ComboFix 11-05-04.02 - Iperia 05.05.2011 0:32.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.47.1044.18.3327.2078 [GMT 2:00]
Kjører fra: c:\documents and settings\Iperia\Mine dokumenter\Downloads\ComboFix.exe
* Opprettet nytt gjenopprettingspunkt
.
ADVARSEL -DENNE MASKINEN HAR IKKE GJENOPPRETTINGSKONSOLLEN INSTALLERT !!
.
.
((((((((((((((((((((((((((((((((((((((( Andre slettinger )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programfiler\YouTube Downloader Toolbar\IE\4.3\yoUTubedownloadertoolbarie.dll
E:\install.exe
F:\Autorun.inf
.
.
((((((((((((((((((((((((((( Filer Opprettet Fra 2011-04-04 til 2011-05-04 )))))))))))))))))))))))))))))))))
.
.
2011-05-04 22:14 . 2011-05-04 22:14 -------- d-----w- c:\documents and settings\Iperia\Programdata\Malwarebytes
2011-05-04 22:13 . 2011-05-04 22:13 -------- d-----w- c:\documents and settings\All Users\Programdata\Malwarebytes
2011-05-04 22:13 . 2010-12-20 16:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-04 22:13 . 2011-05-04 22:13 -------- d-----w- c:\programfiler\Malwarebytes' Anti-Malware
2011-05-04 22:13 . 2010-12-20 16:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-04 22:11 . 2011-05-04 22:11 -------- d--h--r- c:\documents and settings\Iperia\Siste
2011-05-04 22:06 . 2011-05-04 22:06 -------- d-----w- c:\programfiler\CCleaner
2011-05-02 18:12 . 2011-05-02 18:13 -------- d-----w- c:\programfiler\OpenVPN
2011-04-28 00:00 . 2011-04-28 00:00 -------- d-----w- c:\programfiler\RAMBooster.Net
2011-04-27 23:57 . 2011-04-27 23:57 -------- d-----w- c:\documents and settings\Iperia\Programdata\Uniblue
2011-04-27 23:57 . 2011-04-27 23:57 -------- d-----w- c:\programfiler\Uniblue
2011-04-27 19:15 . 2011-04-27 19:15 -------- d-----w- c:\programfiler\fliptoast
2011-04-27 19:03 . 2011-02-23 14:54 29520 ----a-w- c:\windows\system32\SmartDefragBootTime.exe
2011-04-27 19:03 . 2011-02-23 15:04 13496 ----a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2011-04-27 19:02 . 2011-04-27 19:02 -------- d-----w- c:\documents and settings\Iperia\Programdata\IObit
2011-04-27 19:01 . 2011-04-27 19:01 -------- d-----w- c:\documents and settings\All Users\Programdata\IObit
2011-04-27 19:01 . 2011-04-27 19:03 -------- d-----w- c:\programfiler\IObit
2011-04-27 18:17 . 2011-04-29 01:38 -------- d-----w- c:\documents and settings\Iperia\Programdata\.minecraft
2011-04-27 17:32 . 2011-04-27 17:32 -------- d-----w- c:\programfiler\Ribbit Phone
2011-04-27 17:32 . 2011-04-27 17:32 -------- d-----w- c:\documents and settings\Iperia\Programdata\com.adobe.example.SimplePhone.83548B8E1549C0B02E90A4FC5E44CB1E33F76C25.1
2011-04-27 12:08 . 2011-04-27 12:08 -------- d-----w- c:\documents and settings\Iperia\Programdata\com.w3i.FlipToast
2011-04-23 00:57 . 2009-11-12 11:48 7168 ----a-w- c:\windows\system32\drivers\StarOpen.sys
2011-04-23 00:57 . 2011-04-23 00:57 -------- d-----w- c:\programfiler\CDBurnerXP
2011-04-23 00:56 . 2011-04-23 00:56 -------- d-----w- c:\documents and settings\Iperia\Lokale innstillinger\Programdata\Evernote
2011-04-23 00:56 . 2011-04-23 00:56 -------- d-----w- c:\programfiler\Evernote
2011-04-23 00:21 . 2011-04-23 00:21 -------- d-----w- C:\Nexus
2011-04-16 11:34 . 2011-04-16 11:34 -------- d-----w- C:\ubuntu
2011-04-12 05:24 . 2009-08-06 17:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2011-04-12 05:24 . 2009-08-06 17:23 215920 ----a-w- c:\windows\system32\muweb.dll
