ComboFix 09-10-16.09 - Tormod Kvalsvik 18.10.2009 1:26.1.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.47.1044.18.1023.483 [GMT 2:00] Kjører fra: d:\nedlasting\ComboFix.exe AV: CA Anti-Virus *On-access scanning disabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93} ADVARSEL -DENNE MASKINEN HAR IKKE GJENOPPRETTINGSKONSOLLEN INSTALLERT !! . ((((((((((((((((((((((((((( Filer Opprettet Fra 2009-09-17 til 2009-10-17 ))))))))))))))))))))))))))))))))) . 2009-10-17 23:09 . 2009-10-17 23:09 -------- d-----w- c:\documents and settings\Tormod Kvalsvik\Programdata\Malwarebytes 2009-10-17 23:09 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-10-17 23:09 . 2009-10-17 23:09 -------- d-----w- c:\programfiler\Malwarebytes' Anti-Malware 2009-10-17 23:09 . 2009-10-17 23:09 -------- d-----w- c:\documents and settings\All Users\Programdata\Malwarebytes 2009-10-17 23:09 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-10-16 16:30 . 2001-10-06 12:02 5632 ----a-w- c:\windows\system32\ptpusb.dll 2009-10-16 16:30 . 2008-04-14 16:22 159232 ----a-w- c:\windows\system32\ptpusd.dll 2009-10-15 20:46 . 2009-10-15 20:58 -------- d-----w- c:\documents and settings\Tormod Kvalsvik\Programdata\Apple Computer 2009-10-15 20:46 . 2009-05-18 12:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-10-15 20:46 . 2008-04-17 11:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll 2009-10-15 20:41 . 2009-10-16 16:33 -------- d-----w- c:\documents and settings\Tormod Kvalsvik\Lokale innstillinger\Programdata\Apple Computer 2009-10-14 15:05 . 2009-10-14 15:05 -------- d--h--w- c:\windows\PIF 2009-10-13 14:39 . 2009-10-15 19:18 -------- d-----w- c:\documents and settings\Anita Kjørlaug 2009-10-12 19:05 . 2009-10-15 14:03 -------- d-----w- c:\documents and settings\Tormod Kvalsvik\Lokale innstillinger\Programdata\Google 2009-10-12 16:24 . 2009-10-12 16:25 -------- d-----w- c:\programfiler\Fellesfiler\Adobe 2009-10-12 16:21 . 2009-10-12 16:21 -------- d-----w- c:\programfiler\Google 2009-10-12 16:21 . 2009-10-12 16:28 -------- d-----w- c:\documents and settings\Tormod Kvalsvik\Lokale innstillinger\Programdata\Adobe 2009-10-12 16:00 . 2009-10-12 16:00 -------- d-----w- c:\documents and settings\Tormod Kvalsvik\DoctorWeb 2009-10-11 16:22 . 2009-10-11 16:22 -------- d-----w- c:\documents and settings\All Users\Programdata\HP Product Assistant 2009-10-11 15:56 . 2009-10-11 15:56 -------- d-----w- c:\documents and settings\All Users\Programdata\Maxtor 2009-10-11 15:56 . 2009-10-11 15:56 44384 ----a-w- c:\windows\system32\drivers\tifsfilt.sys 2009-10-11 15:56 . 2009-10-11 15:56 441760 ----a-w- c:\windows\system32\drivers\timntr.sys 2009-10-11 15:56 . 2009-10-11 15:56 132224 ----a-w- c:\windows\system32\drivers\snapman.sys 2009-10-11 15:56 . 2009-10-11 15:56 368480 ----a-w- c:\windows\system32\drivers\tdrpman.sys 2009-10-11 15:55 . 2009-10-11 15:55 -------- d-----w- c:\programfiler\Fellesfiler\Maxtor 2009-10-11 15:55 . 2009-10-11 15:55 -------- d-----w- c:\programfiler\Maxtor 2009-10-11 09:51 . 2009-10-17 21:53 -------- d-----w- c:\documents and settings\Tormod Kvalsvik\Programdata\HpUpdate 2009-10-11 09:51 . 