Hej Super team
Vil i lige tjekke loggen, tror jeg har en trojaner der hedder noget med zues.exe den lagde i mappen C:/bruger/morgan/appdata/roaming/uformcy/zues.exe
jeg har kørt ccleaner, malwarebytes. startede op i fejlsikret tilstand slettede mappen og søgte i regedit fandt ikke noget. Den havde lagt sig i opstartsfasen før.
men her er loggen fra dds:
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by Morgan at 10:47:46 on 2012-05-05
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.45.1030.18.4044.2004 [GMT 2:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
C:\Windows\SysWOW64\ezSharedSvcHost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files (x86)\ZyXEL\NetUSB Share Center\Share Center.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Windows\system32\DllHost.exe
c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpConnectionManager.exe
C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Secunia\PSI\PSIA.exe
C:\Program Files (x86)\Secunia\PSI\PSI_TRAY.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe
C:\Program Files (x86)\Secunia\PSI\sua.exe
C:\Windows\system32\msiexec.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Secunia\PSI\SUA\b736655d1b8c65dd87d073b388389e53\JavaJRE_6u31_32-bit.exe
C:\Users\Morgan\AppData\Local\Temp\60377607-a0fb-49b0-adba-9c435df33687\jre-6u31-windows-i586.exe
C:\Windows\SysWOW64\msiexec.exe
C:\Windows\syswow64\MsiExec.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe
C:\Windows\syswow64\MsiExec.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.dk/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Hjælp til logon til Windows Live ID: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - “C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll”
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - “C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll”
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: {E9DF9360-97F8-4690-AFE6-996C80790DA4} - No File
uRun: [EPSON SX130 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHJE.EXE /FU “C:\Users\Morgan\AppData\Local\Temp\E_SCA8E.tmp” /EF “HKCU”
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [Skype] “C:\Program Files (x86)\Skype\Phone\Skype.exe” /minimized /regrun
uRun: [DAEMON Tools Lite] “C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe” -autorun
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [Adobe Reader Speed Launcher] “C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe”
mRun: [Adobe ARM] “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [StartCCC] “c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” MSRun
mRun: [ZyXEL USB Share Center] C:\Program Files (x86)\ZyXEL\NetUSB Share Center\Share Center.exe -mini
mRun: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
mRun: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
mRun: [<NO NAME>]
mRun: [EEventManager] “C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe”
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [APSDaemon] “C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe”
mRun: [iTunesHelper] “C:\Program Files (x86)\iTunes\iTunesHelper.exe”
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SECUNI~1.LNK - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: HideFastUserSwitching = 0 (0x0)
IE: Free YouTube to MP3 Converter - C:\Users\Morgan\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: {B30C9F17-BF16-481e-BAEA-44A86128E1B4} - C:\Program Files (x86)\FreeYouTubeToMP3TURBOConverter\ytmRunner.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} - hxxp://kitchenplanner.ikea.com/DK/Core/Player/2020PlayerAX_IKEA_Win32.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.5.1.0.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{058D42E1-7C7D-409F-8305-C72CA7C2C243} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{9E1771AF-CCC9-4F9A-BA3A-39B89D7C0C94} : DhcpNameServer = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SEH: EasyBits ShellExecute Hook: {e54729e8-bb3d-4270-9d49-7389ea579090} - C:\Windows\SysWow64\EZUPBH~1.DLL
{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
{9030D464-4C02-4ABF-8ECC-5164760863C6}
{d2ce3e00-f94a-4740-988e-03dc2f38c34f}
{DBC80044-A445-435b-BC74-9C25C1C588A9}
{8dcb7100-df86-4384-8842-8fa844297b3f}
TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB-X64: {E9DF9360-97F8-4690-AFE6-996C80790DA4} - No File
mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun-x64: [Adobe Reader Speed Launcher] “C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe”
mRun-x64: [Adobe ARM] “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
mRun-x64: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun-x64: [StartCCC] “c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” MSRun
mRun-x64: [ZyXEL USB Share Center] C:\Program Files (x86)\ZyXEL\NetUSB Share Center\Share Center.exe -mini
mRun-x64: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
mRun-x64: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
mRun-x64: [(Standard)]
mRun-x64: [EEventManager] “C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe”
