ComboFix 08-12-04.04 - kinestig 2008-12-05 11:21:38.1 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1044.18.1159 [GMT 1:00] Kjører fra: c:\users\kinestig\Desktop\ComboFix.exe * Opprettet nytt gjenopprettingspunkt . ((((((((((((((((((((((((((((((((((((((( Andre slettinger ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\program files\GamesBar\oberontb.dll c:\windows\system32\bitcometres.dll . ((((((((((((((((((((((((((( Filer Opprettet Fra 2008-11-05 til 2008-12-05 ))))))))))))))))))))))))))))))))) . 2008-12-05 10:23 . 2008-12-05 10:23 d-------- c:\users\kinestig\AppData\Roaming\Malwarebytes 2008-12-05 10:23 . 2008-12-05 10:23 d-------- c:\programdata\Malwarebytes 2008-12-05 10:23 . 2008-12-05 10:23 d-------- c:\program files\Malwarebytes' Anti-Malware 2008-12-05 10:23 . 2008-12-03 19:52 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys 2008-12-05 10:23 . 2008-12-03 19:52 15,504 --a------ c:\windows\System32\drivers\mbam.sys 2008-12-05 00:10 . 2008-12-05 00:10 d-------- c:\program files\CCleaner 2008-12-04 19:53 . 2008-12-04 19:53 d-------- C:\PerfLogs 2008-11-26 08:08 . 2008-10-21 06:25 1,645,568 --a------ c:\windows\System32\connect.dll 2008-11-26 08:08 . 2008-08-28 04:40 712,704 --a------ c:\windows\System32\WindowsCodecs.dll 2008-11-26 08:08 . 2008-08-28 04:40 425,472 --a------ c:\windows\System32\PhotoMetadataHandler.dll 2008-11-26 08:08 . 2008-08-28 04:40 347,136 --a------ c:\windows\System32\WindowsCodecsExt.dll 2008-11-26 08:08 . 2008-10-22 04:57 241,152 --a------ c:\windows\System32\PortableDeviceApi.dll 2008-11-26 08:08 . 2008-01-19 08:36 160,768 --a------ c:\windows\System32\PortableDeviceTypes.dll 2008-11-26 08:08 . 2008-01-19 08:36 94,720 --a------ c:\windows\System32\PortableDeviceClassExtension.dll 2008-11-15 19:40 . 2008-10-16 22:13 1,809,944 --a------ c:\windows\System32\wuaueng.dll 2008-11-15 19:40 . 2008-10-16 21:56 1,524,736 --a------ c:\windows\System32\wucltux.dll 2008-11-15 19:40 . 2008-10-16 22:09 51,224 --a------ c:\windows\System32\wuauclt.exe 2008-11-15 19:40 . 2008-10-16 22:09 43,544 --a------ c:\windows\System32\wups2.dll 2008-11-15 19:39 . 2008-10-16 22:12 561,688 --a------ c:\windows\System32\wuapi.dll 2008-11-15 19:39 . 2008-10-16 14:08 162,064 --a------ c:\windows\System32\wuwebv.dll 2008-11-15 19:39 . 2008-10-16 21:55 83,456 --a------ c:\windows\System32\wudriver.dll 2008-11-15 19:39 . 2008-10-16 22:08 34,328 --a------ c:\windows\System32\wups.dll 2008-11-15 19:39 . 2008-10-16 13:56 31,232 --a------ c:\windows\System32\wuapp.exe 2008-11-13 07:15 . 2008-09-10 04:40 1,334,272 --a------ c:\windows\System32\msxml6.dll 2008-11-13 07:15 . 2008-09-05 06:14 1,191,936 --a------ c:\windows\System32\msxml3.dll 2008-11-13 07:15 . 2008-08-27 02:05 212,480 --a------ c:\windows\System32\drivers\mrxsmb10.sys 2008-11-12 21:12 . 2008-11-12 21:12 54,156 --ah----- c:\windows\QTFont.qfn 2008-11-12 21:12 . 2008-11-12 21:12 1,409 --a------ c:\windows\QTFont.for 2008-11-12 21:08 . 2008-11-12 21:08 d-------- c:\program files\Sony Setup 2008-11-12 19:35 . 2008-11-12 19:35 1,024 --a------ c:\windows\System32\gncontent.cch 2008-11-12 19:05 . 2008-11-12 19:05 d-------- c:\users\kinestig\AppData\Roaming\Sony 2008-11-12 19:05 . 2008-11-12 19:05 d-------- c:\programdata\Sony 2008-11-12 18:57 . 2008-11-12 18:57 d-------- c:\program files\Common Files\Sony Shared 2008-11-12 18:56 . 2008-11-12 18:56 d-------- c:\program files\Sony 2008-11-11 23:46 . 2008-11-11 23:46 d-------- c:\program files\Common Files\xing shared 2008-11-11 23:45 . 2008-11-11 23:45 d-------- c:\program files\Real 2008-11-11 23:19 . 2008-11-12 20:34 d-------- c:\users\kinestig\AppData\Roaming\Teleca 2008-11-11 23:14 . 2007-04-03 13:59 99,080 --a------ c:\windows\System32\drivers\s616unic.sys 2008-11-11 23:14 . 2007-04-03 13:59 11,016 --a------ c:\windows\System32\drivers\s616cr.sys 2008-11-11 23:13 . 2007-04-03 13:59 100,360 --a------ c:\windows\System32\drivers\s616mgmt.sys 2008-11-11 23:12 . 2007-04-03 13:59 98,568 --a------ c:\windows\System32\drivers\s616obex.sys 2008-11-11 23:11 . 