windows\system32\drivers\srl4c93.sys
2009-03-27 17:47    22,304    a-------    c:\windows\system32\drivers\rqj6cd6.sys
2009-03-27 17:46    12,032    ac------    c:\windows\system32\dllcache\rio8drv.sys
2009-03-27 17:45    42,112    ac------    c:\windows\system32\dllcache\imapi.sys
2009-03-27 17:42    22,304    a-------    c:\windows\system32\drivers\fer1432.sys
2009-03-27 17:41    12,288    ac------    c:\windows\system32\dllcache\fsvga.sys
2009-03-27 17:41    12,288    a-------    c:\windows\system32\drivers\fsvga.sys
2009-03-18 11:06    40    a-------    c:\windows\system32\d3d9prs.dat
2009-03-18 11:05    <DIR>    --d-----    c:\programmer\GrandBilliards
2009-03-11 15:00    0    a-------    c:\windows\system32\commonpriv.log.lock
2009-03-11 10:00    <DIR>    --d-h---    C:\$AVG8.VAULT$
2009-03-11 09:54    10,520    a-------    c:\windows\system32\avgrsstx.dll
2009-03-11 09:53    <DIR>    --d-----    c:\docume~1\bruger\applic~1\AVGTOOLBAR
2009-03-11 09:53    <DIR>    --d-----    c:\programmer\AVG
2009-03-11 09:53    <DIR>    --d-----    c:\docume~1\alluse~1\applic~1\avg8
2009-03-10 22:24    <DIR>    --d-----    c:\programmer\fælles filer\Adobe
2009-03-10 22:11    0    a-------    c:\documents and settings\bruger\temp.dat
2009-03-10 22:11    <DIR>    --d-----    c:\documents and settings\bruger\.oces
2009-03-10 21:48    <DIR>    --d-----    c:\documents and settings\bruger\cbt
2009-03-10 21:42    <DIR>    --d-----    c:\docume~1\bruger\applic~1\Cryptomathic
2009-03-10 21:41    <DIR>    -cd-h---    c:\docume~1\alluse~1\applic~1\{D166A25B-41F0-45EA-B10E-DE7D7B5C3455}
2009-03-10 21:41    <DIR>    --d-----    c:\programmer\DanID
2009-03-10 07:37    0    a--shr--    C:\ctfb
2009-03-09 23:10    81,390    a-------    c:\windows\system32\drivers\6ac7d5f4.sys
2009-03-09 23:09    2    a-------    C:\618081077
2009-03-03 09:16    0    a--shr--    C:\ctf

==================== Find3M  ====================

2009-03-27 18:04    325,198    a-------    c:\windows\system32\perfh006.dat
2009-03-27 18:04    47,474    a-------    c:\windows\system32\perfc006.dat
2009-03-27 17:59    71,636    a-------    c:\windows\Huawei ModemsUninstall.exe
2009-03-27 17:51    22,304    a-------    c:\windows\system32\drivers\nmg260a.sys
2009-03-27 17:50    22,304    a-------    c:\windows\system32\drivers\poh67d4.sys
2009-03-27 17:49    22,304    a-------    c:\windows\system32\drivers\qjibcf8.sys
2009-03-27 17:48    22,304    a-------    c:\windows\system32\drivers\jreca97.sys
2009-03-27 17:47    22,304    a-------    c:\windows\system32\drivers\oihd57e.sys
2009-03-10 02:38    14,336    a-------    c:\windows\system32\svchost.exe
2009-02-06 18:52    49,504    a-------    c:\windows\system32\sirenacm.dll
2009-01-26 15:52    378,210    a-------    c:\windows\system32\usecache.dll
2009-01-06 12:16    86,327    a-------    c:\windows\pchealth\helpctr\offlinecache\index.dat

============= FINISH: 19:42:14.52 ===============

Smider malware log ind når den er færdig.
Avatar billede f-arn Guru
27. marts 2009 - 19:47 #5
Jeg vil nu helt ha' dem i omvendt rækkefølge!
Avatar billede f-arn Guru
27. marts 2009 - 19:48 #6
Altaå DDS.txt lavet efter Malwarebytes.
Avatar billede hojben Novice
27. marts 2009 - 20:10 #7
Malwarebytes' Anti-Malware 1.35
Database version: 1906
Windows 5.1.2600 Service Pack 3

27-03-2009 20:08:22
mbam-log-2009-03-27 (20-08-22).txt

Skan type: Fuldstændig skanning (C:\|)
Objekter skannet: 84547
Tid tilbagelagt: 27 minute(s), 3 second(s)

Inficerede Hukommelses Processer: 0
Inficerede Hukommelses Moduler: 0
Inficerede Registeringsdatabase Nøgler: 2
Inficerede Registeringsdatabase Værdier: 0
Inficerede Registeringsdatabase Filer: 0
Inficerede Mapper: 2
Inficerede Filer: 2

Inficerede Hukommelses Processer:
(Ingen mistænkelige filer fundet)

Inficerede Hukommelses Moduler:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Nøgler:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ICF (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\AGprotect (Malware.Trace) -> Quarantined and deleted successfully.

Inficerede Registeringsdatabase Værdier:
(Ingen mistænkelige filer fundet)

Inficerede Registeringsdatabase Filer:
(Ingen mistænkelige filer fundet)

Inficerede Mapper:
C:\RECYCLER\S-1-5-21-0243336031-4052116379-881863308-0850 (Trojan.Agent) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-0243336031-4052116379-881863308-0851 (Trojan.Agent) -> Quarantined and deleted successfully.

Inficerede Filer:
C:\RECYCLER\S-1-5-21-0243336031-4052116379-881863308-0850\Desktop.ini (Trojan.Agent) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-0243336031-4052116379-881863308-0851\Desktop.ini (Trojan.Agent) -> Quarantined and deleted successfully.

************************************
************************************


DDS (Ver_09-03-16.01) - NTFSx86 
Run by Bruger at 20:09:25.03 on 27-03-2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional  5.1.2600.3.1252.45.1030.18.511.198 [GMT 1:00]

AV: AVG Anti-Virus *On-access scanning disabled* (Outdated)

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
svchost.exe
C:\Programmer\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Windows Live\Messenger\msnmsgr.exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmer\3\3Connect\AutoUpdateSrv.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wscntfy.exe
C:\Programmer\Mobile Partner\Mobile Partner.exe
C:\Programmer\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Bruger\Skrivebord\dds.scr

============== Pseudo HJT Report ===============

mSearchAssistant = hxxp://www.google.com/ie
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\programmer\fælles filer\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\programmer\avg\avg8\avgssie.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\programmer\java\jre6\bin\ssv.dll
BHO: Hjælp til tilmelding til Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\programmer\fælles filer\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\programmer\avg\avg8\avgtoolbar.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\programmer\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\programmer\google\googletoolbarnotifier\5.0.926.3450\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\programmer\google\google toolbar\component\fastsearch_219B3E1547538286.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\programmer\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\programmer\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\programmer\google\google toolbar\GoogleToolbar.dll
TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\programmer\avg\avg8\avgtoolbar.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [msnmsgr] "c:\programmer\windows live\messenger\msnmsgr.exe" /background
uRun: [swg] c:\programmer\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRunOnce: [Malwarebytes' Anti-Malware] c:\programmer\malwarebytes' anti-malware\mbamgui.exe /install /silent
mRunOnce: [Malwarebytes Anti-Malware (reboot)] "c:\programmer\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\docume~1\alluse~1\menuen~1\progra~1\start\opdate~1.lnk - c:\programmer\3\3connect\AutoUpdateSrv.exe
Trusted Zone: danid.dk
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {9df01f00-08e7-4dbe-9070-94841463b3fe} - hxxps://danid.dk/csp/authenticode/csp.exe
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: {F60F7C9A-BFD1-42C7-AD35-524C1033DF4E} = 194.239.134.83 193.162.153.164
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\programmer\avg\avg8\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\bruger\applic~1\mozilla\firefox\profiles\i0rvbkky.default\
FF - component: c:\programmer\avg\avg8\firefox\components\avgssff.dll
FF - component: c:\programmer\avg\avg8\toolbarff\components\vmAVGConnector.dll
FF - component: c:\programmer\nokia\nokia pc suite 7\bkmrksync\components\BkMrkExt.dll

