Annie_P Skrevet 26. juli 2008 Forfatter Del Skrevet 26. juli 2008 Har installert og kjørt MBAM. Under er loggen. Prøve Hijack nå. MBAM-logg: Malwarebytes' Anti-Malware 1.23 Database versjon: 993 Windows 5.1.2600 Service Pack 2 09:12:36 26.07.2008 mbam-log-7-26-2008 (09-12-18).txt Skanntype: Rask Skann Objekter skannet: 40414 Tid tilbakelagt: 5 minute(s), 59 second(s) Minneprosesser infisert: 0 Minnemoduler infisert: 0 Registernøkler infisert: 2 Registerverdier infisert: 0 Registerfiler infisert: 0 Mapper infisert: 0 Filer infisert: 1 Minneprosesser infisert: (Ingen mistenkelige filer funnet) Minnemoduler infisert: (Ingen mistenkelige filer funnet) Registernøkler infisert: HKEY_CLASSES_ROOT\fdkowvbp.bgrv (Trojan.FakeAlert) -> No action taken. HKEY_CLASSES_ROOT\fdkowvbp.toolbar.1 (Trojan.FakeAlert) -> No action taken. Registerverdier infisert: (Ingen mistenkelige filer funnet) Registerfiler infisert: (Ingen mistenkelige filer funnet) Mapper infisert: (Ingen mistenkelige filer funnet) Filer infisert: C:\WINDOWS\grswptdl.exe (Trojan.FakeAlert) -> No action taken. Lenke til kommentar
Annie_P Skrevet 26. juli 2008 Forfatter Del Skrevet 26. juli 2008 Her kommer Hijack-loggen. Maskinen ser forøvrig ut til å fungere ok for øyeblikket. Får ikke opp alle sidene om kjøp av antivirusprogram, og ikononen jeg savnet i går er tilbake. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 09:17, on 26.07.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe C:\Programfiler\D-Link\AirPlus Xtreme G\AirPlusCFG.exe C:\Programfiler\Alpha Networks\ANIWZCS Service\WZCSLDR.exe C:\Programfiler\SweetIM\Messenger\SweetIM.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe C:\HP\KBD\KBD.EXE C:\Programfiler\Java\jre1.5.0_05\bin\jusched.exe C:\Programfiler\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\WINDOWS\system32\ctfmon.exe C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Programfiler\HP\Digital Imaging\bin\hpqtra08.exe C:\Programfiler\Windows Live\Messenger\msnmsgr.exe C:\Programfiler\HP\Digital Imaging\bin\hpqSTE08.exe C:\Programfiler\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\ALCXMNTR.EXE C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe c:\windows\system\hpsysdrv.exe C:\Programfiler\Fellesfiler\Real\Update_OB\realsched.exe C:\Programfiler\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programfiler\AVG\AVG8\avgtoolbar.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programfiler\google\googletoolbar2.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programfiler\google\googletoolbar2.dll O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programfiler\AVG\AVG8\avgtoolbar.dll O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [HPBootOp] "C:\Programfiler\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run O4 - HKLM\..\Run: [HP Software Update] C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [D-Link AirPlus Xtreme G] C:\Programfiler\D-Link\AirPlus Xtreme G\AirPlusCFG.exe O4 - HKLM\..\Run: [ANIWZCSService] C:\Programfiler\Alpha Networks\ANIWZCS Service\WZCSLDR.exe O4 - HKLM\..\Run: [sweetIM] C:\Programfiler\SweetIM\Messenger\SweetIM.exe O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.5.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [TkBellExe] "realsched.exe" -osboot O4 - HKCU\..\Run: [swg] C:\Programfiler\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE') O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user') O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programfiler\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: Hurtigstart for Adobe Reader.lnk = C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_05\bin\npjpi150_05.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_05\bin\npjpi150_05.dll O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programfiler\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: Tilkoblingshjelp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra 'Tools' menuitem: Tilkoblingshjelp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com.edgesuite.net/co...ex/qtplugin.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock...ash/swflash.cab O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://eurofoto.no/uploader/ImageUploader4.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programfiler\AVG\AVG8\avgpp.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FELLES~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: avgrsstx.dll O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe -- End of file - 8573 bytes Lenke til kommentar
norbat Skrevet 26. juli 2008 Del Skrevet 26. juli 2008 Du må la MBAM slette det den finner: Det kommer en meldingsboks om at scannen er ferdig, klikk Ok Klikk på Vis resultat-knappen.Hvis det er funnet malware, vil du nå se hva som er funnet. Klikk så på Fjern valgte -knappen for å fjerne malwaren som evt. ble funnet. Post gjerne loggen. Oppdater java'en: http://java.com/en/download/index.jsp Sjekket du filene som ble nevnt på Virustotal? Hvis ikke, gjør det og gi tilbakemelding på om det blir funnet noe på dem. Det skulle holde å sjekke fila C:\WINDOWS\system32\mswmnnove.dll Lenke til kommentar
Annie_P Skrevet 26. juli 2008 Forfatter Del Skrevet 26. juli 2008 Du må la MBAM slette det den finner: Det kommer en meldingsboks om at scannen er ferdig, klikk Ok Klikk på Vis resultat-knappen.Hvis det er funnet malware, vil du nå se hva som er funnet. Klikk så på Fjern valgte -knappen for å fjerne malwaren som evt. ble funnet. Post gjerne loggen. Oppdater java'en: http://java.com/en/download/index.jsp Sjekket du filene som ble nevnt på Virustotal? Hvis ikke, gjør det og gi tilbakemelding på om det blir funnet noe på dem. Det skulle holde å sjekke fila C:\WINDOWS\system32\mswmnnove.dll Jeg har opopdater java. Har også kjørt MBAM. Den fant to infiserte filer. Har postet loggen jeg fikk etter at jeg klikket på fhjerning. Har også kjørt Virustotal, det ser ikke ut som den fant noe. Prøver å lime inn rapporten derfra. Her loggen etter fjerning: Malwarebytes' Anti-Malware 1.23 Database versjon: 994 Windows 5.1.2600 Service Pack 2 19:55:19 26.07.2008 mbam-log-7-26-2008 (19-55-19).txt Skanntype: Rask Skann Objekter skannet: 40323 Tid tilbakelagt: 7 minute(s), 23 second(s) Minneprosesser infisert: 0 Minnemoduler infisert: 0 Registernøkler infisert: 2 Registerverdier infisert: 0 Registerfiler infisert: 0 Mapper infisert: 0 Filer infisert: 0 Minneprosesser infisert: (Ingen mistenkelige filer funnet) Minnemoduler infisert: (Ingen mistenkelige filer funnet) Registernøkler infisert: HKEY_CLASSES_ROOT\fdkowvbp.bgrv (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\fdkowvbp.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully. Registerverdier infisert: (Ingen mistenkelige filer funnet) Registerfiler infisert: (Ingen mistenkelige filer funnet) Mapper infisert: (Ingen mistenkelige filer funnet) Filer infisert: (Ingen mistenkelige filer funnet) File mswmnnove.dll received on 07.26.2008 20:07:57 (CET) Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED Result: 0/34 (0%) Loading server information... Your file is queued in position: 1. Estimated start time is between 40 and 58 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Compact Print results Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result AhnLab-V3 2008.7.26.0 2008.07.25 - AntiVir 7.8.1.12 2008.07.25 - Authentium 5.1.0.4 2008.07.26 - Avast 4.8.1195.0 2008.07.26 - AVG 8.0.0.130 2008.07.25 - BitDefender 7.2 2008.07.26 - CAT-QuickHeal 9.50 2008.07.25 - ClamAV 0.93.1 2008.07.26 - DrWeb 4.44.0.09170 2008.07.26 - eSafe 7.0.17.0 2008.07.24 - eTrust-Vet 31.6.5983 2008.07.26 - Ewido 4.0 2008.07.26 - F-Prot 4.4.4.56 2008.07.26 - F-Secure 7.60.13501.0 2008.07.26 - Fortinet 3.14.0.0 2008.07.26 - GData 2.0.7306.1023 2008.07.26 - Ikarus T3.1.1.34.0 2008.07.26 - Kaspersky 7.0.0.125 2008.07.26 - McAfee 5347 2008.07.25 - Microsoft 1.3704 2008.07.26 - NOD32v2 3300 2008.07.25 - Norman 5.80.02 2008.07.25 - Panda 9.0.0.4 2008.07.26 - PCTools 4.4.2.0 2008.07.26 - Rising 20.54.52.00 2008.07.26 - Sophos 4.31.0 2008.07.26 - Sunbelt 3.1.1536.1 2008.07.25 - Symantec 10 2008.07.26 - TheHacker 6.2.96.389 2008.07.25 - TrendMicro 8.700.0.1004 2008.07.26 - VBA32 3.12.8.1 2008.07.26 - ViRobot 2008.7.26.1311 2008.07.26 - VirusBuster 4.5.11.0 2008.07.26 - Webwasher-Gateway 6.6.2 2008.07.26 - Additional information File size: 9844 bytes MD5...: f8a067cf4e34668f3e1dedb6d51a6588 SHA1..: fc06e27d83685f3019be8f25ce53677bcd581301 SHA256: 03102a91f033953d619361c85aa596dadca44f953cfeb53468760fae7f5f2109 SHA512: 751cee5dac23c37f8f2a7c9c222b03f9a24db7c0c7e8d9cf0dfb730a7ad45e41 69e71c3de9ab4dfaa52951855c4c816a73450b5538a7d7ae9475fa2ee87a6ca1 PEiD..: - PEInfo: - Lenke til kommentar
Annie_P Skrevet 26. juli 2008 Forfatter Del Skrevet 26. juli 2008 Nå fikk jeg opp en melding om infisert fil fra AVG Resident shiled alert. Det står at filen under er infisert.....Ser ut som om viruset heter Vundo. Noen som vet om dette er det samme som jeg har slitt med før? Lenke til kommentar
norbat Skrevet 26. juli 2008 Del Skrevet 26. juli 2008 (endret) Ok, Filene gir ingen treff på noen søkemotorer. Dette indikerer at filene kan tilhøre en eller annen infeksjon. Det du kunne ha gjort, er å høyreklikke på filene og byttet filnavn på de. Hvis alt kjører normalt og ingen programmer som du bruker fungerer greit, så kan du slette filene etter noen dager. Det gjelder altså filene: C:\WINDOWS\system32\msrun9er-.dll -> høyreklikk og legg til filendelsen bak -> msrun9er-.dll.bak C:\WINDOWS\system32\mswmnnove.dll -> høyreklikk og legg til filendelsen bak -> mswmnove.dll.bak Ut over dette ser ting og tang bra ut. Du kan fjerne combofix ved å skrive combofix /u i kjør-feltet (start->kjør). Behold gjerne SAS og/eller MBAM. Edit: Hvilken fil er det du mener? Endret 26. juli 2008 av norbat Lenke til kommentar
snippsat Skrevet 26. juli 2008 Del Skrevet 26. juli 2008 han mener vundo Jøss vundo er en type infeksjon. Denne kan lage 100vis av filer. Derfor spør norbat,viss du hadde følgt med litt her så skjønner du kansje at han ikke skal ha noe hjelp innen dette feltet Lenke til kommentar
Annie_P Skrevet 28. juli 2008 Forfatter Del Skrevet 28. juli 2008 Ok, Filene gir ingen treff på noen søkemotorer. Dette indikerer at filene kan tilhøre en eller annen infeksjon. Det du kunne ha gjort, er å høyreklikke på filene og byttet filnavn på de. Hvis alt kjører normalt og ingen programmer som du bruker fungerer greit, så kan du slette filene etter noen dager. Det gjelder altså filene: C:\WINDOWS\system32\msrun9er-.dll -> høyreklikk og legg til filendelsen bak -> msrun9er-.dll.bak C:\WINDOWS\system32\mswmnnove.dll -> høyreklikk og legg til filendelsen bak -> mswmnove.dll.bak Ut over dette ser ting og tang bra ut. Du kan fjerne combofix ved å skrive combofix /u i kjør-feltet (start->kjør). Behold gjerne SAS og/eller MBAM. Edit: Hvilken fil er det du mener? Jeg finner ikke filene som skal ha ny filending. Har gått gjennom windows-mappen og brukt "søk" funksjonen. Kan disse filene være skjult? (Bruker XP, ikke Vista) Lenke til kommentar
Annie_P Skrevet 28. juli 2008 Forfatter Del Skrevet 28. juli 2008 Jeg får fremdeles opp ny virusvarsel. AVG gir melding om tre ulike virus: Trojan Horse Clicker.OVI Trojan Horse Clicker.OVG Trojan Horse Clicker.OVF Jeg klikker på "Remove threats", men etter en stund gåtr alarmen igjen. Lenke til kommentar
Annie_P Skrevet 28. juli 2008 Forfatter Del Skrevet 28. juli 2008 Hva med systemrestore, har du tilgang til det? Og rensing etterpå(gammel restore må vekk)... Tror jeg har tilgang til system restore (hvis det er installsjonen slik den var dajeg kjøpte maskinen? Dette ligger på D). Vil helst prøve å løse problemet slik at jeg slipper å bruke restore.....er så mye drivere og oppdateringer at det blir utrolig tungvint å kjøre restore. Nå tenkte jeg på systemgjenoppretting, ikke nyinstall. av OS.. Jeg er ikke helt inne i begrepene her.....Når jeg kjører systemgjenoppretting er det mye som endrer seg på maskinen selv om de gamle mappene ligger der.....vet ikke helt hva som skjer...det jeg har gjort tidliger er full formatering og ny installasjon. Det ser også ut som Compaq-maskinen lager noe som systegjenopprettingspunkt. Etter det jeg forstår skal det være mulig å gå tilbake til sist disse punktene og få et oppsett av maskinen som er identisk med det som var på "gjenopporettinsgstispunktet". Jeg greier imidlertid ikke å finne disse punktene. Når jeg følger manualen ender jeg bare opp med å nyinstallere Windows. Mulig jeg har misforstått dette med gjenopprettingspunkt...? Lenke til kommentar
norbat Skrevet 28. juli 2008 Del Skrevet 28. juli 2008 Last ned ny combofix, kjør programmet og post loggen. Lenke til kommentar
Annie_P Skrevet 28. juli 2008 Forfatter Del Skrevet 28. juli 2008 Last ned ny combofix, kjør programmet og post loggen. ComboFix 08-07-24.3 - Compaq_Eier 2008-07-28 23:03:24.4 - NTFSx86 Running from: C:\Documents and Settings\Compaq_Eier\Skrivebord\ComboFix.exe . ((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-28 ))))))))))))))))))))))))))))))) . 2008-07-26 19:25 . 2008-07-26 19:25 <DIR> d-------- C:\Programfiler\Sun 2008-07-26 19:25 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl 2008-07-26 09:23 . 2008-07-28 19:29 <DIR> dr-h----- C:\Documents and Settings\Compaq_Eier\Siste 2008-07-26 09:17 . 2008-07-26 09:17 <DIR> d-------- C:\Programfiler\Trend Micro 2008-07-26 09:02 . 2008-07-26 09:02 <DIR> d-------- C:\Programfiler\Malwarebytes' Anti-Malware 2008-07-26 09:02 . 2008-07-26 09:02 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\Malwarebytes 2008-07-26 09:02 . 2008-07-26 09:02 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Malwarebytes 2008-07-26 09:02 . 2008-07-23 20:21 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2008-07-26 09:02 . 2008-07-23 20:21 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2008-07-25 23:31 . 2006-01-03 05:40 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS 2008-07-25 23:31 . 2008-06-12 06:34 <DIR> dr------- C:\Documents and Settings\Administrator\Start-meny 2008-07-25 23:31 . 2005-10-20 23:51 <DIR> d--h----- C:\Documents and Settings\Administrator\Skrivere 2008-07-25 23:31 . 2005-10-20 23:51 <DIR> d-------- C:\Documents and Settings\Administrator\Skrivebord 2008-07-25 23:31 . 2008-06-12 06:34 <DIR> dr-h----- C:\Documents and Settings\Administrator\Siste 2008-07-25 23:31 . 2008-06-12 06:34 <DIR> dr-h----- C:\Documents and Settings\Administrator\Programdata 2008-07-25 23:31 . 2008-06-12 06:34 <DIR> dr------- C:\Documents and Settings\Administrator\Mine dokumenter 2008-07-25 23:31 . 2005-10-27 04:33 <DIR> d--h----- C:\Documents and Settings\Administrator\Maler 2008-07-25 23:31 . 2008-07-28 23:06 <DIR> d--h----- C:\Documents and Settings\Administrator\Lokale innstillinger 2008-07-25 23:31 . 2008-06-11 22:48 <DIR> dr------- C:\Documents and Settings\Administrator\Favoritter 2008-07-25 23:31 . 2005-10-20 23:51 <DIR> d--h----- C:\Documents and Settings\Administrator\AndrMask 2008-07-25 23:31 . 2008-07-25 23:31 <DIR> d-------- C:\Documents and Settings\Administrator 2008-07-25 22:16 . 2008-07-25 22:16 <DIR> d--hs---- C:\WINDOWS\ftpcache 2008-07-24 21:02 . 2008-07-24 21:02 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\AVS4YOU 2008-07-24 20:53 . 2008-07-24 20:53 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\AVS4YOU 2008-07-24 20:49 . 2008-07-24 20:53 <DIR> d-------- C:\Programfiler\Fellesfiler\AVSMedia 2008-07-24 20:42 . 2008-07-24 20:54 <DIR> d-------- C:\Programfiler\AVS4YOU 2008-07-24 20:32 . 2008-07-28 17:59 <DIR> d--h----- C:\$AVG8.VAULT$ 2008-07-20 21:34 . 2008-07-20 21:34 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-07-20 21:34 . 2008-07-20 21:34 1,409 --a------ C:\WINDOWS\QTFont.for 2008-07-18 21:40 . 2004-08-04 01:03 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll 2008-07-18 21:40 . 2001-10-06 14:02 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll 2008-07-18 18:20 . 2008-07-18 18:20 <DIR> d-------- C:\WINDOWS\.jagex_cache_32 2008-07-18 18:20 . 2008-07-18 18:20 0 --a------ C:\Documents and Settings\Compaq_Eier\jagex_runescape_preferences.dat 2008-07-18 17:49 . 2008-07-18 17:49 <DIR> d-------- C:\Programfiler\Guitar Pro 5 2008-07-18 16:07 . 2008-07-18 16:07 1,409 --a------ C:\WINDOWS\system32\tmpEE08F.FOT 2008-07-14 18:37 . 2008-07-16 22:13 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\U3 2008-07-13 22:02 . 2008-07-18 18:16 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\skypePM 2008-07-13 22:02 . 2008-07-13 22:02 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat 2008-07-13 21:51 . 2008-07-13 21:51 <DIR> d-------- C:\Programfiler\Skype 2008-07-13 21:51 . 2008-07-13 21:51 <DIR> d-------- C:\Programfiler\Fellesfiler\Skype 2008-07-13 21:51 . 2008-07-18 21:49 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\Skype 2008-07-13 21:51 . 2008-07-13 21:51 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Skype 2008-07-13 21:44 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys 2008-07-13 21:44 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\dllcache\usbaudio.sys 2008-07-13 21:44 . 2004-08-04 01:03 21,504 --a------ C:\WINDOWS\system32\hidserv.dll 2008-07-13 21:44 . 2004-08-04 01:03 21,504 --a------ C:\WINDOWS\system32\dllcache\hidserv.dll 2008-07-13 21:44 . 2001-08-17 22:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys 2008-07-13 21:44 . 2001-08-17 22:02 9,600 --a------ C:\WINDOWS\system32\dllcache\hidusb.sys 2008-07-13 21:04 . 2008-07-13 21:04 268 --ah----- C:\sqmdata00.sqm 2008-07-13 21:04 . 2008-07-13 21:04 244 --ah----- C:\sqmnoopt00.sqm . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-28 15:33 --------- d---a-w C:\Documents and Settings\All Users\Programdata\TEMP 2008-07-26 17:25 --------- d-----w C:\Programfiler\Java 2008-07-20 19:34 --------- d-----w C:\Programfiler\QuickTime 2008-07-19 07:44 96,520 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys 2008-07-19 07:44 76,040 ----a-w C:\WINDOWS\system32\drivers\avgtdix.sys 2008-07-19 07:44 10,520 ----a-w C:\WINDOWS\system32\avgrsstx.dll 2008-07-18 20:16 --------- d-----w C:\Documents and Settings\All Users\Programdata\Microsoft Help 2008-07-18 14:09 --------- d-----w C:\Programfiler\PonyGirl2 2008-07-13 19:38 --------- d-----w C:\Documents and Settings\Compaq_Eier\Programdata\HP 2008-06-20 17:43 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll 2008-06-20 17:43 246,784 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll 2008-06-20 17:43 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys 2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys 2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys 2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys 2008-06-19 20:58 1,024 ----a-w C:\Documents and Settings\All Users\Programdata\pdfdoc2.dll 2008-06-18 20:44 --------- d-----w C:\Programfiler\CCleaner 2008-06-15 21:13 --------- d-----w C:\Documents and Settings\All Users\Programdata\WLInstaller 2008-06-14 18:00 272,256 ------w C:\WINDOWS\system32\drivers\bthport.sys 2008-06-14 18:00 272,256 ------w C:\WINDOWS\system32\dllcache\bthport.sys 2008-06-14 09:17 --------- d-----w C:\Programfiler\MSBuild 2008-06-14 09:17 --------- d-----w C:\Programfiler\Microsoft Works 2008-06-14 09:16 --------- d-----w C:\Programfiler\Microsoft.NET 2008-06-14 05:40 --------- d-----w C:\Programfiler\Microsoft CAPICOM 2.1.0.2 2008-06-14 05:33 --------- d-----w C:\Programfiler\MSXML 4.0 2008-06-13 12:28 --------- d-----w C:\Documents and Settings\All Users\Programdata\QuickTime 2008-06-12 21:18 --------- d-----w C:\Documents and Settings\All Users\Programdata\SUPERAntiSpyware.com 2008-06-12 21:17 --------- d-----w C:\Programfiler\SUPERAntiSpyware 2008-06-12 21:17 --------- d-----w C:\Programfiler\Fellesfiler\Wise Installation Wizard 2008-06-12 21:17 --------- d-----w C:\Documents and Settings\Compaq_Eier\Programdata\SUPERAntiSpyware.com 2008-06-12 17:20 --------- d-----w C:\Programfiler\directx 2008-06-12 17:16 --------- d-----w C:\Programfiler\Eidos Interactive 2008-06-12 13:26 --------- d-----w C:\Programfiler\SweetIM 2008-06-12 13:25 --------- d-----w C:\Documents and Settings\Compaq_Eier\Programdata\AVGTOOLBAR 2008-06-12 13:15 --------- d-----w C:\Programfiler\AVG 2008-06-12 13:15 --------- d-----w C:\Documents and Settings\All Users\Programdata\avg8 2008-06-12 12:46 --------- d-----w C:\Documents and Settings\All Users\Programdata\SweetIM 2008-06-12 11:28 --------- d-----w C:\Programfiler\Windows Live 2008-06-12 11:27 --------- dcsh--w C:\Programfiler\Fellesfiler\WindowsLiveInstaller 2008-06-11 20:54 --------- d-----w C:\Programfiler\HP 2008-06-11 20:54 --------- d-----w C:\Documents and Settings\All Users\Programdata\HP 2008-06-11 20:51 --------- d-----w C:\Programfiler\Fellesfiler\Hewlett-Packard 2008-06-11 20:49 --------- d-----w C:\Documents and Settings\Compaq_Eier\Programdata\HPQ 2008-06-11 20:46 1,869 --sha-r C:\WINDOWS\system32\drivers\103C_HP_CPC_RF147AA-UUW SR1939SC EL630_YC_0Pres_QCZB630_E63NOheREA1_48_IAMETHYST-M_SMSI_V1.0_B3.48_T060324_WXH2_L414_M447_J160_7AMD_8Athlon 64_92.19_#060918_N10EC8139_Z_G10025954_OHL-DT-ST DVDRRW GSA-H21N_DLCD905A.MRK 2008-06-11 19:52 --------- d-----w C:\Programfiler\Google 2008-06-11 19:44 --------- d-----w C:\Programfiler\Fellesfiler\Adobe 2008-06-11 19:42 --------- d-----w C:\Documents and Settings\Compaq_Eier\Programdata\AdobeUM 2008-06-11 19:10 --------- d--h--w C:\Programfiler\InstallShield Installation Information 2008-06-11 19:10 --------- d-----w C:\Programfiler\D-Link 2008-06-11 19:10 --------- d-----w C:\Programfiler\Alpha Networks 2008-06-11 19:07 --------- d-----w C:\Programfiler\Fellesfiler\Symantec Shared 2008-06-11 19:07 --------- d-----w C:\Documents and Settings\All Users\Programdata\Symantec 2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys 2008-05-07 05:16 1,290,752 ----a-w C:\WINDOWS\system32\quartz.dll 2008-05-07 05:16 1,290,752 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll . ((((((((((((((((((((((((((((( snapshot@2008-07-25_23.52.34.20 ))))))))))))))))))))))))))))))))))))))))) . - 2005-08-26 21:55:46 49,248 ----a-w C:\WINDOWS\system32\java.exe + 2008-06-09 23:21:01 135,168 ----a-w C:\WINDOWS\system32\java.exe - 2005-08-26 21:55:58 49,250 ----a-w C:\WINDOWS\system32\javaw.exe + 2008-06-09 23:21:04 135,168 ----a-w C:\WINDOWS\system32\javaw.exe - 2005-08-27 00:14:46 127,078 ----a-w C:\WINDOWS\system32\javaws.exe + 2008-06-10 00:32:34 139,264 ----a-w C:\WINDOWS\system32\javaws.exe - 2008-01-25 19:33:26 122,880 ----a-w C:\WINDOWS\system32\msrun9er-.dll + 2007-07-25 15:33:09 122,880 ----a-w C:\WINDOWS\system32\msrun9er-.dll - 2007-01-30 20:32:01 9,844 ----a-w C:\WINDOWS\system32\mswmnnove.dll + 2006-06-05 21:40:23 9,844 ----a-w C:\WINDOWS\system32\mswmnnove.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Programfiler\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-06-11 21:18 171448] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360] "MsnMsgr"="C:\Programfiler\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184] "SUPERAntiSpyware"="C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544] "9c7ce"="c:\programfiler\qtvxhhfjwzafh\uehjlvv.exe" [2006-03-15 00:15 1554066] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 23:14 237568] "HPBootOp"="C:\Programfiler\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 23:34 249856] "HP Software Update"="C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152] "D-Link AirPlus Xtreme G"="C:\Programfiler\D-Link\AirPlus Xtreme G\AirPlusCFG.exe" [2003-11-04 17:00 2502656] "ANIWZCSService"="C:\Programfiler\Alpha Networks\ANIWZCS Service\WZCSLDR.exe" [2003-08-21 16:12 32768] "SweetIM"="C:\Programfiler\SweetIM\Messenger\SweetIM.exe" [2008-03-27 19:31 111928] "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-19 09:44 1232152] "GrooveMonitor"="C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016] "KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 16:44 61440] "SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784] "QuickTime Task"="C:\Programfiler\QuickTime\qttask.exe" [2008-07-20 21:34 413696] "9c7ce"="c:\programfiler\qtvxhhfjwzafh\uehjlvv.exe" [2006-03-15 00:15 1554066] "TkBellExe"="realsched.exe" [bU] C:\Documents and Settings\Administrator\Start-meny\Programmer\Oppstart\ Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-01-03 05:07:26 27136] C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\ HP Digital Imaging Monitor.lnk - C:\Programfiler\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472] Hurtigstart for Adobe Reader.lnk - C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2007-04-19 13:41 294912 C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=avgrsstx.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hposid01.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqCopy.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpfccopy.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpoews01.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"= "C:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Programfiler\\Windows Live\\Messenger\\livecall.exe"= "C:\\Programfiler\\AVG\\AVG8\\avgupd.exe"= "C:\\Programfiler\\AVG\\AVG8\\avgemc.exe"= "C:\\Programfiler\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "C:\\Programfiler\\Microsoft Office\\Office12\\GROOVE.EXE"= "C:\\Programfiler\\Microsoft Office\\Office12\\ONENOTE.EXE"= "C:\\Programfiler\\Skype\\Phone\\Skype.exe"= R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-19 09:44] R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-19 09:44] R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-19 09:44] R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-19 09:44] R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys [2003-10-22 15:27] . Contents of the 'Scheduled Tasks' folder "2008-07-13 19:13:39 C:\WINDOWS\Tasks\Internett-tjenester.job" - C:\Programfiler\Hewlett-Packard\SDP\HPSdpApp.exea/remind /LaunchPoint reminder /App C:\Programfiler\Hewlett-Packard\Internet Services\StartIS.aml . . ------- Supplementary Scan ------- . R0 -: HKCU-Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=NB_NO&c=63&bd=PRESARIO&pf=desktop R0 -: HKCU-Main,Default_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=NB_NO&c=63&bd=PRESARIO&pf=desktop R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 R0 -: HKLM-Main,Search Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=NB_NO&c=63&bd=PRESARIO&pf=desktop R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=NB_NO&c=63&bd=PRESARIO&pf=desktop O8 -: E&ksporter til Microsoft Excel - C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-28 23:06:37 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... C:\WINDOWS\system32\msrun9er-.dll 122880 bytes executable scan completed successfully hidden files: 1 ************************************************************************** . Completion time: 2008-07-28 23:07:48 ComboFix-quarantined-files.txt 2008-07-28 21:07:44 ComboFix2.txt 2008-07-26 17:36:36 ComboFix3.txt 2008-07-25 22:37:04 ComboFix4.txt 2008-07-25 21:54:21 Pre-Run: 135,822,139,392 byte ledig Post-Run: 135,941,431,296 byte ledig 228 --- E O F --- 2008-07-22 07:20:29 Lenke til kommentar
snippsat Skrevet 29. juli 2008 Del Skrevet 29. juli 2008 (endret) Kopiere fet tekst under bildet->åpne notisblokk og lim inn. Lagre på skrivebordet som CFScript.txt Gjør som på bildet combofix vil starte,Post logg c:\combofix.txt File:: C:\WINDOWS\system32\msrun9er-.dll C:\WINDOWS\system32\msrun9er-.dll C:\WINDOWS\system32\mswmnnove.dll C:\WINDOWS\system32\mswmnnove.dll Registry:: [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "9c7ce"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "9c7ce"=- --- Last ned kjør CCleaner 'Valg'->'Avansert'. Fjern avkryssingen framfor: "bare slett midlertidige filer som er eldere enn 48 t. Kjør og register-renser"svar ja til og reparere"-->backup svar ja når du blir spørt. Kjør register-renser et par ganger til alle feil er borte. --- I post #19 fikk du ikke CFCript.txt til og virke. Post combofix loggen så vi ser det virker. --- Restart --- En runde med MBAM --- Scann nå med AVG Finner den noe nå må du ta med plassering,altså stien til filen. Ikke hva det er som i post #30 Endret 29. juli 2008 av SNIPPSAT Lenke til kommentar
Annie_P Skrevet 31. juli 2008 Forfatter Del Skrevet 31. juli 2008 ComboFix 08-07-24.3 - Compaq_Eier 2008-07-31 9:38:37.5 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1044.18.135 [GMT 2:00] Running from: C:\Documents and Settings\Compaq_Eier\Skrivebord\ComboFix.exe Command switches used :: C:\Documents and Settings\Compaq_Eier\Skrivebord\CFScript.txt * Created a new restore point FILE :: C:\WINDOWS\system32\msrun9er-.dll C:\WINDOWS\system32\mswmnnove.dll . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\system32\msrun9er-.dll C:\WINDOWS\system32\mswmnnove.dll . ((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-31 ))))))))))))))))))))))))))))))) . 2008-07-31 09:31 . 2008-07-31 09:34 <DIR> dr-h----- C:\Documents and Settings\Compaq_Eier\Siste 2008-07-30 22:44 . 2008-07-30 22:44 268 --ah----- C:\sqmdata02.sqm 2008-07-30 22:44 . 2008-07-30 22:44 244 --ah----- C:\sqmnoopt02.sqm 2008-07-29 17:09 . 2008-07-29 17:20 <DIR> d-------- C:\Programfiler\ZC Video Converter 2008-07-29 16:33 . 2008-07-29 16:33 <DIR> d-------- C:\Programfiler\Red Kawa 2008-07-29 16:33 . 2008-07-29 16:33 <DIR> d-------- C:\Programfiler\AviSynth 2.5 2008-07-29 00:16 . 2008-07-29 00:16 268 --ah----- C:\sqmdata01.sqm 2008-07-29 00:16 . 2008-07-29 00:16 244 --ah----- C:\sqmnoopt01.sqm 2008-07-26 19:25 . 2008-07-26 19:25 <DIR> d-------- C:\Programfiler\Sun 2008-07-26 19:25 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl 2008-07-26 09:17 . 2008-07-26 09:17 <DIR> d-------- C:\Programfiler\Trend Micro 2008-07-26 09:02 . 2008-07-26 09:02 <DIR> d-------- C:\Programfiler\Malwarebytes' Anti-Malware 2008-07-26 09:02 . 2008-07-26 09:02 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\Malwarebytes 2008-07-26 09:02 . 2008-07-26 09:02 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Malwarebytes 2008-07-26 09:02 . 2008-07-23 20:21 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2008-07-26 09:02 . 2008-07-23 20:21 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2008-07-25 23:31 . 2006-01-03 05:40 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS 2008-07-25 23:31 . 2008-06-12 06:34 <DIR> dr------- C:\Documents and Settings\Administrator\Start-meny 2008-07-25 23:31 . 2005-10-20 23:51 <DIR> d--h----- C:\Documents and Settings\Administrator\Skrivere 2008-07-25 23:31 . 2005-10-20 23:51 <DIR> d-------- C:\Documents and Settings\Administrator\Skrivebord 2008-07-25 23:31 . 2008-06-12 06:34 <DIR> dr-h----- C:\Documents and Settings\Administrator\Siste 2008-07-25 23:31 . 2008-06-12 06:34 <DIR> dr-h----- C:\Documents and Settings\Administrator\Programdata 2008-07-25 23:31 . 2008-06-12 06:34 <DIR> dr------- C:\Documents and Settings\Administrator\Mine dokumenter 2008-07-25 23:31 . 2005-10-27 04:33 <DIR> d--h----- C:\Documents and Settings\Administrator\Maler 2008-07-25 23:31 . 2008-07-31 09:40 <DIR> d--h----- C:\Documents and Settings\Administrator\Lokale innstillinger 2008-07-25 23:31 . 2008-06-11 22:48 <DIR> dr------- C:\Documents and Settings\Administrator\Favoritter 2008-07-25 23:31 . 2005-10-20 23:51 <DIR> d--h----- C:\Documents and Settings\Administrator\AndrMask 2008-07-25 23:31 . 2008-07-25 23:31 <DIR> d-------- C:\Documents and Settings\Administrator 2008-07-25 22:16 . 2008-07-25 22:16 <DIR> d--hs---- C:\WINDOWS\ftpcache 2008-07-24 21:02 . 2008-07-24 21:02 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\AVS4YOU 2008-07-24 20:53 . 2008-07-24 20:53 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\AVS4YOU 2008-07-24 20:49 . 2008-07-24 20:53 <DIR> d-------- C:\Programfiler\Fellesfiler\AVSMedia 2008-07-24 20:42 . 2008-07-24 20:54 <DIR> d-------- C:\Programfiler\AVS4YOU 2008-07-24 20:32 . 2008-07-29 10:44 <DIR> d--h----- C:\$AVG8.VAULT$ 2008-07-20 21:34 . 2008-07-20 21:34 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-07-20 21:34 . 2008-07-20 21:34 1,409 --a------ C:\WINDOWS\QTFont.for 2008-07-18 21:40 . 2004-08-04 01:03 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll 2008-07-18 21:40 . 2001-10-06 14:02 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll 2008-07-18 18:20 . 2008-07-18 18:20 <DIR> d-------- C:\WINDOWS\.jagex_cache_32 2008-07-18 18:20 . 2008-07-18 18:20 0 --a------ C:\Documents and Settings\Compaq_Eier\jagex_runescape_preferences.dat 2008-07-18 17:49 . 2008-07-18 17:49 <DIR> d-------- C:\Programfiler\Guitar Pro 5 2008-07-18 16:07 . 2008-07-18 16:07 1,409 --a------ C:\WINDOWS\system32\tmpEE08F.FOT 2008-07-14 18:37 . 2008-07-16 22:13 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\U3 2008-07-13 22:02 . 2008-07-18 18:16 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\skypePM 2008-07-13 22:02 . 2008-07-13 22:02 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat 2008-07-13 21:51 . 2008-07-13 21:51 <DIR> d-------- C:\Programfiler\Skype 2008-07-13 21:51 . 2008-07-13 21:51 <DIR> d-------- C:\Programfiler\Fellesfiler\Skype 2008-07-13 21:51 . 2008-07-18 21:49 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\Skype 2008-07-13 21:51 . 2008-07-13 21:51 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Skype 2008-07-13 21:44 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys 2008-07-13 21:44 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\dllcache\usbaudio.sys 2008-07-13 21:44 . 2004-08-04 01:03 21,504 --a------ C:\WINDOWS\system32\hidserv.dll 2008-07-13 21:44 . 2004-08-04 01:03 21,504 --a------ C:\WINDOWS\system32\dllcache\hidserv.dll 2008-07-13 21:44 . 2001-08-17 22:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys 2008-07-13 21:44 . 2001-08-17 22:02 9,600 --a------ C:\WINDOWS\system32\dllcache\hidusb.sys 2008-07-13 21:04 . 2008-07-13 21:04 268 --ah----- C:\sqmdata00.sqm 2008-07-13 21:04 . 2008-07-13 21:04 244 --ah----- C:\sqmnoopt00.sqm 2008-06-19 22:50 . 2008-06-19 22:50 <DIR> d-------- C:\Ny mappe 2008-06-19 22:47 . 2008-06-19 22:58 1,024 --a------ C:\Documents and Settings\All Users\Programdata\pdfdoc2.dll 2008-06-19 22:43 . 2001-10-29 01:42 116,224 --a------ C:\WINDOWS\system32\pdfmonnt.dll 2008-06-19 22:19 . 2008-06-19 22:19 <DIR> d-------- C:\temp 2008-06-18 22:44 . 2008-06-18 22:44 <DIR> d-------- C:\Programfiler\CCleaner 2008-06-17 00:15 . 2008-07-30 16:50 <DIR> d-a------ C:\Documents and Settings\All Users\Programdata\TEMP 2008-06-17 00:15 . 2003-07-06 14:07 372,736 --a------ C:\WINDOWS\system32\IJL_11.DLL 2008-06-17 00:15 . 2004-03-09 00:00 212,240 --a------ C:\WINDOWS\system32\RICHTX32.OCX 2008-06-15 23:56 . 2008-06-15 23:57 1,156 --a------ C:\WINDOWS\mozver.dat 2008-06-15 23:54 . 2008-06-15 23:54 0 --a------ C:\WINDOWS\nsreg.dat 2008-06-15 23:28 . 2008-06-15 23:28 <DIR> d-------- C:\WINDOWS\Sun 2008-06-14 11:18 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll 2008-06-14 11:17 . 2008-06-14 11:17 <DIR> d-------- C:\Programfiler\MSBuild 2008-06-14 11:16 . 2008-06-14 11:16 <DIR> d-------- C:\Programfiler\Microsoft.NET 2008-06-14 11:14 . 2008-06-14 11:17 <DIR> d-------- C:\WINDOWS\SHELLNEW 2008-06-14 11:13 . 2008-07-18 22:16 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Microsoft Help 2008-06-14 11:12 . 2008-06-14 11:12 <DIR> dr-h----- C:\MSOCache 2008-06-14 07:40 . 2008-06-14 07:40 <DIR> d-------- C:\Programfiler\Microsoft CAPICOM 2.1.0.2 2008-06-14 07:33 . 2008-06-14 07:33 <DIR> d-------- C:\Programfiler\MSXML 4.0 2008-06-13 18:49 . 2008-06-13 18:49 <DIR> d-------- C:\SEMAFOR 2008-06-13 18:49 . 1995-05-11 22:00 398,416 --a------ C:\WINDOWS\system\VBRUN300.DLL 2008-06-13 18:49 . 2003-02-10 15:30 54,811 --a------ C:\WINDOWS\SETUPSE.EXE 2008-06-13 18:49 . 1993-04-27 22:00 7,008 --a------ C:\WINDOWS\system\SETUPKIT.DLL 2008-06-13 14:39 . 2008-04-23 06:22 6,066,176 --------- C:\WINDOWS\system32\dllcache\ieframe.dll 2008-06-13 14:39 . 2007-04-17 11:32 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat 2008-06-13 14:39 . 2007-03-08 07:11 1,007,616 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui 2008-06-13 14:39 . 2008-04-23 06:22 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll 2008-06-13 14:39 . 2008-04-23 06:22 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll 2008-06-13 14:39 . 2008-04-23 06:22 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll 2008-06-13 14:39 . 2008-04-23 06:22 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll 2008-06-13 14:39 . 2008-04-23 06:22 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll 2008-06-13 14:39 . 2008-04-22 09:39 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe 2008-06-13 14:29 . 1999-11-10 11:05 86,016 --a------ C:\WINDOWS\unvise32qt.exe 2008-06-13 14:29 . 1999-12-17 09:13 86,016 --a------ C:\WINDOWS\unvise32.exe 2008-06-13 14:28 . 2008-06-13 14:29 <DIR> d-------- C:\WINDOWS\system32\QuickTime 2008-06-13 14:28 . 2008-07-20 21:34 <DIR> d-------- C:\Programfiler\QuickTime 2008-06-13 14:28 . 2008-06-13 14:28 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\QuickTime 2008-06-13 14:28 . 2008-06-13 14:28 361 --a------ C:\WINDOWS\system32\QuickTime.qtp 2008-06-13 14:27 . 2008-06-14 20:00 272,256 --------- C:\WINDOWS\system32\drivers\bthport.sys 2008-06-13 14:27 . 2008-06-14 20:00 272,256 --------- C:\WINDOWS\system32\dllcache\bthport.sys 2008-06-13 14:26 . 2008-06-13 14:52 65 --a------ C:\WINDOWS\Artplant_sj2.ini 2008-06-13 14:23 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll 2008-06-13 14:23 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll 2008-06-13 14:23 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui 2008-06-12 23:18 . 2008-06-12 23:18 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\SUPERAntiSpyware.com 2008-06-12 23:17 . 2008-06-12 23:17 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware 2008-06-12 23:17 . 2008-06-12 23:17 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard 2008-06-12 23:17 . 2008-06-12 23:17 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\SUPERAntiSpyware.com 2008-06-12 19:20 . 2008-06-12 19:20 <DIR> d-------- C:\Programfiler\directx 2008-06-12 19:16 . 2008-06-12 19:16 <DIR> d-------- C:\Programfiler\Eidos Interactive 2008-06-12 15:15 . 2008-07-31 09:01 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg 2008-06-12 15:15 . 2008-06-12 15:15 <DIR> d-------- C:\Programfiler\AVG 2008-06-12 15:15 . 2008-06-12 15:25 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\AVGTOOLBAR 2008-06-12 15:15 . 2008-06-12 15:15 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\avg8 2008-06-12 15:15 . 2008-07-19 09:44 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys 2008-06-12 15:15 . 2008-07-19 09:44 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys 2008-06-12 15:15 . 2008-07-19 09:44 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll 2008-06-12 14:46 . 2008-06-12 15:26 <DIR> d-------- C:\Programfiler\SweetIM 2008-06-12 14:46 . 2008-06-12 14:46 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\SweetIM 2008-06-12 13:28 . 2008-06-12 14:47 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Contacts 2008-06-12 13:27 . 2008-06-12 13:27 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE 2008-06-12 13:24 . 2008-06-12 13:28 <DIR> d-------- C:\Programfiler\Windows Live 2008-06-12 13:24 . 2008-06-12 13:27 <DIR> d--hsc--- C:\Programfiler\Fellesfiler\WindowsLiveInstaller 2008-06-12 13:23 . 2008-06-15 23:13 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\WLInstaller 2008-06-12 07:34 . 2008-07-18 16:09 <DIR> d-------- C:\Programfiler\PonyGirl2 2008-06-12 06:36 . 2008-07-30 22:44 249 --a------ C:\WINDOWS\system\hpsysdrv.dat 2008-06-12 06:31 . 2008-07-29 17:09 <DIR> dr------- C:\Programfiler 2008-06-12 06:31 . 2008-06-12 06:34 <DIR> dr------- C:\Documents and Settings\Default User\Start-meny . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-26 17:25 --------- d-----w C:\Programfiler\Java 2008-06-20 17:43 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll 2008-06-20 17:43 246,784 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll 2008-06-20 17:43 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys 2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys 2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys 2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys 2008-06-14 09:17 --------- d-----w C:\Programfiler\Microsoft Works 2008-06-11 20:54 --------- d-----w C:\Programfiler\HP 2008-06-11 19:52 --------- d-----w C:\Programfiler\Google 2008-06-11 19:10 --------- d--h--w C:\Programfiler\InstallShield Installation Information 2008-06-11 19:07 --------- d-----w C:\Programfiler\Fellesfiler\Symantec Shared 2008-06-11 19:07 --------- d-----w C:\Documents and Settings\All Users\Programdata\Symantec 2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys 2008-05-07 05:16 1,290,752 ----a-w C:\WINDOWS\system32\quartz.dll 2008-05-07 05:16 1,290,752 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll 2008-04-23 20:22 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll 2008-04-22 07:43 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe 2008-04-22 07:43 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe 2008-04-20 05:07 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll . ((((((((((((((((((((((((((((( snapshot@2008-07-25_23.52.34.20 ))))))))))))))))))))))))))))))))))))))))) . + 2008-07-29 14:26:55 68,608 ----a-w C:\WINDOWS\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll + 2008-07-29 14:27:05 72,192 ----a-w C:\WINDOWS\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll + 2008-07-29 14:27:06 4,308,992 ----a-w C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll + 2008-07-29 14:27:07 482,304 ----a-w C:\WINDOWS\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll + 2008-07-29 14:27:02 2,878,976 ----a-w C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll + 2008-07-29 14:26:49 258,048 ----a-w C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll + 2008-07-29 14:26:49 114,176 ----a-w C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll + 2008-07-29 14:27:12 260,096 ----a-w C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll + 2008-07-29 14:26:58 5,025,792 ----a-w C:\WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll + 2008-07-29 14:26:54 10,752 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll + 2008-07-29 14:26:49 503,808 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll + 2008-07-29 14:26:51 13,312 ----a-w C:\WINDOWS\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll + 2008-07-29 14:27:03 8,192 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll + 2008-07-29 14:27:04 36,864 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll + 2008-07-29 14:27:05 5,632 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll + 2008-07-29 14:26:53 413,696 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll + 2008-07-29 14:26:53 36,864 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll + 2008-07-29 14:26:54 647,168 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll + 2008-07-29 14:26:54 73,728 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll + 2008-07-29 14:26:52 745,472 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll + 2008-07-29 14:27:14 110,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll + 2008-07-29 14:27:14 372,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll + 2008-07-29 14:26:44 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll + 2008-07-29 14:27:13 667,648 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll + 2008-07-29 14:27:15 5,632 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll + 2008-07-29 14:26:48 12,800 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll + 2008-07-29 14:26:47 32,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll + 2008-07-29 14:26:48 7,168 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll + 2008-07-29 14:27:09 110,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll + 2008-07-29 14:26:55 81,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll + 2008-07-29 14:27:10 389,120 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll + 2008-07-29 14:27:08 716,800 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll + 2008-07-29 14:26:50 884,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll + 2008-07-29 14:27:03 5,050,368 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll + 2008-07-29 14:26:57 188,416 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll + 2008-07-29 14:26:56 397,312 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll + 2008-07-29 14:26:57 81,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll + 2008-07-29 14:27:11 700,416 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll + 2008-07-29 14:27:08 368,640 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll + 2008-07-29 14:27:12 258,048 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll + 2008-07-29 14:27:08 299,008 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll + 2008-07-29 14:27:09 131,072 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll + 2008-07-29 14:26:55 258,048 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll + 2008-07-29 14:26:58 114,688 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll + 2008-07-29 14:27:13 835,584 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll + 2008-07-29 14:26:59 86,016 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll + 2008-07-29 14:27:00 823,296 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll + 2008-07-29 14:27:01 5,316,608 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll + 2008-07-29 14:27:01 2,035,712 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll + 2008-07-29 14:27:11 3,018,752 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll + 2008-07-29 14:31:20 26,624 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\09ba68e4f1dd1f43a42a6f416665941e\Accessibility.ni.dll + 2008-07-29 14:31:21 860,160 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\68cd2eb2d2079f409785c4436a861dae\AspNetMMCExt.ni.dll + 2008-07-29 14:31:22 237,568 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\5fc6a03f31fb284482c24e504a840f73\CustomMarshalers.ni.dll + 2008-07-29 14:31:21 15,360 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\dfsvc\ea5a8c8cbd3dd04b8363cc320a571474\dfsvc.ni.exe + 2008-07-29 14:31:23 880,640 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\5389a653faf42040b9fcc34a9c302b22\Microsoft.Build.Engine.ni.dll + 2008-07-29 14:31:23 81,920 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\d21b854f038a354f841e0e89696a58a5\Microsoft.Build.Framework.ni.dll + 2008-07-29 14:31:25 1,691,648 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\807e2455ad63394da95929d341ca0d57\Microsoft.Build.Tasks.ni.dll + 2008-07-29 14:31:26 163,840 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\469534dc03d08741b7f33f9f6b20487d\Microsoft.Build.Utilities.ni.dll + 2008-07-29 14:31:29 1,724,416 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\0abdfdd79eee8a4bbdfb7223525661c0\Microsoft.VisualBasic.ni.dll + 2008-07-29 14:27:52 11,415,552 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\8e6f6dfdedf32544938ff5dfb4cc7449\mscorlib.ni.dll + 2008-07-29 14:31:30 962,560 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\6f38c4f36827094fb6a49a8eaecbe900\System.Configuration.ni.dll + 2008-07-29 14:28:39 6,688,768 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\b2f388d73df9e948879bc0b3d940862b\System.Data.ni.dll + 2008-07-29 14:31:31 1,712,128 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Deployment\13a3725e76df5b4fb1b927888e90a69f\System.Deployment.ni.dll + 2008-07-29 14:28:53 10,723,328 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Design\65e2b7447fd79d458f67534b7a1ae320\System.Design.ni.dll + 2008-07-29 14:31:33 1,220,608 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\32dea38a177f7e4c94dd774d14dfa5f3\System.DirectoryServices.ni.dll + 2008-07-29 14:31:34 512,000 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\f67828f5e802a14bae3f0836b7cc1970\System.DirectoryServices.Protocols.ni.dll + 2008-07-29 14:28:08 229,376 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\22f85751a8e76a4ba58b7a05100a1b5b\System.Drawing.Design.ni.dll + 2008-07-29 14:28:11 1,626,112 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\499e97cd8bba974fbd737cffa830e5a7\System.Drawing.ni.dll + 2008-07-29 14:31:35 659,456 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\6ba5c94bebd2fc4592aafaeff9c523ca\System.EnterpriseServices.ni.dll + 2008-07-29 14:31:35 294,912 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\6ba5c94bebd2fc4592aafaeff9c523ca\System.EnterpriseServices.Wrapper.dll + 2008-07-29 14:31:36 729,088 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Security\c232abc40b03b24b96c8412d7047470d\System.Security.ni.dll + 2008-07-29 14:31:37 684,032 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\3238040f8b5aad40b1f46bcc713cbb6f\System.Transactions.ni.dll + 2008-07-29 14:31:56 2,310,144 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\dbd43bffded554478495d70709646599\System.Web.Mobile.ni.dll + 2008-07-29 14:31:56 237,568 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\c96f173c7ea0ee4fa8e94ff535e30b26\System.Web.RegularExpressions.ni.dll + 2008-07-29 14:31:59 1,945,600 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\2b530c76075fe74c8cf8832e4b0caf7a\System.Web.Services.ni.dll + 2008-07-29 14:31:51 11,808,768 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\5e47984b90ca2d47a99b8ac9f7f7bfa7\System.Web.ni.dll + 2008-07-29 14:28:23 13,107,200 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\69102b6b67cba443a614acefb5715404\System.Windows.Forms.ni.dll + 2008-07-29 14:28:32 5,640,192 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\6862868c3d3af14aaccbe36570e7a993\System.Xml.ni.dll + 2008-07-29 14:28:06 8,093,696 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\2f3920b5b4d9d1469983783573b5cdf8\System.ni.dll - 2003-02-21 02:09:46 57,344 ----a-w C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe + 2005-09-23 05:28:52 72,704 ----a-w C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe - 2003-02-21 02:09:32 5,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp10.dll + 2005-09-23 05:28:52 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp10.dll + 2005-09-23 05:28:56 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp20_mscorwks.dll + 2005-09-23 05:28:58 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp20_perfcounter.dll + 2005-09-23 05:28:56 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\SharedReg12.dll - 2003-02-21 01:43:50 131,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll + 2005-09-23 05:28:52 86,528 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll + 2005-09-23 05:28:36 18,944 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll + 2005-09-23 05:28:42 136,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll + 2005-09-23 05:28:44 4,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll + 2005-09-23 05:29:04 183,808 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\vbc7ui.dll + 2005-09-23 05:28:28 208,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\Vsavb7rtUI.dll + 2005-09-23 05:28:56 10,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll + 2005-09-23 05:28:58 138,240 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AdoNetDiag.dll + 2005-09-23 05:28:36 87,552 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\alink.dll + 2005-09-23 05:28:58 55,488 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe + 2005-09-23 05:28:32 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe + 2005-09-23 05:28:32 10,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll + 2005-09-23 05:28:32 8,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll + 2005-09-23 05:28:32 23,552 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll + 2005-09-23 05:28:32 70,656 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll + 2005-09-23 05:28:32 13,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe + 2005-09-23 05:28:32 26,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe + 2005-09-23 05:28:32 106,496 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe + 2005-09-23 05:28:32 29,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe + 2005-09-23 05:28:32 29,888 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe + 2005-09-23 05:28:32 503,808 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AspNetMMCExt.dll + 2005-09-23 05:28:56 106,496 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CasPol.exe + 2005-09-23 05:28:56 88,576 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll + 2005-09-23 05:28:42 76,984 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\csc.exe + 2005-09-23 05:28:42 1,144,832 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscomp.dll + 2005-09-23 05:28:42 13,312 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll + 2005-09-23 05:28:58 17,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Culture.dll + 2005-09-23 05:28:56 68,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll + 2005-09-23 05:28:44 31,936 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cvtres.exe + 2005-09-23 05:28:38 52,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfdll.dll + 2005-09-23 05:28:38 4,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe + 2005-09-23 05:29:12 547,840 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll + 2005-09-23 05:28:56 788,992 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll + 2005-09-23 05:28:50 9,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\fusion.dll + 2005-09-23 05:28:56 9,728 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExec.exe + 2005-09-23 05:28:56 8,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll + 2005-09-23 05:28:56 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEHost.dll + 2005-09-23 05:28:56 5,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll + 2005-09-23 05:28:56 224,952 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ilasm.exe + 2005-09-23 05:28:56 28,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe + 2005-09-23 05:28:56 55,296 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll + 2005-09-23 05:28:56 72,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll + 2005-09-23 05:28:48 40,960 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\jsc.exe + 2005-09-23 05:01:16 609,472 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe + 2005-09-23 04:29:48 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1025.dll + 2005-09-23 04:32:24 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1028.dll + 2005-09-23 04:34:10 82,944 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1029.dll + 2005-09-23 04:34:12 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1030.dll + 2005-09-23 04:34:44 85,504 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1031.dll + 2005-09-23 04:36:24 87,552 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1032.dll + 2005-09-23 01:46:14 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1033.dll + 2005-09-23 04:38:26 81,408 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1035.dll + 2005-09-23 04:38:52 86,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1036.dll + 2005-09-23 04:40:30 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1037.dll + 2005-09-23 04:40:32 83,968 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1038.dll + 2005-09-23 04:40:56 84,480 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1040.dll + 2005-09-23 04:42:58 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1041.dll + 2005-09-23 04:44:58 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1042.dll + 2005-09-23 04:46:38 83,456 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1043.dll + 2005-09-23 04:46:38 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1044.dll + 2005-09-23 04:46:40 83,456 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1045.dll + 2005-09-23 04:47:04 82,432 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1046.dll + 2005-09-23 04:47:30 82,432 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1049.dll + 2005-09-23 04:47:32 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1053.dll + 2005-09-23 04:47:32 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1055.dll + 2005-09-23 04:30:18 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.2052.dll + 2005-09-23 04:47:06 84,480 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.2070.dll + 2005-09-23 04:29:50 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.3076.dll + 2005-09-23 04:36:48 85,504 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.3082.dll + 2005-09-23 05:57:06 245,408 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\unicows.dll + 2005-09-23 05:28:48 413,696 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Engine.dll + 2005-09-23 05:28:48 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll + 2005-09-23 05:28:48 647,168 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Tasks.dll + 2005-09-23 05:28:48 73,728 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll + 2005-09-23 05:28:48 745,472 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll + 2005-09-23 05:29:10 110,592 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.Data.dll + 2005-09-23 05:29:10 372,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.dll + 2005-09-23 05:29:08 667,648 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.dll + 2005-09-23 05:28:30 28,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll + 2005-09-23 05:29:10 5,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll + 2005-09-23 05:28:30 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll + 2005-09-23 05:28:30 12,800 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll + 2005-09-23 05:28:30 7,168 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll + 2005-09-23 05:28:32 87,552 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll + 2005-09-23 05:28:48 69,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe + 2005-09-23 05:28:56 800,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll + 2005-09-23 05:28:56 73,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll + 2005-09-23 05:28:56 288,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordbi.dll + 2005-09-23 05:28:56 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll + 2005-09-23 05:28:56 326,144 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll + 2005-09-23 05:28:56 81,408 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorld.dll + 2005-09-23 05:28:56 4,308,992 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll + 2005-09-23 05:28:56 102,400 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorpe.dll + 2005-09-23 05:29:00 330,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll + 2005-09-23 05:28:56 67,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll + 2005-09-23 05:28:50 9,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll + 2005-09-23 05:28:56 226,816 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll + 2005-09-23 05:28:56 66,240 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe + 2005-09-23 05:28:56 10,240 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscortim.dll + 2005-09-23 05:28:50 5,615,616 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll + 2005-09-23 05:29:00 22,528 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MUI\0409\mscorsecr.dll + 2005-09-23 05:28:56 96,440 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ngen.exe + 2005-09-23 05:28:56 14,848 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\normalization.dll + 2005-09-23 05:28:56 78,336 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll + 2005-09-23 05:28:50 136,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\peverify.dll + 2005-09-23 05:28:56 53,248 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe + 2005-09-23 05:28:56 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe + 2005-09-23 05:29:02 59,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe + 2005-09-23 05:28:58 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll + 2005-09-23 05:28:56 107,520 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\shfusion.dll + 2005-09-23 05:29:00 85,504 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll + 2005-09-23 05:28:56 377,344 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\SOS.dll + 2005-09-23 05:28:56 110,592 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll + 2005-09-23 05:28:58 389,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.configuration.dll + 2005-09-23 05:28:56 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll + 2005-09-23 05:28:56 2,878,976 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.dll + 2005-09-23 05:28:56 482,304 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll + 2005-09-23 05:28:56 716,800 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.SqlXml.dll + 2005-09-23 05:28:38 884,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Deployment.dll + 2005-09-23 05:28:56 5,050,368 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Design.dll + 2005-09-23 05:28:56 397,312 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll + 2005-09-23 05:28:56 188,416 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll + 2005-09-23 05:28:56 3,018,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.dll + 2005-09-23 05:28:56 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll + 2005-09-23 05:28:56 700,416 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll + 2005-09-23 05:28:56 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll + 2005-09-23 05:28:56 47,616 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll + 2005-09-23 05:28:56 114,176 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Wrapper.dll + 2005-09-23 05:28:56 368,640 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Management.dll + 2005-09-23 05:28:56 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll + 2005-09-23 05:28:56 299,008 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Remoting.dll + 2005-09-23 05:28:56 131,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll + 2005-09-23 05:28:56 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Security.dll + 2005-09-23 05:28:56 114,688 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll + 2005-09-23 05:28:56 260,096 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Transactions.dll + 2005-09-23 05:28:56 5,025,792 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.dll + 2005-09-23 05:28:56 835,584 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.Mobile.dll + 2005-09-23 05:28:56 86,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll + 2005-09-23 05:28:56 823,296 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.Services.dll + 2005-09-23 05:28:56 5,316,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll + 2005-09-23 05:28:56 2,035,712 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.XML.dll + 2005-09-23 05:28:56 71,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL + 2005-09-23 05:29:06 1,140,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\vbc.exe + 2005-09-23 05:28:30 1,306,624 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll + 2005-09-23 05:28:32 298,496 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\webengine.dll + 2005-09-23 05:28:56 28,160 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll + 2006-12-31 02:16:36 313,344 ----a-w C:\WINDOWS\system32\avisynth.dll + 2004-05-26 12:37:34 719,872 ----a-w C:\WINDOWS\system32\devil.dll + 2005-09-23 05:28:38 83,456 ----a-w C:\WINDOWS\system32\dfshim.dll - 2005-08-26 21:55:46 49,248 ----a-w C:\WINDOWS\system32\java.exe + 2008-06-09 23:21:01 135,168 ----a-w C:\WINDOWS\system32\java.exe - 2005-08-26 21:55:58 49,250 ----a-w C:\WINDOWS\system32\javaw.exe + 2008-06-09 23:21:04 135,168 ----a-w C:\WINDOWS\system32\javaw.exe - 2005-08-27 00:14:46 127,078 ----a-w C:\WINDOWS\system32\javaws.exe + 2008-06-10 00:32:34 139,264 ----a-w C:\WINDOWS\system32\javaws.exe - 2004-07-15 05:34:06 16,896 ----a-w C:\WINDOWS\system32\mscorier.dll + 2005-09-23 05:28:52 150,016 ----a-w C:\WINDOWS\system32\mscorier.dll - 2003-02-21 02:09:14 106,496 ----a-w C:\WINDOWS\system32\mscories.dll + 2005-09-23 05:28:52 74,240 ----a-w C:\WINDOWS\system32\mscories.dll - 2008-06-14 05:53:26 53,572 ----a-w C:\WINDOWS\system32\perfc009.dat + 2008-07-29 14:28:56 63,152 ----a-w C:\WINDOWS\system32\perfc009.dat - 2008-06-14 05:53:26 61,348 ----a-w C:\WINDOWS\system32\perfc014.dat + 2008-07-29 14:28:56 71,738 ----a-w C:\WINDOWS\system32\perfc014.dat - 2008-06-14 05:53:26 381,828 ----a-w C:\WINDOWS\system32\perfh009.dat + 2008-07-29 14:28:56 402,542 ----a-w C:\WINDOWS\system32\perfh009.dat - 2008-06-14 05:53:26 386,354 ----a-w C:\WINDOWS\system32\perfh014.dat + 2008-07-29 14:28:56 406,516 ----a-w C:\WINDOWS\system32\perfh014.dat + 2008-07-29 14:26:49 258,048 ----a-w C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll + 2008-07-29 14:26:49 114,176 ----a-w C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll . -- Snapshot reset to current date -- . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Programfiler\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-06-11 21:18 171448] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360] "MsnMsgr"="C:\Programfiler\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184] "SUPERAntiSpyware"="C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544] "ccleaner"="C:\Programfiler\CCleaner\CCleaner.exe" [2008-05-28 16:40 1197296] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 23:14 237568] "HPBootOp"="C:\Programfiler\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 23:34 249856] "HP Software Update"="C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152] "D-Link AirPlus Xtreme G"="C:\Programfiler\D-Link\AirPlus Xtreme G\AirPlusCFG.exe" [2003-11-04 17:00 2502656] "ANIWZCSService"="C:\Programfiler\Alpha Networks\ANIWZCS Service\WZCSLDR.exe" [2003-08-21 16:12 32768] "SweetIM"="C:\Programfiler\SweetIM\Messenger\SweetIM.exe" [2008-03-27 19:31 111928] "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-19 09:44 1232152] "GrooveMonitor"="C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016] "KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 16:44 61440] "SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784] "QuickTime Task"="C:\Programfiler\QuickTime\qttask.exe" [2008-07-20 21:34 413696] "9c7ce"="c:\programfiler\qtvxhhfjwzafh\uehjlvv.exe" [2006-03-15 00:15 1554066] "TkBellExe"="realsched.exe" [bU] C:\Documents and Settings\Administrator\Start-meny\Programmer\Oppstart\ Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-01-03 05:07:26 27136] C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\ HP Digital Imaging Monitor.lnk - C:\Programfiler\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472] Hurtigstart for Adobe Reader.lnk - C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2007-04-19 13:41 294912 C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=avgrsstx.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hposid01.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqCopy.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpfccopy.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpoews01.exe"= "C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"= "C:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Programfiler\\Windows Live\\Messenger\\livecall.exe"= "C:\\Programfiler\\AVG\\AVG8\\avgupd.exe"= "C:\\Programfiler\\AVG\\AVG8\\avgemc.exe"= "C:\\Programfiler\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "C:\\Programfiler\\Microsoft Office\\Office12\\GROOVE.EXE"= "C:\\Programfiler\\Microsoft Office\\Office12\\ONENOTE.EXE"= "C:\\Programfiler\\Skype\\Phone\\Skype.exe"= R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-19 09:44] R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-19 09:44] R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-19 09:44] R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-19 09:44] R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys [2003-10-22 15:27] . Contents of the 'Scheduled Tasks' folder "2008-07-13 19:13:39 C:\WINDOWS\Tasks\Internett-tjenester.job" - C:\Programfiler\Hewlett-Packard\SDP\HPSdpApp.exea/remind /LaunchPoint reminder /App C:\Programfiler\Hewlett-Packard\Internet Services\StartIS.aml . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-31 09:40:54 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-07-31 9:42:00 ComboFix-quarantined-files.txt 2008-07-31 07:41:56 ComboFix2.txt 2008-07-28 21:07:50 ComboFix3.txt 2008-07-26 17:36:36 ComboFix4.txt 2008-07-25 22:37:04 ComboFix5.txt 2008-07-31 07:35:23 Pre-Run: 135,637,913,600 byte ledig Post-Run: 135,633,760,256 byte ledig 518 --- E O F --- 2008-07-22 07:20:29 Lenke til kommentar
snippsat Skrevet 31. juli 2008 Del Skrevet 31. juli 2008 (endret) Kopiere fet tekst under,lim inn i notisblokk. Lagrer på skrivebordet som fjerne.reg Dobbelklikk på fjerne fjerne.reg(svar ja) REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "9c7ce"=- Når du har kjørt det i post #34. Se om avg finner noe nå. Endret 31. juli 2008 av SNIPPSAT Lenke til kommentar
Annie_P Skrevet 31. juli 2008 Forfatter Del Skrevet 31. juli 2008 Kopiere fet tekst under,lim inn i notisblokk.Lagrer på skrivebordet som fjerne.reg Dobbelklikk på fjerne fjerne.reg(svar ja) REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "9c7ce"=- Når du har kjørt det i post #34. Se om avg finner noe nå. Nå har jeg kjørt MBAM og AVG uten at den finner noe. Skal kjøre det du skrev over i kveld, rekker ikke å gjøre det nå. Kjenner at humøret steg flere hakk da det ikke dukket opp noe da MBAM og AVG ble kjørt :-) Lenke til kommentar
Kjetil.. Skrevet 31. juli 2008 Del Skrevet 31. juli 2008 Fint om du legger loggene i spoiler Når jeg ikke kunne gå inn på min datamaskin gikk jeg: www.filefront.com (eller annen upload side) og kom meg inn på min datamaskin, gode minner fra før jeg fant ut hvordan man skal fjerne virus... Lenke til kommentar
Annie_P Skrevet 1. august 2008 Forfatter Del Skrevet 1. august 2008 Har kjørt AVG en gang til uten at den finner noe. HURRA! Tusen takk for alle som kommer med råd til an glad dataamatør! Lenke til kommentar
snippsat Skrevet 1. august 2008 Del Skrevet 1. august 2008 Ja der er det bra. Du kan fjerne combofix ved å skrive combofix /u fra kjør-vinduet. Denne kommandoen gjør at filer i karantene og backups blir slette. Systemgjenopprettingsmappa nullstilt etc. Surf trygt. Lenke til kommentar
Anbefalte innlegg
Opprett en konto eller logg inn for å kommentere
Du må være et medlem for å kunne skrive en kommentar
Opprett konto
Det er enkelt å melde seg inn for å starte en ny konto!
Start en kontoLogg inn
Har du allerede en konto? Logg inn her.
Logg inn nå