ComboFix 10-02-11.04 - Nyrud 12.02.2010 9:23.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.47.1044.18.3326.1271 [GMT 1:00] Kjører fra: c:\users\Nyrud\Desktop\ComboFix.exe AV: avast! antivirus 4.8.1368 [VPS 100114-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B} SP: avast! antivirus 4.8.1368 [VPS 100114-1] *enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} SP: COMODO Defense+ *enabled* (Updated) {043803A4-4F86-4ef7-AFC5-F6E02A79969B} SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Andre slettinger ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500 c:\windows\system32\gatherWirelessInfo.vbs . ((((((((((((((((((((((((((( Filer Opprettet Fra 2010-01-12 til 2010-02-12 ))))))))))))))))))))))))))))))))) . 2010-02-10 07:40 . 2009-12-11 11:43 302080 ----a-w- c:\windows\system32\drivers\srv.sys 2010-02-10 07:40 . 2009-12-11 11:43 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys 2010-02-10 07:39 . 2009-12-08 20:01 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe 2010-02-10 07:39 . 2009-12-08 20:01 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe 2010-02-06 23:42 . 2010-02-11 22:50 -------- d-----w- c:\users\Nyrud\AppData\Roaming\vlc 2010-02-02 09:54 . 2010-02-02 09:54 -------- d-----w- c:\program files\Common Files\Adobe 2010-02-02 09:52 . 2010-02-02 09:55 -------- d-----w- c:\users\Nyrud\AppData\Local\Adobe 2010-01-29 08:07 . 2010-01-29 08:07 -------- d-----w- c:\users\Nyrud\AppData\Local\PunkBuster 2010-01-29 08:06 . 2010-02-11 19:04 139128 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys 2010-01-29 08:06 . 2010-01-29 08:06 138056 ----a-w- c:\users\Nyrud\AppData\Roaming\PnkBstrK.sys 2010-01-29 08:06 . 2010-02-11 19:04 215128 ----a-w- c:\windows\system32\PnkBstrB.exe 2010-01-29 08:06 . 2010-01-29 08:06 75064 ----a-w- c:\windows\system32\PnkBstrA.exe 2010-01-29 08:06 . 2010-01-29 08:06 2434856 ----a-w- c:\windows\system32\pbsvc_bc2.exe 2010-01-23 16:12 . 2010-01-23 16:12 -------- d-----w- c:\users\Nyrud\AppData\Roaming\RenPy 2010-01-15 14:39 . 2010-01-15 14:39 -------- d-----w- c:\program files\Paint.NET 2010-01-15 14:38 . 2010-02-06 23:21 -------- d-----w- c:\users\Nyrud\AppData\Local\Paint.NET 2010-01-14 21:45 . 2009-07-30 15:48 705536 ----a-w- c:\windows\system32\cohelper.dll 2010-01-14 21:16 . 2010-02-05 11:03 -------- d-----w- c:\program files\SystemRequirementsLab 2010-01-14 21:16 . 2010-02-05 11:03 -------- d-----w- c:\users\Nyrud\SystemRequirementsLab 2010-01-14 20:46 . 2010-01-14 20:46 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys 2010-01-14 20:46 . 2010-01-23 17:27 -------- d-----w- c:\users\Nyrud\AppData\Local\eSupport.com 2010-01-14 18:13 . 2010-01-14 18:13 -------- d-----w- c:\users\Nyrud\AppData\Roaming\Malwarebytes 2010-01-14 18:12 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-14 18:12 . 2010-01-14 18:12 -------- d-----w- c:\programdata\Malwarebytes 2010-01-14 18:12 . 2010-01-14 18:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-01-14 18:12 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-01-14 17:57 . 2010-01-14 17:57 -------- d-----w- c:\program files\Lavalys 2010-01-14 14:55 . 2010-01-14 14:55 1 ----a-w- c:\users\Nyrud\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys 2010-01-14 14:54 . 