ComboFix 08-12-04.04 - kinestig 2008-12-05 11:21:38.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1044.18.1159 [GMT 1:00]
Kjører fra: c:\users\kinestig\Desktop\ComboFix.exe
* Opprettet nytt gjenopprettingspunkt
.
((((((((((((((((((((((((((((((((((((((( Andre slettinger )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\GamesBar\oberontb.dll
c:\windows\system32\bitcometres.dll
.
((((((((((((((((((((((((((( Filer Opprettet Fra 2008-11-05 til 2008-12-05 )))))))))))))))))))))))))))))))))
.
2008-12-05 10:23 . 2008-12-05 10:23
d-------- c:\users\kinestig\AppData\Roaming\Malwarebytes
2008-12-05 10:23 . 2008-12-05 10:23 d-------- c:\programdata\Malwarebytes
2008-12-05 10:23 . 2008-12-05 10:23 d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-05 10:23 . 2008-12-03 19:52 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2008-12-05 10:23 . 2008-12-03 19:52 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2008-12-05 00:10 . 2008-12-05 00:10 d-------- c:\program files\CCleaner
2008-12-04 19:53 . 2008-12-04 19:53 d-------- C:\PerfLogs
2008-11-26 08:08 . 2008-10-21 06:25 1,645,568 --a------ c:\windows\System32\connect.dll
2008-11-26 08:08 . 2008-08-28 04:40 712,704 --a------ c:\windows\System32\WindowsCodecs.dll
2008-11-26 08:08 . 2008-08-28 04:40 425,472 --a------ c:\windows\System32\PhotoMetadataHandler.dll
2008-11-26 08:08 . 2008-08-28 04:40 347,136 --a------ c:\windows\System32\WindowsCodecsExt.dll
2008-11-26 08:08 . 2008-10-22 04:57 241,152 --a------ c:\windows\System32\PortableDeviceApi.dll
2008-11-26 08:08 . 2008-01-19 08:36 160,768 --a------ c:\windows\System32\PortableDeviceTypes.dll
2008-11-26 08:08 . 2008-01-19 08:36 94,720 --a------ c:\windows\System32\PortableDeviceClassExtension.dll
2008-11-15 19:40 . 2008-10-16 22:13 1,809,944 --a------ c:\windows\System32\wuaueng.dll
2008-11-15 19:40 . 2008-10-16 21:56 1,524,736 --a------ c:\windows\System32\wucltux.dll
2008-11-15 19:40 . 2008-10-16 22:09 51,224 --a------ c:\windows\System32\wuauclt.exe
2008-11-15 19:40 . 2008-10-16 22:09 43,544 --a------ c:\windows\System32\wups2.dll
2008-11-15 19:39 . 2008-10-16 22:12 561,688 --a------ c:\windows\System32\wuapi.dll
2008-11-15 19:39 . 2008-10-16 14:08 162,064 --a------ c:\windows\System32\wuwebv.dll
2008-11-15 19:39 . 2008-10-16 21:55 83,456 --a------ c:\windows\System32\wudriver.dll
2008-11-15 19:39 . 2008-10-16 22:08 34,328 --a------ c:\windows\System32\wups.dll
2008-11-15 19:39 . 2008-10-16 13:56 31,232 --a------ c:\windows\System32\wuapp.exe
2008-11-13 07:15 . 2008-09-10 04:40 1,334,272 --a------ c:\windows\System32\msxml6.dll
2008-11-13 07:15 . 2008-09-05 06:14 1,191,936 --a------ c:\windows\System32\msxml3.dll
2008-11-13 07:15 . 2008-08-27 02:05 212,480 --a------ c:\windows\System32\drivers\mrxsmb10.sys
2008-11-12 21:12 . 2008-11-12 21:12 54,156 --ah----- c:\windows\QTFont.qfn
2008-11-12 21:12 . 2008-11-12 21:12 1,409 --a------ c:\windows\QTFont.for
2008-11-12 21:08 . 2008-11-12 21:08 d-------- c:\program files\Sony Setup
2008-11-12 19:35 . 2008-11-12 19:35 1,024 --a------ c:\windows\System32\gncontent.cch
2008-11-12 19:05 . 2008-11-12 19:05 d-------- c:\users\kinestig\AppData\Roaming\Sony
2008-11-12 19:05 . 2008-11-12 19:05 d-------- c:\programdata\Sony
2008-11-12 18:57 . 2008-11-12 18:57 d-------- c:\program files\Common Files\Sony Shared
2008-11-12 18:56 . 2008-11-12 18:56 d-------- c:\program files\Sony
2008-11-11 23:46 . 2008-11-11 23:46 d-------- c:\program files\Common Files\xing shared
2008-11-11 23:45 . 2008-11-11 23:45 d-------- c:\program files\Real
2008-11-11 23:19 . 2008-11-12 20:34 d-------- c:\users\kinestig\AppData\Roaming\Teleca
2008-11-11 23:14 . 2007-04-03 13:59 99,080 --a------ c:\windows\System32\drivers\s616unic.sys
2008-11-11 23:14 . 2007-04-03 13:59 11,016 --a------ c:\windows\System32\drivers\s616cr.sys
2008-11-11 23:13 . 2007-04-03 13:59 100,360 --a------ c:\windows\System32\drivers\s616mgmt.sys
2008-11-11 23:12 . 2007-04-03 13:59 98,568 --a------ c:\windows\System32\drivers\s616obex.sys
