ATF cleaner done!
Here's my combofix log as prompted by the CFScript document followed by my HJT log:ComboFix 08-08-19.03 - Xxxxx 2008-08-20 23:39:57.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1044.18.1329 [GMT 2:00]
Running from: C:\Documents and Settings\Xxxxx.XXXXXX\Skrivebord\ComboFix.exe
Command switches used :: C:\Documents and Settings\Xxxxx.XXXXXX\Skrivebord\CFScript.txt
* Created a new restore point
FILE ::
C:\DOCUME~1\XXXXX~1.VAN\LOKALE~1\Temp\_A00F888BEE.exe
C:\WINDOWS\system32\__c0096791.dat
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\DOCUME~1\XXXXX~1.VAN\LOKALE~1\Temp\_A00F888BEE.exe
C:\WINDOWS\system32\__c0096791.dat
C:\WINDOWS\system32\~.exe
.
((((((((((((((((((((((((( Files Created from 2008-07-20 to 2008-08-20 )))))))))))))))))))))))))))))))
.
2008-08-20 00:34 . 2008-08-20 00:34 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\SUPERAntiSpyware.com
2008-08-20 00:33 . 2008-08-20 00:33 <DIR> d-------- C:\Documents and Settings\Xxxxx.XXXXXX\Programdata\SUPERAntiSpyware.com
2008-08-20 00:32 . 2008-08-20 00:32 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard
2008-08-20 00:24 . 2008-08-20 23:36 <DIR> dr-h----- C:\Documents and Settings\Xxxxx.XXXXXX\Siste
2008-08-19 23:05 . 2008-08-19 23:39 <DIR> d-------- C:\Programfiler\EsetOnlineScanner
2008-08-19 22:51 . 2008-08-20 00:08 <DIR> d-------- C:\Programfiler\Trend Micro
2008-08-15 12:02 . 2008-08-19 22:34 <DIR> d-------- C:\WINDOWS\system32\PAV
2008-08-15 12:02 . 2007-09-28 13:24 83,896 --a------ C:\WINDOWS\system32\drivers\pavdrv51.sys
2008-08-15 12:02 . 2007-03-15 18:38 54,832 --a------ C:\WINDOWS\system32\pavcpl.cpl
2008-08-15 12:02 . 2008-08-15 12:02 246 --a------ C:\WINDOWS\system32\PavCPL.dat
2008-08-15 11:49 . 2008-08-15 11:49 4,124 --a------ C:\WINDOWS\system32\tmp.reg
2008-08-15 11:42 . 2008-08-15 11:42 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Avg8
2008-08-15 11:38 . 2008-08-15 11:38 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\sentinel
2008-08-15 08:44 . 2008-08-15 12:02 <DIR> d-------- C:\Programfiler\Panda Security
2008-08-15 08:36 . 2008-08-15 08:36 15,661 --a------ C:\WINDOWS\LpAGENT.XML
2008-08-15 08:36 . 2008-08-15 08:36 821 --a------ C:\WINDOWS\LeAGENT.XML
2008-08-15 08:34 . 2008-05-01 16:34 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-15 08:31 . 2008-08-15 08:31 <DIR> d-------- C:\WINDOWS\OPTIONS
2008-08-15 08:31 . 2005-11-16 10:08 78,976 --a------ C:\WINDOWS\system32\drivers\Rtenicxp.sys
2008-08-12 14:51 . 2008-08-12 14:51 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Kaspersky Lab Setup Files
2008-08-12 11:12 . 2008-08-12 11:13 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\Lavasoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-20 09:55 --------- d-----w C:\Programfiler\Java
2008-08-15 10:02 --------- d--h--w C:\Programfiler\InstallShield Installation Information
2008-08-15 09:37 --------- d-----w C:\Programfiler\Spybot - Search & Destroy
2008-08-15 09:36 --------- d-----w C:\Documents and Settings\All Users\Programdata\Spybot - Search & Destroy
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
.
