ComboFix 11-01-08.05 - Gerhardsen 10.01.2011 15:58:39.3.2 - x86 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.47.1033.18.2047.1197 [GMT 1:00] Kjører fra: c:\users\Gerhardsen\Downloads\ComboFix.exe AV: Norton 360 *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855} FW: Norton 360 *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E} SP: Norton 360 *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Andre slettinger ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\programdata\Local . ((((((((((((((((((((((((((( Filer Opprettet Fra 2010-12-10 til 2011-01-10 ))))))))))))))))))))))))))))))))) . 2011-01-10 11:31 . 2011-01-10 11:31 -------- d-----w- c:\programdata\Malwarebytes 2011-01-10 11:31 . 2011-01-10 22:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-01-10 11:23 . 2011-01-10 11:23 -------- d-----r- C:\MSOCache 2011-01-09 22:38 . 2011-01-09 22:38 -------- d-----w- c:\programdata\SUPERAntiSpyware.com 2011-01-09 22:38 . 2011-01-09 23:53 -------- d-----w- c:\program files\SUPERAntiSpyware 2011-01-09 22:19 . 2010-05-06 04:01 44080 ----a-r- c:\windows\system32\drivers\SymIMV.sys 2011-01-09 21:41 . 2011-01-09 22:04 -------- d-----w- c:\program files\Spybot - Search & Destroy 2011-01-09 21:41 . 2011-01-09 22:02 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2011-01-09 12:48 . 2008-04-17 21:12 107368 ----a-r- c:\windows\system32\GEARAspi.dll 2011-01-09 12:48 . 2009-05-18 22:17 26600 ----a-r- c:\windows\system32\drivers\GEARAspiWDM.sys 2011-01-09 12:48 . 2011-01-09 12:48 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2011-01-03 10:47 . 2011-01-10 22:38 -------- d-----w- c:\programdata\Norton 2011-01-03 10:21 . 2010-11-16 11:01 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{13BEB3B8-680A-495F-A776-92C002C013D3}\mpengine.dll 2010-12-22 00:33 . 2010-12-22 00:35 -------- d-----w- c:\windows\WindowsMobile 2010-12-20 17:37 . 2010-12-20 17:37 -------- d-----w- c:\program files\Common Files\Adobe 2010-12-20 17:29 . 2010-12-20 17:29 -------- d-----w- c:\program files\Common Files\Adobe AIR 2010-12-16 16:07 . 2010-12-16 16:07 -------- d-----w- c:\program files\AnvSoft 2010-12-16 12:29 . 2008-11-24 11:00 974848 ----a-w- c:\windows\system32\mfc70.dll 2010-12-16 12:29 . 2008-11-24 11:00 487424 ----a-w- c:\windows\system32\msvcp70.dll 2010-12-16 12:29 . 2008-11-24 11:00 344064 ----a-w- c:\windows\system32\msvcr70.dll 2010-12-16 00:25 . 2010-12-19 17:20 4277016 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll 2010-12-16 00:25 . 2010-12-19 17:19 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2010-12-15 23:39 . 2010-12-16 12:35 -------- d-----w- c:\program files\Common Files\AVSMedia 2010-12-15 23:38 . 2010-09-14 16:38 1700352 ----a-w- c:\windows\system32\GdiPlus.dll 2010-12-15 23:38 . 2010-09-14 16:38 24576 ----a-w- c:\windows\system32\msxml3a.dll 2010-12-15 23:24 . 2010-12-15 23:24 737072 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll 2010-12-15 23:03 . 2010-12-17 17:13 4277016 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2010-12-15 22:52 . 2010-12-15 22:52 -------- d-----w- c:\program files\VideoLAN 2010-12-15 22:51 . 2010-12-17 17:12 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2010-12-15 22:51 . 2010-12-15 22:51 539968 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2010-12-15 21:32 . 2010-10-12 04:25 516096 ----a-w- c:\program files\Windows Mail\wab.exe 2010-12-15 21:27 . 2010-10-27 04:32 2048 ----a-w- c:\windows\system32\tzres.dll 2010-12-15 21:27 . 