2007-04-03 13:59 23,176 --a------ c:\windows\System32\drivers\s616nd5.sys 2008-11-11 23:10 . 2007-04-03 13:59 108,680 --a------ c:\windows\System32\drivers\s616mdm.sys 2008-11-11 23:10 . 2007-04-03 13:59 15,112 --a------ c:\windows\System32\drivers\s616mdfl.sys 2008-11-11 23:10 . 2007-04-03 13:59 12,424 --a------ c:\windows\System32\drivers\s616cmnt.sys 2008-11-11 23:10 . 2007-04-03 13:59 12,424 --a------ c:\windows\System32\drivers\s616cm.sys 2008-11-11 23:09 . 2007-04-03 13:59 83,208 --a------ c:\windows\System32\drivers\s616bus.sys 2008-11-11 23:09 . 2007-04-03 13:59 12,424 --a------ c:\windows\System32\drivers\s616whnt.sys 2008-11-11 23:09 . 2007-04-03 13:59 12,424 --a------ c:\windows\System32\drivers\s616wh.sys 2008-11-11 22:58 . 2007-04-23 15:54 100,488 --a------ c:\windows\System32\drivers\s115mgmt.sys 2008-11-11 22:57 . 2007-04-23 15:54 98,568 --a------ c:\windows\System32\drivers\s115obex.sys 2008-11-11 22:56 . 2007-04-23 15:54 108,680 --a------ c:\windows\System32\drivers\s115mdm.sys 2008-11-11 22:56 . 2007-04-23 15:54 15,112 --a------ c:\windows\System32\drivers\s115mdfl.sys 2008-11-11 22:56 . 2007-04-23 15:54 12,424 --a------ c:\windows\System32\drivers\s115cmnt.sys 2008-11-11 22:56 . 2007-04-23 15:54 12,424 --a------ c:\windows\System32\drivers\s115cm.sys 2008-11-11 22:55 . 2008-11-11 22:55 d-------- c:\users\kinestig\AppData\Roaming\Sony Ericsson 2008-11-11 22:55 . 2007-04-23 15:54 83,208 --a------ c:\windows\System32\drivers\s115bus.sys 2008-11-11 22:55 . 2007-04-23 15:54 12,424 --a------ c:\windows\System32\drivers\s115whnt.sys 2008-11-11 22:55 . 2007-04-23 15:54 12,424 --a------ c:\windows\System32\drivers\s115wh.sys 2008-11-11 22:54 . 2008-11-12 20:34 d-------- c:\program files\Sony Ericsson 2008-11-11 22:54 . 2008-11-12 20:34 d-------- c:\program files\Common Files\Teleca Shared 2008-11-09 10:33 . 2008-11-15 23:46 d-------- c:\programdata\GamesBar 2008-11-06 20:58 . 2008-11-06 20:58 d-------- c:\programdata\Sony Online Entertainment 2008-11-06 18:00 . 2008-11-09 10:50 d-a------ c:\programdata\TEMP 2008-11-06 18:00 . 2008-11-06 18:00 d-------- c:\programdata\Sandlot Games 2008-11-06 17:59 . 2008-12-05 11:22 d-------- c:\program files\GamesBar . (((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-04 20:53 --------- d-----w c:\program files\Common Files\Oberon Media 2008-12-04 20:53 --------- d-----w c:\program files\Acer GameZone 2008-12-04 20:50 --------- d-----w c:\programdata\Symantec 2008-12-04 20:50 --------- d-----w c:\program files\Common Files\Symantec Shared 2008-12-04 20:02 --------- d-----w c:\programdata\NVIDIA 2008-12-04 19:04 174 --sha-w c:\program files\desktop.ini 2008-12-04 18:56 --------- d-----w c:\program files\Windows Sidebar 2008-12-04 18:56 --------- d-----w c:\program files\Windows Photo Gallery 2008-12-04 18:56 --------- d-----w c:\program files\Windows Mail 2008-12-04 18:56 --------- d-----w c:\program files\Windows Defender 2008-12-04 18:56 --------- d-----w c:\program files\Windows Collaboration 2008-12-04 18:56 --------- d-----w c:\program files\Windows Calendar 2008-12-04 18:40 82,432 ----a-w c:\windows\System32\axaltocm.dll 2008-12-04 18:40 101,888 ----a-w c:\windows\System32\ifxcardm.dll 2008-12-04 09:53 --------- d-----w c:\program files\Full Tilt Poker 2008-11-30 05:36 --------- d-----w c:\users\kinestig\AppData\Roaming\LimeWire 2008-11-27 06:50 --------- d-----w c:\programdata\Microsoft Help 2008-11-13 20:16 28,124 ----a-w c:\users\kinestig\AppData\Roaming\nvModes.dat 2008-11-12 19:36 --------- d-----w c:\program files\PokerStars 2008-11-11 22:46 --------- d-----w c:\program files\Common Files\Real 2008-11-11 22:36 --------- d-----w c:\program files\BitComet 2008-10-15 07:10 --------- d--h--w c:\program files\InstallShield Installation Information 2008-10-13 17:36 --------- d-----w c:\users\kinestig\AppData\Roaming\vlc 2008-10-13 17:32 --------- d-----w c:\program files\VideoLAN 2008-10-11 08:52 --------- d-----w c:\program files\Google 2008-10-02 03:49 827,392 ----a-w c:\windows\System32\wininet.dll 2008-09-30 15:43 1,286,152 ----a-w c:\windows\System32\msxml4.dll 2008-09-18 05:09 3,601,464 ----a-w