2009-10-11 09:51 -------- d-----w- c:\windows\Hewlett-Packard 2009-10-10 13:10 . 2008-10-16 12:06 268648 ----a-w- c:\windows\system32\mucltui.dll 2009-10-10 12:00 . 2009-10-10 12:00 -------- d-----w- c:\documents and settings\Tormod Kvalsvik\Programdata\Ahead 2009-10-10 07:35 . 2009-10-10 07:35 -------- d-----w- c:\windows\system32\LogFiles 2009-10-10 00:31 . 2009-10-10 00:31 -------- d-----w- c:\documents and settings\All Users\Programdata\SUPERAntiSpyware.com 2009-10-10 00:31 . 2009-10-10 00:31 -------- d-----w- c:\programfiler\SUPERAntiSpyware 2009-10-10 00:31 . 2009-10-10 00:31 -------- d-----w- c:\documents and settings\Tormod Kvalsvik\Programdata\SUPERAntiSpyware.com 2009-10-10 00:31 . 2009-10-10 00:31 -------- d-----w- c:\programfiler\Fellesfiler\Wise Installation Wizard 2009-10-10 00:09 . 2009-10-10 00:09 -------- d-----w- c:\programfiler\MSXML 4.0 2009-10-10 00:01 . 2009-10-10 00:01 -------- d-----w- c:\programfiler\Fellesfiler\Scanner 2009-10-09 23:58 . 2009-10-09 23:58 -------- d-sh--w- c:\documents and settings\Anders Kvalsvik\PrivacIE 2009-10-09 23:52 . 2009-10-13 14:43 739752 ----a-w- c:\windows\system32\drivers\vetefile.sys 2009-10-09 23:52 . 2009-10-13 14:43 133576 ----a-w- c:\windows\system32\drivers\veteboot.sys 2009-10-09 23:52 . 2009-10-09 23:54 91376 ----a-w- c:\windows\system32\isafprod.dll 2009-10-09 23:52 . 2009-10-09 23:54 26352 ----a-w- c:\windows\system32\drivers\vet-filt.sys 2009-10-09 23:52 . 2009-10-09 23:54 21488 ----a-w- c:\windows\system32\drivers\vetfddnt.sys 2009-10-09 23:52 . 2009-10-09 23:54 21104 ----a-w- c:\windows\system32\drivers\vet-rec.sys 2009-10-09 23:52 . 2009-10-09 23:54 161008 ----a-w- c:\windows\system32\drivers\vetmonnt.sys 2009-10-09 23:52 . 2008-03-10 23:46 83256 ----a-w- c:\windows\system32\vetredir.dll 2009-10-09 23:52 . 2008-03-10 23:46 99592 ----a-w- c:\windows\system32\isafeif.dll 2009-10-09 23:52 . 2009-10-10 00:04 -------- d-----w- c:\documents and settings\All Users\Programdata\CA 2009-10-09 23:52 . 2009-10-10 00:01 -------- d-----w- c:\programfiler\CA 2009-10-09 23:37 . 2009-10-09 23:37 -------- d-----w- c:\documents and settings\Tormod Kvalsvik\Lokale innstillinger\Programdata\Qurb4 2009-10-09 23:11 . 2000-06-26 09:45 106496 ----a-w- c:\windows\system32\TwnLib20.dll 2009-10-09 23:11 . 2001-06-26 06:15 38912 ----a-w- c:\windows\system32\picn20.dll 2009-10-09 23:11 . 2001-07-06 16:24 283920 ----a-w- c:\windows\system32\ImagXpr5.dll 2009-10-09 23:11 . 2001-07-06 12:41 569344 ----a-w- c:\windows\system32\imagr5.dll 2009-10-09 23:11 . 2001-07-06 10:44 544768 ----a-w- c:\windows\system32\imagx5.dll 2009-10-09 23:11 . 2009-10-09 23:11 -------- d-----w- c:\programfiler\Fellesfiler\Ahead 2009-10-09 23:11 . 2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe 2009-10-09 23:11 . 2009-10-09 23:11 -------- d-----w- c:\programfiler\Ahead 2009-10-09 22:54 . 2009-10-09 22:54 -------- d-----w- c:\documents and settings\Anders Kvalsvik\Lokale innstillinger\Programdata\Powercinema 2009-10-09 22:36 . 2009-10-09 22:36 -------- d-----w- c:\documents and settings\Tormod Kvalsvik\Programdata\CyberLink 2009-10-09 22:32 . 