ComboFix 10-02-18.09 - Vegard 19.02.2010 17:35:35.6.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.47.1044.18.3066.1827 [GMT 1:00] Kjører fra: c:\users\Vegard\Desktop\ComboFix.exe SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Andre slettinger ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\010112010146116101.xxe c:\windows\0101120101465155.xxe c:\windows\bk23567.dat c:\windows\rdr_1257946018.exe c:\windows\rdr_1257946021.exe c:\windows\rdr_1257946022.exe c:\windows\rdr_1257999400.exe c:\windows\rdr_1257999430.exe c:\windows\rdr_1257999437.exe c:\windows\rdr_1258015574.exe c:\windows\rdr_1258015579.exe c:\windows\rdr_1258015580.exe c:\windows\rdr_1258015581.exe c:\windows\rdr_1258054356.exe c:\windows\rdr_1258054360.exe c:\windows\Suyin.reg . ((((((((((((((((((((((((((( Filer Opprettet Fra 2010-01-19 til 2010-02-19 ))))))))))))))))))))))))))))))))) . 2010-02-19 16:48 . 2010-02-19 16:49 -------- d-----w- c:\users\Vegard\AppData\Local\temp 2010-02-19 16:48 . 2010-02-19 16:48 -------- d-----w- c:\users\Gjest\AppData\Local\temp 2010-02-19 16:48 . 2010-02-19 16:48 -------- d-----w- c:\users\Default\AppData\Local\temp 2010-02-17 10:58 . 2010-02-17 10:58 -------- d-----w- c:\program files\iPod 2010-02-17 10:58 . 2010-02-17 10:59 -------- d-----w- c:\program files\iTunes 2010-02-17 10:54 . 2010-02-17 10:55 -------- d-----w- c:\program files\QuickTime 2010-02-17 10:51 . 2010-02-17 10:51 72488 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe 2010-02-16 11:08 . 2010-02-16 11:08 -------- d-----w- c:\programdata\NCH Software 2010-02-16 11:08 . 2010-02-16 11:08 -------- d-----w- c:\users\Vegard\AppData\Roaming\NCH Software 2010-02-15 18:29 . 2010-02-15 18:29 -------- d-----w- c:\program files\NCH Software 2010-02-15 18:01 . 2009-12-08 20:01 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe 2010-02-15 18:01 . 2009-12-08 20:01 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe 2010-02-12 14:49 . 2010-02-12 14:49 -------- d-----w- c:\users\Gjest\AppData\Roaming\Apple Computer 2010-02-12 14:49 . 2010-02-12 14:49 -------- d-----w- c:\users\Gjest\AppData\Local\Apple Computer 2010-02-03 17:03 . 2010-02-03 17:03 -------- d-----w- c:\program files\Common Files\Symantec Shared 2010-02-03 17:03 . 2010-01-18 17:22 84912 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20100202.041\naveng.sys 2010-02-03 17:03 . 2010-01-18 17:22 371248 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20100202.041\eeCtrl.sys 2010-02-03 17:03 . 2010-01-18 17:22 2747440 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20100202.041\cceraser.dll 2010-02-03 17:03 . 2010-01-18 17:22 259440 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20100202.041\ecmsvr32.dll 2010-02-03 17:03 . 2010-01-18 17:22 177520 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20100202.041\naveng32.dll 2010-02-03 17:03 . 2010-01-18 17:22 1647984 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20100202.041\navex32a.dll 2010-02-03 17:03 . 2010-01-18 17:22 1323568 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20100202.041\navex15.sys 2010-02-03 17:03 . 2010-01-18 17:22 102448 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20100202.041\ERASER.sys 2010-02-03 17:02 . 2010-01-18 17:22 102448 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\BinHub\ERASER.sys 2010-02-03 17:02 . 2010-01-18 17:22 84912 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\BinHub\naveng.sys 2010-02-03 17:02 . 2010-01-18 17:22 371248 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\BinHub\eeCtrl.sys 2010-02-03 17:02 . 2010-01-18 17:22 2747440 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\BinHub\cceraser.dll 2010-02-03 17:02 . 2010-01-18 17:22 259440 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\BinHub\ecmsvr32.dll 2010-02-03 17:02 . 2010-01-18 17:22 177520 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\BinHub\naveng32.dll 2010-02-03 17:02 . 2010-01-18 17:22 1647984 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\BinHub\navex32a.dll 2010-02-03 17:02 . 2010-01-18 17:22 1323568 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\BinHub\navex15.sys 2010-02-03 03:31 . 2010-02-03 17:17 -------- d-----w- c:\programdata\Norton 2010-02-03 03:31 . 2010-02-03 17:02 -------- d-----w- c:\programdata\Symantec 2010-02-03 03:31 . 2010-02-03 03:31 -------- d-----w- c:\programdata\NortonInstaller 2010-02-03 00:31 . 2010-02-03 00:33 -------- d-----w- c:\program files\DivX 2010-02-03 00:31 . 2010-02-03 00:31 -------- d-----w- c:\program files\Common Files\DivX Shared 2010-01-22 20:08 . 2009-12-16 11:44 834048 ----a-w- c:\windows\system32\wininet.dll 2010-01-22 20:08 . 2009-12-18 13:01 78336 ----a-w- c:\windows\system32\ieencode.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-02-19 16:39 . 2008-05-13 05:59 94938 ----a-w- c:\windows\system32\perfc014.dat 2010-02-19 16:39 . 