2010-01-14 14:54 -------- d-----w- c:\users\Nyrud\AppData\Roaming\OpenOffice.org 2010-01-14 14:53 . 2010-01-14 14:53 -------- d-----w- c:\program files\JRE 2010-01-14 14:53 . 2010-01-14 14:53 -------- d-----w- c:\program files\OpenOffice.org 3 2010-01-14 14:52 . 2009-10-11 03:17 411368 ----a-w- c:\windows\system32\deploytk.dll 2010-01-14 14:51 . 2010-01-14 17:46 -------- d-----w- c:\program files\Java 2010-01-14 14:42 . 2006-10-18 19:12 12664 ----a-r- c:\windows\system32\drivers\AsIO.sys 2010-01-14 14:42 . 2006-01-10 08:50 24576 ----a-r- c:\windows\system32\AsIO.dll 2010-01-14 14:42 . 2010-01-14 14:49 -------- d-----w- c:\program files\ASUS 2010-01-14 14:25 . 2010-01-14 14:25 -------- d-----w- c:\program files\Windows Portable Devices 2010-01-14 14:25 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll 2010-01-14 14:25 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll 2010-01-14 14:25 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll 2010-01-14 14:23 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll 2010-01-14 14:23 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll 2010-01-14 14:23 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll 2010-01-14 14:11 . 2010-01-14 14:11 -------- d-----w- c:\windows\system32\RTCOM 2010-01-14 14:11 . 2010-01-14 14:11 319456 ----a-w- c:\windows\DIFxAPI.dll 2010-01-14 14:11 . 2007-10-11 03:04 1826816 ----a-w- c:\windows\SkyTel.exe 2010-01-14 14:11 . 2007-07-25 01:33 135168 ----a-w- c:\windows\system32\SRSWOW.dll 2010-01-14 14:11 . 2006-12-13 02:30 339968 ----a-w- c:\windows\system32\SRSTSXT.dll 2010-01-14 14:11 . 2007-07-26 10:06 1191936 ----a-w- c:\windows\RtlUpd.exe 2010-01-14 14:11 . 2007-05-17 03:26 185776 ----a-w- c:\windows\system32\SRSTSHD.dll 2010-01-14 14:11 . 2007-04-16 09:09 167936 ----a-w- c:\windows\system32\SRSHP360.dll 2010-01-14 14:11 . 2007-10-29 07:29 27136 ----a-w- c:\windows\system32\RtkCoInst.dll 2010-01-14 14:11 . 2007-10-24 11:50 2101248 ----a-w- c:\windows\system32\RtkAPO.dll 2010-01-14 14:11 . 2007-10-17 07:27 582656 ----a-w- c:\windows\system32\RtkPgExt.dll 2010-01-14 14:11 . 2007-03-23 07:34 266240 ----a-w- c:\windows\system32\RtkApoApi.dll 2010-01-14 14:10 . 2007-10-31 04:35 4702208 ----a-w- c:\windows\RtHDVCpl.exe 2010-01-14 14:10 . 2007-11-01 06:29 2011224 ----a-w- c:\windows\system32\drivers\RTKVHDA.sys 2010-01-14 14:10 . 2007-07-30 10:26 126976 ----a-w- c:\windows\system32\maxxaudioapo.dll 2010-01-14 14:10 . 2010-01-14 14:10 -------- d-----w- c:\program files\Realtek 2010-01-14 14:10 . 2010-01-14 21:49 -------- d--h--w- c:\program files\InstallShield Installation Information 2010-01-14 14:10 . 2007-07-26 09:09 520192 ------r- c:\windows\RtlExUpd.dll 2010-01-14 13:47 . 2010-01-14 13:47 -------- d-----w- c:\program files\uTorrent 2010-01-14 13:33 . 2010-01-14 13:34 -------- d-----w- c:\windows\system32\ca-ES 2010-01-14 13:33 . 2010-01-14 13:34 -------- d-----w- c:\windows\system32\eu-ES 2010-01-14 13:33 . 2010-01-14 13:34 -------- d-----w- c:\windows\system32\vi-VN 2010-01-14 13:25 . 2010-01-14 13:25 -------- d-----w- c:\windows\system32\EventProviders 2010-01-14 13:23 . 2009-04-11 05:03 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll 2010-01-14 13:21 . 2009-04-11 06:28 29184 ----a-w- c:\windows\system32\wsepno.dll 2010-01-14 13:20 . 2009-04-11 06:28 155136 ----a-w- c:\windows\system32\rasmontr.dll 2010-01-14 12:44 . 