2008-11-11 23:11 . 2007-04-03 13:59 23,176 --a------ c:\windows\System32\drivers\s616nd5.sys
2008-11-11 23:10 . 2007-04-03 13:59 108,680 --a------ c:\windows\System32\drivers\s616mdm.sys
2008-11-11 23:10 . 2007-04-03 13:59 15,112 --a------ c:\windows\System32\drivers\s616mdfl.sys
2008-11-11 23:10 . 2007-04-03 13:59 12,424 --a------ c:\windows\System32\drivers\s616cmnt.sys
2008-11-11 23:10 . 2007-04-03 13:59 12,424 --a------ c:\windows\System32\drivers\s616cm.sys
2008-11-11 23:09 . 2007-04-03 13:59 83,208 --a------ c:\windows\System32\drivers\s616bus.sys
2008-11-11 23:09 . 2007-04-03 13:59 12,424 --a------ c:\windows\System32\drivers\s616whnt.sys
2008-11-11 23:09 . 2007-04-03 13:59 12,424 --a------ c:\windows\System32\drivers\s616wh.sys
2008-11-11 22:58 . 2007-04-23 15:54 100,488 --a------ c:\windows\System32\drivers\s115mgmt.sys
2008-11-11 22:57 . 2007-04-23 15:54 98,568 --a------ c:\windows\System32\drivers\s115obex.sys
2008-11-11 22:56 . 2007-04-23 15:54 108,680 --a------ c:\windows\System32\drivers\s115mdm.sys
2008-11-11 22:56 . 2007-04-23 15:54 15,112 --a------ c:\windows\System32\drivers\s115mdfl.sys
2008-11-11 22:56 . 2007-04-23 15:54 12,424 --a------ c:\windows\System32\drivers\s115cmnt.sys
2008-11-11 22:56 . 2007-04-23 15:54 12,424 --a------ c:\windows\System32\drivers\s115cm.sys
2008-11-11 22:55 . 2008-11-11 22:55 d-------- c:\users\kinestig\AppData\Roaming\Sony Ericsson
2008-11-11 22:55 . 2007-04-23 15:54 83,208 --a------ c:\windows\System32\drivers\s115bus.sys
2008-11-11 22:55 . 2007-04-23 15:54 12,424 --a------ c:\windows\System32\drivers\s115whnt.sys
2008-11-11 22:55 . 2007-04-23 15:54 12,424 --a------ c:\windows\System32\drivers\s115wh.sys
2008-11-11 22:54 . 2008-11-12 20:34 d-------- c:\program files\Sony Ericsson
2008-11-11 22:54 . 2008-11-12 20:34 d-------- c:\program files\Common Files\Teleca Shared
2008-11-09 10:33 . 2008-11-15 23:46 d-------- c:\programdata\GamesBar
2008-11-06 20:58 . 2008-11-06 20:58 d-------- c:\programdata\Sony Online Entertainment
2008-11-06 18:00 . 2008-11-09 10:50 d-a------ c:\programdata\TEMP
2008-11-06 18:00 . 2008-11-06 18:00 d-------- c:\programdata\Sandlot Games
2008-11-06 17:59 . 2008-12-05 11:22 d-------- c:\program files\GamesBar
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-04 20:53 --------- d-----w c:\program files\Common Files\Oberon Media
2008-12-04 20:53 --------- d-----w c:\program files\Acer GameZone
2008-12-04 20:50 --------- d-----w c:\programdata\Symantec
2008-12-04 20:50 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-12-04 20:02 --------- d-----w c:\programdata\NVIDIA
2008-12-04 19:04 174 --sha-w c:\program files\desktop.ini
2008-12-04 18:56 --------- d-----w c:\program files\Windows Sidebar
2008-12-04 18:56 --------- d-----w c:\program files\Windows Photo Gallery
2008-12-04 18:56 --------- d-----w c:\program files\Windows Mail
2008-12-04 18:56 --------- d-----w c:\program files\Windows Defender
2008-12-04 18:56 --------- d-----w c:\program files\Windows Collaboration
2008-12-04 18:56 --------- d-----w c:\program files\Windows Calendar
2008-12-04 18:40 82,432 ----a-w c:\windows\System32\axaltocm.dll
2008-12-04 18:40 101,888 ----a-w c:\windows\System32\ifxcardm.dll
2008-12-04 09:53 --------- d-----w c:\program files\Full Tilt Poker
2008-11-30 05:36 --------- d-----w c:\users\kinestig\AppData\Roaming\LimeWire
2008-11-27 06:50 --------- d-----w c:\programdata\Microsoft Help
2008-11-13 20:16 28,124 ----a-w c:\users\kinestig\AppData\Roaming\nvModes.dat
2008-11-12 19:36 --------- d-----w c:\program files\PokerStars
2008-11-11 22:46 --------- d-----w c:\program files\Common Files\Real
2008-11-11 22:36 --------- d-----w c:\program files\BitComet
2008-10-15 07:10 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-13 17:36 --------- d-----w c:\users\kinestig\AppData\Roaming\vlc
2008-10-13 17:32 --------- d-----w c:\program files\VideoLAN
2008-10-11 08:52 --------- d-----w c:\program files\Google