2008-05-13 05:59 492402 ----a-w- c:\windows\system32\perfh014.dat 2010-02-19 16:32 . 2008-09-21 17:54 42142 ----a-w- c:\programdata\nvModes.dat 2010-02-19 16:30 . 2008-09-21 17:55 12 ----a-w- c:\windows\bthservsdp.dat 2010-02-19 16:30 . 2008-09-23 13:32 -------- d-----w- c:\users\Vegard\AppData\Roaming\DNA 2010-02-19 16:12 . 2009-11-25 23:19 -------- d-----w- c:\program files\Steam 2010-02-19 16:11 . 2008-09-23 13:32 -------- d-----w- c:\program files\DNA 2010-02-18 15:54 . 2009-01-27 21:25 -------- d-----w- c:\programdata\Google Updater 2010-02-17 10:58 . 2008-10-19 16:38 -------- d-----w- c:\program files\Common Files\Apple 2010-02-12 14:45 . 2008-09-27 17:34 107936 ----a-w- c:\users\Gjest\AppData\Local\GDIPFONTCACHEV1.DAT 2010-02-12 14:03 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail 2010-02-12 13:49 . 2008-05-12 20:14 -------- d-----w- c:\programdata\Microsoft Help 2010-02-05 22:47 . 2009-01-27 21:25 -------- d-----w- c:\program files\Google 2010-01-24 13:36 . 2008-09-28 13:28 -------- d-----w- c:\program files\Microsoft Silverlight 2010-01-15 21:59 . 2009-03-15 19:50 1 ----a-w- c:\users\Vegard\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys 2010-01-14 10:12 . 2009-10-17 17:18 181120 ------w- c:\windows\system32\MpSigStub.exe 2009-12-25 23:09 . 2009-12-25 23:03 -------- d-----w- c:\users\Vegard\AppData\Roaming\ICAClient 2009-12-25 23:02 . 2009-12-25 23:02 -------- d-----w- c:\program files\Citrix 2009-12-23 12:49 . 2009-04-15 19:21 -------- d-----w- c:\users\Vegard\AppData\Roaming\uTorrent 2009-12-11 11:43 . 2010-02-11 12:06 302080 ----a-w- c:\windows\system32\drivers\srv.sys 2009-12-11 11:43 . 2010-02-11 12:06 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys 2009-12-08 20:01 . 2010-02-11 12:06 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys 2009-12-08 17:26 . 2010-02-11 12:06 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys 2009-12-04 18:30 . 2010-02-11 12:06 12288 ----a-w- c:\windows\system32\tsbyuv.dll 2009-12-04 18:29 . 2010-02-11 12:06 1314816 ----a-w- c:\windows\system32\quartz.dll 2009-12-04 18:28 . 2010-02-11 12:06 22528 ----a-w- c:\windows\system32\msyuv.dll 2009-12-04 18:28 . 2010-02-11 12:06 31744 ----a-w- c:\windows\system32\msvidc32.dll 2009-12-04 18:28 . 2010-02-11 12:06 123904 ----a-w- c:\windows\system32\msvfw32.dll 2009-12-04 18:28 . 2010-02-11 12:06 13312 ----a-w- c:\windows\system32\msrle32.dll 2009-12-04 18:28 . 2010-02-11 12:06 82944 ----a-w- c:\windows\system32\mciavi32.dll 2009-12-04 18:28 . 2010-02-11 12:06 50176 ----a-w- c:\windows\system32\iyuv_32.dll 2009-12-04 18:27 . 2010-02-11 12:06 91136 ----a-w- c:\windows\system32\avifil32.dll 2009-12-04 15:56 . 2010-02-11 12:06 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys 2009-12-04 15:56 . 2010-02-11 12:06 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2008-09-22 09:34 . 2008-09-22 09:32 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT . (((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret ))))))))))))))))))))))))))))))))))))))))))))) . . *Merk* tomme oppføringer & gyldige standardoppføringer vises ikke REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-03-04 21:38 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920] "Google Update"="c:\users\Vegard\AppData\Local\Google\Update\GoogleUpdate.exe" [2008-09-21 133104] "BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-12 323392] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-27 39408] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656] "Steam"="c:\program files\steam\steam.exe" [2009-11-25 1217808] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-02-22 1037608] "BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-06 34040] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-04-03 13535776] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-04-03 92704] "RtHDVCpl"="RtHDVCpl.exe" [2008-08-07 6265376] "PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704] "LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-07-25 809480] "eAudio"="c:\program files\Acer\Empowering Technology\eAudio\eAudio.exe" [2008-03-07 544768] "eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-04 526896] "ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-04-30 397312] "ArcadeDeluxeAgent"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" [2008-04-10 147456] "CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2008-04-10 167936] "PlayMovie"="c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" [2008-04-18 167936] "WarReg_PopUp"="c:\program files\Acer\WR_PopUp\WarReg_PopUp.exe" [2008-01-29 303104] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "autodetect"="c:\windows\system32\SupportAppXL\AutoDect.exe" [2008-11-04 91648] "APVXDWIN"="c:\program files\Panda Security\Panda Antivirus Pro 2010\APVXDWIN.EXE" [2009-06-05 574720] "SCANINICIO"="c:\program files\Panda Security\Panda Antivirus Pro 2010\Inicio.exe" [2009-04-21 56064] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-22 141608] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856] c:\users\Vegard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper og Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2008-9-21 1216512] BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-2-12 723496] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk /p \??