2008-05-27 04:59 18904 ----a-w- c:\windows\system32\StructuredQuerySchemaTrivial.bin 2010-01-14 12:24 . 2010-01-14 12:24 -------- d-----w- C:\PerfLogs 2010-01-14 12:07 . 2008-01-19 07:29 705536 ----a-w- c:\windows\system32\imagesp1.dll 2010-01-14 12:05 . 2008-01-19 07:36 75776 ----a-w- c:\windows\system32\synceng.dll 2010-01-14 12:04 . 2008-01-19 07:36 80896 ----a-w- c:\windows\system32\wbem\WMIPICMP.dll 2010-01-14 12:03 . 2008-01-19 07:36 357888 ----a-w- c:\windows\system32\wbemcomn.dll 2010-01-14 12:03 . 2008-01-19 07:34 102400 ----a-w- c:\windows\system32\wbem\mofinstall.dll 2010-01-14 12:02 . 2008-01-19 07:36 129536 ----a-w- c:\windows\system32\sqmapi.dll 2010-01-14 12:02 . 2008-01-19 07:36 139264 ----a-w- c:\windows\system32\SmiInstaller.dll 2010-01-14 12:00 . 2008-01-19 07:35 35328 ----a-w- c:\windows\system32\mspatcha.dll 2010-01-14 12:00 . 2008-01-19 07:34 305152 ----a-w- c:\windows\system32\msdelta.dll 2010-01-14 12:00 . 2008-01-19 07:34 258560 ----a-w- c:\windows\system32\dpx.dll 2010-01-14 10:48 . 2007-08-09 03:03 353280 ----a-w- c:\windows\system32\idecoiins.dll 2010-01-14 10:48 . 2007-08-09 03:03 353280 ----a-w- c:\windows\system32\idecoi.dll 2010-01-14 10:48 . 2007-10-12 08:01 3276 ----a-r- c:\windows\system32\drivers\nvphy.bin 2010-01-14 10:47 . 2007-10-12 08:14 199680 ----a-w- c:\windows\system32\fdco1.dll 2010-01-14 10:46 . 2010-01-14 10:46 -------- d-----w- c:\users\Nyrud\AppData\Roaming\InstallShield 2010-01-14 10:45 . 2010-01-14 10:45 315392 ----a-w- c:\windows\HideWin.exe 2010-01-14 10:44 . 2006-10-18 05:44 7680 ----a-w- c:\windows\system32\drivers\ASACPI.sys 2010-01-14 10:44 . 2007-08-01 03:39 12536 ----a-w- c:\windows\system32\drivers\ASUSHWIO.SYS 2010-01-14 10:25 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll 2010-01-14 10:07 . 2009-06-15 14:52 499712 ----a-w- c:\windows\system32\kerberos.dll 2010-01-14 10:07 . 2009-06-15 14:53 270848 ----a-w- c:\windows\system32\schannel.dll 2010-01-14 09:55 . 2010-01-14 09:55 -------- d-----w- c:\program files\AGEIA Technologies 2010-01-14 09:55 . 2010-01-14 09:55 -------- d-----w- c:\windows\system32\AGEIA 2010-01-14 09:54 . 2010-01-14 21:49 -------- d-----w- c:\program files\NVIDIA Corporation 2010-01-14 09:53 . 2009-11-21 02:34 76392 ----a-w- c:\windows\system32\OpenCL.dll 2010-01-14 09:53 . 2009-11-21 02:34 11515752 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys 2010-01-14 09:53 . 2009-11-21 02:34 9333352 ----a-w- c:\windows\system32\nvd3dum.dll 2010-01-14 09:53 . 2009-11-21 02:34 4241000 ----a-w- c:\windows\system32\nvwgf2um.dll 2010-01-14 09:53 . 2009-11-21 02:34 14064232 ----a-w- c:\windows\system32\nvoglv32.dll 2010-01-14 09:53 . 2009-11-21 02:34 4001384 ----a-w- c:\windows\system32\nvcuda.dll 2010-01-14 09:53 . 2009-11-21 02:34 2243176 ----a-w- c:\windows\system32\nvcuvid.dll 2010-01-14 09:53 . 2009-11-21 02:34 1989224 ----a-w- c:\windows\system32\nvcuvenc.dll 2010-01-14 09:53 . 2009-11-21 02:34 182888 ----a-w- c:\windows\system32\nvcod178.dll 2010-01-14 09:53 . 2009-11-21 02:34 182888 ----a-w- c:\windows\system32\nvcod.dll 2010-01-14 09:53 . 2009-11-21 02:34 11381352 ----a-w- c:\windows\system32\nvcompiler.dll 2010-01-14 09:53 . 2010-01-14 21:37 -------- d-----w- C:\NVIDIA 2010-01-14 09:16 . 