2009-10-09 22:32 28352 ----a-w- c:\windows\system32\drivers\MxlW2k.sys 2009-10-09 22:29 . 2009-10-09 22:31 -------- d-----w- c:\programfiler\Musicmatch 2009-10-09 22:23 . 2003-12-05 16:46 10368 ------w- c:\windows\system32\drivers\pfc.sys 2009-10-09 22:23 . 2009-10-09 22:44 -------- d-----w- c:\documents and settings\Tormod Kvalsvik\Lokale innstillinger\Programdata\Powercinema 2009-10-09 22:23 . 2009-10-09 22:23 -------- d-----w- c:\programfiler\X10 Hardware 2009-10-09 22:23 . 2009-10-09 22:23 -------- d-----w- c:\programfiler\Common Files 2009-10-09 22:23 . 2002-01-05 01:37 344064 ----a-w- c:\windows\system32\msvcr70.dll 2009-10-09 22:23 . 1999-06-25 07:56 127184 ----a-w- c:\windows\Unwise.exe 2009-10-09 22:22 . 2009-10-09 22:22 -------- d-----w- c:\documents and settings\All Users\Programdata\CyberLink 2009-10-09 22:22 . 2009-10-09 22:22 -------- d-----w- c:\programfiler\CyberLink 2009-10-09 22:22 . 2009-10-09 22:23 -------- d-----w- c:\programfiler\Home Cinema 2009-10-09 22:20 . 2009-10-09 22:29 -------- d--h--w- c:\programfiler\InstallShield Installation Information 2009-10-09 22:20 . 2009-10-09 22:20 -------- d-----w- c:\programfiler\Logitech 2009-10-09 22:20 . 2009-10-09 22:22 -------- d-----w- c:\programfiler\Fellesfiler\InstallShield 2009-10-09 22:15 . 2009-10-09 22:15 -------- d-----w- c:\programfiler\Fellesfiler\Nero 2009-10-09 22:15 . 2009-10-09 22:15 -------- d-----w- c:\programfiler\Nero 2009-10-09 22:12 . 2009-10-11 10:16 -------- d-----w- c:\programfiler\AskTBar 2009-10-09 21:59 . 2009-10-09 21:59 -------- d-----w- c:\documents and settings\Anders Kvalsvik\Programdata\HP 2009-10-09 21:54 . 2009-10-09 21:55 -------- d-----w- c:\documents and settings\Tormod Kvalsvik\Programdata\GetRightToGo 2009-10-09 21:42 . 2009-10-16 14:33 -------- d-----w- c:\documents and settings\Tormod Kvalsvik\Programdata\ImgBurn 2009-10-09 21:42 . 2009-10-09 21:42 -------- d-----w- c:\programfiler\ImgBurn 2009-10-09 21:35 . 2009-10-09 21:39 8 ----a-w- c:\windows\system32\nvModes.dat 2009-10-09 21:32 . 2009-10-09 21:32 -------- d-----w- c:\documents and settings\Tormod Kvalsvik\Programdata\.BitTornado 2009-10-09 21:31 . 2009-10-09 21:31 -------- d-----w- c:\programfiler\BitTornado 2009-10-09 20:17 . 2009-10-09 20:17 -------- d-----w- c:\documents and settings\Tormod Kvalsvik\Programdata\HP 2009-10-09 20:17 . 2009-10-09 20:17 -------- d-----w- c:\documents and settings\All Users\Programdata\HP 2009-10-09 20:15 . 2009-10-09 20:16 -------- d-----w- c:\programfiler\Fellesfiler\HP 2009-10-09 20:13 . 2009-10-09 20:14 -------- d-----w- c:\programfiler\Hewlett-Packard 2009-10-09 20:13 . 2009-10-09 20:13 -------- d-----w- c:\documents and settings\Tormod Kvalsvik\Programdata\Skype 2009-10-09 20:13 . 2009-10-09 20:13 -------- d-----w- c:\programfiler\Fellesfiler\Hewlett-Packard 2009-10-09 20:12 . 2006-04-12 10:04 16496 ----a-r- c:\windows\system32\drivers\HPZipr12.sys 2009-10-09 20:12 . 2006-04-12 10:04 49664 ----a-r- c:\windows\system32\drivers\HPZid412.sys 2009-10-09 20:12 . 2009-10-09 20:12 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache 2009-10-09 20:12 . 2006-01-03 17:12 77824 ----a-r- c:\windows\system32\HPZIDS01.dll 2009-10-09 20:12 . 