2011-04-12 05:21 . 2011-04-12 05:21 -------- d-----w- c:\documents and settings\Iperia\Programdata\Qualys
2011-04-11 10:58 . 2011-04-11 10:58 -------- d-----w- c:\documents and settings\Iperia\Lokale innstillinger\Programdata\MPlayer
2011-04-11 10:55 . 2011-04-28 02:36 -------- d-----w- c:\documents and settings\Iperia\.umplayer
2011-04-11 10:55 . 2011-04-11 10:57 -------- d-----w- c:\programfiler\UMPlayer
2011-04-08 06:18 . 2011-04-08 06:18 -------- d-----w- c:\documents and settings\Iperia\quickstart
2011-04-06 20:16 . 2011-04-28 00:05 -------- d-----w- c:\programfiler\Browser Cleaner
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-19 23:41 . 2010-09-23 14:22 138184 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-04-19 23:41 . 2010-09-23 14:22 183112 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-03-15 05:01 . 2011-03-15 05:01 86016 ----a-w- c:\windows\system32\frapsvid.dll
2011-02-11 07:17 . 2011-02-11 07:17 732240 ----a-w- c:\documents and settings\Iperia\VnetAuto.exe
2010-08-17 16:32 . 2010-08-17 16:32 36868 ----a-w- c:\programfiler\uninst-Particular.exe
2011-03-04 12:00 . 2011-03-13 16:42 142296 ----a-w- c:\programfiler\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Merk* tomme oppføringer & gyldige standardoppføringer vises ikke
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{cd90bf73-20f6-44ef-993d-bb920303bd2e}"= "c:\programfiler\Veoh_Web_Player\tbVeoh.dll" [2010-06-13 2734688]
.
[HKEY_CLASSES_ROOT\clsid\{cd90bf73-20f6-44ef-993d-bb920303bd2e}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cd90bf73-20f6-44ef-993d-bb920303bd2e}]
2010-06-13 17:10 2734688 ----a-w- c:\programfiler\Veoh_Web_Player\tbVeoh.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{cd90bf73-20f6-44ef-993d-bb920303bd2e}"= "c:\programfiler\Veoh_Web_Player\tbVeoh.dll" [2010-06-13 2734688]
.
[HKEY_CLASSES_ROOT\clsid\{cd90bf73-20f6-44ef-993d-bb920303bd2e}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CD90BF73-20F6-44EF-993D-BB920303BD2E}"= "c:\programfiler\Veoh_Web_Player\tbVeoh.dll" [2010-06-13 2734688]
.
[HKEY_CLASSES_ROOT\clsid\{cd90bf73-20f6-44ef-993d-bb920303bd2e}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Iperia\Programdata\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Iperia\Programdata\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Iperia\Programdata\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\programfiler\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"Steam"="c:\programfiler\Steam\Steam.exe" [2010-12-04 1242448]
"RGSC"="c:\programfiler\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe" [2008-11-14 305064]
"VeohPlugin"="c:\programfiler\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2010-07-06 2634048]
"VOIPlay"="c:\programfiler\VOIPlay\voiplay.exe" [2010-10-05 1374568]
"Wakoopa"="c:\programfiler\Wakoopa\Wakoopa.exe" [2009-03-25 573440]
"GameTracker"="c:\programfiler\GameTracker\GTLite.exe" [2010-09-02 4018984]
"X-Lite 4"="c:\programfiler\CounterPath\X-Lite 4\X-Lite4.exe" [2010-08-11 2863616]
"uTorrent"="c:\programfiler\uTorrent\uTorrent.exe" [2011-04-06 399736]
"Skype"="c:\programfiler\Skype\Phone\Skype.exe" [2010-10-11 14940040]
"Jotta"="c:\programfiler\Jotta\jotta.exe" [2011-03-19 2510664]
