ComboFix 10-10-15.01 - BTK Asus 16.10.2010 4:38.1.2 - x86 Kjører fra: c:\users\BTK Asus\Downloads\ComboFix.exe . ((((((((((((((((((((((((((( Filer Opprettet Fra 2010-09-16 til 2010-10-16 ))))))))))))))))))))))))))))))))) . 2010-10-16 05:14 . 2010-10-16 05:14 -------- d-----w- c:\users\Default\AppData\Local\temp 2010-10-15 07:51 . 2010-09-09 22:52 6084944 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC4CCE4C-B44A-4004-884C-7516A771ADCB}\mpengine.dll 2010-10-13 11:12 . 2010-10-13 11:14 -------- d-----w- c:\program files\Common Files\Adobe 2010-10-13 00:58 . 2010-08-21 05:36 224256 ----a-w- c:\windows\system32\schannel.dll 2010-10-13 00:54 . 2010-08-21 05:33 530432 ----a-w- c:\windows\system32\comctl32.dll 2010-10-13 00:48 . 2010-09-01 04:26 164864 ----a-w- c:\program files\Windows Media Player\wmplayer.exe 2010-10-13 00:47 . 2010-09-01 04:23 12625408 ----a-w- c:\windows\system32\wmploc.DLL 2010-10-13 00:44 . 2010-08-26 04:39 109056 ----a-w- c:\windows\system32\t2embed.dll 2010-10-13 00:40 . 2010-08-27 03:31 310784 ----a-w- c:\windows\system32\drivers\srv.sys 2010-10-13 00:40 . 2010-08-27 05:46 168448 ----a-w- c:\windows\system32\srvsvc.dll 2010-10-13 00:40 . 2010-08-27 03:30 308736 ----a-w- c:\windows\system32\drivers\srv2.sys 2010-10-13 00:39 . 2010-08-27 03:30 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys 2010-10-13 00:35 . 2010-06-29 04:57 4247040 ----a-w- c:\program files\Windows NT\Accessories\wordpad.exe 2010-10-13 00:34 . 2010-06-29 05:02 1413632 ----a-w- c:\windows\system32\ole32.dll 2010-10-12 23:42 . 2010-08-31 04:32 954752 ----a-w- c:\windows\system32\mfc40.dll 2010-10-12 23:42 . 2010-08-31 04:32 954288 ----a-w- c:\windows\system32\mfc40u.dll 2010-10-12 22:57 . 2010-09-01 02:34 2327552 ----a-w- c:\windows\system32\win32k.sys 2010-10-12 22:54 . 2010-05-05 06:46 363520 ----a-w- c:\windows\system32\StructuredQuery.dll 2010-10-12 22:52 . 2010-08-21 05:36 738816 ----a-w- c:\windows\system32\wmpmde.dll 2010-10-12 20:05 . 2010-10-13 09:58 -------- d-----w- c:\program files\uTorrent 2010-10-12 20:03 . 2010-10-12 20:19 -------- d-----w- c:\users\BTK Asus\AppData\Roaming\uTorrent 2010-10-12 08:28 . 2010-10-12 08:28 -------- d-----w- C:\found.003 2010-10-12 06:55 . 2010-10-12 06:55 -------- d-----w- C:\found.002 2010-10-10 00:23 . 2010-10-10 00:26 -------- d-----w- c:\users\BTK Asus\AppData\Roaming\vlc 2010-10-10 00:20 . 2010-10-10 00:20 -------- d-----w- c:\program files\VideoLAN 2010-10-05 19:44 . 2010-10-05 19:44 -------- d-----w- c:\users\BTK Asus\AppData\Local\Windows Live Writer 2010-10-05 19:44 . 2010-10-05 19:44 -------- d-----w- c:\users\BTK Asus\AppData\Roaming\Windows Live Writer 2010-10-05 19:28 . 2010-10-05 19:28 -------- d-----w- c:\windows\no 2010-10-05 19:26 . 2010-10-05 19:26 -------- d-----w- c:\windows\en 2010-10-05 19:18 . 2009-09-04 15:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll 2010-10-05 19:18 . 2009-09-04 15:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll 2010-10-05 19:18 . 2009-09-04 15:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll 2010-10-05 19:15 . 2010-08-11 04:44 2983424 ----a-w- c:\windows\system32\UIRibbon.dll 2010-10-05 19:15 . 2010-08-11 04:35 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll 2010-10-05 19:13 . 2010-05-23 10:11 196608 ----a-w- c:\windows\system32\mfreadwrite.dll 2010-10-05 19:13 . 