mRun-x64: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun-x64: [APSDaemon] “C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe”
mRun-x64: [iTunesHelper] “C:\Program Files (x86)\iTunes\iTunesHelper.exe”
IE-X64: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE-X64: {B30C9F17-BF16-481e-BAEA-44A86128E1B4} - C:\Program Files (x86)\FreeYouTubeToMP3TURBOConverter\ytmRunner.html
SEH-X64: {E54729E8-BB3D-4270-9D49-7389EA579090}: EasyBits Security Shield Hook - prevents launching insecure programs by kids
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys—> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys—> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys—> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-12 140672]
R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-5-14 759048]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe—> C:\Windows\system32\atiesrxx.exe [?]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624]
R2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE [2012-3-11 166400]
R2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [2012-3-11 128512]
R2 ezSharedSvc;Easybits Services for Windows;C:\Windows\System32\ezSharedSvcHost.exe [2011-5-28 514232]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-6-21 85560]
R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-8-6 291896]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-9-1 227896]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-11-10 26680]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-6-18 13336]
R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-6-18 2372096]
R2 Secunia PSI Agent;Secunia PSI Agent;C:\Program Files (x86)\Secunia\PSI\psia.exe [2011-10-14 994360]
R2 Secunia Update Agent;Secunia Update Agent;C:\Program Files (x86)\Secunia\PSI\sua.exe [2011-10-14 399416]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-1 508776]
R2 TeamViewer7;TeamViewer 7;C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-3-22 2886528]
R2 TomTomHOMEService;TomTomHOMEService;C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2012-1-23 92592]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-6-18 2656280]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys—> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys—> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\system32\DRIVERS\clwvd.sys—> C:\Windows\system32\DRIVERS\clwvd.sys [?]
R3 hpCMSrv;HP Connection Manager 4 Service;C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-9-13 1098296]
R3 IntcDAud;Intel(R) lyd for skærm;C:\Windows\system32\DRIVERS\IntcDAud.sys—> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 intelkmd;intelkmd;C:\Windows\system32\DRIVERS\igdpmd64.sys—> C:\Windows\system32\DRIVERS\igdpmd64.sys [?]
R3 MEIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys—> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 PSI;PSI;C:\Windows\system32\DRIVERS\psi_mf.sys—> C:\Windows\system32\DRIVERS\psi_mf.sys [?]
R3 RT80x86;Ralink 802.11n Wireless Driver;C:\Windows\system32\DRIVERS\RT2860.sys—> C:\Windows\system32\DRIVERS\RT2860.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys—> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys—> C:\Windows\system32\DRIVERS\Sftfslh.sys [?]
R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys—> C:\Windows\system32\DRIVERS\Sftplaylh.sys [?]
R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys—> C:\Windows\system32\DRIVERS\Sftredirlh.sys [?]
R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys—> C:\Windows\system32\DRIVERS\Sftvollh.sys [?]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-1 219496]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-1-31 158856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-3-30 257696]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-3-2 183560]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 HPMo4DE3;Mouse Suite Driver_4DE3 (WDF Version);C:\Windows\system32\DRIVERS\HPMo4DE3.sys—> C:\Windows\system32\DRIVERS\HPMo4DE3.sys [?]
S3 HPub4DE3;USB Mouse Low Filter Driver_4DE3 (WDF Version);C:\Windows\system32\Drivers\HPub4DE3.sys—> C:\Windows\system32\Drivers\HPub4DE3.sys [?]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys—> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Netværksinspektion;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\system32\DRIVERS\RtsPStor.sys—> C:\Windows\system32\DRIVERS\RtsPStor.sys [?]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;C:\Windows\system32\DRIVERS\RTL8192su.sys—> C:\Windows\system32\DRIVERS\RTL8192su.sys [?]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS—> C:\Windows\system32\DRIVERS\VSTAZL6.SYS [?]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS—> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS—> C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys—> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys—> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys—> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S3 WatAdminSvc;Tjenesten Windows Aktivering;C:\Windows\system32\Wat\WatAdminSvc.exe—> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
.
=============== Created Last 30 ================
.