"WindowsLivePhone"="c:\programfiler\Windows Live\Device Manager\msgrdvmn.exe" [2008-12-22 787816]
"Aim"="c:\programfiler\AIM\aim.exe" [2011-01-05 4321112]
"SpeedUpMyPC"="c:\programfiler\Uniblue\SpeedUpMyPC\launcher.exe" [2011-01-21 67960]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\programfiler\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"Ai Nap"="c:\program files\ASUS\Ai Suite\AiNap\AiNap.exe" [2007-09-06 1426432]
"CPU Power Monitor"="c:\program files\ASUS\Ai Suite\AiGear3\CpuPowerMonitor.exe" [2007-10-16 626176]
"Cpu Level Up help"="c:\program files\ASUS\Ai Suite\CpuLevelUpHelp.exe" [2007-09-11 880640]
"ATICustomerCare"="c:\programfiler\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-03-04 311296]
"Launch LgDeviceAgent"="c:\programfiler\Logitech\GamePanel Software\LgDevAgt.exe" [2010-02-18 357448]
"Launch LCDMon"="c:\programfiler\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2010-02-18 1573448]
"Launch LGDCore"="c:\programfiler\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2010-02-18 3203144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-04-03 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-03 13670504]
"AdobeAAMUpdater-1.0"="c:\programfiler\Fellesfiler\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"VoddlerNet Manager"="c:\programfiler\Voddler\service\VNetManager.exe" [2011-02-11 676040]
"AdobeCS4ServiceManager"="c:\programfiler\Fellesfiler\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"openvpn-gui"="c:\programfiler\UltraVPN\bin\openvpn-gui.exe" [2010-04-19 370948]
"Mobile Connectivity Suite"="c:\programfiler\HTC\HTC Sync\Application Launcher\Application Launcher.exe" [2009-03-25 573440]
"AdobeCS5ServiceManager"="c:\programfiler\Fellesfiler\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"SwitchBoard"="c:\programfiler\Fellesfiler\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"WindowsLivePhone"="c:\programfiler\Windows Live\Device Manager\msgrdvmn.exe" [2008-12-22 787816]
"googletalk"="c:\programfiler\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"SearchSettings"="c:\programfiler\Fellesfiler\Spigot\Search Settings\SearchSettings.exe" [2011-01-28 526336]
"Adobe Reader Speed Launcher"="c:\programfiler\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\programfiler\Fellesfiler\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"FileZilla Server Interface"="c:\programfiler\FileZilla Server\FileZilla Server Interface.exe" [2010-10-17 1259008]
"SunJavaUpdateSched"="c:\programfiler\Fellesfiler\Java\Java Update\jusched.exe" [2010-10-29 249064]
"RAMBooster.Net"="c:\programfiler\RAMBooster.Net\RAMBooster.exe" [2003-12-07 1363968]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]
.
c:\documents and settings\Iperia\Start-meny\Programmer\Oppstart\
Dropbox.lnk - c:\documents and settings\Iperia\Programdata\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
EvernoteClipper.lnk - c:\programfiler\Evernote\Evernote\EvernoteClipper.exe [2011-4-12 973824]
fliptoast.lnk - c:\programfiler\fliptoast\fliptoast.exe [2011-4-27 142848]
MagicDisc.lnk - c:\programfiler\MagicDisc\MagicDisc.exe [2011-3-25 576000]
OpenOffice.org 3.2.lnk - c:\programfiler\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]
ZooskMessenger.lnk - c:\programfiler\ZooskMessenger\ZooskMessenger.exe [N/A]
.