2010-02-11 22:48 -------- d-----w- c:\users\Nyrud\AppData\Roaming\dvdcss 2010-01-14 08:16 . 2010-01-14 08:16 -------- d-----w- c:\windows\system32\Macromed 2010-01-14 07:42 . 2010-02-10 20:35 -------- d-----w- c:\users\Nyrud\Tracing 2010-01-14 07:41 . 2010-01-14 07:41 -------- d-----w- c:\program files\Microsoft 2010-01-14 07:41 . 2010-01-14 07:41 -------- d-----w- c:\program files\Windows Live SkyDrive 2010-01-14 07:41 . 2010-01-14 07:41 -------- d-----w- c:\program files\Windows Live 2010-01-14 07:40 . 2010-01-14 07:40 -------- d-----w- c:\windows\PCHEALTH 2010-01-14 07:38 . 2010-01-14 07:38 -------- d-----w- c:\program files\Common Files\Windows Live 2010-01-13 21:44 . 2010-02-11 22:52 -------- d-----w- c:\users\Nyrud\AppData\Local\Spotify 2010-01-13 21:44 . 2010-02-11 19:59 -------- d-----w- c:\users\Nyrud\AppData\Roaming\Spotify 2010-01-13 21:44 . 2010-01-13 21:44 -------- d-----w- c:\program files\Spotify 2010-01-13 21:39 . 2010-02-06 15:15 -------- d-----w- c:\program files\Common Files\Steam 2010-01-13 21:38 . 2010-02-11 19:04 -------- d-----w- c:\program files\Steam 2010-01-13 21:27 . 2010-02-12 07:47 -------- d-----w- c:\users\Nyrud\AppData\Roaming\uTorrent 2010-01-13 21:26 . 2010-01-13 21:26 -------- d-----w- c:\program files\VideoLAN 2010-01-13 21:12 . 2010-01-13 21:12 -------- d-----w- c:\program files\CCleaner 2010-01-13 21:10 . 2010-01-13 21:10 52224 ----a-w- c:\users\Nyrud\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll 2010-01-13 21:10 . 2010-02-08 07:39 117760 ----a-w- c:\users\Nyrud\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL . (((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-02-12 07:39 . 2006-11-21 05:16 76272 ----a-w- c:\windows\system32\perfc014.dat 2010-02-12 07:39 . 2006-11-21 05:16 452096 ----a-w- c:\windows\system32\perfh014.dat 2010-02-12 07:32 . 2010-01-14 10:01 34895 ----a-w- c:\programdata\nvModes.dat 2010-02-10 07:43 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail 2010-01-18 20:55 . 2010-01-18 20:55 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf 2010-01-14 14:57 . 2010-01-13 18:16 52776 ----a-w- c:\users\Nyrud\AppData\Local\GDIPFONTCACHEV1.DAT 2010-01-14 14:25 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat 2010-01-14 14:25 . 2010-01-14 14:25 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf 2010-01-14 13:34 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar 2010-01-14 13:34 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar 2010-01-14 13:34 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery 2010-01-14 13:34 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal 2010-01-14 13:34 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration 2010-01-14 13:34 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender 2010-01-14 13:32 . 2010-01-14 13:32 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf 2010-01-14 12:17 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll 2010-01-14 12:17 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll 2010-01-13 19:42 . 2010-01-13 19:42 2560 ----a-w- c:\windows\AppPatch\AcRes.dll 2010-01-13 19:42 . 2010-01-13 19:42 542720 ----a-w- c:\windows\AppPatch\AcLayers.dll 2010-01-13 19:42 . 2010-01-13 19:42 458752 ----a-w- c:\windows\AppPatch\AcSpecfc.dll 2010-01-13 19:42 . 