((((((((((((((((((((((((((((( snapshot@2008-08-20_ 1.01.51.43 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-08-19 23:00:03 45,056 ----a-w C:\WINDOWS\system32\acovcnt.exe
+ 2008-08-20 21:45:12 45,056 ----a-w C:\WINDOWS\system32\acovcnt.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15:00 15360]
"MSMSGS"="C:\Programfiler\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
"SUPERAntiSpyware"="C:\Documents and Settings\Xxxxx\Skrivebord\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2006-08-23 23:22 110592]
"RemoteControl"="C:\Programfiler\ASUSTeK\ASUSDVD\PDVDServ.exe" [2004-11-02 21:24 32768]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 00:17 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 00:13 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 00:17 118784]
"SynTPEnh"="C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe" [2005-10-21 03:26 761945]
"Wireless Console 2"="C:\Programfiler\Wireless Console 2\wcourier.exe" [2005-10-17 18:09 987136]
"ATKMEDIA"="C:\Programfiler\ASUS\ATK Media\DMEDIA.EXE" [2006-05-16 17:29 53248]
"ASUS Live Update"="C:\Programfiler\ASUS\ASUS Live Update\ALU.exe" [2006-02-21 16:20 180224]
"Power_Gear"="C:\Programfiler\ASUS\Power4 Gear\BatteryLife.exe" [2006-03-06 18:13 86016]
"ACMON"="C:\Programfiler\ASUS\Splendid\ACMON.exe" [2006-02-21 20:36 17920]
"ABLKSR"="C:\WINDOWS\ABLKSR\ABLKSR.exe" [2006-01-02 22:14 61440]
"Sony Ericsson PC Suite"="C:\Programfiler\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2006-11-24 01:06 487424]
"Adobe Photo Downloader"="C:\Programfiler\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-12-22 07:29 67752]
"Adobe Reader Speed Launcher"="C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"SunJavaUpdateSched"="C:\Programfiler\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"SMSERIAL"="sm56hlpr.exe" [2006-01-20 00:34 544768 C:\WINDOWS\sm56hlpr.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15:00 15360]
C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart\
Bluetooth Manager.lnk - C:\Programfiler\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2006-02-02 23:19:10 1753088]
MultiFrame.lnk - C:\Programfiler\ASUS\Asus MultiFrame\MultiFrame.exe [2007-01-04 21:52:46 491520]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Documents and Settings\Xxxxx\Skrivebord\SASSEH.DLL" [2008-05-13 10:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Documents and Settings\Xxxxx\Skrivebord\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
2007-02-15 20:02 50736 C:\WINDOWS\system32\avldr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\PandaFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\Programfiler\Panda Software\Panda Administrator 3\Pav_Agent\Pagent.exe"= C:\Programfiler\Panda Software\Panda Administrator 3\Pav_Agent\Pagent.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"19226:TCP"= 19226:TCP:ENABLE
"19226:UDP"= 19226:UDP:ENABLE
R1 ShldDrv;Panda File Shield Driver;C:\WINDOWS\system32\Drivers\ShlDrv51.sys [2007-12-28 09:44]
R2 PavProc;Panda Process Protection Driver;C:\WINDOWS\system32\DRIVERS\PavProc.sys [2007-12-18 11:45]
S3 D100IB;D100IB;C:\WINDOWS\system32\DRIVERS\D100IB5.SYS [2001-10-06 13:42]
S3 USBSAMP;based USB Mass Storage Driver;C:\WINDOWS\system32\DRIVERS\DFSTOR2K.SYS [2001-09-28 09:47]
.
- - - - ORPHANS REMOVED - - - -
Notify-__c0096791 - C:\WINDOWS\system32\__c0096791.dat
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-20 23:44:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Programfiler\ASUS\Asus MultiFrame\HookTitle.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Programfiler\Panda Security\Panda Antivirus 2008\PAVSRV51.EXE
C:\Programfiler\Panda Security\Panda Antivirus 2008\AVENGINE.EXE
C:\Programfiler\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Programfiler\Fellesfiler\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programfiler\Panda Software\Panda Administrator 3\Pav_Agent\Pagentwd.exe
C:\Programfiler\Panda Software\Panda Administrator 3\Scheduler\pavsched.exe
C:\Programfiler\Fellesfiler\Panda Software\PavShld\PavPrSrv.exe
C:\Programfiler\Panda Security\Panda Antivirus 2008\PsImSvc.exe
C:\Programfiler\Panda Security\Panda Antivirus 2008\PsCtrlS.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\WINDOWS\system32\ACEngSvr.exe
C:\WINDOWS\system32\acovcnt.exe
C:\Programfiler\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Programfiler\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Programfiler\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
C:\Programfiler\Fellesfiler\Teleca Shared\Generic.exe
C:\Programfiler\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Programfiler\Sony Ericsson\Mobile2\Mobile Phone Monitor\ToshibaBTServer.exe
.
**************************************************************************
.
Completion time: 2008-08-20 23:47:05 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-20 21:46:59
ComboFix2.txt 2008-08-20 08:36:46
ComboFix3.txt 2008-08-19 23:02:23
Pre-Run: 34,760,928,768 byte ledig
Post-Run: 34,789,667,840 byte ledig
157 --- E O F --- 2008-08-15 10:47:08
HJT log after Combofix prompted by CFScript:Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:56, on 2008-08-20
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programfiler\Panda Security\Panda Antivirus 2008\pavsrv51.exe
C:\Programfiler\Panda Security\Panda Antivirus 2008\AVENGINE.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programfiler\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Programfiler\Fellesfiler\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programfiler\Panda Software\Panda Administrator 3\Pav_Agent\Pagent.exe
C:\Programfiler\Panda Software\Panda Administrator 3\Pav_Agent\pagentwd.exe
C:\Programfiler\Panda Software\Panda Administrator 3\Scheduler\pavsched.exe
C:\Programfiler\Fellesfiler\Panda Software\PavShld\pavprsrv.exe
C:\Programfiler\Panda Security\Panda Antivirus 2008\PsImSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Programfiler\Panda Security\Panda Antivirus 2008\PsCtrls.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\Programfiler\ASUSTeK\ASUSDVD\PDVDServ.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe
C:\Programfiler\Wireless Console 2\wcourier.exe
C:\Programfiler\ASUS\ATK Media\DMEDIA.EXE
C:\Programfiler\ASUS\ASUS Live Update\ALU.exe
C:\Programfiler\ASUS\Power4 Gear\BatteryLife.exe
C:\Programfiler\ASUS\Splendid\ACMON.exe
C:\WINDOWS\sm56hlpr.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Programfiler\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Programfiler\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\WINDOWS\system32\ACEngSvr.exe
C:\Programfiler\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programfiler\Messenger\msmsgs.exe
C:\Documents and Settings\Xxxxx\Skrivebord\SUPERAntiSpyware.exe
C:\WINDOWS\system32\acovcnt.exe
C:\Programfiler\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Programfiler\ASUS\Asus MultiFrame\MultiFrame.exe
C:\Programfiler\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Programfiler\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Programfiler\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Programfiler\Fellesfiler\Teleca Shared\Generic.exe
C:\Programfiler\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Programfiler\Sony Ericsson\Mobile2\Mobile Phone Monitor\ToshibaBTServer.exe
C:\WINDOWS\explorer.exe
C:\Programfiler\Panda Security\Panda Antivirus 2008\avciman.exe
C:\Programfiler\internet explorer\iexplore.exe
C:\Programfiler\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.startsiden.no/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://r.office.microsoft.com/r/rlido11 ... ?clid=1044R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Programfiler\ASUSTeK\ASUSDVD\PDVDServ.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Wireless Console 2] C:\Programfiler\Wireless Console 2\wcourier.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Programfiler\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [ASUS Live Update] C:\Programfiler\ASUS\ASUS Live Update\ALU.exe
O4 - HKLM\..\Run: [Power_Gear] C:\Programfiler\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - HKLM\..\Run: [ACMON] C:\Programfiler\ASUS\Splendid\ACMON.exe
O4 - HKLM\..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Programfiler\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programfiler\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Documents and Settings\Xxxxx\Skrivebord\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: MultiFrame.lnk = ?
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Oppslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.asus.com
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) -
http://www.eset.eu/buxus/docs/OnlineScanner.cabO16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) -
http://www.eurofoto.no/uploader/ImageUploader4.cabO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = xxxxxx.local
O17 - HKLM\Software\..\Telephony: DomainName = xxxxxx.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = xxxxxx.local
O20 - Winlogon Notify: !SASWinLogon - C:\Documents and Settings\Xxxxx\Skrivebord\SASWINLO.dll
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Programfiler\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Programfiler\Panda Security\Panda Antivirus 2008\PsCtrls.exe
O23 - Service: Panda AdminSecure Communications Agent (PAVAGENTE) - Panda Software - C:\Programfiler\Panda Software\Panda Administrator 3\Pav_Agent\Pagent.exe
O23 - Service: Panda AdminSecure Scheduler (PavAtScheduler) - Panda Software - C:\Programfiler\Panda Software\Panda Administrator 3\Scheduler\pavsched.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Security - C:\Programfiler\Fellesfiler\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda Antivirus Report Service (PavReport) - Panda Software - C:\Programfiler\Panda Software\Panda Administrator 3\PavReport\PavReport.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Programfiler\Panda Security\Panda Antivirus 2008\pavsrv51.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Programfiler\Panda Security\Panda Antivirus 2008\PsImSvc.exe
--
End of file - 8574 bytes