2006-04-10 12:03 48128 ----a-w- c:\windows\system32\hpzll054.dll 2009-10-09 20:11 . 2008-04-13 18:45 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys 2009-10-09 20:11 . 2008-04-13 18:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys 2009-10-09 20:11 . 2007-08-09 07:27 73728 ----a-w- c:\windows\system32\HPZipm12.exe 2009-10-09 20:11 . 2006-03-03 19:03 282680 ----a-w- c:\windows\system32\HPZidr12.dll 2009-10-09 20:11 . 2006-03-03 19:03 65536 ----a-w- c:\windows\system32\HPZinw12.exe 2009-10-09 20:11 . 2006-03-03 19:02 204800 ----a-w- c:\windows\system32\HPZipr12.dll 2009-10-09 20:11 . 2006-03-03 19:02 94208 ----a-w- c:\windows\system32\HPZipt12.dll 2009-10-09 20:11 . 2006-03-03 19:02 57344 ----a-w- c:\windows\system32\HPZisn12.dll 2009-10-09 20:11 . 1998-10-29 14:45 306688 ----a-w- c:\windows\IsUninst.exe 2009-10-09 20:09 . 2009-10-11 09:52 -------- d-----w- c:\programfiler\HP 2009-10-09 20:09 . 2009-10-09 20:17 118807 ----a-w- c:\windows\hpoins11.dat 2009-10-09 20:08 . 2009-10-09 22:48 18240 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT 2009-10-09 20:08 . 2008-04-13 18:47 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys 2009-10-09 20:08 . 2008-04-13 18:47 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys 2009-10-09 20:04 . 2009-10-09 20:05 -------- d-----w- c:\programfiler\Canon 2009-10-09 20:04 . 2009-10-09 20:04 -------- d-----w- c:\programfiler\Fellesfiler\Canon 2009-10-09 20:03 . 2009-10-09 20:04 -------- d-----w- c:\documents and settings\All Users\Programdata\QuickTime 2009-10-09 19:59 . 2009-10-09 19:59 -------- d-sh--w- c:\documents and settings\Tormod Kvalsvik\PrivacIE 2009-10-09 19:55 . 2009-10-09 19:55 -------- d-sh--w- c:\documents and settings\Tormod Kvalsvik\IETldCache 2009-10-09 19:53 . 2009-08-07 08:48 100352 -c----w- c:\windows\system32\dllcache\iecompat.dll 2009-10-09 19:53 . 2009-10-09 19:53 -------- d-----w- c:\windows\ie8updates 2009-10-09 19:53 . 2009-08-29 08:00 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll 2009-10-09 19:53 . 2009-08-29 08:00 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll 2009-10-09 19:53 . 2009-08-29 08:00 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll 2009-10-09 19:53 . 2009-08-29 08:00 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll 2009-10-09 19:53 . 2009-08-29 08:00 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll 2009-10-09 19:53 . 2009-08-29 08:00 11069440 -c----w- c:\windows\system32\dllcache\ieframe.dll 2009-10-09 19:51 . 2009-10-09 19:52 -------- dc-h--w- c:\windows\ie8 2009-10-09 18:54 . 2008-06-14 17:36 272256 -c----w- c:\windows\system32\dllcache\bthport.sys 2009-10-09 18:53 . 2009-06-21 21:49 153088 -c----w- c:\windows\system32\dllcache\triedit.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-10-15 20:49 . 2009-10-15 20:41 -------- d-----w- c:\documents and settings\All Users\Programdata\Apple 2009-10-15 20:46 . 2009-10-15 20:45 -------- d-----w- c:\programfiler\iTunes 2009-10-15 20:46 . 2009-10-15 20:45 -------- d-----w- c:\documents and settings\All Users\Programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2009-10-15 20:45 . 