2008-10-02 03:49 827,392 ----a-w c:\windows\System32\wininet.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\System32\msxml4.dll
2008-09-18 05:09 3,601,464 ----a-w c:\windows\System32\ntkrnlpa.exe
2008-09-18 05:09 3,549,240 ----a-w c:\windows\System32\ntoskrnl.exe
2008-09-18 02:16 2,032,640 ----a-w c:\windows\System32\win32k.sys
2008-07-02 11:53 28,124 ----a-w c:\users\Kristian\AppData\Roaming\nvModes.dat
2008-06-17 20:19 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-06-17 20:19 32,768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-06-17 20:19 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
(((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Merk* tomme oppføringer & gyldige standardoppføringer vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-11 39408]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-03-21 486856]
"CTZDetec.exe"="c:\program files\Creative\Creative Media Lite\CTZDetec.exe" [2007-12-18 401408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-12-14 102400]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-04-25 457216]
"eAudio"="c:\acer\Empowering Technology\eAudio\eAudio.exe" [2007-08-31 1286144]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-12-14 174616]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2007-12-14 707080]
"PlayMovie"="c:\program files\Acer Arcade Deluxe\Play Movie\PMVService.exe" [2007-12-05 200704]
"WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
"PLFSet"="c:\windows\PLFSet.dll" [2007-04-25 45056]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-08-01 151552]
"EverioService"="c:\program files\CyberLink\PCM4Everio\EverioService.exe" [2007-11-01 151552]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 144784]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-03-28 413696]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-11-11 185872]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-12-14 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-14 8501792]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-14 81920]
"RtHDVCpl"="RtHDVCpl.exe" [2007-12-14 c:\windows\RtHDVCpl.exe]
"Skytel"="Skytel.exe" [2007-12-14 c:\windows\SkyTel.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-08-01 151552]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2008-02-27 1216512]
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-03-29 719664]
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-12-22 535336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{076EC745-F577-417A-9FAD-34F4387961C7}"= c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Acer Arcade Deluxe.exe:Acer Arcade Deluxe
"{EE7C081D-4161-49B8-9C96-1E4960D5DFC1}"= c:\program files\Acer Arcade Deluxe\VideoMagician\VideoMagician.exe:VideoMagician
"{AEAC0F7A-ED71-4430-A83B-218DBA12596D}"= c:\program files\Acer Arcade Deluxe\HomeMedia\HomeMedia.exe:HomeMedia
"{BB5E7DE3-C0BE-4E97-99CA-E55AFAD63DBA}"= c:\program files\Acer Arcade Deluxe\DV Wizard\DV Wizard.exe:DV Wizard
"{AB7579B6-2D46-4EC5-B27A-21B8D3DD542E}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4AE25EAC-AE03-4218-B91C-BB46A722CCB6}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{D4AC5F0B-9304-4C5A-9B9B-D96933AEB60A}"= c:\program files\Acer Arcade Deluxe\DVDivine\DVDivine.exe:DVDivine
"{B0675215-D538-4CA7-959A-E25A96760045}"= c:\program files\Acer Arcade Deluxe\Play Movie\PlayMovie.exe:Play Movie
"{0213179B-7879-4297-8B06-F7FF7B2011A2}"= c:\program files\Acer Arcade Deluxe\Play Movie\PMVService.exe:Play Movie Resident Program
"{5FD2D0D3-18D8-48A5-BB11-37A15B31726E}"= c:\program files\Acer\Acer VCM\VC.exe:Acer VCM
"{668E8040-5500-45DC-80B2-86108B3101F5}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{40A5FDA6-2EE8-414C-B87C-57A912ABD449}"= c:\program files\CyberLink\PowerDirector Express\PDX.EXE:CyberLink PowerDirector Express
