Trojaner - Dropper.Generic_c.MMI
Windows 7 Home PremiumSystemtype: 64-bit operativsystem
Jeg har - ligesom flere andre - problemer med den trojanske hest, der angriber c:\Windows\System32\services.exe
Nogen, der kan hjælpe? Tal gerne til mig, som om jeg er seks år gammel - jeg er lidt ude på dybt vand, når det handler om at rode med systemfiler og logs.
Jeg har kørt OTL med følgende i boksen "Custom Scans/Fixes":
%systemroot%\*. /rp /s
%systemroot%\*. /mp /s
Med følgende resultat (OTL genererede ingen "Extras"-log):
OTL logfile created on: 7/23/2012 2:39:04 PM - Run 3
OTL by OldTimer - Version Folder = C:\Users\RasmusJette\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Danmark | Language: DAN | Date Format: dd-MM-yyyy
8.00 Gb Total Physical Memory | 5.84 Gb Available Physical Memory | 73.00% Memory free
16.00 Gb Paging File | 13.84 Gb Available in Paging File | 86.54% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 1384.54 Gb Total Space | 636.20 Gb Free Space | 45.95% Space Free | Partition Type: NTFS
Drive D: | 12.63 Gb Total Space | 1.54 Gb Free Space | 12.17% Space Free | Partition Type: NTFS
Computer Name: RASMUSJETTE-HP | User Name: RasmusJette | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== LOP Check ==========
[2011/09/01 23:45:40 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\Alawar Stargaze
[2011/11/27 01:15:48 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\Artifex Mundi
[2010/12/11 20:12:09 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\AVG
[2011/10/25 22:24:29 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\AVG2012
[2012/01/04 17:27:33 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\Awem
[2011/07/13 14:08:33 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\Boolat Games
[2011/10/26 22:59:38 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\Casual Box
[2011/12/12 00:44:49 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\casualArts
[2011/07/17 23:57:34 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\CattaleGames
[2010/11/12 19:49:06 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\Cryptomathic
[2011/10/20 11:48:23 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\DailyMagic
[2010/10/26 00:00:07 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\dBpoweramp
[2011/12/22 00:17:31 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\Deep Shadows
[2011/12/13 23:44:59 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\GameInvest
[2011/02/21 23:12:19 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\GetRightToGo
[2011/12/28 23:53:48 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\HitPoint Studios
[2011/12/03 00:50:26 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\Hive Cluster
[2010/10/18 17:26:15 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\ICAClient
[2011/12/05 00:16:34 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\PlayFavoriteGames
[2011/12/05 00:08:12 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\Rovio
[2011/12/28 23:53:12 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\Samsung
[2010/10/30 00:10:24 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\Scholastic
[2011/11/03 01:03:24 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\SpinTop Games
[2012/05/04 22:37:39 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\Spotify
[2012/05/04 22:43:20 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\uTorrent
[2011/07/19 22:41:55 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\VampireSagaHL
[2012/01/07 00:10:21 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppData\Roaming\Vso
[2010/10/18 23:56:42 | 000,000,000 | ---D | M] -- C:\Users\RasmusJette\AppD