============= SERVICES / DRIVERS ===============

R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-3-11 298264]
R2 mdvrmng;Mobile IP Route Manager;c:\windows\system32\drivers\mdvrmng.sys [2009-3-27 10240]
S1 avgldx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys --> c:\windows\system32\drivers\avgldx86.sys [?]
S1 avgmfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys --> c:\windows\system32\drivers\avgmfx86.sys [?]
S1 avgtdix;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys --> c:\windows\system32\drivers\avgtdix.sys [?]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-3-11 908056]
S2 giwosi;giwosi;c:\windows\system32\svchost.exe -k netsvcs [2008-4-15 14336]
S3 dae8206;dae8206;c:\windows\system32\drivers\dae8206.sys --> c:\windows\system32\drivers\dae8206.sys [?]
S3 fbs068e;fbs068e;c:\windows\system32\drivers\fbs068e.sys --> c:\windows\system32\drivers\fbs068e.sys [?]
S3 getplus(r) helper;getPlus(R) Helper;c:\programmer\nos\bin\getplus_helpersvc.exe --> c:\programmer\nos\bin\getPlus_HelperSvc.exe [?]
S3 iei5c4e;iei5c4e;c:\windows\system32\drivers\iei5c4e.sys --> c:\windows\system32\drivers\iei5c4e.sys [?]
S3 lil5cde;lil5cde;c:\windows\system32\drivers\lil5cde.sys --> c:\windows\system32\drivers\lil5cde.sys [?]
S3 njgf60c;njgf60c;c:\windows\system32\drivers\njgf60c.sys --> c:\windows\system32\drivers\njgf60c.sys [?]
S3 OZSCR;O2Micro SmartCardBus Smartcard Reader;c:\windows\system32\drivers\ozscr.sys --> c:\windows\system32\drivers\ozscr.sys [?]
SUnknown ICF;ICF; [x]
UnknownUnknown idr15a8;idr15a8; [x]

=============== Created Last 30 ================

2009-03-27 20:08    61,440    a-------    c:\windows\system32\drivers\sfsu.sys
2009-03-27 19:45    <DIR>    --d-----    c:\programmer\CCleaner
2009-03-27 19:39    <DIR>    --d-h---    c:\windows\PIF
2009-03-27 19:38    <DIR>    --d-----    c:\docume~1\bruger\applic~1\Malwarebytes
2009-03-27 19:38    15,504    a-------    c:\windows\system32\drivers\mbam.sys
2009-03-27 19:38    38,496    a-------    c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-27 19:38    <DIR>    --d-----    c:\programmer\Malwarebytes' Anti-Malware
2009-03-27 19:38    <DIR>    --d-----    c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-03-27 18:02    <DIR>    --d-----    c:\docume~1\bruger\applic~1\Birdstep Technology
2009-03-27 18:01    10,240    --------    c:\windows\system32\drivers\mdvrmng.sys
2009-03-27 18:00    102,016    a-------    c:\windows\system32\drivers\ewusbmdm.sys
2009-03-27 18:00    100,992    a-------    c:\windows\system32\drivers\ewusbnet.sys
2009-03-27 18:00    24,448    a-------    c:\windows\system32\drivers\ewdcsc.sys
2009-03-27 18:00    <DIR>    --d-----    c:\windows\LastGood.Tmp
2009-03-27 17:59    <DIR>    --d-----    c:\programmer\3
2009-03-27 17:51    22,304    a-------    c:\windows\system32\drivers\qkjafb0.sys
2009-03-27 17:50    22,304    a-------    c:\windows\system32\drivers\smkd0d2.sys
2009-03-27 17:49    22,304    a-------    c:\windows\system32\drivers\tsm4c30.sys
2009-03-27 17:48    22,304    a-------    c:\windows\system32\drivers\srl4c93.sys
2009-03-27 17:47    22,304    a-------    c:\windows\system32\drivers\rqj6cd6.sys
2009-03-27 17:46    12,032    ac------    c:\windows\system32\dllcache\rio8drv.sys
2009-03-27 17:45    42,112    ac------    c:\windows\system32\dllcache\imapi.sys
2009-03-27 17:42    22,304    a-------    c:\windows\system32\drivers\fer1432.sys
2009-03-27 17:41    12,288    ac------    c:\windows\system32\dllcache\fsvga.sys
2009-03-27 17:41    12,288    a-------    c:\windows\system32\drivers\fsvga.sys
2009-03-18 11:06    40    a-------    c:\windows\system32\d3d9prs.dat
2009-03-18 11:05    <DIR>    --d-----    c:\programmer\GrandBilliards
2009-03-11 15:00    0    a-------    c:\windows\system32\commonpriv.log.lock
2009-03-11 10:00    <DIR>    --d-h---    C:\$AVG8.VAULT$
2009-03-11 09:54    10,520    a-------    c:\windows\system32\avgrsstx.dll
2009-03-11 09:53    <DIR>    --d-----    c:\docume~1\bruger\applic~1\AVGTOOLBAR
2009-03-11 09:53    <DIR>    --d-----    c:\programmer\AVG
2009-03-11 09:53    <DIR>    --d-----    c:\docume~1\alluse~1\applic~1\avg8
2009-03-10 22:24    <DIR>    --d-----    c:\programmer\fælles filer\Adobe
2009-03-10 22:11    0    a-------    c:\documents and settings\bruger\temp.dat
2009-03-10 22:11    <DIR>    --d-----    c:\documents and settings\bruger\.oces
2009-03-10 21:48    <DIR>    --d-----    c:\documents and settings\bruger\cbt
2009-03-10 21:42    <DIR>    --d-----    c:\docume~1\bruger\applic~1\Cryptomathic
2009-03-10 21:41    <DIR>    -cd-h---    c:\docume~1\alluse~1\applic~1\{D166A25B-41F0-45EA-B10E-DE7D7B5C3455}
2009-03-10 21:41    <DIR>    --d-----    c:\programmer\DanID
2009-03-10 07:37    0    a--shr--    C:\ctfb
2009-03-09 23:10    81,390    a-------    c:\windows\system32\drivers\6ac7d5f4.sys
2009-03-09 23:09    2    a-------    C:\618081077
2009-03-03 09:16    0    a--shr--    C:\ctf

==================== Find3M  ====================

2009-03-27 18:04    325,198    a-------    c:\windows\system32\perfh006.dat
2009-03-27 18:04    47,474    a-------    c:\windows\system32\perfc006.dat
2009-03-27 17:59    71,636    a-------    c:\windows\Huawei ModemsUninstall.exe
2009-03-27 17:51    22,304    a-------    c:\windows\system32\drivers\nmg260a.sys
2009-03-27 17:50    22,304    a-------    c:\windows\system32\drivers\poh67d4.sys
2009-03-27 17:49    22,304    a-------    c:\windows\system32\drivers\qjibcf8.sys
2009-03-27 17:48    22,304    a-------    c:\windows\system32\drivers\jreca97.sys
2009-03-27 17:47    22,304    a-------    c:\windows\system32\drivers\oihd57e.sys
2009-03-10 02:38    14,336    a-------    c:\windows\system32\svchost.exe
2009-02-06 18:52    49,504    a-------    c:\windows\system32\sirenacm.dll
2009-01-26 15:52    378,210    a-------    c:\windows\system32\usecache.dll
2009-01-06 12:16    86,327    a-------    c:\windows\pchealth\helpctr\offlinecache\index.dat

============= FINISH: 20:09:42.81 ===============
Avatar billede hojben Novice
27. marts 2009 - 21:16 #8
Reinstallerede AVG og straks skreg den om at filerne i c:\windows\system32\drivers\ var inficeret med: Trojan horse Generic13.LVW
27. marts 2009 - 22:32 #9
-- Hent Combofix fra et af disse links, og gem den på dit skrivebord:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe

-- Kør så combofix.exe, som du hentede tidligere, og følg anvisningerne.
Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når combofix er færdig, og efter det har genstartet, skulle der gerne åbnes en logfil: combofix.txt
Indholdet af denne fil må du gerne lægge herind.
Avatar billede hojben Novice
27. marts 2009 - 23:06 #10
ComboFix 09-03-26.03 - Bruger 2009-03-27 22:42:02.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1030.18.511.93 [GMT 1:00]
Kører fra: c:\documents and settings\Bruger\Skrivebord\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Dannede nyt systemgendannelsespunkt

advarsel -DENNE MASKINE HAR IKKE GENOPRETTELSESKONSOL INSTALLERET !!
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\Bruger\LOKALE~1\Temp\tmp2.tmp

.
(((((((((((((((((((((((((((((((((((((((  Drivers/Tjenester  )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_icf
-------\Legacy_ISODRIVE
-------\Service_ISODrive


(((((((((((((((((((((((((((((  Filer skabt fra 2009-02-27 til 2009-03-27  )))))))))))))))))))))))))))))))))))
.

