Gå til innhold

[LØST] Hjelp: Har fått spyware- fra en kjip nettside


Anbefalte innlegg

Har installert og kjørt MBAM. Under er loggen. Prøve Hijack nå.

 

MBAM-logg:

 

Malwarebytes' Anti-Malware 1.23

Database versjon: 993

Windows 5.1.2600 Service Pack 2

 

09:12:36 26.07.2008

mbam-log-7-26-2008 (09-12-18).txt

 

Skanntype: Rask Skann

Objekter skannet: 40414

Tid tilbakelagt: 5 minute(s), 59 second(s)

 

Minneprosesser infisert: 0

Minnemoduler infisert: 0

Registernøkler infisert: 2

Registerverdier infisert: 0

Registerfiler infisert: 0

Mapper infisert: 0

Filer infisert: 1

 

Minneprosesser infisert:

(Ingen mistenkelige filer funnet)

 

Minnemoduler infisert:

(Ingen mistenkelige filer funnet)

 

Registernøkler infisert:

HKEY_CLASSES_ROOT\fdkowvbp.bgrv (Trojan.FakeAlert) -> No action taken.

HKEY_CLASSES_ROOT\fdkowvbp.toolbar.1 (Trojan.FakeAlert) -> No action taken.

 

Registerverdier infisert:

(Ingen mistenkelige filer funnet)

 

Registerfiler infisert:

(Ingen mistenkelige filer funnet)

 

Mapper infisert:

(Ingen mistenkelige filer funnet)

 

Filer infisert:

C:\WINDOWS\grswptdl.exe (Trojan.FakeAlert) -> No action taken.

Lenke til kommentar
Videoannonse
Annonse

Her kommer Hijack-loggen. Maskinen ser forøvrig ut til å fungere ok for øyeblikket. Får ikke opp alle sidene om kjøp av antivirusprogram, og ikononen jeg savnet i går er tilbake.

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 09:17, on 26.07.2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

C:\WINDOWS\system32\HPZipm12.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\PROGRA~1\AVG\AVG8\avgrsx.exe

C:\PROGRA~1\AVG\AVG8\avgemc.exe

C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe

C:\Programfiler\D-Link\AirPlus Xtreme G\AirPlusCFG.exe

C:\Programfiler\Alpha Networks\ANIWZCS Service\WZCSLDR.exe

C:\Programfiler\SweetIM\Messenger\SweetIM.exe

C:\PROGRA~1\AVG\AVG8\avgtray.exe

C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe

C:\HP\KBD\KBD.EXE

C:\Programfiler\Java\jre1.5.0_05\bin\jusched.exe

C:\Programfiler\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Programfiler\HP\Digital Imaging\bin\hpqtra08.exe

C:\Programfiler\Windows Live\Messenger\msnmsgr.exe

C:\Programfiler\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Programfiler\Mozilla Firefox\firefox.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\ALCXMNTR.EXE

C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe

c:\windows\system\hpsysdrv.exe

C:\Programfiler\Fellesfiler\Real\Update_OB\realsched.exe

C:\Programfiler\Trend Micro\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programfiler\AVG\AVG8\avgtoolbar.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programfiler\google\googletoolbar2.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programfiler\google\googletoolbar2.dll

O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programfiler\AVG\AVG8\avgtoolbar.dll

O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE

O4 - HKLM\..\Run: [HPBootOp] "C:\Programfiler\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run

O4 - HKLM\..\Run: [HP Software Update] C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [D-Link AirPlus Xtreme G] C:\Programfiler\D-Link\AirPlus Xtreme G\AirPlusCFG.exe

O4 - HKLM\..\Run: [ANIWZCSService] C:\Programfiler\Alpha Networks\ANIWZCS Service\WZCSLDR.exe

O4 - HKLM\..\Run: [sweetIM] C:\Programfiler\SweetIM\Messenger\SweetIM.exe

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE

O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.5.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u

O4 - HKLM\..\Run: [TkBellExe] "realsched.exe" -osboot

O4 - HKCU\..\Run: [swg] C:\Programfiler\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE')

O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programfiler\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Hurtigstart for Adobe Reader.lnk = C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_05\bin\npjpi150_05.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_05\bin\npjpi150_05.dll

O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programfiler\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: Tilkoblingshjelp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm

O9 - Extra 'Tools' menuitem: Tilkoblingshjelp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com.edgesuite.net/co...ex/qtplugin.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock...ash/swflash.cab

O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://eurofoto.no/uploader/ImageUploader4.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programfiler\AVG\AVG8\avgpp.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FELLES~1\Skype\SKYPE4~1.DLL

O20 - AppInit_DLLs: avgrsstx.dll

O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

 

--

End of file - 8573 bytes

Lenke til kommentar

Du må la MBAM slette det den finner:

 

Det kommer en meldingsboks om at scannen er ferdig, klikk Ok

Klikk på Vis resultat-knappen.Hvis det er funnet malware, vil du nå se hva som er funnet.

Klikk så på Fjern valgte -knappen for å fjerne malwaren som evt. ble funnet.

Post gjerne loggen.

 

Oppdater java'en: http://java.com/en/download/index.jsp

 

Sjekket du filene som ble nevnt på Virustotal? Hvis ikke, gjør det og gi tilbakemelding på om det blir funnet noe på dem. Det skulle holde å sjekke fila C:\WINDOWS\system32\mswmnnove.dll

Lenke til kommentar
Du må la MBAM slette det den finner:

 

Det kommer en meldingsboks om at scannen er ferdig, klikk Ok

Klikk på Vis resultat-knappen.Hvis det er funnet malware, vil du nå se hva som er funnet.

Klikk så på Fjern valgte -knappen for å fjerne malwaren som evt. ble funnet.

Post gjerne loggen.

 

Oppdater java'en: http://java.com/en/download/index.jsp

 

Sjekket du filene som ble nevnt på Virustotal? Hvis ikke, gjør det og gi tilbakemelding på om det blir funnet noe på dem. Det skulle holde å sjekke fila C:\WINDOWS\system32\mswmnnove.dll

 

Jeg har opopdater java. Har også kjørt MBAM. Den fant to infiserte filer. Har postet loggen jeg fikk etter at jeg klikket på fhjerning. Har også kjørt Virustotal, det ser ikke ut som den fant noe. Prøver å lime inn rapporten derfra.

 

 

 

 

Her loggen etter fjerning:

 

Malwarebytes' Anti-Malware 1.23

Database versjon: 994

Windows 5.1.2600 Service Pack 2

 

19:55:19 26.07.2008

mbam-log-7-26-2008 (19-55-19).txt

 

Skanntype: Rask Skann

Objekter skannet: 40323

Tid tilbakelagt: 7 minute(s), 23 second(s)

 

Minneprosesser infisert: 0

Minnemoduler infisert: 0

Registernøkler infisert: 2

Registerverdier infisert: 0

Registerfiler infisert: 0

Mapper infisert: 0

Filer infisert: 0

 

Minneprosesser infisert:

(Ingen mistenkelige filer funnet)

 

Minnemoduler infisert:

(Ingen mistenkelige filer funnet)

 

Registernøkler infisert:

HKEY_CLASSES_ROOT\fdkowvbp.bgrv (Trojan.FakeAlert) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\fdkowvbp.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.

 

Registerverdier infisert:

(Ingen mistenkelige filer funnet)

 

Registerfiler infisert:

(Ingen mistenkelige filer funnet)

 

Mapper infisert:

(Ingen mistenkelige filer funnet)

 

Filer infisert:

(Ingen mistenkelige filer funnet)

 

 

 

 

File mswmnnove.dll received on 07.26.2008 20:07:57 (CET)

Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED

Result: 0/34 (0%)

Loading server information...

Your file is queued in position: 1.

Estimated start time is between 40 and 58 seconds.

Do not close the window until scan is complete.

The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.

If you are waiting for more than five minutes you have to resend your file.

Your file is being scanned by VirusTotal in this moment,

results will be shown as they're generated.

Compact Compact

Print results Print results

Your file has expired or does not exists.

Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

 

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.