\G:\0autocheck autochk * [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PskSvcRetail] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "VistaSp2"=hex(b):ff,69,04,f5,50,53,ca,01 R0 pavboot;Panda boot driver;c:\windows\System32\drivers\pavboot.sys [20.09.2009 14:48 28544] R1 ShldDrv;Panda File Shield Driver;c:\windows\System32\drivers\ShlDrv51.sys [20.09.2009 14:48 41144] R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl [21.09.2008 19:17 61424] R2 AmFSM;AmFSM;c:\windows\System32\drivers\amm8660.sys [20.09.2009 14:53 49208] R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [03.03.2008 12:11 16384] R2 CLHNService;CLHNService;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [21.09.2008 19:18 81504] R2 Disk Cleaner Service;Disk Cleaner Service;c:\program files\Disk Cleaner\DiskCleanerService.exe [25.03.2009 20:17 79160] R2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [12.05.2008 21:36 24576] R2 Gwmsrv;Panda Goodware Cache Manager;c:\windows\system32\svchost -k Panda --> c:\windows\system32\svchost -k Panda [?] R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [06.04.2008 21:42 50424] R2 NTIPPKernel;NTIPPKernel;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [21.09.2008 19:18 122368] R2 PavProc;Panda Process Protection Driver;c:\windows\System32\drivers\PavProc.sys [20.09.2009 14:48 177416] R2 PskSvcRetail;Panda PSK service;c:\program files\Panda Security\Panda Antivirus Pro 2010\psksvc.exe [20.09.2009 14:53 28928] R2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [21.09.2008 19:04 233472] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [22.09.2008 10:31 43552] S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [16.08.2009 12:33 721904] S2 gupdate;Googles oppdateringstjeneste (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27.12.2009 15:40 135664] S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [04.04.2008 02:03 131072] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [21.01.2008 03:23 179712] S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\System32\drivers\massfilter.sys [14.08.2009 18:11 7168] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ rsmsvcs REG_MULTI_SZ ntmssvc panda REG_MULTI_SZ Gwmsrv LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . Innholdet i mappen 'Scheduled Tasks' (planlagte oppgaver) 2010-02-19 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-27 21:53] 2010-02-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-12-27 14:39] 2010-02-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-12-27 14:39] 2010-02-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-443142323-2617257544-3122356939-1000Core.job - c:\users\Vegard\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-21 20:23] 2010-02-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-443142323-2617257544-3122356939-1000UA.job - c:\users\Vegard\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-21 20:23] . . ------- Tilleggsskanning ------- . uStart Page = about:blank mStart Page = hxxp://no.intl.acer.yahoo.com uInternet Settings,ProxyOverride = *.local IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Google Sidewiki - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html IE: Send bilde til &Bluetooth-enhet... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send side til &Bluetooth-enhet... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm . - - - - TOMME PEKERE FJERNET - - - - AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe AddRemove-HijackThis - c:\program files\Trend Micro\HijackThis\HijackThis.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-02-19 17:49 Windows 6.0.6002 Service Pack 2 NTFS skanner skjulte prosesser ... skanner skjulte autostart-oppføringer ... skanner skjulte filer ... skanning vellykket skjulte filer: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}] "ImagePath"="\??\c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl" . --------------------- LÅSTE REGISTERNØKLER --------------------- [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Tidspunkt ferdig: 2010-02-19 17:54:23 ComboFix-quarantined-files.txt 2010-02-19 16:54 ComboFix2.txt 2009-04-21 20:50 ComboFix3.txt 2008-10-30 23:18 ComboFix4.txt 2008-10-24 10:32 Pre-Run: 4 469 682 176 byte ledig Post-Run: 5 199 802 368 byte ledig - - End Of File - - 855D41E702D287F252C291FAAF63182D