2010-01-13 19:42 2159616 ----a-w- c:\windows\AppPatch\AcGenral.dll 2010-01-13 19:42 . 2010-01-13 19:42 173056 ----a-w- c:\windows\AppPatch\AcXtrnal.dll 2010-01-13 18:16 . 2010-01-13 18:16 680 ----a-w- c:\users\Nyrud\AppData\Local\d3d9caps.dat 2010-01-13 18:16 . 2010-01-13 18:16 53472 ----a-w- c:\windows\system32\wuauclt.exe 2010-01-13 18:16 . 2010-01-13 18:16 44768 ----a-w- c:\windows\system32\wups2.dll 2010-01-13 18:16 . 2010-01-13 18:16 2421760 ----a-w- c:\windows\system32\wucltux.dll 2010-01-13 18:16 . 2010-01-13 18:16 1929952 ----a-w- c:\windows\system32\wuaueng.dll 2010-01-13 18:14 . 2010-01-13 18:14 33792 ----a-w- c:\windows\system32\wuapp.exe 2010-01-13 18:14 . 2010-01-13 18:14 171608 ----a-w- c:\windows\system32\wuwebv.dll 2010-01-13 18:14 . 2010-01-13 18:14 -------- d-sh--we c:\programdata\Start-meny 2010-01-13 18:14 . 2010-01-13 18:14 -------- d-sh--we c:\programdata\Skrivebord 2010-01-13 18:14 . 2010-01-13 18:14 -------- d-sh--we c:\programdata\Programdata 2010-01-13 18:14 . 2010-01-13 18:14 -------- d-sh--we c:\programdata\Maler 2010-01-13 18:14 . 2010-01-13 18:14 -------- d-sh--we c:\programdata\Favoritter 2010-01-13 18:14 . 2010-01-13 18:14 -------- d-sh--we c:\programdata\Dokumenter 2010-01-13 18:14 . 2010-01-13 18:14 -------- d-sh--we c:\program files\Fellesfiler 2010-01-02 06:38 . 2010-01-22 16:07 916480 ----a-w- c:\windows\system32\wininet.dll 2010-01-02 06:32 . 2010-01-22 16:07 109056 ----a-w- c:\windows\system32\iesysprep.dll 2010-01-02 06:32 . 2010-01-22 16:07 71680 ----a-w- c:\windows\system32\iesetup.dll 2010-01-02 04:57 . 2010-01-22 16:07 133632 ----a-w- c:\windows\system32\ieUnatt.exe 2009-12-08 20:01 . 2010-02-10 07:38 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys 2009-12-08 17:26 . 2010-02-10 07:38 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys 2009-12-04 18:30 . 2010-02-10 07:38 12288 ----a-w- c:\windows\system32\tsbyuv.dll 2009-12-04 18:29 . 2010-02-10 07:38 1314816 ----a-w- c:\windows\system32\quartz.dll 2009-12-04 18:28 . 2010-02-10 07:38 22528 ----a-w- c:\windows\system32\msyuv.dll 2009-12-04 18:28 . 2010-02-10 07:38 31744 ----a-w- c:\windows\system32\msvidc32.dll 2009-12-04 18:28 . 2010-02-10 07:38 123904 ----a-w- c:\windows\system32\msvfw32.dll 2009-12-04 18:28 . 2010-02-10 07:38 13312 ----a-w- c:\windows\system32\msrle32.dll 2009-12-04 18:28 . 2010-02-10 07:38 82944 ----a-w- c:\windows\system32\mciavi32.dll 2009-12-04 18:28 . 2010-02-10 07:38 50176 ----a-w- c:\windows\system32\iyuv_32.dll 2009-12-04 18:27 . 2010-02-10 07:38 91136 ----a-w- c:\windows\system32\avifil32.dll 2009-12-04 15:56 . 2010-02-10 07:38 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys 2009-12-04 15:56 . 2010-02-10 07:38 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2009-11-21 02:34 . 2008-02-28 05:34 1249896 ----a-w- c:\windows\system32\nvapi.dll 2009-11-20 19:33 . 2009-11-20 19:33 812648 ----a-w- c:\windows\system32\nvsvc.dll 2009-11-20 19:33 . 2009-11-20 19:33 66664 ----a-w- c:\windows\system32\nvshext.dll 2009-11-20 19:33 . 2009-11-20 19:33 12685928 ----a-w- c:\windows\system32\nvcpl.dll 2009-11-20 19:33 . 2009-11-20 19:33 122984 ----a-w- c:\windows\system32\nvvsvc.exe 2009-11-20 19:33 . 