2009-03-27 22:52 . 2009-03-27 22:52    22,304    --a------    c:\windows\system32\drivers\tlq1c76.sys
2009-03-27 22:51 . 2009-03-27 22:51    22,304    --a------    c:\windows\system32\drivers\tmqf71e.sys
2009-03-27 22:49 . 2009-03-27 22:49    22,304    --a------    c:\windows\system32\drivers\tmqf781.sys
2009-03-27 22:48 . 2009-03-27 22:48    22,304    --a------    c:\windows\system32\drivers\tlq1a46.sys
2009-03-27 22:47 . 2009-03-27 22:47    22,304    --a------    c:\windows\system32\drivers\tmqf296.sys
2009-03-27 22:46 . 2009-03-27 22:46    22,304    --a------    c:\windows\system32\drivers\tlq15fa.sys
2009-03-27 22:45 . 2009-03-27 22:45    22,304    --a------    c:\windows\system32\drivers\tmq2c3f.sys
2009-03-27 22:44 . 2009-03-27 22:44    22,304    --a------    c:\windows\system32\drivers\tmqf731.sys
2009-03-27 22:43 . 2009-03-27 22:43    22,304    --a------    c:\windows\system32\drivers\tlp07fe.sys
2009-03-27 22:42 . 2009-03-27 22:42    22,304    --a------    c:\windows\system32\drivers\tmqea75.sys
2009-03-27 22:41 . 2009-03-27 22:41    22,304    --a------    c:\windows\system32\drivers\tmqc2b1.sys
2009-03-27 22:40 . 2009-03-27 22:40    22,304    --a------    c:\windows\system32\drivers\tmq1bae.sys
2009-03-27 22:37 . 2009-03-27 22:37    22,304    --a------    c:\windows\system32\drivers\tmq2087.sys
2009-03-27 22:36 . 2009-03-27 22:36    22,304    --a------    c:\windows\system32\drivers\tmqf9ed.sys
2009-03-27 22:35 . 2009-03-27 22:35    22,304    --a------    c:\windows\system32\drivers\tmqd319.sys
2009-03-27 22:34 . 2009-03-27 22:34    22,304    --a------    c:\windows\system32\drivers\tlq1ffa.sys
2009-03-27 22:33 . 2009-03-27 22:33    22,304    --a------    c:\windows\system32\drivers\tmqf079.sys
2009-03-27 22:32 . 2009-03-27 22:32    22,304    --a------    c:\windows\system32\drivers\tmqde6d.sys
2009-03-27 22:31 . 2009-03-27 22:31    22,304    --a------    c:\windows\system32\drivers\tmqe86e.sys
2009-03-27 22:30 . 2009-03-27 22:30    22,304    --a------    c:\windows\system32\drivers\tmq034e.sys
2009-03-27 22:29 . 2009-03-27 22:29    22,304    --a------    c:\windows\system32\drivers\tmq11d6.sys
2009-03-27 22:28 . 2009-03-27 22:28    22,304    --a------    c:\windows\system32\drivers\tmqdebd.sys
2009-03-27 22:27 . 2009-03-27 22:27    22,304    --a------    c:\windows\system32\drivers\tmqd73d.sys
2009-03-27 22:26 . 2009-03-27 22:26    22,304    --a------    c:\windows\system32\drivers\tmqf872.sys
2009-03-27 22:25 . 2009-03-27 22:25    22,304    --a------    c:\windows\system32\drivers\tmqe1a1.sys
2009-03-27 22:24 . 2009-03-27 22:24    22,304    --a------    c:\windows\system32\drivers\tmqef62.sys
2009-03-27 22:23 . 2009-03-27 22:23    22,304    --a------    c:\windows\system32\drivers\tpt1bb1.sys
2009-03-27 22:22 . 2009-03-27 22:22    22,304    --a------    c:\windows\system32\drivers\tlpeed5.sys
2009-03-27 22:21 . 2009-03-27 22:21    22,304    --a------    c:\windows\system32\drivers\tlqe1a1.sys
2009-03-27 22:20 . 2009-03-27 22:20    22,304    --a------    c:\windows\system32\drivers\tmq14f6.sys
2009-03-27 22:19 . 2009-03-27 22:19    22,304    --a------    c:\windows\system32\drivers\tmqd87e.sys
2009-03-27 22:18 . 2009-03-27 22:18    22,304    --a------    c:\windows\system32\drivers\tmq2e0a.sys
2009-03-27 22:17 . 2009-03-27 22:17    22,304    --a------    c:\windows\system32\drivers\tmq81a7.sys
2009-03-27 22:16 . 2009-03-27 22:16    22,304    --a------    c:\windows\system32\drivers\tmqf53d.sys
2009-03-27 22:15 . 2009-03-27 22:15    22,304    --a------    c:\windows\system32\drivers\tmqf231.sys
2009-03-27 22:14 . 2009-03-27 22:14    22,304    --a------    c:\windows\system32\drivers\tmqc87a.sys
2009-03-27 22:13 . 2009-03-27 22:13    22,304    --a------    c:\windows\system32\drivers\tmqe922.sys
2009-03-27 22:12 . 2009-03-27 22:12    22,304    --a------    c:\windows\system32\drivers\tmqe36e.sys
2009-03-27 22:11 . 2009-03-27 22:26    22,304    --a------    c:\windows\system32\drivers\tmqfb92.sys
2009-03-27 22:10 . 2009-03-27 22:10    22,304    --a------    c:\windows\system32\drivers\tmqdd55.sys
2009-03-27 22:09 . 2009-03-27 22:09    22,304    --a------    c:\windows\system32\drivers\tmqf282.sys
2009-03-27 22:08 . 2009-03-27 22:08    22,304    --a------    c:\windows\system32\drivers\tmq0c5e.sys
2009-03-27 22:07 . 2009-03-27 22:07    22,304    --a------    c:\windows\system32\drivers\tmqed32.sys
2009-03-27 22:06 . 2009-03-27 22:06    22,304    --a------    c:\windows\system32\drivers\tlq0eca.sys
2009-03-27 22:05 . 2009-03-27 22:05    22,304    --a------    c:\windows\system32\drivers\tmqfa29.sys
2009-03-27 22:04 . 2009-03-27 22:04    22,304    --a------    c:\windows\system32\drivers\tmqf476.sys
2009-03-27 22:03 . 2009-03-27 22:03    22,304    --a------    c:\windows\system32\drivers\thq733d.sys
2009-03-27 22:02 . 2009-03-27 22:02    22,304    --a------    c:\windows\system32\drivers\tmqfeed.sys
2009-03-27 22:01 . 2009-03-27 22:01    22,304    --a------    c:\windows\system32\drivers\tmqd8cd.sys
2009-03-27 22:00 . 2009-03-27 22:00    22,304    --a------    c:\windows\system32\drivers\tmqff52.sys
2009-03-27 21:59 . 2009-03-27 22:32    22,304    --a------    c:\windows\system32\drivers\tmqe832.sys
2009-03-27 21:58 . 2009-03-27 21:58    22,304    --a------    c:\windows\system32\drivers\tmqfa79.sys
2009-03-27 21:57 . 2009-03-27 21:57    22,304    --a------    c:\windows\system32\drivers\tmqfe75.sys
2009-03-27 21:56 . 2009-03-27 21:56    22,304    --a------    c:\windows\system32\drivers\tmq1b4a.sys
2009-03-27 21:55 . 2009-03-27 21:55    22,304    --a------    c:\windows\system32\drivers\tmqc42e.sys
2009-03-27 21:54 . 2009-03-27 21:54    22,304    --a------    c:\windows\system32\drivers\tmqc6e9.sys
2009-03-27 21:53 . 2009-03-27 21:53    22,304    --a------    c:\windows\system32\drivers\tmqe5ed.sys
2009-03-27 21:52 . 2009-03-27 21:52    22,304    --a------    c:\windows\system32\drivers\tmq13a2.sys
2009-03-27 21:51 . 2009-03-27 21:51    22,304    --a------    c:\windows\system32\drivers\tpa1f5e.sys
2009-03-27 21:50 . 2009-03-27 21:50    22,304    --a------    c:\windows\system32\drivers\tmqc6c1.sys
2009-03-27 21:49 . 2009-03-27 21:49    22,304    --a------    c:\windows\system32\drivers\tmqe039.sys
2009-03-27 21:48 . 2009-03-27 21:48    22,304    --a------    c:\windows\system32\drivers\tlq0cd6.sys