c:\documents and settings\All Users\Start-meny\Programmer\Oppstart\
WDDMStatus.lnk - c:\programfiler\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2009-10-14 2049344]
WDSmartWare.lnk - c:\programfiler\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe [2009-10-14 9085760]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programfiler\\Marvell\\61xx\\Apache2\\bin\\Apache.exe"=
"c:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Programfiler\\Steam\\Steam.exe"=
"c:\\Programfiler\\Bonjour\\mDNSResponder.exe"=
"c:\\Programfiler\\Zend\\Zend Studio - 7.1.0\\ZendStudio.exe"=
"c:\\Programfiler\\Adobe\\Adobe Flash Builder 4\\FlashBuilder.exe"=
"c:\\Programfiler\\BitTornado\\btdownloadgui.exe"=
"c:\\Programfiler\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Programfiler\\Autodesk\\Backburner\\manager.exe"=
"c:\\Programfiler\\Autodesk\\Backburner\\server.exe"=
"c:\\Programfiler\\Autodesk\\3ds Max 2009\\3dsmax.exe"=
"c:\\Programfiler\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Programfiler\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Programfiler\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\Programfiler\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"c:\\Programfiler\\Rockstar Games\\Grand Theft Auto IV\\GTAIV.exe"=
"c:\\Programfiler\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Documents and Settings\\Iperia\\Programdata\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Programfiler\\SpacialAudio\\SAMBC\\SAMBC.exe"=
"c:\\Programfiler\\Fellesfiler\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Programfiler\\Electronic Arts\\Battlefield Bad Company 2\\BFBC2Updater.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Programfiler\\Electronic Arts\\Battlefield Bad Company 2\\BFBC2Game.exe"=
"c:\\Programfiler\\HLSW\\hlsw.exe"=
"c:\\Programfiler\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\Documents and Settings\\Iperia\\Mine dokumenter\\sctrans\\win32\\sc_trans.exe"=
"c:\\Programfiler\\CounterPath\\X-Lite 4\\X-Lite4.exe"=
"c:\\Programfiler\\Spotify\\spotify.exe"=
"c:\\Programfiler\\uTorrent\\uTorrent.exe"=
"c:\\Programfiler\\Skype\\Phone\\Skype.exe"=
"c:\\Programfiler\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programfiler\\FrostWire\\FrostWire.exe"=
"c:\\Programfiler\\Opera\\opera.exe"=
"c:\\eclipse\\eclipse.exe"=
"c:\\Programfiler\\Boxee\\BOXEE.exe"=
"c:\\Programfiler\\Mozilla Firefox\\firefox.exe"=
"c:\\wamp\\bin\\apache\\Apache2.2.17\\bin\\httpd.exe"=
"c:\\Programfiler\\Google\\Google Talk\\googletalk.exe"=
"c:\\Programfiler\\Voddler\\service\\voddler.exe"=
"c:\\Programfiler\\mIRC\\mirc.exe"=
"c:\\Programfiler\\AIM\\aim.exe"=
"c:\\Programfiler\\Steam\\steamapps\\kenneiv\\counter-strike\\hl.exe"=
"c:\\wamp\\tools\\xdc\\xdc.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"1723:TCP"= 1723:TCP:VPN
"3248:TCP"= 3248:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R0 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys [15.06.2007 09:52 143256]
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [27.04.2011 21:03 13496]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [15.04.2008 14:00 14336]
R2 Application Updater;Application Updater;c:\programfiler\Application Updater\ApplicationUpdater.exe [28.01.2011 18:10 387072]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\programfiler\Firebird\Firebird_2_1\bin\fbguard.exe -s DefaultInstance --> c:\programfiler\Firebird\Firebird_2_1\bin\fbguard.exe -s DefaultInstance [?]
R2 GS In-Game Service;GS In-Game Service;c:\programfiler\GameTracker\GSInGameService.exe [02.09.2010 21:54 1677096]
R2 MRUWebService;MRU Web Service;c:\programfiler\Marvell\61xx\Apache2\bin\Apache.exe [23.05.2007 02:17 20539]
R2 VoddlerNet;VoddlerNet;c:\programfiler\Voddler\service\voddler.exe [15.12.2010 11:52 1039640]
R2 WDDMService;WD SmartWare Drive Manager;c:\programfiler\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [14.10.2009 14:31 98304]
R3 cxbu0wdm;OMNIKEY 3x21;c:\windows\system32\drivers\cxbu0wdm.sys [25.01.2010 14:56 115712]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\programfiler\Firebird\Firebird_2_1\bin\fbserver.exe -s DefaultInstance --> c:\programfiler\Firebird\Firebird_2_1\bin\fbserver.exe -s DefaultInstance [?]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [23.11.2009 17:37 19720]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [17.08.2010 16:51 14856]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.03.2010 13:16 130384]
S2 mi-raysat_3dsMax2009_32;mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit;c:\programfiler\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe [10.03.2008 00:04 65536]
S2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\programfiler\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [16.06.2009 09:58 20480]
S3 Marvell RAID;Marvell RAID Event Agent;c:\programfiler\Marvell\61xx\svc\mvraidsvc.exe [12.06.2007 20:54 61440]
S3 SkLaggProtocol;Marvell Link Aggregation Protocol (LAGG) Support;c:\windows\system32\DRIVERS\yk51lagg.sys --> c:\windows\system32\DRIVERS\yk51lagg.sys [?]