2009-11-20 19:33 110184 ----a-w- c:\windows\system32\nvmctray.dll . (((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret ))))))))))))))))))))))))))))))))))))))))))))) . . *Merk* tomme oppføringer & gyldige standardoppføringer vises ikke REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-01-05 2002160] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184] "Launch LgDeviceAgent"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2009-08-13 357384] "Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2009-08-13 1573384] "Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2009-08-13 3161608] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000] "RtHDVCpl"="RtHDVCpl.exe" [2007-10-31 4702208] "Skytel"="Skytel.exe" [2007-10-11 1826816] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280] "COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-01-29 1800464] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 13:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\guard32.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "VistaSp2"=hex(b):24,99,b5,0f,1f,95,ca,01 R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [13.01.2010 20:12 114768] R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\System32\drivers\cmdguard.sys [13.01.2010 19:32 130960] R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\System32\drivers\cmdhlp.sys [13.01.2010 19:32 29520] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [05.01.2010 07:56 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [05.01.2010 07:56 74480] R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [13.01.2010 20:12 20560] R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [13.01.2010 20:12 53328] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [20.11.2009 19:17 240232] R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\System32\drivers\LGBusEnum.sys [14.07.2009 15:35 19720] R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [05.01.2010 07:56 7408] S3 DrvAgent32;DrvAgent32;c:\windows\System32\drivers\DrvAgent32.sys [14.01.2010 21:46 23456] S3 FontCache;Windows skriftbuffertjeneste;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [14.01.2010 13:05 21504] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . . ------- Tilleggsskanning ------- . LSP: c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll FF - ProfilePath - c:\users\Nyrud\AppData\Roaming\Mozilla\Firefox\Profiles\cef25bmr.default\ FF - prefs.js: browser.search.selectedEngine - MyAnimeList.net FF - prefs.js: browser.startup.homepage - hxxp://www.google.no/ FF - plugin: c:\program files\NVIDIA Corporation\3D Vision\npnv3dv.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".no"); . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-02-12 09:30 Windows 6.0.6002 Service Pack 2 NTFS skanner skjulte prosesser ... skanner skjulte autostart-oppføringer ... skanner skjulte filer ... skanning vellykket skjulte filer: 0 ************************************************************************** . --------------------- DLL'er Lastet Av Kjørende Prosesser --------------------- - - - - - - - > 'winlogon.exe'(804) c:\windows\system32\guard32.dll - - - - - - - > 'lsass.exe'(712) c:\windows\system32\guard32.dll . Tidspunkt ferdig: 2010-02-12 09:32:02 ComboFix-quarantined-files.txt 2010-02-12 08:32 Pre-Run: 378 281 111 552 byte ledig Post-Run: 378 295 447 552 byte ledig - - End Of File - - CD7C90CC2BED2539A851F99F21AA8653