2010-10-20 04:54 34304 ----a-w- c:\windows\system32\atmlib.dll 2010-12-15 21:27 . 2010-10-20 02:58 294400 ----a-w- c:\windows\system32\atmfd.dll 2010-12-15 21:27 . 2010-10-16 04:36 314368 ----a-w- c:\windows\system32\webio.dll 2010-12-15 21:26 . 2010-10-16 04:41 101760 ----a-w- c:\windows\system32\consent.exe 2010-12-15 21:24 . 2010-10-20 03:00 2327552 ----a-w- c:\windows\system32\win32k.sys 2010-12-14 18:03 . 2010-12-14 18:03 -------- d-----w- C:\BigFishGamesCache 2010-12-14 14:03 . 2010-12-14 14:03 -------- d-----w- c:\program files\Winamp Detect 2010-12-14 13:53 . 2010-12-14 13:53 -------- d-----w- c:\program files\Common Files\PX Storage Engine 2010-12-14 13:52 . 2010-12-14 14:03 -------- d-----w- c:\program files\Winamp 2010-12-14 12:21 . 2010-12-14 12:21 -------- d-----w- c:\program files\ConduitEngine 2010-12-14 12:18 . 2010-12-14 12:18 -------- d-----w- c:\program files\BitTorrent 2010-12-14 10:54 . 2010-12-14 10:54 -------- d-----w- c:\program files\Axesstel 2010-12-14 10:53 . 2010-12-14 10:53 -------- d-----w- c:\program files\Common Files\InstallShield 2010-12-13 21:07 . 2010-12-13 21:16 -------- d-----w- c:\program files\Ubisoft 2010-12-13 20:42 . 2010-12-13 20:42 -------- d-----w- c:\program files\Common Files\Java 2010-12-13 20:42 . 2010-12-13 20:41 472808 ----a-w- c:\windows\system32\deployJava1.dll 2010-12-13 20:41 . 2010-12-13 20:41 -------- d-----w- c:\program files\Java 2010-12-13 20:34 . 2010-12-13 20:34 -------- d-----w- c:\program files\Microsoft Synchronization Services 2010-12-13 20:32 . 2010-12-13 20:32 -------- d-----w- c:\windows\PCHEALTH 2010-12-13 20:32 . 2010-12-13 20:32 -------- d-----w- c:\program files\Microsoft.NET 2010-12-13 20:32 . 2010-12-13 20:32 -------- d-----w- c:\program files\Microsoft Sync Framework 2010-12-13 20:32 . 2010-12-13 20:32 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition 2010-12-13 20:30 . 2010-12-13 20:30 -------- d-----w- c:\program files\Microsoft Visual Studio 8 2010-12-13 20:28 . 2010-12-13 20:28 -------- d-----w- c:\program files\Microsoft Analysis Services 2010-12-13 20:27 . 2010-12-16 10:03 -------- d-----w- c:\programdata\Microsoft Help 2010-12-13 20:22 . 2009-02-24 17:42 116736 ----a-w- c:\windows\system32\drivers\mcdbus.sys 2010-12-13 20:21 . 2010-12-13 20:22 -------- d-----w- c:\program files\MagicDisc 2010-12-13 20:16 . 2010-12-13 20:16 -------- d-----w- c:\windows\system32\Macromed 2010-12-13 19:41 . 2007-01-03 16:20 1732 ----a-w- c:\windows\system32\drivers\nvphy.bin 2010-12-13 19:41 . 2007-02-13 22:55 356352 ----a-w- c:\windows\system32\nvusmu.exe 2010-12-13 19:41 . 2006-11-08 13:48 356352 ----a-w- c:\windows\system32\nvusmb.exe 2010-12-13 19:26 . 2010-12-13 19:26 -------- d-----w- c:\program files\CONEXANT 2010-12-13 16:59 . 2010-12-13 16:59 -------- d-----w- c:\program files\PowerISO 2010-12-13 16:58 . 2010-12-13 16:58 691696 ----a-w- c:\windows\system32\drivers\sptd.sys 2010-12-13 16:57 . 2010-12-13 16:57 -------- d-----w- c:\programdata\DAEMON Tools Lite 2010-12-13 16:05 . 2010-12-13 16:05 -------- d-----w- c:\programdata\TrueSuite 2010-12-13 16:05 . 2010-12-13 16:05 -------- d-----w- c:\windows\system32\wocaffe 2010-12-13 16:05 . 2010-12-13 16:05 -------- d-----w- c:\program files\TrueSuite 2010-12-13 15:56 . 2010-12-13 15:56 -------- d-----w- c:\programdata\NVIDIA 2010-12-13 15:48 . 2009-10-03 05:02 584296 ----a-w- c:\windows\system32\nvuninst.exe 2010-12-13 15:48 . 2010-12-13 15:48 -------- d-----w- c:\windows\system32\Wat 2010-12-13 15:46 . 2010-12-13 15:46 -------- d-----w- c:\windows\nb-NO 2010-12-13 15:46 . 2010-12-13 15:46 -------- d-----w- c:\windows\system32\no 2010-12-13 15:46 . 2010-12-13 15:46 -------- d-----w- c:\windows\system32\XPSViewer 2010-12-13 15:46 . 2010-12-13 15:46 -------- d-----w- c:\windows\system32\drivers\nb-NO 2010-12-13 15:46 . 2010-12-13 15:46 -------- d-----w- c:\windows\system32\drivers\UMDF\nb-NO 2010-12-13 15:46 . 2010-12-13 15:46 -------- d-----w- c:\windows\system32\wbem\nb-NO 2010-12-13 15:41 . 2009-07-13 17:34 3584 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\nb-NO\LXKPTPRC.DLL.mui 2010-12-13 14:59 . 2011-01-08 10:48 -------- d-----w- c:\program files\Norman 2010-12-13 14:47 . 2010-12-13 14:47 -------- d-----w- c:\program files\Telenor 2010-12-13 14:08 . 2010-12-13 21:09 -------- d-----w- c:\programdata\WinZip 2010-12-13 12:54 . 2009-07-24 09:49 114688 ----a-w- c:\windows\system32\RicohMediadriverVer.dll 2010-12-13 12:54 . 2009-06-25 15:58 48128 ----a-w- c:\windows\system32\drivers\rimmptsk.sys 2010-12-13 12:54 . 2009-06-25 15:25 38400 ----a-w- c:\windows\system32\drivers\rixdptsk.sys 2010-12-13 12:54 . 2009-06-25 15:10 44544 ----a-w- c:\windows\system32\drivers\rimsptsk.sys 2010-12-13 12:54 . 2007-07-25 11:48 172032 ----a-w- c:\windows\system32\rixdicon.dll 2010-12-13 12:54 . 2004-09-04 02:00 90112 ----a-w- c:\windows\system32\snymsico.dll 2010-12-13 11:24 . 2010-10-19 09:41 222080 ------w- c:\windows\system32\MpSigStub.exe 2010-12-13 11:22 . 2011-01-08 12:23 -------- d-----w- c:\windows\system32\wbem\Performance 2010-12-13 11:18 . 2011-01-10 13:40 -------- d-----w- c:\users\Gerhardsen 2010-12-13 11:17 . 2010-12-13 11:17 -------- d-----w- C:\Recovery 2010-12-13 11:03 . 2010-09-14 06:02 740352 ----a-w- c:\windows\system32\batmeter.dll 2010-12-13 11:01 . 2010-10-19 08:10 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll 2010-12-13 10:57 . 2011-01-09 17:20 -------- d-sh--w- c:\windows\Installer 2010-12-13 10:46 . 2010-12-13 11:18 -------- d-----w- c:\windows\Panther . (((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-11-11 14:50 . 2010-11-11 14:50 954752 ----a-w- c:\windows\system32\mfc40.dll 2010-11-11 14:50 . 2010-11-11 14:50 954288 ----a-w- c:\windows\system32\mfc40u.dll 2010-11-11 14:50 . 2010-11-11 14:50 12625408 ----a-w- c:\windows\system32\wmploc.DLL 2010-11-11 14:49 . 2010-11-11 14:49 310784 ----a-w- c:\windows\system32\drivers\srv.sys 2010-11-11 14:49 . 2010-11-11 14:49 308736 ----a-w- c:\windows\system32\drivers\srv2.sys 2010-11-11 14:49 . 2010-11-11 14:49 168448 ----a-w- c:\windows\system32\srvsvc.dll 2010-11-11 14:49 . 2010-11-11 14:49 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys 2010-11-11 14:49 . 2010-11-11 14:49 530432 ----a-w- c:\windows\system32\comctl32.dll 2010-11-11 14:48 . 2010-11-11 14:48 641536 ----a-w- c:\windows\system32\CPFilters.dll 2010-11-11 14:48 . 2010-11-11 14:48 417792 ----a-w- c:\windows\system32\msdri.dll 2010-11-11 14:48 . 2010-11-11 14:48 204288 ----a-w- c:\windows\system32\MSNP.ax 2010-11-11 14:48 . 2010-11-11 14:48 199680 ----a-w- c:\windows\system32\mpg2splt.ax 2010-11-11 14:48 . 2010-11-11 14:48 738816 ----a-w- c:\windows\system32\wmpmde.dll 2010-11-11 14:48 . 2010-11-11 14:48 26504 ----a-w- c:\windows\system32\drivers\Diskdump.sys 2010-11-11 14:47 . 2010-11-11 14:47 224256 ----a-w- c:\windows\system32\schannel.dll 2010-11-11 14:47 . 2010-11-11 14:47 109056 ----a-w- c:\windows\system32\t2embed.dll 2010-11-11 14:47 . 2010-11-11 14:47 363520 ----a-w- c:\windows\system32\StructuredQuery.dll 2010-11-11 14:46 . 2010-11-11 14:46 1413632 ----a-w- c:\windows\system32\ole32.dll 2010-11-11 14:45 . 2010-11-11 14:45 316928 ----a-w- c:\windows\system32\spoolsv.exe 2010-11-11 14:44 . 2010-11-11 14:44 190976 ----a-w- c:\windows\system32\drivers\ks.sys 2010-11-11 14:44 . 2010-11-11 14:44 146304 ----a-w- c:\windows\system32\drivers\usbvideo.sys 2010-11-11 14:43 . 2010-11-11 14:43 292864 ----a-w- c:\windows\system32\apphelp.dll 2010-11-11 14:43 . 2010-11-11 14:43 41984 ----a-w- c:\windows\system32\drivers\usbehci.sys 2010-11-11 14:43 . 2010-11-11 14:43 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys 2010-11-11 14:43 . 2010-11-11 14:43 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll 2010-11-11 14:43 . 2010-11-11 14:43 49472 ----a-w- c:\windows\system32\netfxperf.dll 2010-11-11 14:43 . 2010-11-11 14:43 297808 ----a-w- c:\windows\system32\mscoree.dll 2010-11-11 14:43 . 2010-11-11 14:43 295264 ----a-w- c:\windows\system32\PresentationHost.exe 2010-11-11 14:43 . 2010-11-11 14:43 1130824 ----a-w- c:\windows\system32\dfshim.dll 2010-11-11 14:41 . 2010-11-11 14:41 1233920 ----a-w- c:\windows\system32\msxml3.dll 2010-11-11 14:40 . 2010-11-11 14:40 37376 ----a-w- c:\windows\system32\rtutils.dll 2010-11-11 14:40 . 2010-11-11 14:40 82944 ----a-w- c:\windows\system32\iccvid.dll 2010-11-11 14:40 . 2010-11-11 14:40 197632 ----a-w- c:\windows\system32\ir32_32.dll 2010-11-11 14:39 . 2010-11-11 14:39 571904 ----a-w- c:\windows\system32\oleaut32.dll 2010-11-11 14:39 . 2010-11-11 14:39 3955080 ----a-w- c:\windows\system32\ntkrnlpa.exe 2010-11-11 14:39 . 2010-11-11 14:39 3899784 ----a-w- c:\windows\system32\ntoskrnl.exe 2010-11-11 14:38 . 2010-11-11 14:38 427520 ----a-w- c:\windows\system32\vbscript.dll 2010-11-11 14:38 . 2010-11-11 14:38 465408 ----a-w- c:\windows\system32\psisdecd.dll 2010-11-11 14:37 . 2010-11-11 14:37 1286456 ----a-w- c:\windows\system32\ntdll.dll 2010-11-11 14:37 . 2010-11-11 14:37 133720 ----a-w- c:\windows\system32\drivers\ksecpkg.sys 2010-11-11 14:37 . 2010-11-11 14:37 1037312 ----a-w- c:\windows\system32\lsasrv.dll 2010-11-11 14:36 . 2010-11-11 14:36 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys 2010-11-11 14:36 . 2010-11-11 14:36 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys 2010-11-11 14:36 . 2010-11-11 14:36 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2010-11-11 14:35 . 2010-11-11 14:35 67584 ----a-w- c:\windows\system32\asycfilt.dll 2010-11-11 14:35 . 2010-11-11 14:35 132608 ----a-w- c:\windows\system32\cabview.dll 2010-11-11 14:35 . 2010-11-11 14:35 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll 2010-11-11 14:35 . 2010-11-11 14:35 85504 ----a-w- c:\windows\system32\secproc_ssp.dll 2010-11-11 14:35 . 2010-11-11 14:35 369152 ----a-w- c:\windows\system32\secproc.dll 2010-11-11 14:35 . 2010-11-11 14:35 365568 ----a-w- c:\windows\system32\secproc_isv.dll 2010-11-11 14:35 . 2010-11-11 14:35 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe 2010-11-11 14:35 . 2010-11-11 14:35 320512 ----a-w- c:\windows\system32\RMActivate.exe 2010-11-11 14:35 . 2010-11-11 14:35 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe 2010-11-11 14:35 . 2010-11-11 14:35 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe 2010-11-11 14:34 . 2010-11-11 14:34 1286016 ----a-w- c:\windows\system32\drivers\tcpip.sys 2010-11-11 14:34 . 2010-11-11 14:34 172032 ----a-w- c:\windows\system32\wintrust.dll 2010-11-11 14:34 . 2010-11-11 14:34 740864 ----a-w- c:\windows\system32\inetcomm.dll 2010-11-11 14:33 . 2010-11-11 14:33 285696 ----a-w- c:\windows\system32\winlogon.exe 2010-11-11 14:33 . 2010-11-11 14:33 2614272 ----a-w- c:\windows\explorer.exe 2010-11-11 14:33 . 2010-11-11 14:33 84992 ----a-w- c:\windows\system32\drivers\sdbus.sys 2010-11-11 14:33 . 2010-11-11 14:33 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys 2010-11-11 14:32 . 2010-11-11 14:32 293376 ----a-w- c:\windows\system32\browserchoice.exe 2010-11-11 14:32 . 2010-11-11 14:32 91648 ----a-w- c:\windows\system32\avifil32.dll 2010-11-11 14:32 . 2010-11-11 14:32 84480 ----a-w- c:\windows\system32\mciavi32.dll 2010-11-11 14:32 . 2010-11-11 14:32 50176 ----a-w- c:\windows\system32\iyuv_32.dll 2010-11-11 14:32 . 2010-11-11 14:32 31744 ----a-w- c:\windows\system32\msvidc32.dll 2010-11-11 14:32 . 2010-11-11 14:32 22016 ----a-w- c:\windows\system32\msyuv.dll 2010-11-11 14:32 . 2010-11-11 14:32 13312 ----a-w- c:\windows\system32\msrle32.dll 2010-11-11 14:32 . 2010-11-11 14:32 1328640 ----a-w- c:\windows\system32\quartz.dll 2010-11-11 14:32 . 2010-11-11 14:32 12288 ----a-w- c:\windows\system32\tsbyuv.dll 2010-11-11 14:32 . 2010-11-11 14:32 194488 ----a-w- c:\windows\system32\drivers\fvevol.sys 2010-11-11 14:31 . 2010-11-11 14:31 257024 ----a-w- c:\windows\system32\msv1_0.dll 2010-11-11 14:31 . 2010-11-11 14:31 34816 ----a-w- c:\windows\system32\msasn1.dll 2010-11-11 14:31 . 2010-11-11 14:31 728648 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys 2010-11-11 14:31 . 2010-11-11 14:31 507568 ----a-w- c:\windows\system32\winload.exe 2010-11-11 14:31 . 2010-11-11 14:31 442920 ----a-w- c:\windows\system32\winresume.exe 2010-11-11 14:31 . 2010-11-11 14:31 1320960 ----a-w- c:\windows\system32\CertEnroll.dll 2010-11-11 14:30 . 2010-11-11 14:30 70656 ----a-w- c:\windows\system32\fontsub.dll . (((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret ))))))))))))))))))))))))))))))))))))))))))))) . . *Merk* tomme oppføringer & gyldige standardoppføringer vises ikke REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files\BitTorrentBar\tbBitT.dll" [2010-11-29 3908192] [HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}] 2010-11-29 14:26 3908192 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}] 2010-11-29 14:26 3908192 ----a-w- c:\program files\BitTorrentBar\tbBitT.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files\BitTorrentBar\tbBitT.dll" [2010-11-29 3908192] "{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngine.dll" [2010-11-29 3908192] [HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}] [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{88C7F2AA-F93F-432C-8F0E-B7D85967A527}"= "c:\program files\BitTorrentBar\tbBitT.dll" [2010-11-29 3908192] [HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BitTorrent"="c:\program files\BitTorrent\BitTorrent.exe" [2010-12-14 397688] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-12-14 2424560] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-10-03 13826664] "PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2010-04-12 180224] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-11-30 74752] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288] "Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072] c:\users\Gerhardsen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDockPlus2\ObjectDock.exe [N/A] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler] "{1984D045-52CF-49cd-DB77-08F378FEA4DB}"= "c:\program files\Stardock\ObjectDockPlus2\ODMenu.dll" [2010-03-24 511344] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [2010-04-29 26112] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-01-09 102448] R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [2010-03-20 101504] R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-12-13 1343400] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-12-13 691696] S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0403000.005\SYMDS.SYS [2009-10-15 328752] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0403000.005\SYMEFA.SYS [2010-04-22 173104] S1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20101123.003\BHDrvx86.sys [2010-11-23 691248] S1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0403000.005\ccHPx86.sys [2010-02-26 501888] S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20110107.002\IDSvix86.sys [2010-12-01 353912] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0403000.005\Ironx86.SYS [2010-04-29 116784] S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\System32\Drivers\N360\0403000.005\SYMTDIV.SYS [2010-05-06 339504] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 N360;Norton 360;c:\program files\Norton 360\Engine\4.3.0.5\ccSvcHst.exe [2010-02-26 126392] S2 SesamService;Sesam Control Service;c:\program files\Telenor\mobilt bredband\Sesam\BIN\SecMIPService.exe [2009-02-17 1237800] S3 ATSwpWDF;AuthenTec TruePrint USB WBF WDF Driver;c:\windows\system32\Drivers\ATSwpWDF.sys [2009-12-03 625224] S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000] S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360] S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992] S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336] S3 wtsmpadap;Sesam Virtual Adapter;c:\windows\system32\DRIVERS\wtsmpadap.sys [2009-01-30 39720] S3 WtSmpFlt;Sesam Adapter;c:\windows\system32\DRIVERS\wtsmpflt.sys [2009-01-30 277032] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr . . ------- Tilleggsskanning ------- . uStart Page = hxxp://www.google.no/ IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL FF - ProfilePath - c:\users\Gerhardsen\AppData\Roaming\Mozilla\Firefox\Profiles\9djpbfmq.default\ FF - prefs.js: browser.startup.homepage - www.google.no FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard FF - Ext: BitTorrentBar Community Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - %profile%\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527} FF - Ext: Norton IPS: {BBDA0591-3099-440a-AA10-41764D9DB4DB} - c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn FF - Ext: Norton Toolbar: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62} - c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\N360] "ImagePath"="\"c:\program files\Norton 360\Engine\4.3.0.5\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\4.3.0.5\diMaster.dll\" /prefetch:1" . --------------------- LÅSTE REGISTERNØKLER --------------------- [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . --------------------- DLL'er Lastet Av Kjørende Prosesser --------------------- - - - - - - - > 'Explorer.exe'(5332) c:\program files\Stardock\ObjectDockPlus2\ODMenu.dll . Tidspunkt ferdig: 2011-01-10 16:08:13 ComboFix-quarantined-files.txt 2011-01-10 15:08 ComboFix2.txt 2011-01-10 01:19 ComboFix3.txt 2011-01-10 00:57 Pre-Run: 120 371 113 984 bytes free Post-Run: 120 327 729 152 bytes free - - End Of File - - EF82EA6277C5054461FD9C2EFA8FDFFA