2009-10-15 20:45 -------- d-----w- c:\programfiler\iPod 2009-10-15 20:45 . 2009-10-15 20:41 -------- d-----w- c:\programfiler\Fellesfiler\Apple 2009-10-15 20:45 . 2009-10-15 20:44 -------- d-----w- c:\documents and settings\All Users\Programdata\Apple Computer 2009-10-15 20:44 . 2009-10-15 20:44 -------- d-----w- c:\programfiler\Bonjour 2009-10-15 20:44 . 2009-10-15 20:44 -------- d-----w- c:\programfiler\QuickTime 2009-10-15 20:42 . 2009-10-15 20:42 -------- d-----w- c:\programfiler\Apple Software Update 2009-10-09 20:00 . 2003-04-25 12:00 47118 ----a-w- c:\windows\system32\perfc014.dat 2009-10-09 20:00 . 2003-04-25 12:00 321302 ----a-w- c:\windows\system32\perfh014.dat 2009-10-09 17:34 . 2009-10-09 17:34 -------- d-----w- c:\documents and settings\All Users\Programdata\NVIDIA Corporation 2009-10-09 17:34 . 2009-10-09 17:33 -------- d-----w- c:\programfiler\NVIDIA Corporation 2009-10-09 17:14 . 2009-10-09 17:14 13104 ----a-r- c:\documents and settings\Tormod Kvalsvik\Lokale innstillinger\Programdata\GDIPFONTCACHEV1.DAT 2009-10-09 16:14 . 2009-10-09 16:14 -------- d-----w- c:\programfiler\microsoft frontpage 2009-10-09 16:13 . 2009-10-09 16:11 -------- d-----w- c:\programfiler\Elektroniske tjenester 2009-10-09 16:12 . 2009-10-09 16:12 -------- d-----w- c:\programfiler\Fellesfiler\Tjenester 2009-10-09 16:11 . 2009-10-09 16:11 21704 ----a-w- c:\windows\system32\emptyregdb.dat 2009-09-27 16:19 . 2009-09-27 16:19 3674112 ----a-w- c:\windows\system32\nvwssr.dll 2009-09-27 14:12 . 2009-10-09 17:08 7655872 ----a-w- c:\windows\system32\drivers\nv4_mini.sys 2009-09-27 14:12 . 2009-10-09 17:08 5900416 ----a-w- c:\windows\system32\nv4_disp.dll 2009-09-27 14:12 . 2009-09-27 14:12 888832 ----a-w- c:\windows\system32\nvapi.dll 2009-09-27 14:12 . 2009-09-27 14:12 2194024 ----a-w- c:\windows\system32\nvcuvid.dll 2009-09-27 14:12 . 2009-09-27 14:12 2007040 ----a-w- c:\windows\system32\nvcuda.dll 2009-09-27 14:12 . 2009-09-27 14:12 1714792 ----a-w- c:\windows\system32\nvcuvenc.dll 2009-09-27 14:12 . 2009-09-27 14:12 170600 ----a-w- c:\windows\system32\nvcodins.dll 2009-09-27 14:12 . 2009-09-27 14:12 170600 ----a-w- c:\windows\system32\nvcod.dll 2009-09-27 14:12 . 2009-09-27 14:12 1604482 ----a-w- c:\windows\system32\nvdata.bin 2009-09-27 14:12 . 2009-09-27 14:12 10756096 ----a-w- c:\windows\system32\nvoglnt.dll 2009-09-11 14:20 . 2003-04-25 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll 2009-09-04 21:05 . 2003-04-25 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll 2009-08-29 08:00 . 2003-04-25 12:00 916480 ----a-w- c:\windows\system32\wininet.dll 2009-08-28 17:42 . 2009-10-15 20:42 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys 2009-08-28 17:42 . 2009-10-15 20:42 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll 2009-08-26 08:02 . 2003-04-25 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll 2009-08-05 09:01 . 2003-04-25 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll 2009-08-04 21:00 . 2003-04-25 12:00 2190976 ----a-w- c:\windows\system32\ntoskrnl.exe 2009-08-04 17:52 . 2009-08-04 17:52 1193832 ----a-w- c:\windows\system32\FM20.DLL 2009-08-04 17:30 . 2002-09-09 14:07 2067840 ----a-w- c:\windows\system32\ntkrnlpa.exe 2009-07-29 04:38 . 