2009-03-27 21:47 . 2009-03-27 21:47    22,304    --a------    c:\windows\system32\drivers\tmqfa8e.sys
2009-03-27 21:46 . 2009-03-27 21:46    22,304    --a------    c:\windows\system32\drivers\tmqedbd.sys
2009-03-27 21:45 . 2009-03-27 22:20    22,304    --a------    c:\windows\system32\drivers\tmqe665.sys
2009-03-27 21:44 . 2009-03-27 21:44    22,304    --a------    c:\windows\system32\drivers\tmq241f.sys
2009-03-27 21:43 . 2009-03-27 21:43    22,304    --a------    c:\windows\system32\drivers\tmq25ea.sys
2009-03-27 21:42 . 2009-03-27 21:42    22,304    --a------    c:\windows\system32\drivers\tmqfd4a.sys
2009-03-27 21:41 . 2009-03-27 21:52    22,304    --a------    c:\windows\system32\drivers\tmqe2a5.sys
2009-03-27 21:40 . 2009-03-27 21:40    22,304    --a------    c:\windows\system32\drivers\tmqd9d1.sys
2009-03-27 21:39 . 2009-03-27 21:39    22,304    --a------    c:\windows\system32\drivers\tmqdade.sys
2009-03-27 21:38 . 2009-03-27 21:38    22,304    --a------    c:\windows\system32\drivers\tmqdc79.sys
2009-03-27 21:37 . 2009-03-27 21:37    22,304    --a------    c:\windows\system32\drivers\tmqd909.sys
2009-03-27 21:36 . 2009-03-27 21:36    22,304    --a------    c:\windows\system32\drivers\tmqea12.sys
2009-03-27 21:35 . 2009-03-27 21:35    22,304    --a------    c:\windows\system32\drivers\tmqe27d.sys
2009-03-27 21:34 . 2009-03-27 21:34    22,304    --a------    c:\windows\system32\drivers\tmtba81.sys
2009-03-27 21:33 . 2009-03-27 21:33    22,304    --a------    c:\windows\system32\drivers\tmqfe25.sys
2009-03-27 21:32 . 2009-03-27 21:32    22,304    --a------    c:\windows\system32\drivers\tmqf655.sys
2009-03-27 21:31 . 2009-03-27 21:31    22,304    --a------    c:\windows\system32\drivers\tmq3012.sys
2009-03-27 21:30 . 2009-03-27 21:30    22,304    --a------    c:\windows\system32\drivers\tmqf4b2.sys
2009-03-27 21:29 . 2009-03-27 21:29    22,304    --a------    c:\windows\system32\drivers\tmqfac9.sys
2009-03-27 21:28 . 2009-03-27 21:28    22,304    --a------    c:\windows\system32\drivers\tmq1277.sys
2009-03-27 21:27 . 2009-03-27 21:27    22,304    --a------    c:\windows\system32\drivers\tmqf12d.sys
2009-03-27 21:26 . 2009-03-27 21:26    22,304    --a------    c:\windows\system32\drivers\tmqe36d.sys
2009-03-27 21:25 . 2009-03-27 21:25    22,304    --a------    c:\windows\system32\drivers\tmqe219.sys
2009-03-27 21:24 . 2009-03-27 21:24    22,304    --a------    c:\windows\system32\drivers\tmqe269.sys
2009-03-27 21:23 . 2009-03-27 21:23    22,304    --a------    c:\windows\system32\drivers\tmqfc82.sys
2009-03-27 21:22 . 2009-03-27 21:33    22,304    --a------    c:\windows\system32\drivers\tmqea3a.sys
2009-03-27 21:21 . 2009-03-27 21:21    22,304    --a------    c:\windows\system32\drivers\tmq4377.sys
2009-03-27 21:20 . 2009-03-27 21:20    22,304    --a------    c:\windows\system32\drivers\tmqef25.sys
2009-03-27 21:19 . 2009-03-27 21:19    22,304    --a------    c:\windows\system32\drivers\tmq3ec7.sys
2009-03-27 21:18 . 2009-03-27 21:29    22,304    --a------    c:\windows\system32\drivers\tmqfec5.sys
2009-03-27 21:17 . 2009-03-27 21:17    22,304    --a------    c:\windows\system32\drivers\tmqe7ce.sys
2009-03-27 21:16 . 2009-03-27 21:16    22,304    --a------    c:\windows\system32\drivers\tmqfe76.sys
2009-03-27 21:15 . 2009-03-27 21:15    22,304    --a------    c:\windows\system32\drivers\tmqe062.sys
2009-03-27 21:14 . 2009-03-27 21:14    22,304    --a------    c:\windows\system32\drivers\tmt16b2.sys
2009-03-27 21:13 . 2009-03-27 21:34    22,304    --a------    c:\windows\system32\drivers\tmq2536.sys
2009-03-27 21:12 . 2009-03-27 21:12    22,304    --a------    c:\windows\system32\drivers\tmtbcc5.sys
2009-03-27 21:11 . 2009-03-27 21:11    22,304    --a------    c:\windows\system32\drivers\thq79a5.sys
2009-03-27 21:09 . 2009-03-27 21:11    <DIR>    d--------    c:\windows\system32\drivers\Avg
2009-03-27 21:09 . 2009-03-27 21:09    325,640    --a------    c:\windows\system32\drivers\avgldx86.sys
2009-03-27 21:09 . 2009-03-27 21:09    107,912    --a------    c:\windows\system32\drivers\avgtdix.sys
2009-03-27 19:45 . 2009-03-27 19:45    <DIR>    d--------    c:\programmer\CCleaner
2009-03-27 19:39 . 2009-03-27 19:39    <DIR>    d--h-----    c:\windows\PIF
2009-03-27 19:38 . 2009-03-27 19:38    <DIR>    d--------    c:\programmer\Malwarebytes' Anti-Malware
2009-03-27 19:38 . 2009-03-27 19:38    <DIR>    d--------    c:\documents and settings\Bruger\Application Data\Malwarebytes
2009-03-27 19:38 . 2009-03-27 19:38    <DIR>    d--------    c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-27 19:38 . 2009-03-26 16:49    38,496    --a------    c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-27 19:38 . 2009-03-26 16:49    15,504    --a------    c:\windows\system32\drivers\mbam.sys
2009-03-27 18:02 . 2009-03-27 18:02    <DIR>    d--------    c:\documents and settings\Bruger\Application Data\Birdstep Technology
2009-03-27 18:01 . 2007-05-28 18:00    10,240    ---------    c:\windows\system32\drivers\mdvrmng.sys
2009-03-27 18:00 . 2009-03-27 18:00    <DIR>    d--------    c:\windows\LastGood.Tmp
2009-03-27 18:00 . 2008-05-30 12:14    102,016    --a------    c:\windows\system32\drivers\ewusbmdm.sys
2009-03-27 18:00 . 2008-05-30 12:14    100,992    --a------    c:\windows\system32\drivers\ewusbnet.sys
2009-03-27 18:00 . 2008-05-30 12:14    24,448    --a------    c:\windows\system32\drivers\ewdcsc.sys
2009-03-27 17:59 . 2009-03-27 17:59    <DIR>    d--------    c:\programmer\3
2009-03-27 17:51 . 2009-03-27 17:51    22,304    --a------    c:\windows\system32\drivers\tsm68c8.sys
2009-03-27 17:50 . 2009-03-27 17:50    22,304    --a------    c:\windows\system32\drivers\tsr8060.sys
2009-03-27 17:49 . 2009-03-27 17:49    22,304    --a------    c:\windows\system32\drivers\tsr74a8.sys
2009-03-27 17:48 . 2009-03-27 17:48    22,304    --a------    c:\windows\system32\drivers\tsr8ce0.sys
2009-03-27 17:47 . 2008-04-13 11:40    96,384    --a------    c:\windows\system32\drivers\scsiport.sys
2009-03-27 17:46 . 2008-04-13 11:32    196,224    --a------    c:\windows\system32\drivers\rdpdr.sys
2009-03-27 17:45 . 2008-04-13 11:53    264,832    --a------    c:\windows\system32\drivers\http.sys
2009-03-27 17:42 . 2009-03-27 17:42    22,304    --a------    c:\windows\system32\drivers\fer1432.sys
2009-03-27 17:41 . 2001-10-04 16:46    12,288    --a------    c:\windows\system32\drivers\fsvga.sys