2010-05-23 10:11 3181568 ----a-w- c:\windows\system32\mf.dll 2010-10-05 19:13 . 2010-05-23 10:15 1619456 ----a-w- c:\windows\system32\WMVDECOD.DLL 2010-10-05 19:11 . 2010-10-05 19:11 15712 ----a-w- c:\program files\Common Files\Windows Live\.cache\1e0d12de1cb64c10a\MeshBetaRemover.exe 2010-10-05 19:11 . 2010-10-05 19:11 94040 ----a-w- c:\program files\Common Files\Windows Live\.cache\1794306c1cb64c109\DSETUP.dll 2010-10-05 19:11 . 2010-10-05 19:11 525656 ----a-w- c:\program files\Common Files\Windows Live\.cache\1794306c1cb64c109\DXSETUP.exe 2010-10-05 19:11 . 2010-10-05 19:11 1691480 ----a-w- c:\program files\Common Files\Windows Live\.cache\1794306c1cb64c109\dsetup32.dll 2010-10-05 19:11 . 2010-10-05 19:11 525656 ----a-w- c:\program files\Common Files\Windows Live\.cache\d58c0101cb64c108\DXSETUP.exe 2010-10-05 19:11 . 2010-10-05 19:11 94040 ----a-w- c:\program files\Common Files\Windows Live\.cache\d58c0101cb64c108\DSETUP.dll 2010-10-05 19:11 . 2010-10-05 19:11 1691480 ----a-w- c:\program files\Common Files\Windows Live\.cache\d58c0101cb64c108\dsetup32.dll 2010-10-05 19:09 . 2010-10-05 19:45 -------- d-----w- c:\users\BTK Asus\AppData\Local\Windows Live 2010-09-30 19:57 . 2010-03-04 04:04 146304 ----a-w- c:\windows\system32\drivers\usbvideo.sys 2010-09-30 19:57 . 2010-03-04 03:57 190976 ----a-w- c:\windows\system32\drivers\ks.sys 2010-09-30 17:40 . 2010-06-19 06:15 2048 ----a-w- c:\windows\system32\tzres.dll 2010-09-30 17:31 . 2010-08-27 05:30 13312 ----a-w- c:\program files\Internet Explorer\iecompat.dll 2010-09-22 22:47 . 2010-09-22 22:47 49016 ----a-w- c:\windows\system32\sirenacm.dll 2010-09-22 22:32 . 2010-09-22 22:32 301936 ----a-w- c:\windows\WLXPGSS.SCR 2010-09-21 12:13 . 2010-09-21 12:13 1564072 ----a-w- c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDRES.DLL 2010-09-21 12:08 . 2010-09-21 12:08 439168 ----a-w- c:\program files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll 2010-09-21 12:06 . 2010-09-21 12:06 853912 ----a-w- c:\program files\Common Files\Microsoft Shared\Windows Live\wlidcli.dll 2010-09-21 12:06 . 2010-09-21 12:06 57752 ----a-w- c:\program files\Common Files\Microsoft Shared\Windows Live\msidcrl40.dll 2010-09-21 12:03 . 2010-09-21 12:03 332160 ----a-w- c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL 2010-09-21 12:03 . 2010-09-21 12:03 237952 ----a-w- c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDPROV.DLL 2010-09-21 12:03 . 2010-09-21 12:03 208768 ----a-w- c:\windows\system32\LIVESSP.DLL 2010-09-21 12:03 . 2010-09-21 12:03 193408 ----a-w- c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE 2010-09-21 12:03 . 2010-09-21 12:03 1710464 ----a-w- c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 2010-09-21 12:03 . 2010-09-21 12:03 145280 ----a-w- c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL 2010-09-16 11:15 . 2010-08-21 05:32 316928 ----a-w- c:\windows\system32\spoolsv.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . . (((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret ))))))))))))))))))))))))))))))))))))))))))))) . . *Merk* tomme oppføringer & gyldige standardoppføringer vises ikke REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2009-12-09 01:19 94208 ----a-w- c:\users\BTK Asus\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2009-12-09 01:19 94208 ----a-w- c:\users\BTK Asus\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2009-12-09 01:19 94208 ----a-w- c:\users\BTK Asus\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Google Update"="c:\users\BTK Asus\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-09-27 133104] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X] "lxdxmon.exe"="c:\program files\Lexmark 3600-4600 Series\lxdxmon.exe" [2008-03-20 668328] "lxdxamon"="c:\program files\Lexmark 3600-4600 Series\lxdxamon.exe" [2008-03-20 16040] "AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2008-12-04 114688] "AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2008-12-17 622592] "AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2008-05-21 94208] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552] "MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-09-15 1094224] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 lxdxCATSCustConnectService;lxdxCATSCustConnectService;c:\windows\system32\spool\DRIVERS\W32X86\3\\lxdxserv.exe [2009-10-16 94208] R3 cmeu0wdm;CardMan 2020;c:\windows\system32\DRIVERS\cmeu0wdm.sys [2005-05-23 43737] R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-06-22 100480] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-26 1343400] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 lxdx_device;lxdx_device;c:\windows\system32\lxdxcoms.exe [2008-02-28 594600] S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-04-29 304464] S2 SesamService;Sesam Control Service;c:\program files\Telenor\mobilt bredband\Sesam\BIN\SecMIPService.exe [2009-02-17 1237800] S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2010-04-13 45736] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-04-29 20952] S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-03-25 42368] S3 netr28;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28.sys [2009-05-18 599040] S3 wtsmpadap;Sesam Virtual Adapter;c:\windows\system32\DRIVERS\wtsmpadap.sys [2009-01-30 39720] S3 WtSmpFlt;Sesam Adapter;c:\windows\system32\DRIVERS\wtsmpflt.sys [2009-01-30 277032] . Innholdet i mappen 'Scheduled Tasks' (planlagte oppgaver) 2010-10-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3585956754-2932109991-1459755388-1001Core.job - c:\users\BTK Asus\AppData\Local\Google\Update\GoogleUpdate.exe [2009-09-27 17:48] 2010-10-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3585956754-2932109991-1459755388-1001UA.job - c:\users\BTK Asus\AppData\Local\Google\Update\GoogleUpdate.exe [2009-09-27 17:48] . . ------- Tilleggsskanning ------- . uStart Page = hxxp://th.msn.com IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 IE: {{0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\Windows Live\Companion\companioncore.dll Trusted Zone: buypass.no Trusted Zone: headit.no Trusted Zone: norsk-tipping.no Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll . - - - - TOMME PEKERE FJERNET - - - - WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) . --------------------- LÅSTE REGISTERNØKLER --------------------- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . --------------------- DLL'er Lastet Av Kjørende Prosesser --------------------- - - - - - - - > 'Explorer.exe'(1808) c:\users\BTK Asus\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll . Tidspunkt ferdig: 2010-10-16 08:44:37 ComboFix-quarantined-files.txt 2010-10-16 06:44 Pre-Run: 14 114 365 440 bytes free Post-Run: 14 789 574 656 bytes free - - End Of File - - A786E4D796372C997C3DAFD9987846CE