2012-05-05 08:40:52 ———— d——-w- C:\Users\Morgan\AppData\Local\Secunia PSI
2012-05-04 22:11:30 ———— d——-w- C:\Program Files (x86)\Secunia
2012-05-04 21:55:44 ———— d——-w- C:\Users\Morgan\AppData\Roaming\SUPERAntiSpyware.com
2012-05-04 21:55:20 ———— d——-w- C:\ProgramData\SUPERAntiSpyware.com
2012-05-04 21:55:20 ———— d——-w- C:\Program Files\SUPERAntiSpyware
2012-05-04 20:32:37 ———— d——-w- C:\Program Files (x86)\ESET
2012-05-04 10:16:10 8917360 ——a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{525A65D3-9F13-4458-85D2-9045A058EB7E}\mpengine.dll
2012-05-04 10:06:41 ———— d——-w- C:\Users\Morgan\AppData\Local\{DB9ECC98-5A43-4149-AF1C-7BDB3F09D447}
2012-05-04 10:06:30 ———— d——-w- C:\Users\Morgan\AppData\Local\{4585AC07-6EC4-4263-A13A-8F92D3147132}
2012-05-03 13:48:27 ———— d——-w- C:\Users\Morgan\AppData\Local\{5C041A27-9830-4C1C-A0BB-755A2F7B07EF}
2012-05-03 13:48:17 ———— d——-w- C:\Users\Morgan\AppData\Local\{0055BCD4-FAF0-4E66-B824-01111540F366}
2012-05-03 13:47:36 ———— d——-w- C:\Users\Morgan\AppData\Local\{ED11083F-CF31-47B1-AE3E-75EB4932B621}
2012-05-02 19:35:29 ———— d——-w- C:\Program Files (x86)\Ralink
2012-05-02 19:13:59 2240864 ——a-w- C:\Windows\System32\drivers\rt2860.sys
2012-05-02 18:01:13 8917360 ——a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-05-02 17:58:08 ———— d——-w- C:\Users\Morgan\AppData\Local\{BA7DB6FD-06C5-4C9B-A322-1DD9AA968718}
2012-05-02 17:57:58 ———— d——-w- C:\Users\Morgan\AppData\Local\{CAAAC634-5AFD-41E6-9EA1-EF520BAE924F}
2012-05-01 12:43:53 ———— d——-w- C:\Users\Morgan\AppData\Local\{9FC9B034-03EF-48AD-AB32-CE87A63974D0}
2012-05-01 12:43:43 ———— d——-w- C:\Users\Morgan\AppData\Local\{E1F3F10F-0240-465B-B3E2-1793A030E4BE}
2012-04-30 19:12:56 ———— d——-w- C:\Users\Morgan\AppData\Local\{6AD05474-A50C-400A-9EEA-2AE3F8E13739}
2012-04-30 19:12:46 ———— d——-w- C:\Users\Morgan\AppData\Local\{95C0D37E-5F18-417E-B627-5772253D5C49}
2012-04-30 18:02:18 ———— d——-w- C:\Users\Morgan\AppData\Local\{1986AE41-1ECC-4379-AB9F-DE661064859E}
2012-04-29 18:56:45 ———— d——-w- C:\Users\Morgan\AppData\Local\{E8184A4A-7391-4E90-9126-D11281B0153B}
2012-04-29 18:56:35 ———— d——-w- C:\Users\Morgan\AppData\Local\{12B6B5BC-00E2-4263-B897-FD52DAC2BE79}
2012-04-28 22:02:08 ———— d——-w- C:\Users\Morgan\AppData\Roaming\Ytox
2012-04-28 22:02:08 ———— d——-w- C:\Users\Morgan\AppData\Roaming\Egwaeh
2012-04-28 19:57:28 ———— d——-w- C:\Users\Morgan\AppData\Local\{00F7E146-A7BB-4B2D-A59F-BE2917718C7E}
2012-04-28 19:57:18 ———— d——-w- C:\Users\Morgan\AppData\Local\{AEC4917B-02EF-47E1-863A-CDE1C68E992A}
2012-04-28 09:17:14 ———— d——-w- C:\Users\Morgan\AppData\Local\{FD2DE051-83B1-439D-82B1-73BD147382FC}
2012-04-27 19:24:05 ———— d——-w- C:\Windows\SysWow64\20-20 Technologies
2012-04-27 19:14:15 ———— d——-w- C:\Users\Morgan\AppData\Local\{5E543120-5A93-449F-AFF8-A0EBED340555}