"{44D17434-9B09-4AE0-90D6-4B4EB18AE299}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{1034533E-C479-40B2-9FCF-E42A95F00D72}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{1AE80AC3-2FD4-4699-B718-DF9498731F44}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{887C5E4E-FC84-4269-A9A6-4FC85C019EAB}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{161745C5-7D0C-4CDD-8B76-B630359BB10D}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{1F49363E-CBDE-452B-8E9D-5426B7445760}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{0F654946-63F7-4CCE-8A64-7E3DC68B409D}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"TCP Query User{AC4296DB-346E-44B6-8791-152A1A6B6EB9}c:\\program files\\bitcomet\\bitcomet.exe"= UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{18EE58D8-B5EC-4351-B952-26C47374364E}c:\\program files\\bitcomet\\bitcomet.exe"= TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"TCP Query User{F6C97E1B-FF8C-4AB8-9FF9-C7CBDAAFCD56}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{315FD070-2EA7-452C-9EFA-979964035F9D}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{5E480965-D3FF-4302-ADEA-1EFF05632644}c:\\program files\\bitcomet\\bitcomet.exe"= UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{7C158006-263B-4893-8530-65C18ACFA9E8}c:\\program files\\bitcomet\\bitcomet.exe"= TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"{A5A0FBEF-C40B-4FAE-8EC0-7C953F428448}"= UDP:11102:BitComet 11102 TCP
"{018E838E-9779-4174-B08E-A65F5518F9CD}"= TCP:11102:BitComet 11102 UDP
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-08-10 97928]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};\??\c:\program files\Acer Arcade Deluxe\Play Movie\[u]0[/u]00.fcl [2008-02-27 21:12:34 41456]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-08-10 231704]
R2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2008-02-27 233472]
R3 winbondcir;Winbond IR Transceiver;c:\windows\system32\DRIVERS\winbondcir.sys [2007-12-22 43008]
S3 A310;AVerMedia A310 DVB-T;c:\windows\system32\DRIVERS\AVerA310USB.sys [2007-12-22 26368]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2007-12-22 179712]
S3 BDASwCap;AVerMedia A310 BDA DVBT Capture Device;c:\windows\system32\drivers\AVerA310Cap.sys [2007-12-22 42240]
S3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\DRIVERS\s115bus.sys [2008-11-11 83208]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s115mdfl.sys [2008-11-11 15112]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s115mdm.sys [2008-11-11 108680]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s115mgmt.sys [2008-11-11 100488]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s115obex.sys [2008-11-11 98568]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3ac694a5-e4e0-11dc-a181-806e6f6e6963}]
\shell\AutoRun\command - F:\start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d647a40d-6a96-11dd-b342-8621bab8f78e}]
\shell\AutoRun\command - I:\LaunchU3.exe -a
.
- - - - TOMME PEKERE FJERNET - - - -
HKCU-RunOnce-Shockwave Updater - c:\windows\System32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1100465 -Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; GTB5; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET
HKLM-Run-SetPanel - c:\acer\APanel\APanel.cmd
HKLM-Run-Acer Tour - (no file)
HKLM-Run-eRecoveryService - (no file)
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-05 11:24:56
Windows 6.0.6001 Service Pack 1 NTFS
skanner skjulte prosesser ...
skanner skjulte autostart-oppføringer ...
skanner skjulte filer ...
skanning vellykket
skjulte filer: 0
**************************************************************************
.
--------------------- DLL'er Lastet Av Kjørende Prosesser ---------------------
- - - - - - - > 'winlogon.exe'(900)
c:\windows\system32\avgrsstx.dll
- - - - - - - > 'lsass.exe'(776)
c:\windows\system32\avgrsstx.dll
.
Tidspunkt ferdig: 2008-12-05 11:26:17
ComboFix-quarantined-files.txt 2008-12-05 10:26:14
Pre-Run: 77 895 565 312 byte ledig
Post-Run: 77,670,916,096 byte ledig
244 --- E O F --- 2008-12-04 18:43:02