S3 SkVlanProtocol;Marvell Virtual LAN (VLAN) Support;c:\windows\system32\drivers\skvlan.sys [17.05.2006 02:15 19328]
S3 SwitchBoard;SwitchBoard;c:\programfiler\Fellesfiler\Adobe\SwitchBoard\SwitchBoard.exe [19.02.2010 14:37 517096]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [19.08.2010 10:02 11520]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.03.2010 13:16 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Innholdet i mappen 'Scheduled Tasks' (planlagte oppgaver)
.
2011-05-04 c:\windows\Tasks\AdobeAAMUpdater-1.0-IPERIA-499323BF-Iperia.job
- c:\programfiler\Fellesfiler\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-02-28 02:44]
.
2011-05-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-484763869-688789844-1801674531-1004Core.job
- c:\documents and settings\Iperia\Lokale innstillinger\Programdata\Google\Update\GoogleUpdate.exe [2010-08-17 13:49]
.
2011-05-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-484763869-688789844-1801674531-1004UA.job
- c:\documents and settings\Iperia\Lokale innstillinger\Programdata\Google\Update\GoogleUpdate.exe [2010-08-17 13:49]
.
2011-05-04 c:\windows\Tasks\SmartDefrag_Startup.job
- c:\programfiler\IObit\Smart Defrag 2\SmartDefrag.exe [2011-04-27 15:31]
.
2011-05-04 c:\windows\Tasks\SpeedUpMyPC.job
- c:\programfiler\Uniblue\SpeedUpMyPC\spmonitor.exe [2011-04-27 13:40]
.
.
------- Tilleggsskanning -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2653012
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Evernote 4.0 - c:\programfiler\Evernote\Evernote\EvernoteIE.dll/204
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {{A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://c:\programfiler\Evernote\Evernote\EvernoteIE.dll/204
TCP: {8831D70F-943D-4C26-BD86-699051733456} = 192.168.10.1
FF - ProfilePath - c:\documents and settings\Iperia\Programdata\Mozilla\Firefox\Profiles\v99k0gyt.default\
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr=greentree_ff1&type=937811&p=
.
.
------- Filassosiasjoner -------
.
.txt=
.
- - - - TOMME PEKERE FJERNET - - - -
.
HKCU-Run-AdobeBridge - (no file)
HKLM-Run-nwiz - nwiz.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-05-05 00:39
Windows 5.1.2600 Service Pack 3 NTFS
.
skanner skjulte prosesser ...
.
skanner skjulte autostart-oppføringer ...
.
skanner skjulte filer ...
.
.
c:\docume~1\Iperia\LOKALE~1\Temp\catchme.dll 53248 bytes executable
.
skanning vellykket
skjulte filer: 1
.
**************************************************************************
.
--------------------- LÅSTE REGISTERNØKLER ---------------------
.
[HKEY_USERS\S-1-5-21-484763869-688789844-1801674531-1004\Software\SecuROM\License information*]
"datasecu"=hex:ef,9c,33,7b,6e,d0,1e,af,1e,70,72,e2,37,33,22,25,a5,6e,c2,f8,7d,
d7,2d,be,1f,36,88,18,b2,71,28,be,1e,b5,0d,46,bc,99,bd,a8,7b,af,c2,66,64,93,\
"rkeysecu"=hex:e6,e0,f5,d8,38,af,79,ba,8b,0e,8e,26,87,9a,ad,c0
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10g_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10g_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
--------------------- DLL'er Lastet Av Kjørende Prosesser ---------------------
.
- - - - - - - > 'winlogon.exe'(1156)
c:\programfiler\Fellesfiler\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Tidspunkt ferdig: 2011-05-05 00:40:47
ComboFix-quarantined-files.txt 2011-05-04 22:40
.
Pre-Run: 213 673 426 944 byte ledig
Post-Run: 213 636 091 904 byte ledig
.
- - End Of File - - 08692551FA25D9F3D42D8F448700ABB6