2012-04-27 19:14:05 ———— d——-w- C:\Users\Morgan\AppData\Local\{1F77E63F-137C-4C86-B279-FABC7119AF65}
2012-04-26 12:41:04 ———— d——-w- C:\Users\Morgan\AppData\Local\{D70C7F9F-73BD-451C-9981-C14B79BB1DB3}
2012-04-26 12:40:54 ———— d——-w- C:\Users\Morgan\AppData\Local\{589AA9E6-5BEB-432C-A704-036B4711ADFE}
2012-04-25 18:36:10 ———— d——-w- C:\Program Files\iPod
2012-04-25 18:36:09 ———— d——-w- C:\Program Files\iTunes
2012-04-25 18:34:37 ———— d——-w- C:\Users\Morgan\AppData\Local\Apple Computer
2012-04-25 18:34:14 34152 ——a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2012-04-25 18:34:14 126312 ——a-w- C:\Windows\System32\GEARAspi64.dll
2012-04-25 18:34:14 107368 ——a-w- C:\Windows\SysWow64\GEARAspi.dll
2012-04-25 18:33:44 ———— d——-w- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2012-04-25 18:33:44 ———— d——-w- C:\Program Files (x86)\iTunes
2012-04-25 18:33:23 ———— d——-w- C:\Users\Morgan\AppData\Local\Apple
2012-04-25 18:32:53 ———— d——-w- C:\Program Files\Bonjour
2012-04-25 18:32:53 ———— d——-w- C:\Program Files (x86)\Bonjour
2012-04-25 13:44:56 ———— d——-w- C:\Users\Morgan\AppData\Local\{57007C37-3AB4-476D-AB4D-8C41E94CCCD1}
2012-04-25 13:44:46 ———— d——-w- C:\Users\Morgan\AppData\Local\{821A3E52-B5DC-4908-90FC-B79F2C0E22BB}
2012-04-25 13:35:13 ———— d——-w- C:\Users\Morgan\AppData\Local\{14B00204-4EA6-4FD9-8FD7-F029533FEB68}
2012-04-25 13:35:03 ———— d——-w- C:\Users\Morgan\AppData\Local\{ABFC0AEC-626B-4066-A127-4C29DC5B8F91}
2012-04-24 12:40:13 ———— d——-w- C:\Users\Morgan\AppData\Local\{D34B1909-AB39-4164-A3D6-D468B75DB694}
2012-04-24 12:40:02 ———— d——-w- C:\Users\Morgan\AppData\Local\{30C25BE4-732C-42AC-AF97-24B8815A6BCE}
2012-04-23 20:03:37 ———— d——-w- C:\Users\Morgan\AppData\Local\{3064A5FD-CEAA-4884-B373-B43B3ADCB1C3}
2012-04-23 20:03:27 ———— d——-w- C:\Users\Morgan\AppData\Local\{DDFCE79F-E413-433A-8A90-7FB0F3EAD784}
2012-04-23 19:33:23 ———— d——-w- C:\Users\Morgan\AppData\Local\{2A591349-DFED-4387-99A8-8A965C765A6A}
2012-04-23 19:33:13 ———— d——-w- C:\Users\Morgan\AppData\Local\{149CC3BA-AA5B-4AB3-B428-4BD7130526EC}
2012-04-23 12:26:49 ———— d——-w- C:\Users\Morgan\AppData\Local\{E17F8C0D-98E6-4E20-82F6-724B9E70BCB8}
2012-04-22 14:48:00 ———— d——-w- C:\Users\Morgan\AppData\Local\{3327175C-0858-49EF-ADF3-E8E76B22B961}
2012-04-22 14:47:50 ———— d——-w- C:\Users\Morgan\AppData\Local\{E67F253F-047A-41DB-ABB2-EF27343535BD}
2012-04-21 20:46:39 ———— d——-w- C:\Users\Morgan\AppData\Local\{9255D83E-EFB8-471A-8AF4-AFF83512DAC1}
2012-04-21 20:46:29 ———— d——-w- C:\Users\Morgan\AppData\Local\{CA81A84F-A671-457A-A33B-958303C5462A}
2012-04-21 16:36:40 ———— d——-w- C:\Users\Morgan\AppData\Local\{7B672AB9-595E-4BDE-A25B-A00EB5524531}
2012-04-21 13:11:42 ———— d——-w- C:\Users\Morgan\AppData\Local\{0135B4D7-B3CB-4055-9D1E-5B77149C5D7C}