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-27 21:52    22,304    ----a-w    c:\windows\system32\drivers\tlpd995.sys
2009-03-27 21:51    22,304    ----a-w    c:\windows\system32\drivers\thq93d1.sys
2009-03-27 21:50    22,304    ----a-w    c:\windows\system32\drivers\tmqc315.sys
2009-03-27 21:49    22,304    ----a-w    c:\windows\system32\drivers\thq6979.sys
2009-03-27 21:48    22,304    ----a-w    c:\windows\system32\drivers\thq869e.sys
2009-03-27 21:47    22,304    ----a-w    c:\windows\system32\drivers\tmqe0c6.sys
2009-03-27 21:46    22,304    ----a-w    c:\windows\system32\drivers\thl3729.sys
2009-03-27 21:45    22,304    ----a-w    c:\windows\system32\drivers\tgk4025.sys
2009-03-27 21:44    22,304    ----a-w    c:\windows\system32\drivers\tmqdffd.sys
2009-03-27 21:43    22,304    ----a-w    c:\windows\system32\drivers\thqa425.sys
2009-03-27 21:42    22,304    ----a-w    c:\windows\system32\drivers\tmqcaf9.sys
2009-03-27 21:41    22,304    ----a-w    c:\windows\system32\drivers\slpd2b5.sys
2009-03-27 21:40    22,304    ----a-w    c:\windows\system32\drivers\tlqc9b9.sys
2009-03-27 21:39    22,304    ----a-w    c:\windows\system32\drivers\tmqfc5a.sys
2009-03-27 21:38    22,304    ----a-w    c:\windows\system32\drivers\tmq2dba.sys
2009-03-27 21:37    22,304    ----a-w    c:\windows\system32\drivers\tmq0a06.sys
2009-03-27 21:36    22,304    ----a-w    c:\windows\system32\drivers\tmqf0bf.sys
2009-03-27 21:35    22,304    ----a-w    c:\windows\system32\drivers\thq534a.sys
2009-03-27 21:34    22,304    ----a-w    c:\windows\system32\drivers\tlp221b.sys
2009-03-27 21:33    22,304    ----a-w    c:\windows\system32\drivers\tmqd391.sys
2009-03-27 21:32    22,304    ----a-w    c:\windows\system32\drivers\tmq172b.sys
2009-03-27 21:31    22,304    ----a-w    c:\windows\system32\drivers\tmqe3bd.sys
2009-03-27 21:30    22,304    ----a-w    c:\windows\system32\drivers\thq90c5.sys
2009-03-27 21:29    22,304    ----a-w    c:\windows\system32\drivers\tlq025e.sys
2009-03-27 21:28    22,304    ----a-w    c:\windows\system32\drivers\tmqd32d.sys
2009-03-27 21:27    22,304    ----a-w    c:\windows\system32\drivers\tmq2ee6.sys
2009-03-27 21:26    22,304    ----a-w    c:\windows\system32\drivers\tmq2446.sys
2009-03-27 21:25    22,304    ----a-w    c:\windows\system32\drivers\tmqc8a5.sys
2009-03-27 21:24    22,304    ----a-w    c:\windows\system32\drivers\tmqd04a.sys
2009-03-27 21:23    22,304    ----a-w    c:\windows\system32\drivers\tmqffde.sys
2009-03-27 21:22    22,304    ----a-w    c:\windows\system32\drivers\tmq0222.sys
2009-03-27 21:21    22,304    ----a-w    c:\windows\system32\drivers\tlp2f72.sys
2009-03-27 21:20    22,304    ----a-w    c:\windows\system32\drivers\tlqf425.sys
2009-03-27 21:19    22,304    ----a-w    c:\windows\system32\drivers\tmq052e.sys
2009-03-27 21:18    22,304    ----a-w    c:\windows\system32\drivers\tmq26da.sys
2009-03-27 21:17    22,304    ----a-w    c:\windows\system32\drivers\tmq20ea.sys
2009-03-27 21:16    22,304    ----a-w    c:\windows\system32\drivers\tmq2112.sys
2009-03-27 21:15    22,304    ----a-w    c:\windows\system32\drivers\tmqf1b9.sys
2009-03-27 21:14    22,304    ----a-w    c:\windows\system32\drivers\tmq0f07.sys
2009-03-27 21:13    22,304    ----a-w    c:\windows\system32\drivers\tmqe6a1.sys
2009-03-27 21:12    22,304    ----a-w    c:\windows\system32\drivers\tmq223e.sys
2009-03-27 21:11    22,304    ----a-w    c:\windows\system32\drivers\tmqed09.sys
2009-03-27 21:10    22,304    ----a-w    c:\windows\system32\drivers\tmq1f0a.sys
2009-03-27 21:09    22,304    ----a-w    c:\windows\system32\drivers\thq9219.sys
2009-03-27 21:08    22,304    ----a-w    c:\windows\system32\drivers\thqb7fd.sys
2009-03-27 21:07    22,304    ----a-w    c:\windows\system32\drivers\thq9daa.sys
2009-03-27 21:06    22,304    ----a-w    c:\windows\system32\drivers\thq9f39.sys
2009-03-27 21:05    22,304    ----a-w    c:\windows\system32\drivers\tmqe652.sys
2009-03-27 21:04    22,304    ----a-w    c:\windows\system32\drivers\tmqef61.sys
2009-03-27 21:03    22,304    ----a-w    c:\windows\system32\drivers\thq6a69.sys
2009-03-27 21:02    22,304    ----a-w    c:\windows\system32\drivers\tmq174e.sys
2009-03-27 21:01    22,304    ----a-w    c:\windows\system32\drivers\tmqc3f1.sys
2009-03-27 21:00    22,304    ----a-w    c:\windows\system32\drivers\tmqf371.sys
2009-03-27 20:59    22,304    ----a-w    c:\windows\system32\drivers\tmq1b9a.sys
2009-03-27 20:58    22,304    ----a-w    c:\windows\system32\drivers\tmqc739.sys
2009-03-27 20:57    22,304    ----a-w    c:\windows\system32\drivers\tmqea25.sys
2009-03-27 20:56    22,304    ----a-w    c:\windows\system32\drivers\tmq188e.sys
2009-03-27 20:55    22,304    ----a-w    c:\windows\system32\drivers\tmq23ba.sys
2009-03-27 20:54    22,304    ----a-w    c:\windows\system32\drivers\tmq32f6.sys
2009-03-27 20:53    22,304    ----a-w    c:\windows\system32\drivers\tmqd5e9.sys
2009-03-27 20:52    22,304    ----a-w    c:\windows\system32\drivers\thq9a75.sys
2009-03-27 20:51    22,304    ----a-w    c:\windows\system32\drivers\tmqd625.sys
2009-03-27 20:50    22,304    ----a-w    c:\windows\system32\drivers\tlqe63d.sys
2009-03-27 20:49    22,304    ----a-w    c:\windows\system32\drivers\tmqf49d.sys
2009-03-27 20:48    22,304    ----a-w    c:\windows\system32\drivers\tlq065a.sys
2009-03-27 20:47    22,304    ----a-w    c:\windows\system32\drivers\tmq277a.sys
2009-03-27 20:46    22,304    ----a-w    c:\windows\system32\drivers\tmqdca1.sys
2009-03-27 20:45    22,304    ----a-w    c:\windows\system32\drivers\tmqdf0d.sys
2009-03-27 20:44    22,304    ----a-w    c:\windows\system32\drivers\tmq1906.sys
2009-03-27 20:43    22,304    ----a-w    c:\windows\system32\drivers\tmq183f.sys
2009-03-27 20:42    22,304    ----a-w    c:\windows\system32\drivers\tmqe396.sys
2009-03-27 20:41    22,304    ----a-w    c:\windows\system32\drivers\tmq2e1f.sys
2009-03-27 20:40    22,304    ----a-w    c:\windows\system32\drivers\tmq2fc2.sys
2009-03-27 20:39    22,304    ----a-w    c:\windows\system32\drivers\tmq1ee2.sys
2009-03-27 20:38    22,304    ----a-w    c:\windows\system32\drivers\tmqdda5.sys
2009-03-27 20:37    22,304    ----a-w    c:\windows\system32\drivers\tmq1f6e.sys
2009-03-27 20:36    22,304    ----a-w    c:\windows\system32\drivers\tmqe769.sys
2009-03-27 20:35    22,304    ----a-w    c:\windows\system32\drivers\tmq1d66.sys
2009-03-27 20:34    22,304    ----a-w    c:\windows\system32\drivers\tmqfd35.sys
2009-03-27 20:33    22,304    ----a-w    c:\windows\system32\drivers\tmqc239.sys
2009-03-27 20:32    22,304    ----a-w    c:\windows\system32\drivers\tmqf191.sys
2009-03-27 20:31    22,304    ----a-w    c:\windows\system32\drivers\tmq146b.sys
2009-03-27 20:30    22,304    ----a-w    c:\windows\system32\drivers\tmq070e.sys
2009-03-27 20:29    22,304    ----a-w    c:\windows\system32\drivers\tmqece2.sys
2009-03-27 20:28    22,304    ----a-w    c:\windows\system32\drivers\thqc122.sys
2009-03-27 20:27    22,304    ----a-w    c:\windows\system32\drivers\tmq0cae.sys
2009-03-27 20:26    22,304    ----a-w    c:\windows\system32\drivers\tmq204f.sys
2009-03-27 20:25    22,304    ----a-w    c:\windows\system32\drivers\tmqdfc1.sys
2009-03-27 20:24    22,304    ----a-w    c:\windows\system32\drivers\tmqca95.sys
2009-03-27 20:23    22,304    ----a-w    c:\windows\system32\drivers\tmqf565.sys
2009-03-27 20:22    22,304    ----a-w    c:\windows\system32\drivers\tmqd819.sys
2009-03-27 20:21    22,304    ----a-w    c:\windows\system32\drivers\tmq25db.sys
2009-03-27 20:20    22,304    ----a-w    c:\windows\system32\drivers\tmqd229.sys
2009-03-27 20:19    22,304    ----a-w    c:\windows\system32\drivers\tmacde1.sys
2009-03-27 20:18    22,304    ----a-w    c:\windows\system32\drivers\tmqd6c5.sys
2009-03-27 20:17    22,304    ----a-w    c:\windows\system32\drivers\tmqe4fe.sys
2009-03-27 20:16    22,304    ----a-w    c:\windows\system32\drivers\tmqf2e5.sys
2009-03-27 20:15    22,304    ----a-w    c:\windows\system32\drivers\tmqda21.sys
2009-03-27 20:14    22,304    ----a-w    c:\windows\system32\drivers\tmqf48a.sys
2009-03-27 20:13    22,304    ----a-w    c:\windows\system32\drivers\thqbe79.sys
.