2003-04-25 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll 2009-07-29 04:38 . 2003-04-25 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll . (((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret ))))))))))))))))))))))))))))))))))))))))))))) . . *Merk* tomme oppføringer & gyldige standardoppføringer vises ikke REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{9CB65206-89C4-402c-BA80-02D8C59F9B1D}"= "c:\programfiler\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL" [2009-10-09 57344] [HKEY_CLASSES_ROOT\clsid\{9cb65206-89c4-402c-ba80-02d8c59f9b1d}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSMSGS"="c:\programfiler\Messenger\msmsgs.exe" [2008-04-14 1695232] "SUPERAntiSpyware"="c:\programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-09-15 1998576] "swg"="c:\programfiler\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-10-12 39408] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208] "QuickTime Task"="c:\programfiler\QuickTime\QTTask.exe" [2009-09-04 417792] "HP Software Update"="c:\programfiler\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576] "PCMService"="c:\programfiler\Home Cinema\PowerCinema\PCMService.exe" [2004-10-08 81920] "MMTray"="c:\programfiler\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2004-08-29 131072] "mmtask"="c:\programfiler\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2004-08-29 53248] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "cctray"="c:\programfiler\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-10-09 181488] "CAVRID"="c:\programfiler\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2009-10-09 230640] "CaPPcl"="c:\programfiler\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe" [2008-08-27 472304] "MaxBlastMonitor.exe"="c:\programfiler\Maxtor\MaxBlast\MaxBlastMonitor.exe" [2008-06-27 1325800] "AcronisTimounterMonitor"="c:\programfiler\Maxtor\MaxBlast\TimounterMonitor.exe" [2008-06-27 904776] "Maxtor Scheduler2 Service"="c:\programfiler\Fellesfiler\Maxtor\Schedule2\schedhlp.exe" [2008-06-27 136472] "Adobe Reader Speed Launcher"="c:\programfiler\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "iTunesHelper"="c:\programfiler\iTunes\iTunesHelper.exe" [2009-09-21 305440] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360] c:\documents and settings\All Users\Start-meny\Programmer\Oppstart\ HP Digital Imaging Monitor.lnk - c:\programfiler\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472] Logitech Music Anywhere Settings.lnk - c:\programfiler\Logitech\Music Anywhere\LMASysTray.exe [2009-10-10 184320] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\programfiler\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 13:21 548352 ----a-w- c:\programfiler\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Programfiler\\BitTornado\\btdownloadgui.exe"= "c:\\Programfiler\\CA\\CA Internet Security Suite\\CA Anti-Spyware\\CAAntiSpyware.exe"= "c:\\WINDOWS\\system32\\mmc.exe"= "c:\\Programfiler\\Bonjour\\mDNSResponder.exe"= "c:\\Programfiler\\iTunes\\iTunes.