c:\windows\System32\ntkrnlpa.exe 2008-09-18 05:09 3,549,240 ----a-w c:\windows\System32\ntoskrnl.exe 2008-09-18 02:16 2,032,640 ----a-w c:\windows\System32\win32k.sys 2008-07-02 11:53 28,124 ----a-w c:\users\Kristian\AppData\Roaming\nvModes.dat 2008-06-17 20:19 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat 2008-06-17 20:19 32,768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat 2008-06-17 20:19 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat . (((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret ))))))))))))))))))))))))))))))))))))))))))))) . . *Merk* tomme oppføringer & gyldige standardoppføringer vises ikke REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920] "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-11 39408] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-03-21 486856] "CTZDetec.exe"="c:\program files\Creative\Creative Media Lite\CTZDetec.exe" [2007-12-18 401408] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-12-14 102400] "eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-04-25 457216] "eAudio"="c:\acer\Empowering Technology\eAudio\eAudio.exe" [2007-08-31 1286144] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-12-14 174616] "LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2007-12-14 707080] "PlayMovie"="c:\program files\Acer Arcade Deluxe\Play Movie\PMVService.exe" [2007-12-05 200704] "WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344] "PLFSet"="c:\windows\PLFSet.dll" [2007-04-25 45056] "Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-08-01 151552] "EverioService"="c:\program files\CyberLink\PCM4Everio\EverioService.exe" [2007-11-01 151552] "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 144784] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-03-28 413696] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-11-11 185872] "NvSvc"="c:\windows\system32\nvsvc.dll" [2007-12-14 86016] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-14 8501792] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-14 81920] "RtHDVCpl"="RtHDVCpl.exe" [2007-12-14 c:\windows\RtHDVCpl.exe] "Skytel"="Skytel.exe" [2007-12-14 c:\windows\SkyTel.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-08-01 151552] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2008-02-27 1216512] BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-03-29 719664] Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-12-22 535336] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UacDisableNotify"=dword:00000001 "InternetSettingsDisableNotify"=dword:00000001 "AutoUpdateDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{076EC745-F577-417A-9FAD-34F4387961C7}"= c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Acer Arcade Deluxe.exe:Acer Arcade Deluxe "{EE7C081D-4161-49B8-9C96-1E4960D5DFC1}"= c:\program files\Acer Arcade Deluxe\VideoMagician\VideoMagician.exe:VideoMagician "{AEAC0F7A-ED71-4430-A83B-218DBA12596D}"= c:\program files\Acer Arcade Deluxe\HomeMedia\HomeMedia.exe:HomeMedia "{BB5E7DE3-C0BE-4E97-99CA-E55AFAD63DBA}"= c:\program files\Acer Arcade Deluxe\DV Wizard\DV Wizard.exe:DV Wizard "{AB7579B6-2D46-4EC5-B27A-21B8D3DD542E}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{4AE25EAC-AE03-4218-B91C-BB46A722CCB6}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{D4AC5F0B-9304-4C5A-9B9B-D96933AEB60A}"= c:\program files\Acer Arcade Deluxe\DVDivine\DVDivine.exe:DVDivine "{B0675215-D538-4CA7-959A-E25A96760045}"= c:\program files\Acer Arcade Deluxe\Play Movie\PlayMovie.exe:Play Movie "{0213179B-7879-4297-8B06-F7FF7B2011A2}"= c:\program files\Acer Arcade Deluxe\Play Movie\PMVService.exe:Play Movie Resident Program "{5FD2D0D3-18D8-48A5-BB11-37A15B31726E}"= c:\program files\Acer\Acer VCM\VC.exe:Acer VCM "{668E8040-5500-45DC-80B2-86108B3101F5}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) "{40A5FDA6-2EE8-414C-B87C-57A912ABD449}"= c:\program files\CyberLink\PowerDirector Express\PDX.EXE:CyberLink PowerDirector Express "{44D17434-9B09-4AE0-90D6-4B4EB18AE299}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook "{1034533E-C479-40B2-9FCF-E42A95F00D72}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{1AE80AC3-2FD4-4699-B718-DF9498731F44}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{887C5E4E-FC84-4269-A9A6-4FC85C019EAB}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) "{161745C5-7D0C-4CDD-8B76-B630359BB10D}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire "{1F49363E-CBDE-452B-8E9D-5426B7445760}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire "{0F654946-63F7-4CCE-8A64-7E3DC68B409D}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe "TCP Query User{AC4296DB-346E-44B6-8791-152A1A6B6EB9}c:\\program files\\bitcomet\\bitcomet.exe"= UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client "UDP Query User{18EE58D8-B5EC-4351-B952-26C47374364E}c:\\program files\\bitcomet\\bitcomet.exe"= TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client "TCP Query User{F6C97E1B-FF8C-4AB8-9FF9-C7CBDAAFCD56}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire "UDP Query User{315FD070-2EA7-452C-9EFA-979964035F9D}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire "TCP Query User{5E480965-D3FF-4302-ADEA-1EFF05632644}c:\\program files\\bitcomet\\bitcomet.exe"= UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client "UDP Query User{7C158006-263B-4893-8530-65C18ACFA9E8}c:\\program files\\bitcomet\\bitcomet.exe"= TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client "{A5A0FBEF-C40B-4FAE-8EC0-7C953F428448}"= UDP:11102:BitComet 11102 TCP "{018E838E-9779-4174-B08E-A65F5518F9CD}"= TCP:11102:BitComet 11102 UDP R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-08-10 97928] R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};\??\c:\program files\Acer Arcade Deluxe\Play Movie\[u]0[/u]00.fcl [2008-02-27 21:12:34 41456] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-08-10 231704] R2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2008-02-27 233472] R3 winbondcir;Winbond IR Transceiver;c:\windows\system32\DRIVERS\winbondcir.sys [2007-12-22 43008] S3 A310;AVerMedia A310 DVB-T;c:\windows\system32\DRIVERS\AVerA310USB.sys [2007-12-22 26368] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2007-12-22 179712] S3 BDASwCap;AVerMedia A310 BDA DVBT Capture Device;c:\windows\system32\drivers\AVerA310Cap.sys [2007-12-22 42240] S3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\DRIVERS\s115bus.sys [2008-11-11 83208] S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s115mdfl.sys [2008-11-11 15112] S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s115mdm.sys [2008-11-11 108680] S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s115mgmt.sys [2008-11-11 100488] S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s115obex.sys [2008-11-11 98568] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3ac694a5-e4e0-11dc-a181-806e6f6e6963}] \shell\AutoRun\command - F:\start.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d647a40d-6a96-11dd-b342-8621bab8f78e}] \shell\AutoRun\command - I:\LaunchU3.exe -a . - - - - TOMME PEKERE FJERNET - - - - HKCU-RunOnce-Shockwave Updater - c:\windows\System32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1100465 -Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; GTB5; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET HKLM-Run-SetPanel - c:\acer\APanel\APanel.cmd HKLM-Run-Acer Tour - (no file) HKLM-Run-eRecoveryService - (no file) ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-05 11:24:56 Windows 6.0.6001 Service Pack 1 NTFS skanner skjulte prosesser ... skanner skjulte autostart-oppføringer ... skanner skjulte filer ... skanning vellykket skjulte filer: 0 ************************************************************************** . --------------------- DLL'er Lastet Av Kjørende Prosesser --------------------- - - - - - - - > 'winlogon.exe'(900) c:\windows\system32\avgrsstx.dll - - - - - - - > 'lsass.exe'(776) c:\windows\system32\avgrsstx.dll . Tidspunkt ferdig: 2008-12-05 11:26:17 ComboFix-quarantined-files.txt 2008-12-05 10:26:14 Pre-Run: 77 895 565 312 byte ledig Post-Run: 77,670,916,096 byte ledig 244 --- E O F --- 2008-12-04 18:43:02