(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-15 15360]
"msnmsgr"="c:\programmer\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"swg"="c:\programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-13 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-11 1932568]

c:\documents and settings\All Users\Menuen Start\Programmer\Start\
Opdateringsagent.lnk - c:\programmer\3\3Connect\AutoUpdateSrv.exe [2008-10-23 442368]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-11 09:54 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmer\\Messenger\\msmsgs.exe"=
"c:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programmer\\AVG\\AVG8\\avgemc.exe"=
"c:\\Programmer\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programmer\\AVG\\AVG8\\avgnsx.exe"=

R1 avgldx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-03-27 325640]
R1 avgtdix;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-03-27 107912]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-03-11 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-11 298264]
R2 mdvrmng;Mobile IP Route Manager;c:\windows\system32\drivers\mdvrmng.sys [2009-03-27 10240]
S2 giwosi;giwosi;c:\windows\System32\svchost.exe -k netsvcs [2008-04-15 14336]
S3 dae8206;dae8206;c:\windows\system32\drivers\dae8206.sys --> c:\windows\system32\drivers\dae8206.sys [?]
S3 fbs068e;fbs068e;c:\windows\system32\drivers\fbs068e.sys --> c:\windows\system32\drivers\fbs068e.sys [?]
S3 getplus(r) helper;getPlus(R) Helper;c:\programmer\NOS\bin\getPlus_HelperSvc.exe --> c:\programmer\NOS\bin\getPlus_HelperSvc.exe [?]
S3 iei5c4e;iei5c4e;c:\windows\system32\drivers\iei5c4e.sys --> c:\windows\system32\drivers\iei5c4e.sys [?]
S3 lil5cde;lil5cde;c:\windows\system32\drivers\lil5cde.sys --> c:\windows\system32\drivers\lil5cde.sys [?]
S3 njgf60c;njgf60c;c:\windows\system32\drivers\njgf60c.sys --> c:\windows\system32\drivers\njgf60c.sys [?]
S3 OZSCR;O2Micro SmartCardBus Smartcard Reader;c:\windows\system32\DRIVERS\ozscr.sys --> c:\windows\system32\DRIVERS\ozscr.sys [?]

--- Andre Services/Drivers i Hukommelsen ---

*NewlyCreated* - JJE07C6
*Deregistered* - jje07c6

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
giwosi

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\shell\autorun\command - H:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{593cf540-02ab-11de-9920-e6b67ecd7c8e}]
\Shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{593cf543-02ab-11de-9920-e6b67ecd7c8e}]
\shell\autorun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5e785522-f874-11dd-98fd-000f1fa05c12}]
\Shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7c14f840-02a5-11de-991e-a4fce4796d8e}]
\shell\autorun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9ba62305-fa03-11dd-9902-000f1fa05c12}]
\Shell\AutoRun\command - F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9f8f2560-02a1-11de-991c-ec44d66f9c32}]
\Shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9f8f2563-02a1-11de-991c-ec44d66f9c32}]
\Shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9f8f2564-02a1-11de-991c-e0a558d429f6}]
\Shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9f8f2565-02a1-11de-991c-e0a558d429f6}]
\Shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cdb00cd0-0e14-11de-9927-c0327252e87b}]
\shell\autorun\command - F:\AutoRun.exe
.
.
------- Yderligere scanning -------
.
Trusted Zone: danid.dk
DPF: {9df01f00-08e7-4dbe-9070-94841463b3fe} - hxxps://danid.dk/csp/authenticode/csp.exe
FF - ProfilePath - c:\documents and settings\Bruger\Application Data\Mozilla\Firefox\Profiles\i0rvbkky.default\
FF - component: c:\programmer\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\programmer\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - component: c:\programmer\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-27 22:56:52
Windows 5.1.2600 Service Pack 3 NTFS

scanner skjulte processer ... 

scanner skjulte autostarter ...

scanner skjulte filer ... 