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R1 SASDIFSV;SASDIFSV;c:\programfiler\SUPERAntiSpyware\sasdifsv.sys [15.09.2009 11:42 9968] R1 SASKUTIL;SASKUTIL;c:\programfiler\SUPERAntiSpyware\SASKUTIL.SYS [15.09.2009 11:42 74480] R2 MaxSch2Svc;Maxtor Scheduler2 Service;c:\programfiler\Fellesfiler\Maxtor\Schedule2\schedul2.exe [27.06.2008 17:03 431384] R3 PhTVTune;MEDION TV-TUNER 7134 MK2/3;c:\windows\system32\drivers\PhTVTune.sys [09.10.2009 18:29 24704] R3 PPCtlPriv;PPCtlPriv;c:\programfiler\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [10.10.2009 02:01 185584] R3 PRISM_A00;CREATIX 802.11g Driver;c:\windows\system32\drivers\PRISMA00.sys [09.10.2009 18:27 380736] R3 SASENUM;SASENUM;c:\programfiler\SUPERAntiSpyware\SASENUM.SYS [15.09.2009 11:42 7408] S3 USBAAPL;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl.sys [15.10.2009 22:42 40448] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Innholdet i mappen 'Scheduled Tasks' (planlagte oppgaver) 2009-10-15 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\programfiler\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34] 2009-10-11 c:\windows\Tasks\CAAntiSpywareScan_Daily as Anders Kvalsvik at 02 01.job - c:\programfiler\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe [2009-10-10 16:44] . . ------- Tilleggsskanning ------- . uInternet Connection Wizard,ShellNext = hxxp://www.my-etrust.com/Redirect/router.aspx?OEM=&prod=SL&app=inclient&lang=en&date=1255105322&link_id=1&dest=Install_Buy_Link_PA&lic=LELCC-ECMXZ-C4W4X-IW4LM&ver=4.0.0.185 uInternet Settings,ProxyOverride = *.local IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 LSP: c:\windows\system32\VetRedir.dll . - - - - TOMME PEKERE FJERNET - - - - HKLM-Run-nwiz - c:\programfiler\NVIDIA Corporation\nView\nwiz.exe HKLM-Run-Cmaudio - cmicnfg.cpl HKLM-Run-NWEReboot - (no file) AddRemove-NVIDIA nView Desktop Manager - c:\programfiler\NVIDIA Corporation\nView\nViewSetup.exe AddRemove-{6B103F43-069C-11D6-9EA2-0050BAE317E1} - c:\programfiler\Uninstall_PCM.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-18 01:29 Windows 5.1.2600 Service Pack 3 NTFS skanner skjulte prosesser ... skanner skjulte autostart-oppføringer ... skanner skjulte filer ... skanning vellykket skjulte filer: 0 ************************************************************************** . --------------------- DLL'er Lastet Av Kjørende Prosesser --------------------- - - - - - - - > 'winlogon.exe'(1752) c:\programfiler\SUPERAntiSpyware\SASWINLO.dll c:\programfiler\CA\SharedComponents\PPRT\bin\CACheck.dll c:\programfiler\CA\SharedComponents\PPRT\bin\CAHook.dll c:\programfiler\CA\SharedComponents\PPRT\bin\CAServer.dll - - - - - - - > 'lsass.exe'(2008) c:\windows\system32\relog_ap.dll - - - - - - - > 'explorer.exe'(392) c:\programfiler\CA\SharedComponents\PPRT\bin\CACheck.dll c:\programfiler\CA\SharedComponents\PPRT\bin\CAHook.dll c:\programfiler\CA\SharedComponents\PPRT\bin\CAServer.dll c:\programfiler\CyberLink\Shared Files\CLRCEngine.dll c:\windows\system32\webcheck.dll . Tidspunkt ferdig: 2009-10-17 1:30 ComboFix-quarantined-files.txt 2009-10-17 23:30 Pre-Run: 59 165 687 808 byte ledig Post-Run: 60 070 707 200 byte ledig 290 --- E O F --- 2009-10-14 19:38