Email:

 

Antivirus Version Last Update Result

AhnLab-V3 2008.7.26.0 2008.07.25 -

AntiVir 7.8.1.12 2008.07.25 -

Authentium 5.1.0.4 2008.07.26 -

Avast 4.8.1195.0 2008.07.26 -

AVG 8.0.0.130 2008.07.25 -

BitDefender 7.2 2008.07.26 -

CAT-QuickHeal 9.50 2008.07.25 -

ClamAV 0.93.1 2008.07.26 -

DrWeb 4.44.0.09170 2008.07.26 -

eSafe 7.0.17.0 2008.07.24 -

eTrust-Vet 31.6.5983 2008.07.26 -

Ewido 4.0 2008.07.26 -

F-Prot 4.4.4.56 2008.07.26 -

F-Secure 7.60.13501.0 2008.07.26 -

Fortinet 3.14.0.0 2008.07.26 -

GData 2.0.7306.1023 2008.07.26 -

Ikarus T3.1.1.34.0 2008.07.26 -

Kaspersky 7.0.0.125 2008.07.26 -

McAfee 5347 2008.07.25 -

Microsoft 1.3704 2008.07.26 -

NOD32v2 3300 2008.07.25 -

Norman 5.80.02 2008.07.25 -

Panda 9.0.0.4 2008.07.26 -

PCTools 4.4.2.0 2008.07.26 -

Rising 20.54.52.00 2008.07.26 -

Sophos 4.31.0 2008.07.26 -

Sunbelt 3.1.1536.1 2008.07.25 -

Symantec 10 2008.07.26 -

TheHacker 6.2.96.389 2008.07.25 -

TrendMicro 8.700.0.1004 2008.07.26 -

VBA32 3.12.8.1 2008.07.26 -

ViRobot 2008.7.26.1311 2008.07.26 -

VirusBuster 4.5.11.0 2008.07.26 -

Webwasher-Gateway 6.6.2 2008.07.26 -

Additional information

File size: 9844 bytes

MD5...: f8a067cf4e34668f3e1dedb6d51a6588

SHA1..: fc06e27d83685f3019be8f25ce53677bcd581301

SHA256: 03102a91f033953d619361c85aa596dadca44f953cfeb53468760fae7f5f2109

SHA512: 751cee5dac23c37f8f2a7c9c222b03f9a24db7c0c7e8d9cf0dfb730a7ad45e41

69e71c3de9ab4dfaa52951855c4c816a73450b5538a7d7ae9475fa2ee87a6ca1

PEiD..: -

PEInfo: -

Lenke til kommentar

Ok,

Filene gir ingen treff på noen søkemotorer. Dette indikerer at filene kan tilhøre en eller annen infeksjon. Det du kunne ha gjort, er å høyreklikke på filene og byttet filnavn på de. Hvis alt kjører normalt og ingen programmer som du bruker fungerer greit, så kan du slette filene etter noen dager. Det gjelder altså filene:

 

 

C:\WINDOWS\system32\msrun9er-.dll -> høyreklikk og legg til filendelsen bak -> msrun9er-.dll.bak

C:\WINDOWS\system32\mswmnnove.dll -> høyreklikk og legg til filendelsen bak -> mswmnove.dll.bak

 

Ut over dette ser ting og tang bra ut.

Du kan fjerne combofix ved å skrive combofix /u i kjør-feltet (start->kjør).

Behold gjerne SAS og/eller MBAM.

 

Edit: Hvilken fil er det du mener?

Endret av norbat
Lenke til kommentar
Ok,

Filene gir ingen treff på noen søkemotorer. Dette indikerer at filene kan tilhøre en eller annen infeksjon. Det du kunne ha gjort, er å høyreklikke på filene og byttet filnavn på de. Hvis alt kjører normalt og ingen programmer som du bruker fungerer greit, så kan du slette filene etter noen dager. Det gjelder altså filene:

 

 

C:\WINDOWS\system32\msrun9er-.dll -> høyreklikk og legg til filendelsen bak -> msrun9er-.dll.bak

C:\WINDOWS\system32\mswmnnove.dll -> høyreklikk og legg til filendelsen bak -> mswmnove.dll.bak

 

Ut over dette ser ting og tang bra ut.

Du kan fjerne combofix ved å skrive combofix /u i kjør-feltet (start->kjør).

Behold gjerne SAS og/eller MBAM.

 

Edit: Hvilken fil er det du mener?

 

Jeg finner ikke filene som skal ha ny filending. Har gått gjennom windows-mappen og brukt "søk" funksjonen. Kan disse filene være skjult? (Bruker XP, ikke Vista)

Lenke til kommentar

Jeg får fremdeles opp ny virusvarsel. AVG gir melding om tre ulike virus:

 

Trojan Horse Clicker.OVI

Trojan Horse Clicker.OVG

Trojan Horse Clicker.OVF

 

Jeg klikker på "Remove threats", men etter en stund gåtr alarmen igjen.

Lenke til kommentar
Hva med systemrestore, har du tilgang til det? Og rensing etterpå(gammel restore må vekk)... ;)

 

Tror jeg har tilgang til system restore (hvis det er installsjonen slik den var dajeg kjøpte maskinen? Dette ligger på D). Vil helst prøve å løse problemet slik at jeg slipper å bruke restore.....er så mye drivere og oppdateringer at det blir utrolig tungvint å kjøre restore.

 

Nå tenkte jeg på systemgjenoppretting, ikke nyinstall. av OS.. ;)

 

Jeg er ikke helt inne i begrepene her.....Når jeg kjører systemgjenoppretting er det mye som endrer seg på maskinen selv om de gamle mappene ligger der.....vet ikke helt hva som skjer...det jeg har gjort tidliger er full formatering og ny installasjon. Det ser også ut som Compaq-maskinen lager noe som systegjenopprettingspunkt. Etter det jeg forstår skal det være mulig å gå tilbake til sist disse punktene og få et oppsett av maskinen som er identisk med det som var på "gjenopporettinsgstispunktet". Jeg greier imidlertid ikke å finne disse punktene. Når jeg følger manualen ender jeg bare opp med å nyinstallere Windows. Mulig jeg har misforstått dette med gjenopprettingspunkt...?

Lenke til kommentar
Last ned ny combofix, kjør programmet og post loggen.

 

ComboFix 08-07-24.3 - Compaq_Eier 2008-07-28 23:03:24.4 - NTFSx86

Running from: C:\Documents and Settings\Compaq_Eier\Skrivebord\ComboFix.exe

.

 

((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-28 )))))))))))))))))))))))))))))))

.

 

2008-07-26 19:25 . 2008-07-26 19:25 <DIR> d-------- C:\Programfiler\Sun

2008-07-26 19:25 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl

2008-07-26 09:23 . 2008-07-28 19:29 <DIR> dr-h----- C:\Documents and Settings\Compaq_Eier\Siste

2008-07-26 09:17 . 2008-07-26 09:17 <DIR> d-------- C:\Programfiler\Trend Micro

2008-07-26 09:02 . 2008-07-26 09:02 <DIR> d-------- C:\Programfiler\Malwarebytes' Anti-Malware

2008-07-26 09:02 . 2008-07-26 09:02 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\Malwarebytes

2008-07-26 09:02 . 2008-07-26 09:02 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Malwarebytes

2008-07-26 09:02 . 2008-07-23 20:21 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys

2008-07-26 09:02 . 2008-07-23 20:21 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys

2008-07-25 23:31 . 2006-01-03 05:40 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS

2008-07-25 23:31 . 2008-06-12 06:34 <DIR> dr------- C:\Documents and Settings\Administrator\Start-meny

2008-07-25 23:31 . 2005-10-20 23:51 <DIR> d--h----- C:\Documents and Settings\Administrator\Skrivere

2008-07-25 23:31 . 2005-10-20 23:51 <DIR> d-------- C:\Documents and Settings\Administrator\Skrivebord

2008-07-25 23:31 . 2008-06-12 06:34 <DIR> dr-h----- C:\Documents and Settings\Administrator\Siste

2008-07-25 23:31 . 2008-06-12 06:34 <DIR> dr-h----- C:\Documents and Settings\Administrator\Programdata

2008-07-25 23:31 . 2008-06-12 06:34 <DIR> dr------- C:\Documents and Settings\Administrator\Mine dokumenter

2008-07-25 23:31 . 2005-10-27 04:33 <DIR> d--h----- C:\Documents and Settings\Administrator\Maler

2008-07-25 23:31 . 2008-07-28 23:06 <DIR> d--h----- C:\Documents and Settings\Administrator\Lokale innstillinger

2008-07-25 23:31 . 2008-06-11 22:48 <DIR> dr------- C:\Documents and Settings\Administrator\Favoritter

2008-07-25 23:31 . 2005-10-20 23:51 <DIR> d--h----- C:\Documents and Settings\Administrator\AndrMask

2008-07-25 23:31 . 2008-07-25 23:31 <DIR> d-------- C:\Documents and Settings\Administrator

2008-07-25 22:16 . 2008-07-25 22:16 <DIR> d--hs---- C:\WINDOWS\ftpcache

2008-07-24 21:02 . 2008-07-24 21:02 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\AVS4YOU

2008-07-24 20:53 . 2008-07-24 20:53 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\AVS4YOU

2008-07-24 20:49 . 2008-07-24 20:53 <DIR> d-------- C:\Programfiler\Fellesfiler\AVSMedia

2008-07-24 20:42 . 2008-07-24 20:54 <DIR> d-------- C:\Programfiler\AVS4YOU

2008-07-24 20:32 . 2008-07-28 17:59 <DIR> d--h----- C:\$AVG8.VAULT$

2008-07-20 21:34 . 2008-07-20 21:34 54,156 --ah----- C:\WINDOWS\QTFont.qfn

2008-07-20 21:34 . 2008-07-20 21:34 1,409 --a------ C:\WINDOWS\QTFont.for

2008-07-18 21:40 . 2004-08-04 01:03 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll

2008-07-18 21:40 . 2001-10-06 14:02 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll

2008-07-18 18:20 . 2008-07-18 18:20 <DIR> d-------- C:\WINDOWS\.jagex_cache_32

2008-07-18 18:20 . 2008-07-18 18:20 0 --a------ C:\Documents and Settings\Compaq_Eier\jagex_runescape_preferences.dat

2008-07-18 17:49 . 2008-07-18 17:49 <DIR> d-------- C:\Programfiler\Guitar Pro 5

2008-07-18 16:07 . 2008-07-18 16:07 1,409 --a------ C:\WINDOWS\system32\tmpEE08F.FOT

2008-07-14 18:37 . 2008-07-16 22:13 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\U3

2008-07-13 22:02 . 2008-07-18 18:16 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\skypePM

2008-07-13 22:02 . 2008-07-13 22:02 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat

2008-07-13 21:51 . 2008-07-13 21:51 <DIR> d-------- C:\Programfiler\Skype

2008-07-13 21:51 . 2008-07-13 21:51 <DIR> d-------- C:\Programfiler\Fellesfiler\Skype

2008-07-13 21:51 . 2008-07-18 21:49 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\Skype

2008-07-13 21:51 . 2008-07-13 21:51 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Skype

2008-07-13 21:44 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys

2008-07-13 21:44 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\dllcache\usbaudio.sys

2008-07-13 21:44 . 2004-08-04 01:03 21,504 --a------ C:\WINDOWS\system32\hidserv.dll

2008-07-13 21:44 . 2004-08-04 01:03 21,504 --a------ C:\WINDOWS\system32\dllcache\hidserv.dll

2008-07-13 21:44 . 2001-08-17 22:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys

2008-07-13 21:44 . 2001-08-17 22:02 9,600 --a------ C:\WINDOWS\system32\dllcache\hidusb.sys

2008-07-13 21:04 . 2008-07-13 21:04 268 --ah----- C:\sqmdata00.sqm

2008-07-13 21:04 . 2008-07-13 21:04 244 --ah----- C:\sqmnoopt00.sqm

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-07-28 15:33 --------- d---a-w C:\Documents and Settings\All Users\Programdata\TEMP

2008-07-26 17:25 --------- d-----w C:\Programfiler\Java

2008-07-20 19:34 --------- d-----w C:\Programfiler\QuickTime

2008-07-19 07:44 96,520 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys

2008-07-19 07:44 76,040 ----a-w C:\WINDOWS\system32\drivers\avgtdix.sys

2008-07-19 07:44 10,520 ----a-w C:\WINDOWS\system32\avgrsstx.dll

2008-07-18 20:16 --------- d-----w C:\Documents and Settings\All Users\Programdata\Microsoft Help

2008-07-18 14:09 --------- d-----w C:\Programfiler\PonyGirl2

2008-07-13 19:38 --------- d-----w C:\Documents and Settings\Compaq_Eier\Programdata\HP

2008-06-20 17:43 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll

2008-06-20 17:43 246,784 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll

2008-06-20 17:43 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll

2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys

2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys

2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys

2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys

2008-06-19 20:58 1,024 ----a-w C:\Documents and Settings\All Users\Programdata\pdfdoc2.dll

2008-06-18 20:44 --------- d-----w C:\Programfiler\CCleaner

2008-06-15 21:13 --------- d-----w C:\Documents and Settings\All Users\Programdata\WLInstaller

2008-06-14 18:00 272,256 ------w C:\WINDOWS\system32\drivers\bthport.sys

2008-06-14 18:00 272,256 ------w C:\WINDOWS\system32\dllcache\bthport.sys

2008-06-14 09:17 --------- d-----w C:\Programfiler\MSBuild

2008-06-14 09:17 --------- d-----w C:\Programfiler\Microsoft Works

2008-06-14 09:16 --------- d-----w C:\Programfiler\Microsoft.NET

2008-06-14 05:40 --------- d-----w C:\Programfiler\Microsoft CAPICOM 2.1.0.2

2008-06-14 05:33 --------- d-----w C:\Programfiler\MSXML 4.0

2008-06-13 12:28 --------- d-----w C:\Documents and Settings\All Users\Programdata\QuickTime

2008-06-12 21:18 --------- d-----w C:\Documents and Settings\All Users\Programdata\SUPERAntiSpyware.com

2008-06-12 21:17 --------- d-----w C:\Programfiler\SUPERAntiSpyware

2008-06-12 21:17 --------- d-----w C:\Programfiler\Fellesfiler\Wise Installation Wizard

2008-06-12 21:17 --------- d-----w C:\Documents and Settings\Compaq_Eier\Programdata\SUPERAntiSpyware.com

2008-06-12 17:20 --------- d-----w C:\Programfiler\directx

2008-06-12 17:16 --------- d-----w C:\Programfiler\Eidos Interactive

2008-06-12 13:26 --------- d-----w C:\Programfiler\SweetIM

2008-06-12 13:25 --------- d-----w C:\Documents and Settings\Compaq_Eier\Programdata\AVGTOOLBAR

2008-06-12 13:15 --------- d-----w C:\Programfiler\AVG

2008-06-12 13:15 --------- d-----w C:\Documents and Settings\All Users\Programdata\avg8

2008-06-12 12:46 --------- d-----w C:\Documents and Settings\All Users\Programdata\SweetIM

2008-06-12 11:28 --------- d-----w C:\Programfiler\Windows Live

2008-06-12 11:27 --------- dcsh--w C:\Programfiler\Fellesfiler\WindowsLiveInstaller

2008-06-11 20:54 --------- d-----w C:\Programfiler\HP

2008-06-11 20:54 --------- d-----w C:\Documents and Settings\All Users\Programdata\HP

2008-06-11 20:51 --------- d-----w C:\Programfiler\Fellesfiler\Hewlett-Packard

2008-06-11 20:49 --------- d-----w C:\Documents and Settings\Compaq_Eier\Programdata\HPQ

2008-06-11 20:46 1,869 --sha-r C:\WINDOWS\system32\drivers\103C_HP_CPC_RF147AA-UUW SR1939SC EL630_YC_0Pres_QCZB630_E63NOheREA1_48_IAMETHYST-M_SMSI_V1.0_B3.48_T060324_WXH2_L414_M447_J160_7AMD_8Athlon 64_92.19_#060918_N10EC8139_Z_G10025954_OHL-DT-ST DVDRRW GSA-H21N_DLCD905A.MRK

2008-06-11 19:52 --------- d-----w C:\Programfiler\Google

2008-06-11 19:44 --------- d-----w C:\Programfiler\Fellesfiler\Adobe

2008-06-11 19:42 --------- d-----w C:\Documents and Settings\Compaq_Eier\Programdata\AdobeUM

2008-06-11 19:10 --------- d--h--w C:\Programfiler\InstallShield Installation Information

2008-06-11 19:10 --------- d-----w C:\Programfiler\D-Link

2008-06-11 19:10 --------- d-----w C:\Programfiler\Alpha Networks

2008-06-11 19:07 --------- d-----w C:\Programfiler\Fellesfiler\Symantec Shared

2008-06-11 19:07 --------- d-----w C:\Documents and Settings\All Users\Programdata\Symantec

2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys

2008-05-07 05:16 1,290,752 ----a-w C:\WINDOWS\system32\quartz.dll

2008-05-07 05:16 1,290,752 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll

.

 

((((((((((((((((((((((((((((( snapshot@2008-07-25_23.52.34.20 )))))))))))))))))))))))))))))))))))))))))

.

- 2005-08-26 21:55:46 49,248 ----a-w C:\WINDOWS\system32\java.exe

+ 2008-06-09 23:21:01 135,168 ----a-w C:\WINDOWS\system32\java.exe

- 2005-08-26 21:55:58 49,250 ----a-w C:\WINDOWS\system32\javaw.exe

+ 2008-06-09 23:21:04 135,168 ----a-w C:\WINDOWS\system32\javaw.exe

- 2005-08-27 00:14:46 127,078 ----a-w C:\WINDOWS\system32\javaws.exe

+ 2008-06-10 00:32:34 139,264 ----a-w C:\WINDOWS\system32\javaws.exe

- 2008-01-25 19:33:26 122,880 ----a-w C:\WINDOWS\system32\msrun9er-.dll

+ 2007-07-25 15:33:09 122,880 ----a-w C:\WINDOWS\system32\msrun9er-.dll

- 2007-01-30 20:32:01 9,844 ----a-w C:\WINDOWS\system32\mswmnnove.dll

+ 2006-06-05 21:40:23 9,844 ----a-w C:\WINDOWS\system32\mswmnnove.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"swg"="C:\Programfiler\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-06-11 21:18 171448]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]

"MsnMsgr"="C:\Programfiler\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]

"SUPERAntiSpyware"="C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]

"9c7ce"="c:\programfiler\qtvxhhfjwzafh\uehjlvv.exe" [2006-03-15 00:15 1554066]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 23:14 237568]

"HPBootOp"="C:\Programfiler\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 23:34 249856]

"HP Software Update"="C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]

"D-Link AirPlus Xtreme G"="C:\Programfiler\D-Link\AirPlus Xtreme G\AirPlusCFG.exe" [2003-11-04 17:00 2502656]

"ANIWZCSService"="C:\Programfiler\Alpha Networks\ANIWZCS Service\WZCSLDR.exe" [2003-08-21 16:12 32768]

"SweetIM"="C:\Programfiler\SweetIM\Messenger\SweetIM.exe" [2008-03-27 19:31 111928]

"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-19 09:44 1232152]

"GrooveMonitor"="C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]

"KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 16:44 61440]

"SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]

"QuickTime Task"="C:\Programfiler\QuickTime\qttask.exe" [2008-07-20 21:34 413696]

"9c7ce"="c:\programfiler\qtvxhhfjwzafh\uehjlvv.exe" [2006-03-15 00:15 1554066]

"TkBellExe"="realsched.exe" [bU]

 

C:\Documents and Settings\Administrator\Start-meny\Programmer\Oppstart\

Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-01-03 05:07:26 27136]

 

C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\

HP Digital Imaging Monitor.lnk - C:\Programfiler\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]

Hurtigstart for Adobe Reader.lnk - C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2007-04-19 13:41 294912 C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=avgrsstx.dll

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqste08.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hposfx08.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hposid01.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpoews01.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=

"C:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"=

"C:\\Programfiler\\Windows Live\\Messenger\\livecall.exe"=

"C:\\Programfiler\\AVG\\AVG8\\avgupd.exe"=

"C:\\Programfiler\\AVG\\AVG8\\avgemc.exe"=

"C:\\Programfiler\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"C:\\Programfiler\\Microsoft Office\\Office12\\GROOVE.EXE"=

"C:\\Programfiler\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"C:\\Programfiler\\Skype\\Phone\\Skype.exe"=

 

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-19 09:44]

R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-19 09:44]

R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-19 09:44]

R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-19 09:44]

R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys [2003-10-22 15:27]

.

Contents of the 'Scheduled Tasks' folder

"2008-07-13 19:13:39 C:\WINDOWS\Tasks\Internett-tjenester.job"

- C:\Programfiler\Hewlett-Packard\SDP\HPSdpApp.exea/remind /LaunchPoint reminder /App C:\Programfiler\Hewlett-Packard\Internet Services\StartIS.aml

.

.

------- Supplementary Scan -------

.

R0 -: HKCU-Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=NB_NO&c=63&bd=PRESARIO&pf=desktop

R0 -: HKCU-Main,Default_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=NB_NO&c=63&bd=PRESARIO&pf=desktop

R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

R0 -: HKLM-Main,Search Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=NB_NO&c=63&bd=PRESARIO&pf=desktop

R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=NB_NO&c=63&bd=PRESARIO&pf=desktop

O8 -: E&ksporter til Microsoft Excel - C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000

 

 

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-28 23:06:37

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

 

C:\WINDOWS\system32\msrun9er-.dll 122880 bytes executable

 

scan completed successfully

hidden files: 1

 

**************************************************************************

.

Completion time: 2008-07-28 23:07:48

ComboFix-quarantined-files.txt 2008-07-28 21:07:44

ComboFix2.txt 2008-07-26 17:36:36

ComboFix3.txt 2008-07-25 22:37:04

ComboFix4.txt 2008-07-25 21:54:21

 

Pre-Run: 135,822,139,392 byte ledig

Post-Run: 135,941,431,296 byte ledig

 

228 --- E O F --- 2008-07-22 07:20:29

Lenke til kommentar

Kopiere fet tekst under bildet->åpne notisblokk og lim inn.

Lagre på skrivebordet som CFScript.txt

Gjør som på bildet combofix vil starte,Post logg c:\combofix.txt

cfscriptyt1.gif

 

File::

C:\WINDOWS\system32\msrun9er-.dll

C:\WINDOWS\system32\msrun9er-.dll

C:\WINDOWS\system32\mswmnnove.dll

C:\WINDOWS\system32\mswmnnove.dll

 

Registry::

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"9c7ce"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"9c7ce"=-

 

---

Last ned kjør CCleaner

'Valg'->'Avansert'. Fjern avkryssingen framfor: "bare slett midlertidige filer som er eldere enn 48 t.

Kjør og register-renser"svar ja til og reparere"-->backup svar ja når du blir spørt.

Kjør register-renser et par ganger til alle feil er borte.

---

I post #19 fikk du ikke CFCript.txt til og virke.

Post combofix loggen så vi ser det virker.

---

Restart

---

En runde med MBAM

---

Scann nå med AVG

Finner den noe nå må du ta med plassering,altså stien til filen.

Ikke hva det er som i post #30

Endret av SNIPPSAT
Lenke til kommentar

ComboFix 08-07-24.3 - Compaq_Eier 2008-07-31 9:38:37.5 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1044.18.135 [GMT 2:00]

Running from: C:\Documents and Settings\Compaq_Eier\Skrivebord\ComboFix.exe

Command switches used :: C:\Documents and Settings\Compaq_Eier\Skrivebord\CFScript.txt

* Created a new restore point

 

FILE ::

C:\WINDOWS\system32\msrun9er-.dll

C:\WINDOWS\system32\mswmnnove.dll

.

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\WINDOWS\system32\msrun9er-.dll

C:\WINDOWS\system32\mswmnnove.dll

 

.

((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-31 )))))))))))))))))))))))))))))))

.

 

2008-07-31 09:31 . 2008-07-31 09:34 <DIR> dr-h----- C:\Documents and Settings\Compaq_Eier\Siste

2008-07-30 22:44 . 2008-07-30 22:44 268 --ah----- C:\sqmdata02.sqm

2008-07-30 22:44 . 2008-07-30 22:44 244 --ah----- C:\sqmnoopt02.sqm

2008-07-29 17:09 . 2008-07-29 17:20 <DIR> d-------- C:\Programfiler\ZC Video Converter

2008-07-29 16:33 . 2008-07-29 16:33 <DIR> d-------- C:\Programfiler\Red Kawa

2008-07-29 16:33 . 2008-07-29 16:33 <DIR> d-------- C:\Programfiler\AviSynth 2.5

2008-07-29 00:16 . 2008-07-29 00:16 268 --ah----- C:\sqmdata01.sqm

2008-07-29 00:16 . 2008-07-29 00:16 244 --ah----- C:\sqmnoopt01.sqm

2008-07-26 19:25 . 2008-07-26 19:25 <DIR> d-------- C:\Programfiler\Sun

2008-07-26 19:25 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl

2008-07-26 09:17 . 2008-07-26 09:17 <DIR> d-------- C:\Programfiler\Trend Micro

2008-07-26 09:02 . 2008-07-26 09:02 <DIR> d-------- C:\Programfiler\Malwarebytes' Anti-Malware

2008-07-26 09:02 . 2008-07-26 09:02 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\Malwarebytes

2008-07-26 09:02 . 2008-07-26 09:02 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Malwarebytes

2008-07-26 09:02 . 2008-07-23 20:21 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys

2008-07-26 09:02 . 2008-07-23 20:21 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys

2008-07-25 23:31 . 2006-01-03 05:40 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS

2008-07-25 23:31 . 2008-06-12 06:34 <DIR> dr------- C:\Documents and Settings\Administrator\Start-meny

2008-07-25 23:31 . 2005-10-20 23:51 <DIR> d--h----- C:\Documents and Settings\Administrator\Skrivere

2008-07-25 23:31 . 2005-10-20 23:51 <DIR> d-------- C:\Documents and Settings\Administrator\Skrivebord

2008-07-25 23:31 . 2008-06-12 06:34 <DIR> dr-h----- C:\Documents and Settings\Administrator\Siste

2008-07-25 23:31 . 2008-06-12 06:34 <DIR> dr-h----- C:\Documents and Settings\Administrator\Programdata

2008-07-25 23:31 . 2008-06-12 06:34 <DIR> dr------- C:\Documents and Settings\Administrator\Mine dokumenter

2008-07-25 23:31 . 2005-10-27 04:33 <DIR> d--h----- C:\Documents and Settings\Administrator\Maler

2008-07-25 23:31 . 2008-07-31 09:40 <DIR> d--h----- C:\Documents and Settings\Administrator\Lokale innstillinger

2008-07-25 23:31 . 2008-06-11 22:48 <DIR> dr------- C:\Documents and Settings\Administrator\Favoritter

2008-07-25 23:31 . 2005-10-20 23:51 <DIR> d--h----- C:\Documents and Settings\Administrator\AndrMask

2008-07-25 23:31 . 2008-07-25 23:31 <DIR> d-------- C:\Documents and Settings\Administrator

2008-07-25 22:16 . 2008-07-25 22:16 <DIR> d--hs---- C:\WINDOWS\ftpcache

2008-07-24 21:02 . 2008-07-24 21:02 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\AVS4YOU

2008-07-24 20:53 . 2008-07-24 20:53 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\AVS4YOU

2008-07-24 20:49 . 2008-07-24 20:53 <DIR> d-------- C:\Programfiler\Fellesfiler\AVSMedia

2008-07-24 20:42 . 2008-07-24 20:54 <DIR> d-------- C:\Programfiler\AVS4YOU

2008-07-24 20:32 . 2008-07-29 10:44 <DIR> d--h----- C:\$AVG8.VAULT$

2008-07-20 21:34 . 2008-07-20 21:34 54,156 --ah----- C:\WINDOWS\QTFont.qfn

2008-07-20 21:34 . 2008-07-20 21:34 1,409 --a------ C:\WINDOWS\QTFont.for

2008-07-18 21:40 . 2004-08-04 01:03 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll

2008-07-18 21:40 . 2001-10-06 14:02 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll

2008-07-18 18:20 . 2008-07-18 18:20 <DIR> d-------- C:\WINDOWS\.jagex_cache_32

2008-07-18 18:20 . 2008-07-18 18:20 0 --a------ C:\Documents and Settings\Compaq_Eier\jagex_runescape_preferences.dat

2008-07-18 17:49 . 2008-07-18 17:49 <DIR> d-------- C:\Programfiler\Guitar Pro 5

2008-07-18 16:07 . 2008-07-18 16:07 1,409 --a------ C:\WINDOWS\system32\tmpEE08F.FOT

2008-07-14 18:37 . 2008-07-16 22:13 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\U3

2008-07-13 22:02 . 2008-07-18 18:16 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\skypePM

2008-07-13 22:02 . 2008-07-13 22:02 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat

2008-07-13 21:51 . 2008-07-13 21:51 <DIR> d-------- C:\Programfiler\Skype

2008-07-13 21:51 . 2008-07-13 21:51 <DIR> d-------- C:\Programfiler\Fellesfiler\Skype

2008-07-13 21:51 . 2008-07-18 21:49 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\Skype

2008-07-13 21:51 . 2008-07-13 21:51 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Skype

2008-07-13 21:44 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys

2008-07-13 21:44 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\dllcache\usbaudio.sys

2008-07-13 21:44 . 2004-08-04 01:03 21,504 --a------ C:\WINDOWS\system32\hidserv.dll

2008-07-13 21:44 . 2004-08-04 01:03 21,504 --a------ C:\WINDOWS\system32\dllcache\hidserv.dll

2008-07-13 21:44 . 2001-08-17 22:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys

2008-07-13 21:44 . 2001-08-17 22:02 9,600 --a------ C:\WINDOWS\system32\dllcache\hidusb.sys

2008-07-13 21:04 . 2008-07-13 21:04 268 --ah----- C:\sqmdata00.sqm

2008-07-13 21:04 . 2008-07-13 21:04 244 --ah----- C:\sqmnoopt00.sqm

2008-06-19 22:50 . 2008-06-19 22:50 <DIR> d-------- C:\Ny mappe

2008-06-19 22:47 . 2008-06-19 22:58 1,024 --a------ C:\Documents and Settings\All Users\Programdata\pdfdoc2.dll

2008-06-19 22:43 . 2001-10-29 01:42 116,224 --a------ C:\WINDOWS\system32\pdfmonnt.dll

2008-06-19 22:19 . 2008-06-19 22:19 <DIR> d-------- C:\temp

2008-06-18 22:44 . 2008-06-18 22:44 <DIR> d-------- C:\Programfiler\CCleaner

2008-06-17 00:15 . 2008-07-30 16:50 <DIR> d-a------ C:\Documents and Settings\All Users\Programdata\TEMP

2008-06-17 00:15 . 2003-07-06 14:07 372,736 --a------ C:\WINDOWS\system32\IJL_11.DLL

2008-06-17 00:15 . 2004-03-09 00:00 212,240 --a------ C:\WINDOWS\system32\RICHTX32.OCX

2008-06-15 23:56 . 2008-06-15 23:57 1,156 --a------ C:\WINDOWS\mozver.dat

2008-06-15 23:54 . 2008-06-15 23:54 0 --a------ C:\WINDOWS\nsreg.dat

2008-06-15 23:28 . 2008-06-15 23:28 <DIR> d-------- C:\WINDOWS\Sun

2008-06-14 11:18 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll

2008-06-14 11:17 . 2008-06-14 11:17 <DIR> d-------- C:\Programfiler\MSBuild

2008-06-14 11:16 . 2008-06-14 11:16 <DIR> d-------- C:\Programfiler\Microsoft.NET

2008-06-14 11:14 . 2008-06-14 11:17 <DIR> d-------- C:\WINDOWS\SHELLNEW

2008-06-14 11:13 . 2008-07-18 22:16 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Microsoft Help

2008-06-14 11:12 . 2008-06-14 11:12 <DIR> dr-h----- C:\MSOCache

2008-06-14 07:40 . 2008-06-14 07:40 <DIR> d-------- C:\Programfiler\Microsoft CAPICOM 2.1.0.2

2008-06-14 07:33 . 2008-06-14 07:33 <DIR> d-------- C:\Programfiler\MSXML 4.0

2008-06-13 18:49 . 2008-06-13 18:49 <DIR> d-------- C:\SEMAFOR

2008-06-13 18:49 . 1995-05-11 22:00 398,416 --a------ C:\WINDOWS\system\VBRUN300.DLL

2008-06-13 18:49 . 2003-02-10 15:30 54,811 --a------ C:\WINDOWS\SETUPSE.EXE

2008-06-13 18:49 . 1993-04-27 22:00 7,008 --a------ C:\WINDOWS\system\SETUPKIT.DLL

2008-06-13 14:39 . 2008-04-23 06:22 6,066,176 --------- C:\WINDOWS\system32\dllcache\ieframe.dll

2008-06-13 14:39 . 2007-04-17 11:32 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat

2008-06-13 14:39 . 2007-03-08 07:11 1,007,616 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui

2008-06-13 14:39 . 2008-04-23 06:22 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll

2008-06-13 14:39 . 2008-04-23 06:22 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll

2008-06-13 14:39 . 2008-04-23 06:22 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll

2008-06-13 14:39 . 2008-04-23 06:22 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll

2008-06-13 14:39 . 2008-04-23 06:22 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll

2008-06-13 14:39 . 2008-04-22 09:39 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe

2008-06-13 14:29 . 1999-11-10 11:05 86,016 --a------ C:\WINDOWS\unvise32qt.exe

2008-06-13 14:29 . 1999-12-17 09:13 86,016 --a------ C:\WINDOWS\unvise32.exe

2008-06-13 14:28 . 2008-06-13 14:29 <DIR> d-------- C:\WINDOWS\system32\QuickTime

2008-06-13 14:28 . 2008-07-20 21:34 <DIR> d-------- C:\Programfiler\QuickTime

2008-06-13 14:28 . 2008-06-13 14:28 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\QuickTime

2008-06-13 14:28 . 2008-06-13 14:28 361 --a------ C:\WINDOWS\system32\QuickTime.qtp

2008-06-13 14:27 . 2008-06-14 20:00 272,256 --------- C:\WINDOWS\system32\drivers\bthport.sys

2008-06-13 14:27 . 2008-06-14 20:00 272,256 --------- C:\WINDOWS\system32\dllcache\bthport.sys

2008-06-13 14:26 . 2008-06-13 14:52 65 --a------ C:\WINDOWS\Artplant_sj2.ini

2008-06-13 14:23 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll

2008-06-13 14:23 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll

2008-06-13 14:23 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui

2008-06-12 23:18 . 2008-06-12 23:18 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\SUPERAntiSpyware.com

2008-06-12 23:17 . 2008-06-12 23:17 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware

2008-06-12 23:17 . 2008-06-12 23:17 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard

2008-06-12 23:17 . 2008-06-12 23:17 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\SUPERAntiSpyware.com

2008-06-12 19:20 . 2008-06-12 19:20 <DIR> d-------- C:\Programfiler\directx

2008-06-12 19:16 . 2008-06-12 19:16 <DIR> d-------- C:\Programfiler\Eidos Interactive

2008-06-12 15:15 . 2008-07-31 09:01 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg

2008-06-12 15:15 . 2008-06-12 15:15 <DIR> d-------- C:\Programfiler\AVG

2008-06-12 15:15 . 2008-06-12 15:25 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Programdata\AVGTOOLBAR

2008-06-12 15:15 . 2008-06-12 15:15 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\avg8

2008-06-12 15:15 . 2008-07-19 09:44 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys

2008-06-12 15:15 . 2008-07-19 09:44 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys

2008-06-12 15:15 . 2008-07-19 09:44 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll

2008-06-12 14:46 . 2008-06-12 15:26 <DIR> d-------- C:\Programfiler\SweetIM

2008-06-12 14:46 . 2008-06-12 14:46 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\SweetIM

2008-06-12 13:28 . 2008-06-12 14:47 <DIR> d-------- C:\Documents and Settings\Compaq_Eier\Contacts

2008-06-12 13:27 . 2008-06-12 13:27 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE

2008-06-12 13:24 . 2008-06-12 13:28 <DIR> d-------- C:\Programfiler\Windows Live

2008-06-12 13:24 . 2008-06-12 13:27 <DIR> d--hsc--- C:\Programfiler\Fellesfiler\WindowsLiveInstaller

2008-06-12 13:23 . 2008-06-15 23:13 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\WLInstaller

2008-06-12 07:34 . 2008-07-18 16:09 <DIR> d-------- C:\Programfiler\PonyGirl2

2008-06-12 06:36 . 2008-07-30 22:44 249 --a------ C:\WINDOWS\system\hpsysdrv.dat

2008-06-12 06:31 . 2008-07-29 17:09 <DIR> dr------- C:\Programfiler

2008-06-12 06:31 . 2008-06-12 06:34 <DIR> dr------- C:\Documents and Settings\Default User\Start-meny

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-07-26 17:25 --------- d-----w C:\Programfiler\Java

2008-06-20 17:43 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll

2008-06-20 17:43 246,784 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll

2008-06-20 17:43 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll

2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys

2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys

2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys

2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys

2008-06-14 09:17 --------- d-----w C:\Programfiler\Microsoft Works

2008-06-11 20:54 --------- d-----w C:\Programfiler\HP

2008-06-11 19:52 --------- d-----w C:\Programfiler\Google

2008-06-11 19:10 --------- d--h--w C:\Programfiler\InstallShield Installation Information

2008-06-11 19:07 --------- d-----w C:\Programfiler\Fellesfiler\Symantec Shared

2008-06-11 19:07 --------- d-----w C:\Documents and Settings\All Users\Programdata\Symantec

2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys

2008-05-07 05:16 1,290,752 ----a-w C:\WINDOWS\system32\quartz.dll

2008-05-07 05:16 1,290,752 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll

2008-04-23 20:22 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll

2008-04-22 07:43 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe

2008-04-22 07:43 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe

2008-04-20 05:07 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll

.

 

((((((((((((((((((((((((((((( snapshot@2008-07-25_23.52.34.20 )))))))))))))))))))))))))))))))))))))))))

.

+ 2008-07-29 14:26:55 68,608 ----a-w C:\WINDOWS\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll

+ 2008-07-29 14:27:05 72,192 ----a-w C:\WINDOWS\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll

+ 2008-07-29 14:27:06 4,308,992 ----a-w C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll

+ 2008-07-29 14:27:07 482,304 ----a-w C:\WINDOWS\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll

+ 2008-07-29 14:27:02 2,878,976 ----a-w C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll

+ 2008-07-29 14:26:49 258,048 ----a-w C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll

+ 2008-07-29 14:26:49 114,176 ----a-w C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll

+ 2008-07-29 14:27:12 260,096 ----a-w C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll

+ 2008-07-29 14:26:58 5,025,792 ----a-w C:\WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll

+ 2008-07-29 14:26:54 10,752 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll

+ 2008-07-29 14:26:49 503,808 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll

+ 2008-07-29 14:26:51 13,312 ----a-w C:\WINDOWS\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll

+ 2008-07-29 14:27:03 8,192 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll

+ 2008-07-29 14:27:04 36,864 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll

+ 2008-07-29 14:27:05 5,632 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll

+ 2008-07-29 14:26:53 413,696 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll

+ 2008-07-29 14:26:53 36,864 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll

+ 2008-07-29 14:26:54 647,168 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll

+ 2008-07-29 14:26:54 73,728 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll

+ 2008-07-29 14:26:52 745,472 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll

+ 2008-07-29 14:27:14 110,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll

+ 2008-07-29 14:27:14 372,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll

+ 2008-07-29 14:26:44 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll

+ 2008-07-29 14:27:13 667,648 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll

+ 2008-07-29 14:27:15 5,632 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll

+ 2008-07-29 14:26:48 12,800 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll

+ 2008-07-29 14:26:47 32,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll

+ 2008-07-29 14:26:48 7,168 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll

+ 2008-07-29 14:27:09 110,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll

+ 2008-07-29 14:26:55 81,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll

+ 2008-07-29 14:27:10 389,120 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll

+ 2008-07-29 14:27:08 716,800 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll

+ 2008-07-29 14:26:50 884,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll

+ 2008-07-29 14:27:03 5,050,368 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll

+ 2008-07-29 14:26:57 188,416 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll

+ 2008-07-29 14:26:56 397,312 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll

+ 2008-07-29 14:26:57 81,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll

+ 2008-07-29 14:27:11 700,416 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll

+ 2008-07-29 14:27:08 368,640 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll

+ 2008-07-29 14:27:12 258,048 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll

+ 2008-07-29 14:27:08 299,008 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll

+ 2008-07-29 14:27:09 131,072 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll

+ 2008-07-29 14:26:55 258,048 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll

+ 2008-07-29 14:26:58 114,688 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll

+ 2008-07-29 14:27:13 835,584 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll

+ 2008-07-29 14:26:59 86,016 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll

+ 2008-07-29 14:27:00 823,296 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll

+ 2008-07-29 14:27:01 5,316,608 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll

+ 2008-07-29 14:27:01 2,035,712 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll

+ 2008-07-29 14:27:11 3,018,752 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll

+ 2008-07-29 14:31:20 26,624 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\09ba68e4f1dd1f43a42a6f416665941e\Accessibility.ni.dll

+ 2008-07-29 14:31:21 860,160 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\68cd2eb2d2079f409785c4436a861dae\AspNetMMCExt.ni.dll

+ 2008-07-29 14:31:22 237,568 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\5fc6a03f31fb284482c24e504a840f73\CustomMarshalers.ni.dll

+ 2008-07-29 14:31:21 15,360 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\dfsvc\ea5a8c8cbd3dd04b8363cc320a571474\dfsvc.ni.exe

+ 2008-07-29 14:31:23 880,640 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\5389a653faf42040b9fcc34a9c302b22\Microsoft.Build.Engine.ni.dll

+ 2008-07-29 14:31:23 81,920 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\d21b854f038a354f841e0e89696a58a5\Microsoft.Build.Framework.ni.dll

+ 2008-07-29 14:31:25 1,691,648 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\807e2455ad63394da95929d341ca0d57\Microsoft.Build.Tasks.ni.dll

+ 2008-07-29 14:31:26 163,840 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\469534dc03d08741b7f33f9f6b20487d\Microsoft.Build.Utilities.ni.dll

+ 2008-07-29 14:31:29 1,724,416 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\0abdfdd79eee8a4bbdfb7223525661c0\Microsoft.VisualBasic.ni.dll

+ 2008-07-29 14:27:52 11,415,552 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\8e6f6dfdedf32544938ff5dfb4cc7449\mscorlib.ni.dll

+ 2008-07-29 14:31:30 962,560 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\6f38c4f36827094fb6a49a8eaecbe900\System.Configuration.ni.dll

+ 2008-07-29 14:28:39 6,688,768 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\b2f388d73df9e948879bc0b3d940862b\System.Data.ni.dll

+ 2008-07-29 14:31:31 1,712,128 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Deployment\13a3725e76df5b4fb1b927888e90a69f\System.Deployment.ni.dll

+ 2008-07-29 14:28:53 10,723,328 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Design\65e2b7447fd79d458f67534b7a1ae320\System.Design.ni.dll

+ 2008-07-29 14:31:33 1,220,608 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\32dea38a177f7e4c94dd774d14dfa5f3\System.DirectoryServices.ni.dll

+ 2008-07-29 14:31:34 512,000 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\f67828f5e802a14bae3f0836b7cc1970\System.DirectoryServices.Protocols.ni.dll

+ 2008-07-29 14:28:08 229,376 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\22f85751a8e76a4ba58b7a05100a1b5b\System.Drawing.Design.ni.dll

+ 2008-07-29 14:28:11 1,626,112 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\499e97cd8bba974fbd737cffa830e5a7\System.Drawing.ni.dll

+ 2008-07-29 14:31:35 659,456 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\6ba5c94bebd2fc4592aafaeff9c523ca\System.EnterpriseServices.ni.dll

+ 2008-07-29 14:31:35 294,912 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\6ba5c94bebd2fc4592aafaeff9c523ca\System.EnterpriseServices.Wrapper.dll

+ 2008-07-29 14:31:36 729,088 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Security\c232abc40b03b24b96c8412d7047470d\System.Security.ni.dll

+ 2008-07-29 14:31:37 684,032 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\3238040f8b5aad40b1f46bcc713cbb6f\System.Transactions.ni.dll

+ 2008-07-29 14:31:56 2,310,144 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\dbd43bffded554478495d70709646599\System.Web.Mobile.ni.dll

+ 2008-07-29 14:31:56 237,568 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\c96f173c7ea0ee4fa8e94ff535e30b26\System.Web.RegularExpressions.ni.dll

+ 2008-07-29 14:31:59 1,945,600 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\2b530c76075fe74c8cf8832e4b0caf7a\System.Web.Services.ni.dll

+ 2008-07-29 14:31:51 11,808,768 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\5e47984b90ca2d47a99b8ac9f7f7bfa7\System.Web.ni.dll

+ 2008-07-29 14:28:23 13,107,200 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\69102b6b67cba443a614acefb5715404\System.Windows.Forms.ni.dll

+ 2008-07-29 14:28:32 5,640,192 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\6862868c3d3af14aaccbe36570e7a993\System.Xml.ni.dll

+ 2008-07-29 14:28:06 8,093,696 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\2f3920b5b4d9d1469983783573b5cdf8\System.ni.dll

- 2003-02-21 02:09:46 57,344 ----a-w C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe

+ 2005-09-23 05:28:52 72,704 ----a-w C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe

- 2003-02-21 02:09:32 5,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp10.dll

+ 2005-09-23 05:28:52 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp10.dll

+ 2005-09-23 05:28:56 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp20_mscorwks.dll

+ 2005-09-23 05:28:58 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp20_perfcounter.dll

+ 2005-09-23 05:28:56 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\SharedReg12.dll

- 2003-02-21 01:43:50 131,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll

+ 2005-09-23 05:28:52 86,528 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll

+ 2005-09-23 05:28:36 18,944 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll

+ 2005-09-23 05:28:42 136,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll

+ 2005-09-23 05:28:44 4,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll

+ 2005-09-23 05:29:04 183,808 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\vbc7ui.dll

+ 2005-09-23 05:28:28 208,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\Vsavb7rtUI.dll

+ 2005-09-23 05:28:56 10,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll

+ 2005-09-23 05:28:58 138,240 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AdoNetDiag.dll

+ 2005-09-23 05:28:36 87,552 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\alink.dll

+ 2005-09-23 05:28:58 55,488 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe

+ 2005-09-23 05:28:32 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe

+ 2005-09-23 05:28:32 10,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll

+ 2005-09-23 05:28:32 8,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll

+ 2005-09-23 05:28:32 23,552 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll

+ 2005-09-23 05:28:32 70,656 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll

+ 2005-09-23 05:28:32 13,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe

+ 2005-09-23 05:28:32 26,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe

+ 2005-09-23 05:28:32 106,496 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe

+ 2005-09-23 05:28:32 29,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe

+ 2005-09-23 05:28:32 29,888 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe

+ 2005-09-23 05:28:32 503,808 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AspNetMMCExt.dll

+ 2005-09-23 05:28:56 106,496 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CasPol.exe

+ 2005-09-23 05:28:56 88,576 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll

+ 2005-09-23 05:28:42 76,984 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\csc.exe

+ 2005-09-23 05:28:42 1,144,832 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscomp.dll

+ 2005-09-23 05:28:42 13,312 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll

+ 2005-09-23 05:28:58 17,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Culture.dll

+ 2005-09-23 05:28:56 68,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll

+ 2005-09-23 05:28:44 31,936 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cvtres.exe

+ 2005-09-23 05:28:38 52,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfdll.dll

+ 2005-09-23 05:28:38 4,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe

+ 2005-09-23 05:29:12 547,840 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll

+ 2005-09-23 05:28:56 788,992 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll

+ 2005-09-23 05:28:50 9,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\fusion.dll

+ 2005-09-23 05:28:56 9,728 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExec.exe

+ 2005-09-23 05:28:56 8,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll

+ 2005-09-23 05:28:56 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEHost.dll

+ 2005-09-23 05:28:56 5,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll

+ 2005-09-23 05:28:56 224,952 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ilasm.exe

+ 2005-09-23 05:28:56 28,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe

+ 2005-09-23 05:28:56 55,296 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll

+ 2005-09-23 05:28:56 72,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll

+ 2005-09-23 05:28:48 40,960 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\jsc.exe

+ 2005-09-23 05:01:16 609,472 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe

+ 2005-09-23 04:29:48 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1025.dll

+ 2005-09-23 04:32:24 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1028.dll

+ 2005-09-23 04:34:10 82,944 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1029.dll

+ 2005-09-23 04:34:12 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1030.dll

+ 2005-09-23 04:34:44 85,504 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1031.dll

+ 2005-09-23 04:36:24 87,552 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1032.dll

+ 2005-09-23 01:46:14 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1033.dll

+ 2005-09-23 04:38:26 81,408 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1035.dll

+ 2005-09-23 04:38:52 86,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1036.dll

+ 2005-09-23 04:40:30 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1037.dll

+ 2005-09-23 04:40:32 83,968 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1038.dll

+ 2005-09-23 04:40:56 84,480 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1040.dll

+ 2005-09-23 04:42:58 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1041.dll

+ 2005-09-23 04:44:58 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1042.dll

+ 2005-09-23 04:46:38 83,456 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1043.dll

+ 2005-09-23 04:46:38 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1044.dll

+ 2005-09-23 04:46:40 83,456 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1045.dll

+ 2005-09-23 04:47:04 82,432 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1046.dll

+ 2005-09-23 04:47:30 82,432 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1049.dll

+ 2005-09-23 04:47:32 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1053.dll

+ 2005-09-23 04:47:32 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1055.dll

+ 2005-09-23 04:30:18 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.2052.dll

+ 2005-09-23 04:47:06 84,480 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.2070.dll

+ 2005-09-23 04:29:50 80,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.3076.dll

+ 2005-09-23 04:36:48 85,504 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.3082.dll

+ 2005-09-23 05:57:06 245,408 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\unicows.dll

+ 2005-09-23 05:28:48 413,696 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Engine.dll

+ 2005-09-23 05:28:48 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll

+ 2005-09-23 05:28:48 647,168 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Tasks.dll

+ 2005-09-23 05:28:48 73,728 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll

+ 2005-09-23 05:28:48 745,472 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll

+ 2005-09-23 05:29:10 110,592 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.Data.dll

+ 2005-09-23 05:29:10 372,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.dll

+ 2005-09-23 05:29:08 667,648 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.dll

+ 2005-09-23 05:28:30 28,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll

+ 2005-09-23 05:29:10 5,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll

+ 2005-09-23 05:28:30 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll

+ 2005-09-23 05:28:30 12,800 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll

+ 2005-09-23 05:28:30 7,168 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll

+ 2005-09-23 05:28:32 87,552 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll

+ 2005-09-23 05:28:48 69,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe

+ 2005-09-23 05:28:56 800,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll

+ 2005-09-23 05:28:56 73,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll

+ 2005-09-23 05:28:56 288,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordbi.dll

+ 2005-09-23 05:28:56 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll

+ 2005-09-23 05:28:56 326,144 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll

+ 2005-09-23 05:28:56 81,408 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorld.dll

+ 2005-09-23 05:28:56 4,308,992 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll

+ 2005-09-23 05:28:56 102,400 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorpe.dll

+ 2005-09-23 05:29:00 330,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll

+ 2005-09-23 05:28:56 67,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll

+ 2005-09-23 05:28:50 9,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll

+ 2005-09-23 05:28:56 226,816 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll

+ 2005-09-23 05:28:56 66,240 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

+ 2005-09-23 05:28:56 10,240 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscortim.dll

+ 2005-09-23 05:28:50 5,615,616 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll

+ 2005-09-23 05:29:00 22,528 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MUI\0409\mscorsecr.dll

+ 2005-09-23 05:28:56 96,440 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ngen.exe

+ 2005-09-23 05:28:56 14,848 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\normalization.dll

+ 2005-09-23 05:28:56 78,336 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll

+ 2005-09-23 05:28:50 136,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\peverify.dll

+ 2005-09-23 05:28:56 53,248 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe

+ 2005-09-23 05:28:56 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe

+ 2005-09-23 05:29:02 59,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe

+ 2005-09-23 05:28:58 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll

+ 2005-09-23 05:28:56 107,520 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\shfusion.dll

+ 2005-09-23 05:29:00 85,504 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll

+ 2005-09-23 05:28:56 377,344 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\SOS.dll

+ 2005-09-23 05:28:56 110,592 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll

+ 2005-09-23 05:28:58 389,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.configuration.dll

+ 2005-09-23 05:28:56 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll

+ 2005-09-23 05:28:56 2,878,976 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.dll

+ 2005-09-23 05:28:56 482,304 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll

+ 2005-09-23 05:28:56 716,800 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.SqlXml.dll

+ 2005-09-23 05:28:38 884,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Deployment.dll

+ 2005-09-23 05:28:56 5,050,368 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Design.dll

+ 2005-09-23 05:28:56 397,312 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll

+ 2005-09-23 05:28:56 188,416 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll

+ 2005-09-23 05:28:56 3,018,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.dll

+ 2005-09-23 05:28:56 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll

+ 2005-09-23 05:28:56 700,416 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll

+ 2005-09-23 05:28:56 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll

+ 2005-09-23 05:28:56 47,616 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll

+ 2005-09-23 05:28:56 114,176 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Wrapper.dll

+ 2005-09-23 05:28:56 368,640 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Management.dll

+ 2005-09-23 05:28:56 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll

+ 2005-09-23 05:28:56 299,008 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Remoting.dll

+ 2005-09-23 05:28:56 131,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll

+ 2005-09-23 05:28:56 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Security.dll

+ 2005-09-23 05:28:56 114,688 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll

+ 2005-09-23 05:28:56 260,096 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Transactions.dll

+ 2005-09-23 05:28:56 5,025,792 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.dll

+ 2005-09-23 05:28:56 835,584 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.Mobile.dll

+ 2005-09-23 05:28:56 86,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll

+ 2005-09-23 05:28:56 823,296 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.Services.dll

+ 2005-09-23 05:28:56 5,316,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll

+ 2005-09-23 05:28:56 2,035,712 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.XML.dll

+ 2005-09-23 05:28:56 71,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL

+ 2005-09-23 05:29:06 1,140,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\vbc.exe

+ 2005-09-23 05:28:30 1,306,624 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll

+ 2005-09-23 05:28:32 298,496 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\webengine.dll

+ 2005-09-23 05:28:56 28,160 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll

+ 2006-12-31 02:16:36 313,344 ----a-w C:\WINDOWS\system32\avisynth.dll

+ 2004-05-26 12:37:34 719,872 ----a-w C:\WINDOWS\system32\devil.dll

+ 2005-09-23 05:28:38 83,456 ----a-w C:\WINDOWS\system32\dfshim.dll

- 2005-08-26 21:55:46 49,248 ----a-w C:\WINDOWS\system32\java.exe

+ 2008-06-09 23:21:01 135,168 ----a-w C:\WINDOWS\system32\java.exe

- 2005-08-26 21:55:58 49,250 ----a-w C:\WINDOWS\system32\javaw.exe

+ 2008-06-09 23:21:04 135,168 ----a-w C:\WINDOWS\system32\javaw.exe

- 2005-08-27 00:14:46 127,078 ----a-w C:\WINDOWS\system32\javaws.exe

+ 2008-06-10 00:32:34 139,264 ----a-w C:\WINDOWS\system32\javaws.exe

- 2004-07-15 05:34:06 16,896 ----a-w C:\WINDOWS\system32\mscorier.dll

+ 2005-09-23 05:28:52 150,016 ----a-w C:\WINDOWS\system32\mscorier.dll

- 2003-02-21 02:09:14 106,496 ----a-w C:\WINDOWS\system32\mscories.dll

+ 2005-09-23 05:28:52 74,240 ----a-w C:\WINDOWS\system32\mscories.dll

- 2008-06-14 05:53:26 53,572 ----a-w C:\WINDOWS\system32\perfc009.dat

+ 2008-07-29 14:28:56 63,152 ----a-w C:\WINDOWS\system32\perfc009.dat

- 2008-06-14 05:53:26 61,348 ----a-w C:\WINDOWS\system32\perfc014.dat

+ 2008-07-29 14:28:56 71,738 ----a-w C:\WINDOWS\system32\perfc014.dat

- 2008-06-14 05:53:26 381,828 ----a-w C:\WINDOWS\system32\perfh009.dat

+ 2008-07-29 14:28:56 402,542 ----a-w C:\WINDOWS\system32\perfh009.dat

- 2008-06-14 05:53:26 386,354 ----a-w C:\WINDOWS\system32\perfh014.dat

+ 2008-07-29 14:28:56 406,516 ----a-w C:\WINDOWS\system32\perfh014.dat

+ 2008-07-29 14:26:49 258,048 ----a-w C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll

+ 2008-07-29 14:26:49 114,176 ----a-w C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll

.

-- Snapshot reset to current date --

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"swg"="C:\Programfiler\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-06-11 21:18 171448]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]

"MsnMsgr"="C:\Programfiler\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]

"SUPERAntiSpyware"="C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]

"ccleaner"="C:\Programfiler\CCleaner\CCleaner.exe" [2008-05-28 16:40 1197296]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 23:14 237568]

"HPBootOp"="C:\Programfiler\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 23:34 249856]

"HP Software Update"="C:\Programfiler\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]

"D-Link AirPlus Xtreme G"="C:\Programfiler\D-Link\AirPlus Xtreme G\AirPlusCFG.exe" [2003-11-04 17:00 2502656]

"ANIWZCSService"="C:\Programfiler\Alpha Networks\ANIWZCS Service\WZCSLDR.exe" [2003-08-21 16:12 32768]

"SweetIM"="C:\Programfiler\SweetIM\Messenger\SweetIM.exe" [2008-03-27 19:31 111928]

"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-19 09:44 1232152]

"GrooveMonitor"="C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]

"KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 16:44 61440]

"SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]

"QuickTime Task"="C:\Programfiler\QuickTime\qttask.exe" [2008-07-20 21:34 413696]

"9c7ce"="c:\programfiler\qtvxhhfjwzafh\uehjlvv.exe" [2006-03-15 00:15 1554066]

"TkBellExe"="realsched.exe" [bU]

 

C:\Documents and Settings\Administrator\Start-meny\Programmer\Oppstart\

Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-01-03 05:07:26 27136]

 

C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\

HP Digital Imaging Monitor.lnk - C:\Programfiler\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]

Hurtigstart for Adobe Reader.lnk - C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2007-04-19 13:41 294912 C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=avgrsstx.dll

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqste08.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hposfx08.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hposid01.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpoews01.exe"=

"C:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=

"C:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"=

"C:\\Programfiler\\Windows Live\\Messenger\\livecall.exe"=

"C:\\Programfiler\\AVG\\AVG8\\avgupd.exe"=

"C:\\Programfiler\\AVG\\AVG8\\avgemc.exe"=

"C:\\Programfiler\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"C:\\Programfiler\\Microsoft Office\\Office12\\GROOVE.EXE"=

"C:\\Programfiler\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"C:\\Programfiler\\Skype\\Phone\\Skype.exe"=

 

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-19 09:44]

R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-19 09:44]

R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-19 09:44]

R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-19 09:44]

R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys [2003-10-22 15:27]

.

Contents of the 'Scheduled Tasks' folder

"2008-07-13 19:13:39 C:\WINDOWS\Tasks\Internett-tjenester.job"

- C:\Programfiler\Hewlett-Packard\SDP\HPSdpApp.exea/remind /LaunchPoint reminder /App C:\Programfiler\Hewlett-Packard\Internet Services\StartIS.aml

.

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-31 09:40:54

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

Completion time: 2008-07-31 9:42:00

ComboFix-quarantined-files.txt 2008-07-31 07:41:56

ComboFix2.txt 2008-07-28 21:07:50

ComboFix3.txt 2008-07-26 17:36:36

ComboFix4.txt 2008-07-25 22:37:04

ComboFix5.txt 2008-07-31 07:35:23

 

Pre-Run: 135,637,913,600 byte ledig

Post-Run: 135,633,760,256 byte ledig

 

518 --- E O F --- 2008-07-22 07:20:29

Lenke til kommentar

Kopiere fet tekst under,lim inn i notisblokk.

Lagrer på skrivebordet som fjerne.reg

Dobbelklikk på fjerne fjerne.reg(svar ja)

 

REGEDIT4

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"9c7ce"=-

 

Når du har kjørt det i post #34.

Se om avg finner noe nå.

Endret av SNIPPSAT
Lenke til kommentar
Kopiere fet tekst under,lim inn i notisblokk.

Lagrer på skrivebordet som fjerne.reg

Dobbelklikk på fjerne fjerne.reg(svar ja)

 

REGEDIT4

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"9c7ce"=-

 

Når du har kjørt det i post #34.

Se om avg finner noe nå.

 

 

Nå har jeg kjørt MBAM og AVG uten at den finner noe. Skal kjøre det du skrev over i kveld, rekker ikke å gjøre det nå. Kjenner at humøret steg flere hakk da det ikke dukket opp noe da MBAM og AVG ble kjørt :-)

Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
  • Hvem er aktive   0 medlemmer

    • Ingen innloggede medlemmer aktive
×
×
  • Opprett ny...