**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\phpeff2]
"ImagePath"="\SystemRoot\System32\drivers\tiffd48.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\6ac7d5f4]
"ImagePath"="\SystemRoot\System32\drivers\6ac7d5f4.sys"
.
--------------------- DLLs startet under kørende Processer ---------------------

- - - - - - - > 'winlogon.exe'(552)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Andre kørende processer ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\WgaTray.exe
c:\windows\system32\scardsvr.exe
c:\programmer\Java\jre6\bin\jqs.exe
c:\programmer\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\programmer\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\combofix\hidec.exe
c:\combofix\Catchme.tmp
.
**************************************************************************
.
Gennemført tid: 2009-03-27 23:02:02 - maskinen blev genstartet
ComboFix-quarantined-files.txt  2009-03-27 22:00:39

Pre-Kørsel: 23.745.343.488 byte ledig
Post-Kørsel: 23,742,636,032 byte ledig

362    --- E O F ---    2009-02-26 06:26:59
27. marts 2009 - 23:18 #11
Lige en hurtig:
La' AVG nappe de
c:\windows\system32\drivers\*
filer ...

(Mere ka' følge...)

<f-arn>: Du må gerne fortsætte.. jeg er måske ikke 'på' de næste dage...
Avatar billede hojben Novice
27. marts 2009 - 23:23 #12
der har ikke været noget efter sidste genstart men AVG fandt dem jo og lige meget hvor mange jeg smed over i Vault'en kom der bare flere..
Avatar billede hojben Novice
27. marts 2009 - 23:28 #13
jo jo startede AVG Tray Icon op og pufpuf var det de selvsammen driverfiler som igen var inficeret..
Avatar billede hojben Novice
28. marts 2009 - 08:37 #14
Hva skal jeg stille op??
Avatar billede arkil Nybegynder
28. marts 2009 - 12:10 #15
Jeg kan godt forstå du spørger hvad du skal stille op.
Nu kan jeg ikke se hvad AVG har fjernet men du gør dette.


-- Hent Avenger her:
http://swandog46.geekstogo.com/avenger.zip


-- Pak Avenger-programmet ud og dobbeltklik på avenger.exe


-- Nu dukker der et lille vindue op, hvor du skal kopiere indholdet mellem de stiplede linier ind, klik "Execute".

