ComboFix 09-08-02.04 - Relacom 03.08.2009 18:59.5.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.47.1044.18.2038.1423 [GMT 2:00]
Kjører fra: c:\documents and settings\Relacom\Skrivebord\CoFix.exe
AV: McAfee VirusScan Enterprise *On-access scanning disabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
.
((((((((((((((((((((((((((((((((((((((( Andre slettinger )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\mrxdavv.sys
c:\windows\system32\kwave.sys
.
((((((((((((((((((((((((((( Filer Opprettet Fra 2009-07-03 til 2009-08-03 )))))))))))))))))))))))))))))))))
.
2009-08-03 16:09 . 2009-08-03 16:09 -------- d-----w- c:\documents and settings\Relacom\Programdata\simon4
2009-08-03 16:06 . 2006-12-08 10:02 251672 ----a-w- c:\windows\system32\xactengine2_5.dll
2009-08-03 16:06 . 2006-11-29 11:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-08-03 16:06 . 2006-11-15 09:38 15128 ----a-w- c:\windows\system32\x3daudio1_1.dll
2009-08-03 16:06 . 2006-09-28 14:05 237848 ----a-w- c:\windows\system32\xactengine2_4.dll
2009-08-03 16:06 . 2006-09-28 14:04 68888 ----a-w- c:\windows\system32\xinput1_3.dll
2009-08-03 16:06 . 2006-09-28 14:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll
2009-08-03 16:06 . 2006-07-28 07:30 236824 ----a-w- c:\windows\system32\xactengine2_3.dll
2009-08-03 16:06 . 2006-07-28 07:30 62744 ----a-w- c:\windows\system32\xinput1_2.dll
2009-08-03 16:05 . 2005-05-26 13:34 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll
2009-08-03 16:05 . 2009-08-03 16:05 278728 ----a-w- c:\windows\system32\drivers\atksgt.sys
2009-08-03 16:05 . 2009-08-03 16:05 25416 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2009-08-03 16:04 . 2009-08-03 16:04 -------- d-----w- c:\programfiler\Trend Micro
2009-08-03 15:55 . 2009-08-03 16:08 -------- d-----w- c:\programfiler\Simon the Sorcerer - Chaos happens
2009-08-03 09:32 . 2009-02-27 10:55 111992 ----a-w- c:\windows\system32\acaptuser32.dll
2009-08-03 08:43 . 2009-08-03 08:43 -------- d-----w- c:\programfiler\Fellesfiler\Macrovision Shared
2009-08-03 08:43 . 2008-04-07 03:38 22872 ----a-r- c:\windows\system32\AdobePDFUI.dll
2009-08-03 08:43 . 2008-04-07 03:38 45392 ----a-r- c:\windows\system32\AdobePDF.dll
2009-08-03 08:25 . 2009-08-03 08:25 -------- d-----w- C:\QUARANTINE
2009-08-01 13:56 . 2009-08-01 13:56 -------- d-----w- c:\documents and settings\Relacom\Programdata\ScummVM
2009-08-01 10:02 . 2009-08-01 10:02 -------- d-----w- c:\documents and settings\All Users\Programdata\DAEMON Tools Lite
2009-08-01 10:02 . 2009-08-01 10:02 -------- d-----w- c:\programfiler\DAEMON Tools Toolbar
2009-08-01 10:02 . 2009-08-01 10:58 -------- d-----w- c:\programfiler\DAEMON Tools Lite
2009-08-01 09:52 . 2009-08-01 09:52 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-08-01 09:52 . 2009-08-01 10:03 -------- d-----w- c:\documents and settings\Relacom\Programdata\DAEMON Tools Lite
2009-07-28 09:00 . 2009-08-03 16:36 -------- d-----w- c:\programfiler\Spybot - Search & Destroy
2009-07-28 09:00 . 2009-08-03 16:36 -------- d-----w- c:\documents and settings\All Users\Programdata\Spybot - Search & Destroy
2009-07-27 15:44 . 2009-07-27 15:55 -------- d-----w- c:\documents and settings\All Users\AdobeTemp
2009-07-27 13:57 . 2009-07-27 13:57 -------- d-----w- c:\documents and settings\All Users\Programdata\SUPERAntiSpyware.com
2009-07-27 13:56 . 2009-07-27 16:01 -------- d-----w- c:\programfiler\SUPERAntiSpyware
2009-07-27 07:02 . 2009-07-27 07:02 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2009-07-27 06:47 . 2009-07-27 06:47 -------- d-----w- c:\documents and settings\Administrator\Lokale innstillinger\Programdata\Mozilla
2009-07-21 23:11 . 2009-07-21 23:11 8416 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2009-07-21 23:11 . 2009-07-21 23:11 8416 ----a-w- c:\windows\system32\drivers\swumx20.sys
2009-07-21 21:09 . 2009-07-21 21:09 -------- d-----w- c:\programfiler\Ashampoo
2009-07-21 20:58 . 2009-07-28 12:18 -------- d-----w- c:\programfiler\Unlocker
2009-07-20 21:48 . 2009-07-20 21:48 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-07-20 21:31 . 2009-07-20 21:31 -------- d-----w- c:\documents and settings\Administrator\Programdata\Malwarebytes
2009-07-20 21:31 . 2009-07-20 21:31 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-07-20 21:26 . 2009-07-13 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-20 20:55 . 2009-07-20 20:55 -------- d-----w- c:\documents and settings\All Users\Programdata\12756714
2009-07-20 20:49 . 2004-08-04 11:00 4224 ----a-w- c:\windows\system32\drivers\beep.sys
2009-07-15 06:24 . 2009-07-15 06:24 -------- d-----w- c:\programfiler\MSECache
2009-07-14 11:49 . 2009-07-14 11:49 83144 ----a-w- c:\documents and settings\LocalService\Lokale innstillinger\Programdata\FontCache3.0.0.0.dat
2009-07-07 18:58 . 2009-07-07 18:58 -------- d-----w- c:\windows\SHELLNEW
2009-07-07 18:58 . 2009-07-07 18:58 -------- d-----w- c:\programfiler\Microsoft.NET
2009-07-07 18:55 . 2009-07-07 18:55 -------- d--h--r- C:\MSOCache
2009-07-06 17:41 . 2009-07-06 13:54 33843104 ----a-w- c:\documents and settings\All Users\Programdata\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Nokia_PC_Suite_7_1_30_9_nor.exe
2009-07-06 17:40 . 2009-07-06 17:40 95232 ----a-w- c:\documents and settings\All Users\Programdata\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\pcswpcsi.exe
2009-07-06 17:40 . 2009-07-06 17:40 8192 ----a-w- c:\documents and settings\All Users\Programdata\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstCCD.exe
2009-07-06 17:40 . 2009-07-06 17:40 61440 ----a-w- c:\documents and settings\All Users\Programdata\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-07-06 17:40 . 2009-07-06 17:40 10240 ----a-w- c:\documents and settings\All Users\Programdata\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCS.exe
2009-07-06 06:09 . 2009-07-06 06:09 152576 ----a-w- c:\documents and settings\Relacom\Programdata\Sun\Java\jre1.6.0_14\lzma.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-03 16:36 . 2008-03-01 12:08 -------- d-----w- c:\documents and settings\Relacom\Programdata\Desktop Sidebar
2009-08-03 09:04 . 2007-08-23 16:44 32040 ----a-w- c:\documents and settings\Relacom\Lokale innstillinger\Programdata\GDIPFONTCACHEV1.DAT
2009-08-03 08:42 . 2007-08-23 19:35 -------- d-----w- c:\programfiler\Fellesfiler\Adobe
2009-08-03 05:32 . 2007-08-23 16:44 -------- d-----w- c:\documents and settings\Relacom\Programdata\Wave Systems Corp
2009-07-28 12:37 . 2009-05-05 06:17 -------- d-----w- c:\programfiler\TeamViewer
2009-07-28 12:18 . 2009-02-20 10:20 -------- d-----w- c:\programfiler\ReNamer
2009-07-27 15:59 . 2009-03-08 20:19 -------- d-----w- c:\programfiler\Fellesfiler\3DO Shared
2009-07-27 14:55 . 2004-09-28 12:07 80868 ----a-w- c:\windows\system32\perfc014.dat
2009-07-27 14:55 . 2004-09-28 12:07 445844 ----a-w- c:\windows\system32\perfh014.dat
2009-07-20 21:27 . 2008-07-07 10:41 -------- d-----w- c:\programfiler\Malwarebytes' Anti-Malware
2009-07-20 21:25 . 2008-07-07 10:42 3775175 ----a-w- c:\documents and settings\All Users\Programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-07-13 11:36 . 2008-07-07 10:42 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-06 17:42 . 2009-05-04 09:44 -------- d-----w- c:\programfiler\Nokia
2009-07-06 17:42 . 2009-05-04 09:45 -------- d-----w- c:\programfiler\Fellesfiler\Nokia
2009-07-06 13:54 . 2009-05-04 09:43 -------- d-----w- c:\documents and settings\All Users\Programdata\Installations
2009-07-06 06:10 . 2007-08-16 16:57 -------- d-----w- c:\programfiler\Java
2009-07-03 17:01 . 2004-09-28 12:07 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-22 10:29 . 2007-08-24 08:37 -------- d-----w- c:\documents and settings\Relacom\Programdata\OpenOffice.org2
2009-06-22 07:08 . 2009-05-04 09:45 -------- d-----w- c:\documents and settings\Relacom\Programdata\Nokia
2009-06-22 06:58 . 2009-06-22 06:58 -------- d-----w- c:\programfiler\PC Connectivity Solution
2009-06-22 06:56 . 2009-06-22 06:56 95232 ----a-w- c:\documents and settings\All Users\Programdata\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Installer\CommonCustomActions\pcswpcsi.exe
2009-06-22 06:56 . 2009-06-22 06:56 8192 ----a-w- c:\documents and settings\All Users\Programdata\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Installer\CommonCustomActions\UninstCCD.exe
2009-06-22 06:56 . 2009-06-22 06:56 61440 ----a-w- c:\documents and settings\All Users\Programdata\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-06-22 06:56 . 2009-06-22 06:56 10240 ----a-w- c:\documents and settings\All Users\Programdata\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Installer\CommonCustomActions\UninstPCS.exe
2009-06-22 06:17 . 2009-06-22 06:56 33692368 ----a-w- c:\documents and settings\All Users\Programdata\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Nokia_PC_Suite_7_1_30_8_nor.exe
2009-06-16 14:43 . 2004-09-28 12:07 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:43 . 2004-09-28 12:07 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-03 19:11 . 2004-09-28 12:07 1294336 ----a-w- c:\windows\system32\quartz.dll
2009-05-21 09:33 . 2008-11-28 11:21 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-07 15:34 . 2004-09-28 12:07 346112 ----a-w- c:\windows\system32\localspl.dll
2008-05-25 13:09 . 2008-05-25 13:09 15574 ----a-w- c:\programfiler\messages.log
2009-08-02 18:25 . 2009-05-03 06:15 134648 ----a-w- c:\programfiler\mozilla firefox\components\brwsrcmp.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-08-03_16.48.06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-03 17:03 . 2009-08-03 17:03 16384 c:\windows\Temp\Perflib_Perfdata_33c.dat
.
(((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Merk* tomme oppføringer & gyldige standardoppføringer vises ikke
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"PC Suite Tray"="c:\programfiler\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-06-25 1414144]
"DAEMON Tools Lite"="c:\programfiler\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sony Ericsson Wireless Manager UI"="c:\windows\system32\semwltray" [X]
"Apoint"="c:\programfiler\Apoint\Apoint.exe" [2007-01-25 159744]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-05-18 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-05-18 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-05-18 138008]
"Dell QuickSet"="c:\programfiler\Dell\QuickSet\quickset.exe" [2007-02-20 1191936]
"Document Manager"="c:\programfiler\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe" [2007-01-30 102400]
"SecureUpgrade"="c:\programfiler\Wave Systems Corp\SecureUpgrade.exe" [2007-01-22 212992]
"IntelZeroConfig"="c:\programfiler\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\programfiler\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]
"ISUSPM Startup"="c:\progra~1\FELLES~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\programfiler\Fellesfiler\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"RoxioDragToDisc"="c:\programfiler\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"PDVDDXSrv"="c:\programfiler\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 118784]
"ShStatEXE"="c:\programfiler\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2006-11-30 112216]
"McAfeeUpdaterUI"="c:\programfiler\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 136768]
"WatcherHelper"="c:\programfiler\Sierra Wireless Inc\3G Watcher\WaHelper.exe" [2006-09-28 95776]
"Watcher3G"="c:\programfiler\Sierra Wireless Inc\3G Watcher\Watcher.exe" [2006-09-28 914976]
"GCXX-Manager-Class"="c:\programfiler\Sony Ericsson\Wireless Manager\GCXXManager.exe" [2005-03-12 811113]
"HP Software Update"="c:\programfiler\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"QuickTime Task"="c:\programfiler\QuickTime\QTTask.exe" [2009-05-26 413696]
"SunJavaUpdateSched"="c:\programfiler\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"Adobe Acrobat Speed Launcher"="c:\programfiler\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2009-02-27 38768]
"Acrobat Assistant 8.0"="c:\programfiler\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2009-02-27 640376]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2007-02-18 303104]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 wvauth
Security Packages REG_SZ kerberos
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programfiler\\McAfee\\Common Framework\\FrameworkService.exe"=
"c:\\Programfiler\\Sierra Wireless Inc\\3G Watcher\\SwiApiMux.exe"=
"c:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Programfiler\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Programfiler\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Programfiler\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Programfiler\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Programfiler\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Programfiler\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Programfiler\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Programfiler\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Programfiler\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\igfxsrvc.exe"=
R2 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;c:\programfiler\Broadcom\ASFIPMon\AsfIpMon.exe -service --> c:\programfiler\Broadcom\ASFIPMon\AsfIpMon.exe -service [?]
R2 GtFlashSwitch;GtFlashSwitch;c:\programfiler\Fellesfiler\GtFlashSwitch\GtFlashSwitch.exe [09.02.2007 14:48 176128]
R2 setrysvc;Sony Ericsson Wireless LAN Tray Service;c:\windows\System32\setrysvc.exe c:\windows\System32\semwltry.exe --> c:\windows\System32\setrysvc.exe c:\windows\System32\semwltry.exe [?]
R2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe [28.09.2004 14:06 5120]
R3 ACGPRS;Sierra Wireless 3G Adapter;c:\windows\system32\drivers\acgprs.sys [12.07.2006 16:59 97920]
R3 DXEC01;DXEC01;c:\windows\system32\drivers\dxec01.sys [02.11.2006 13:32 97536]
R3 swivsp;AC8xx Virtual Serial Port;c:\windows\system32\drivers\swivspnt.sys [15.02.2006 10:06 20736]
S1 saskutil;SASKUTIL;\??\c:\programfiler\SUPERAntiSpyware\SASKUTIL.sys --> c:\programfiler\SUPERAntiSpyware\SASKUTIL.sys [?]
S3 SEM43XX;Driver for Sony Ericsson trådløst 802.11 LAN-kort SEM43XX;c:\windows\system32\drivers\semwl5.SYS [24.08.2007 10:21 368896]
S3 SEMWModem;Sony Ericsson SEMWModem;c:\windows\system32\drivers\GCXX.sys [23.08.2007 21:44 114944]
S3 SEMWWNIC;Sony Ericsson SEMWWNIC;c:\windows\system32\drivers\GCXXNet.sys [23.08.2007 21:44 53248]
S3 Sony_EricssonWWSC;Sony Ericsson SIM Card Reader;c:\windows\system32\drivers\GCXXSC.sys [23.08.2007 21:44 21888]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Innholdet i mappen 'Scheduled Tasks' (planlagte oppgaver)
2009-07-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programfiler\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-08-02 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 16:04]
2009-08-03 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 16:04]
.
.
------- Tilleggsskanning -------
.
uStart Page = hxxp://10.232.231.31/
IE: Append to existing PDF - c:\programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert link target to existing PDF - c:\programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert to Adobe PDF - c:\programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\biolsp.dll
FF - ProfilePath - c:\documents and settings\Relacom\Programdata\Mozilla\Firefox\Profiles\hqrxefoy.default\
FF - component: c:\programfiler\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\programfiler\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\programfiler\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".no");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-08-03 19:04
Windows 5.1.2600 Service Pack 3 NTFS
skanner skjulte prosesser ...
skanner skjulte autostart-oppføringer ...
skanner skjulte filer ...
skanning vellykket
skjulte filer: 0
**************************************************************************
.
--------------------- DLL'er Lastet Av Kjørende Prosesser ---------------------
- - - - - - - > 'winlogon.exe'(848)
c:\windows\System32\SEMLogon.dll
- - - - - - - > 'lsass.exe'(904)
c:\windows\system32\wvauth.dll
c:\windows\system32\biolsp.dll
- - - - - - - > 'explorer.exe'(3624)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\programfiler\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\programfiler\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\programfiler\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_nor.nlr
c:\programfiler\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\programfiler\Roxio\Drag-to-Disc\Shellex.dll
c:\windows\system32\DLAAPI_W.DLL
c:\windows\system32\CDRTC.DLL
c:\programfiler\Roxio\Drag-to-Disc\ShellRes.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Andre Kjørende Prosesser ------------------------
.
c:\programfiler\Intel\Wireless\Bin\EvtEng.exe
c:\programfiler\Intel\Wireless\Bin\S24EvMon.exe
c:\programfiler\Intel\Wireless\Bin\WLKEEPER.exe
c:\windows\system32\setrysvc.EXE
c:\windows\system32\scardsvr.exe
c:\programfiler\Broadcom\ASFIPMon\AsfIpMon.exe
c:\programfiler\Java\jre6\bin\jqs.exe
c:\programfiler\McAfee\Common Framework\FrameworkService.exe
c:\programfiler\McAfee\VirusScan Enterprise\Mcshield.exe
c:\programfiler\McAfee\VirusScan Enterprise\VsTskMgr.exe
c:\programfiler\McAfee\Common Framework\naPrdMgr.exe
c:\programfiler\Dell\QuickSet\NicConfigSvc.exe
c:\windows\system32\HPZipm12.exe
c:\programfiler\Intel\Wireless\Bin\RegSrvc.exe
c:\programfiler\SigmaTel\C-dur-lyd\WDM\stacsv.exe
c:\programfiler\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
c:\windows\system32\igfxsrvc.exe
c:\programfiler\Apoint\ApMsgFwd.exe
c:\programfiler\Apoint\hidfind.exe
c:\programfiler\McAfee\Common Framework\Mctray.exe
c:\windows\system32\semwltray.EXE
c:\programfiler\Apoint\ApntEx.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\msdtc.exe
c:\programfiler\Intel\Wireless\Bin\Dot1XCfg.exe
c:\programfiler\PC Connectivity Solution\ServiceLayer.exe
c:\programfiler\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\programfiler\PC Connectivity Solution\Transports\NclRSSrv.exe
.
**************************************************************************
.
Tidspunkt ferdig: 2009-08-03 19:08 - maskinen ble startet på nytt
ComboFix-quarantined-files.txt 2009-08-03 17:08
ComboFix2.txt 2009-08-03 16:51
Pre-Run: 54*749*110*272 byte ledig
Post-Run: 54*643*388*416 byte ledig
Current=4 Default=4 Failed=2 LastKnownGood=5 Sets=1,2,3,4,5
278 --- E O F --- 2009-07-30 06:11