2012-04-20 17:17:30 ———— d——-w- C:\Users\Morgan\AppData\Local\{2A7A90D5-8817-4CF3-9D8D-1130ED9C2439}
2012-04-20 17:17:20 ———— d——-w- C:\Users\Morgan\AppData\Local\{FECD9621-AFD9-42F3-A349-784865DEAA33}
2012-04-19 13:52:06 ———— d——-w- C:\Users\Morgan\AppData\Local\{A59DC8C5-C0D7-4552-8F90-C3C952138814}
2012-04-19 13:51:56 ———— d——-w- C:\Users\Morgan\AppData\Local\{F8E8CEF9-760B-44FC-8207-1BCB14353F4E}
2012-04-18 17:07:04 ———— d——-w- C:\Users\Morgan\AppData\Local\{D87EC0A5-357D-4E7D-87FA-F9C00E60D8CC}
2012-04-18 17:06:54 ———— d——-w- C:\Users\Morgan\AppData\Local\{8F5634E6-DA82-4759-92E5-959385203C50}
2012-04-16 20:37:30 ———— d——-w- C:\Users\Morgan\AppData\Local\{C5B22872-7F07-440B-83C8-780F21A97579}
2012-04-16 20:37:20 ———— d——-w- C:\Users\Morgan\AppData\Local\{CCFB83AC-BAE9-42D6-B376-A2519B113132}
2012-04-16 17:24:44 ———— d——-w- C:\Windows\da
2012-04-16 17:21:43 ———— d——-w- C:\Windows\pss
2012-04-16 17:21:03 89944 ——a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\4ca5e3e81cd1bf501\DSETUP.dll
2012-04-16 17:21:03 537432 ——a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\4ca5e3e81cd1bf501\DXSETUP.exe
2012-04-16 17:21:03 1801048 ——a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\4ca5e3e81cd1bf501\dsetup32.dll
2012-04-16 17:21:03 15712 ——a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\4cd0bcad1cd1bf502\MeshBetaRemover.exe
2012-04-16 17:19:38 ———— d——-w- C:\Users\Morgan\AppData\Local\{A780B0BF-B2E1-45D4-9B74-E117722F7636}
2012-04-16 17:19:28 ———— d——-w- C:\Users\Morgan\AppData\Local\{C9B0CDB2-72CB-49F7-8356-93A82A0C8889}
2012-04-14 14:28:12 ———— d——-w- C:\Users\Morgan\AppData\Local\{77EC8110-DDBF-4EDC-B4E0-0C58045A0692}
2012-04-13 19:00:05 8769696 ——a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
2012-04-13 18:02:24 ———— d——-w- C:\Users\Morgan\AppData\Local\{0B444B9F-2628-41FD-8745-01912A196914}
2012-04-12 16:17:27 ———— d——-w- C:\Program Files (x86)\Synthesoft
2012-04-12 16:17:26 446464 ——a-w- C:\Windows\SysWow64\PSYCH.SCR
2012-04-12 16:16:57 ———— d——-w- C:\Program Files (x86)\Psych
2012-04-12 16:16:30 49152 ——a-w- C:\Windows\DelCDSP.exe
2012-04-12 16:16:30 114688 ——a-w- C:\Windows\PKCRegD.exe
2012-04-12 16:16:25 ———— d——-w- C:\Program Files (x86)\CDSpectrum Pro
2012-04-12 16:13:58 60328 ——a-w- C:\Windows\Psych_Uninstall.exe
2012-04-12 12:38:19 ———— d——-w- C:\Users\Morgan\AppData\Local\{54F304BE-3F75-49B1-8B80-5E150FBE9884}
2012-04-11 19:44:27 81408 ——a-w- C:\Windows\System32\imagehlp.dll
2012-04-11 19:44:27 23408 ——a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-04-11 19:44:26 172544 ——a-w- C:\Windows\SysWow64\wintrust.dll
2012-04-11 19:44:26 159232 ——a-w- C:\Windows\SysWow64\imagehlp.dll
2012-04-11 19:44:25 5120 ——a-w- C:\Windows\SysWow64\wmi.dll
2012-04-11 19:44:25 5120 ——a-w- C:\Windows\System32\wmi.dll
2012-04-11 19:44:25 220672 ——a-w- C:\Windows\System32\wintrust.dll
2012-04-11 17:34:20 ———— d——-w- C:\Users\Morgan\AppData\Local\{421FC9BA-2B0C-4340-BB03-771DADDF3415}
2012-04-11 13:04:06 ———— d——-w- C:\Users\Morgan\AppData\Local\{D1C2F964-64A9-46FF-A174-83D2F30DCAED}
2012-04-10 18:51:22 ———— d——-w- C:\Users\Morgan\AppData\Roaming\PopSoft
2012-04-10 18:51:22 ———— d——-w- C:\ProgramData\PopSoft
2012-04-10 18:50:08 ———— d——-w- C:\Program Files (x86)\DMXControl
2012-04-10 12:42:43 ———— d——-w- C:\Users\Morgan\AppData\Local\{4EE3BB5E-03A2-4A03-9DCE-569498A73819}
2012-04-09 10:52:34 ———— d——-w- C:\Users\Morgan\AppData\Local\{F79A234D-4F02-4414-8B87-6178DD0317BC}
2012-04-08 08:41:54 ———— d——-w- C:\Users\Morgan\AppData\Local\{2FDF18A9-4957-411D-A9BD-259FC8E3FCFE}
2012-04-06 13:54:29 ———— d——-w- C:\Users\Morgan\AppData\Local\{0F04B131-0A59-4C69-B11C-F3D3FB370FF9}
.
==================== Find3M ====================
.
2012-05-05 08:45:01 525544 ——a-w- C:\Windows\System32\deployJava1.dll
2012-05-04 21:00:15 70304 ——a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-04 21:00:15 419488 ——a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-04-04 13:56:40 24904 ——a-w- C:\Windows\System32\drivers\mbam.sys
2012-04-02 18:58:08 283200 ——a-w- C:\Windows\System32\drivers\dtsoftbus01.sys
2012-03-20 18:44:12 98688 ——a-w- C:\Windows\System32\drivers\NisDrvWFP.sys
2012-03-20 18:44:12 203888 ——a-w- C:\Windows\System32\drivers\MpFilter.sys
2012-03-08 16:50:28 49016 ——a-w- C:\Windows\SysWow64\sirenacm.dll
2012-03-08 16:37:20 302448 ——a-w- C:\Windows\WLXPGSS.SCR
2012-03-06 06:53:37 5559152 ——a-w- C:\Windows\System32\ntoskrnl.exe
2012-03-06 05:59:47 3968368 ——a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-03-06 05:59:41 3913072 ——a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-02-28 06:56:48 2311168 ——a-w- C:\Windows\System32\jscript9.dll
2012-02-28 06:49:56 1390080 ——a-w- C:\Windows\System32\wininet.dll
2012-02-28 06:48:57 1493504 ——a-w- C:\Windows\System32\inetcpl.cpl
2012-02-28 06:42:55 2382848 ——a-w- C:\Windows\System32\mshtml.tlb
2012-02-28 01:18:55 1799168 ——a-w- C:\Windows\SysWow64\jscript9.dll
2012-02-28 01:11:21 1427456 ——a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-02-28 01:11:07 1127424 ——a-w- C:\Windows\SysWow64\wininet.dll
2012-02-28 01:03:16 2382848 ——a-w- C:\Windows\SysWow64\mshtml.tlb
2012-02-17 06:38:26 1031680 ——a-w- C:\Windows\System32\rdpcore.dll
2012-02-17 05:34:22 826880 ——a-w- C:\Windows\SysWow64\rdpcore.dll
2012-02-17 04:58:24 210944 ——a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-02-17 04:57:32 23552 ——a-w- C:\Windows\System32\drivers\tdtcp.sys
2012-02-10 06:36:07 1544192 ——a-w- C:\Windows\System32\DWrite.dll
2012-02-10 05:38:43 1077248 ——a-w- C:\Windows\SysWow64\DWrite.dll
.
============= FINISH: 10:48:25,77 ===============
Håber i kan hjælpe mig.