-----------------------------

Files to delete:
c:\windows\system32\drivers\tlq1c76.sys
c:\windows\system32\drivers\tmqf71e.sys
c:\windows\system32\drivers\tmqf781.sys
c:\windows\system32\drivers\tlq1a46.sys
c:\windows\system32\drivers\tmqf296.sys
c:\windows\system32\drivers\tlq15fa.sys
c:\windows\system32\drivers\tmq2c3f.sys
c:\windows\system32\drivers\tmqf731.sys
c:\windows\system32\drivers\tlp07fe.sys
c:\windows\system32\drivers\tmqea75.sys
c:\windows\system32\drivers\tmqc2b1.sys
c:\windows\system32\drivers\tmq1bae.sys
c:\windows\system32\drivers\tmq2087.sys
c:\windows\system32\drivers\tmqf9ed.sys
c:\windows\system32\drivers\tmqd319.sys
c:\windows\system32\drivers\tlq1ffa.sys
c:\windows\system32\drivers\tmqf079.sys
c:\windows\system32\drivers\tmqde6d.sys
c:\windows\system32\drivers\tmqe86e.sys
c:\windows\system32\drivers\tmq034e.sys
c:\windows\system32\drivers\tmq11d6.sys
c:\windows\system32\drivers\tmqdebd.sys
c:\windows\system32\drivers\tmqd73d.sys
c:\windows\system32\drivers\tmqf872.sys
c:\windows\system32\drivers\tmqe1a1.sys
c:\windows\system32\drivers\tmqef62.sys
c:\windows\system32\drivers\tpt1bb1.sys
c:\windows\system32\drivers\tlpeed5.sys
c:\windows\system32\drivers\tlqe1a1.sys
c:\windows\system32\drivers\tmq14f6.sys
c:\windows\system32\drivers\tmqd87e.sys
c:\windows\system32\drivers\tmq2e0a.sys
c:\windows\system32\drivers\tmq81a7.sys
c:\windows\system32\drivers\tmqf53d.sys
c:\windows\system32\drivers\tmqf231.sys
c:\windows\system32\drivers\tmqc87a.sys
c:\windows\system32\drivers\tmqe922.sys
c:\windows\system32\drivers\tmqe36e.sys
c:\windows\system32\drivers\tmqfb92.sys
c:\windows\system32\drivers\tmqdd55.sys
c:\windows\system32\drivers\tmqf282.sys
c:\windows\system32\drivers\tmq0c5e.sys
c:\windows\system32\drivers\tmqed32.sys
c:\windows\system32\drivers\tlq0eca.sys
c:\windows\system32\drivers\tmqfa29.sys
c:\windows\system32\drivers\tmqf476.sys
c:\windows\system32\drivers\thq733d.sys
c:\windows\system32\drivers\tmqfeed.sys
c:\windows\system32\drivers\tmqd8cd.sys
c:\windows\system32\drivers\tmqff52.sys
c:\windows\system32\drivers\tmqe832.sys
c:\windows\system32\drivers\tmqfa79.sys
c:\windows\system32\drivers\tmqfe75.sys
c:\windows\system32\drivers\tmq1b4a.sys
c:\windows\system32\drivers\tmqc42e.sys
c:\windows\system32\drivers\tmqc6e9.sys
c:\windows\system32\drivers\tmqe5ed.sys
c:\windows\system32\drivers\tmq13a2.sys
c:\windows\system32\drivers\tpa1f5e.sys
c:\windows\system32\drivers\tmqc6c1.sys
c:\windows\system32\drivers\tmqe039.sys
c:\windows\system32\drivers\tlq0cd6.sys
c:\windows\system32\drivers\tmqfa8e.sys
c:\windows\system32\drivers\tmqedbd.sys
c:\windows\system32\drivers\tmqe665.sys
c:\windows\system32\drivers\tmq241f.sys
c:\windows\system32\drivers\tmq25ea.sys
c:\windows\system32\drivers\tmqfd4a.sys
c:\windows\system32\drivers\tmqe2a5.sys
c:\windows\system32\drivers\tmqd9d1.sys
c:\windows\system32\drivers\tmqdade.sys
c:\windows\system32\drivers\tmqdc79.sys
c:\windows\system32\drivers\tmqd909.sys
c:\windows\system32\drivers\tmqea12.sys
c:\windows\system32\drivers\tmqe27d.sys
c:\windows\system32\drivers\tmtba81.sys
c:\windows\system32\drivers\tmqfe25.sys
c:\windows\system32\drivers\tmqf655.sys
c:\windows\system32\drivers\tmq3012.sys
c:\windows\system32\drivers\tmqf4b2.sys
c:\windows\system32\drivers\tmqfac9.sys
c:\windows\system32\drivers\tmq1277.sys
c:\windows\system32\drivers\tmqf12d.sys
c:\windows\system32\drivers\tmqe36d.sys
c:\windows\system32\drivers\tmqe219.sys
c:\windows\system32\drivers\tmqe269.sys
c:\windows\system32\drivers\tmqfc82.sys
c:\windows\system32\drivers\tmqea3a.sys
c:\windows\system32\drivers\tmq4377.sys
c:\windows\system32\drivers\tmqef25.sys
c:\windows\system32\drivers\tmq3ec7.sys
c:\windows\system32\drivers\tmqfec5.sys
c:\windows\system32\drivers\tmqe7ce.sys
c:\windows\system32\drivers\tmqfe76.sys
c:\windows\system32\drivers\tmqe062.sys
c:\windows\system32\drivers\tmt16b2.sys
c:\windows\system32\drivers\tmq2536.sys
c:\windows\system32\drivers\tmtbcc5.sys
c:\windows\system32\drivers\thq79a5.sys
c:\windows\system32\drivers\tsm68c8.sys
c:\windows\system32\drivers\tsr8060.sys
c:\windows\system32\drivers\tsr74a8.sys
c:\windows\system32\drivers\tsr8ce0.sys
c:\windows\system32\drivers\fer1432.sys
c:\windows\System32\drivers\6ac7d5f4.sys
c:\windows\System32\drivers\tiffd48.sys
c:\windows\system32\drivers\tlpd995.sys
c:\windows\system32\drivers\thq93d1.sys
c:\windows\system32\drivers\tmqc315.sys
c:\windows\system32\drivers\thq6979.sys
c:\windows\system32\drivers\thq869e.sys
c:\windows\system32\drivers\tmqe0c6.sys
c:\windows\system32\drivers\thl3729.sys
c:\windows\system32\drivers\tgk4025.sys
c:\windows\system32\drivers\tmqdffd.sys
c:\windows\system32\drivers\thqa425.sys
c:\windows\system32\drivers\tmqcaf9.sys
c:\windows\system32\drivers\slpd2b5.sys
c:\windows\system32\drivers\tlqc9b9.sys
c:\windows\system32\drivers\tmqfc5a.sys
c:\windows\system32\drivers\tmq2dba.sys
c:\windows\system32\drivers\tmq0a06.sys
c:\windows\system32\drivers\tmqf0bf.sys
c:\windows\system32\drivers\thq534a.sys
c:\windows\system32\drivers\tlp221b.sys
c:\windows\system32\drivers\tmqd391.sys
c:\windows\system32\drivers\tmq172b.sys
c:\windows\system32\drivers\tmqe3bd.sys
c:\windows\system32\drivers\thq90c5.sys
c:\windows\system32\drivers\tlq025e.sys
c:\windows\system32\drivers\tmqd32d.sys
c:\windows\system32\drivers\tmq2ee6.sys
c:\windows\system32\drivers\tmq2446.sys
c:\windows\system32\drivers\tmqc8a5.sys
c:\windows\system32\drivers\tmqd04a.sys
c:\windows\system32\drivers\tmqffde.sys
c:\windows\system32\drivers\tmq0222.sys
c:\windows\system32\drivers\tlp2f72.sys
c:\windows\system32\drivers\tlqf425.sys
c:\windows\system32\drivers\tmq052e.sys
c:\windows\system32\drivers\tmq26da.sys
c:\windows\system32\drivers\tmq20ea.sys
c:\windows\system32\drivers\tmq2112.sys
c:\windows\system32\drivers\tmqf1b9.sys
c:\windows\system32\drivers\tmq0f07.sys
c:\windows\system32\drivers\tmqe6a1.sys
c:\windows\system32\drivers\tmq223e.sys
c:\windows\system32\drivers\tmqed09.sys
c:\windows\system32\drivers\tmq1f0a.sys
c:\windows\system32\drivers\thq9219.sys
c:\windows\system32\drivers\thqb7fd.sys
c:\windows\system32\drivers\thq9daa.sy
c:\windows\system32\drivers\thq9f39.sys
c:\windows\system32\drivers\tmqe652.sys
c:\windows\system32\drivers\tmqef61.sys
c:\windows\system32\drivers\thq6a69.sys
c:\windows\system32\drivers\tmq174e.sys
c:\windows\system32\drivers\tmqc3f1.sys
c:\windows\system32\drivers\tmqf371.sys
c:\windows\system32\drivers\tmq1b9a.sys
c:\windows\system32\drivers\tmqc739.sys
c:\windows\system32\drivers\tmqea25.sys
c:\windows\system32\drivers\tmq188e.sys
c:\windows\system32\drivers\tmq23ba.sys
c:\windows\system32\drivers\tmq32f6.sys
c:\windows\system32\drivers\tmqd5e9.sys
c:\windows\system32\drivers\thq9a75.sys
c:\windows\system32\drivers\tmqd625.sys
c:\windows\system32\drivers\tlqe63d.sys
c:\windows\system32\drivers\tmqf49d.sys
c:\windows\system32\drivers\tlq065a.s
c:\windows\system32\drivers\tmq277a.sys
c:\windows\system32\drivers\tmqdca1.sys
c:\windows\system32\drivers\tmqdf0d.sys
c:\windows\system32\drivers\tmq1906.sys
c:\windows\system32\drivers\tmq183f.sys
c:\windows\system32\drivers\tmqe396.sys
c:\windows\system32\drivers\tmq2e1f.sys
c:\windows\system32\drivers\tmq2fc2.sys
c:\windows\system32\drivers\tmq1ee2.sys
c:\windows\system32\drivers\tmqdda5.sys
c:\windows\system32\drivers\tmq1f6e.sys
c:\windows\system32\drivers\tmqe769.sys
c:\windows\system32\drivers\tmq1d66.sys
c:\windows\system32\drivers\tmqfd35.sys
c:\windows\system32\drivers\tmqc239.sys
c:\windows\system32\drivers\tmqf191.sys
c:\windows\system32\drivers\tmq146b.sys
c:\windows\system32\drivers\tmq070e.sys
c:\windows\system32\drivers\tmqece2.sys
c:\windows\system32\drivers\thqc122.sys
c:\windows\system32\drivers\tmq0cae.sys
c:\windows\system32\drivers\tmq204f.sys
c:\windows\system32\drivers\tmqdfc1.sys
c:\windows\system32\drivers\tmqca95.sys
c:\windows\system32\drivers\tmqf565.sys
c:\windows\system32\drivers\tmqd819.sys
c:\windows\system32\drivers\tmq25db.sys
c:\windows\system32\drivers\tmqd229.sys
c:\windows\system32\drivers\tmacde1.sys
c:\windows\system32\drivers\tmqd6c5.sys
c:\windows\system32\drivers\tmqe4fe.sys
c:\windows\system32\drivers\tmqf2e5.sys
c:\windows\system32\drivers\tmqda21.sys
c:\windows\system32\drivers\tmqf48a.sys
c:\windows\system32\drivers\thqbe79.sys
c:\windows\system32\drivers\njgf60c.sys
c:\windows\system32\drivers\dae8206.sys
c:\windows\system32\drivers\fbs068e.sys
c:\windows\system32\drivers\iei5c4e.sys
c:\windows\system32\drivers\lil5cde.sys
Drivers to delete:
dae8206
fbs068e
iei5c4e
lil5cde
njgf60c
Registry keys to delete:
HKEY_LOCAL_MACHINE\System\ControlSet002\Services\phpeff2
HKEY_LOCAL_MACHINE\System\ControlSet002\Services\6ac7d5f4




-----------------------------

-- Programmet vil opfordre dig til at genstarte computeren straks, hvilket du skal gøre. Programmet vil lukke din computer, slette filerne og starte computeren igen.

-- Efter genstarten vil der dukke et notepad-vindue op, med en log for Avengers handlinger. Den må du gerne lægge her ind sammen med en ny log fra Combofix.


Husk at deaktiver AVG inden du begynder >
Højreklik på AVG ikon ved uret - Open AVG User Interface - gå ind under "Resident Shield" fjern flueben ved "Resident Shield active" - klik "Save Changes".
Avatar billede hojben Novice
30. marts 2009 - 16:04 #16
Valgte at reinstallere og slette alt på maskinen da der ik kom svar..

smid et svar :)
30. marts 2009 - 21:58 #17
((Hvem af os ?))
Avatar billede hojben Novice
31. marts 2009 - 08:58 #18
bare dig larry :)
31. marts 2009 - 18:21 #19
Ping...
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester