Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: help with malware removal  (Read 10358 times)

0 Members and 1 Guest are viewing this topic.

smyers0013

    Topic Starter


    Greenhorn

    • Experience: Beginner
    • OS: Unknown
    help with malware removal
    « on: February 06, 2011, 05:22:14 PM »
    hi,

    i've followed the 'malware removal' steps in the 'Read this before requesting malware removal help' topic, and now I am posting my logs so that I can hopefully get some help.

    A couple of things first though -- I couldn't run malarebytes' antimalware program. I don't know why -- I installed it and when i clicked the desktop shortcut a screen for downloading unpdates popped up and disappeared within a split second. I tried downloading updates from the website by following the links in the topic, but the links were dead.

    so, I scanned using SAS and HijackThis. Here are my logs. Thanks in advance to whoever (qualified) helps me!

    also, I forgot to run ccleaner before running SAS, but I'm hoping it's not essential. I DID run it before running HJT though.


    ===============================================


    SAS LOG:

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 02/06/2011 at 11:45 PM

    Application Version : 4.48.1000

    Core Rules Database Version : 6343
    Trace Rules Database Version: 4155

    Scan type       : Complete Scan
    Total Scan Time : 02:09:29

    Memory items scanned      : 655
    Memory threats detected   : 1
    Registry items scanned    : 8496
    Registry threats detected : 0
    File items scanned        : 148853
    File threats detected     : 23

    Rogue.Disk-Cleanup
       C:\USERS\SIRIFE~1\APPDATA\LOCAL\TEMP\WINBDM.DLL
       C:\USERS\SIRIFE~1\APPDATA\LOCAL\TEMP\WINBDM.DLL
       C:\USERS\SIRI FEVANG EKENES\APPDATA\LOCAL\TEMP\WINBDM.DLL

    Trojan.Agent/Gen-FakeAlert
       C:\USERS\SIRI FEVANG EKENES\APPDATA\LOCAL\TEMP\LOW\0.9854071332668755.EXE
       C:\USERS\SIRI FEVANG EKENES\APPDATA\LOCAL\TEMP\LOW\CYYJETMYH\BVTBDVASJMO.EXE

    Adware.Tracking Cookie
       C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@adform[2].txt
       C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@adtech[1].txt
       C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@adviva[1].txt
       C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@adxpose[1].txt
       C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@apmebf[1].txt
       C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][3].txt
       C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@doubleclick[1].txt
       C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@mediaplex[2].txt
       C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@revsci[2].txt
       C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@serving-sys[1].txt
       C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@specificclick[1].txt
       C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@statcounter[2].txt
       C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
       C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@tribalfusion[2].txt
       C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@zanox[1].txt




    ===============================================



    HijackThis LOG:

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 01:03:37, on 07.02.2011
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v8.00 (8.00.6001.18999)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Windows\OEM02Mon.exe
    C:\Windows\sttray.exe
    C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Iomega\Home Storage Manager\Iomega Discovery.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Registry Mechanic\RMTray.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Windows\System32\rundll32.exe
    C:\Users\Siri Fevang Ekenes\AppData\Roaming\drvxslek32k\drvxslek55k.exe
    C:\Windows\System32\rundll32.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Windows\system32\wuauclt.exe
    C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
    C:\Windows\system32\conime.exe
    C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe
    C:\Program Files\Trend Micro\HiJackThis\Sniper.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sol.no/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.no/ig/dell?hl=no&client=dell-row&channel=no&ibd=3070927
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer levert av Dell
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O3 - Toolbar: Norton-verktøylinjen - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [SSDMonitor] C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Iomega Home Storage Manager] C:\Program Files\Iomega\Home Storage Manager\Iomega Discovery.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RMTray.exe /H
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [CTF Products Updater] rundll32.exe "C:\Users\SIRIFE~1\AppData\Local\Temp\winbdm.dll", DepCmd
    O4 - HKCU\..\Run: [qoppnlsys] rundll32.exe "c:\users\sirife~1\appdata\local\temp\iiiijj.dll",s
    O4 - HKCU\..\Run: [drvxslek32k] C:\Users\Siri Fevang Ekenes\AppData\Roaming\drvxslek32k\drvxslek55k.exe
    O4 - HKCU\..\Run: [awwxvsaudio] rundll32.exe "c:\users\sirife~1\appdata\local\temp\awurst.dll",s
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKAL TJENESTE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKAL TJENESTE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETTVERKSTJENESTE')
    O4 - Startup: OneNote 2007 Screen Clipper og Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Google Sidewiki - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
    O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
    O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: Automatisk LiveUpdate-planlegging - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: GTMM Device Service - Option nv - C:\Program Files\Telenor\Mobile Broadband\GtmmDeviceService.exe
    O23 - Service: Googles oppdateringstjeneste (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
    O23 - Service: Sesam Control Service (SesamService) - Swisscom - C:\Program Files\Telenor\Mobile Broadband\Sesam\BIN\SecMIPService.exe
    O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 12002 bytes


    =================================================


    regards, smyers0013

    SuperDave

    • Malware Removal Specialist


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: help with malware removal
    « Reply #1 on: February 07, 2011, 04:41:53 PM »
    Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

    1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
    2. The fixes are specific to your problem and should only be used for this issue on this machine.
    3. If you don't know or understand something, please don't hesitate to ask.
    4. Please DO NOT run any other tools or scans while I am helping you.
    5. It is important that you reply to this thread. Do not start a new topic.
    6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
    7. Absence of symptoms does not mean that everything is clear.

    If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
    **************************************************
    Registry cleaners are extremely powerful applications and their potential for harming your OS far outweighs any small potential for improving your computer's performance.
    Registry Mechanic
    There are a number of them available and some are more safe than others. Keep in mind that no two registry cleaners work entirely the same way. Each vendor uses different criteria as to what constitutes a "bad" entry. One cleaner may find entries on your system that will not cause a problem when removed, another may not find the same entries, and still another may want to remove entries required for a program to work. Without research into what the registry entry selected for deletion is, a registry cleaner can end up being an automated method to cause problems with the registry.

    For routine use by those not familiar with the registry, the benefits to your computer are negligible while the potential risks are great.

    Further reading: XP Fixes Myth #1: Registry Cleaners
    *****************************************************
    Open HijackThis and select Do a system scan only

    Place a check mark next to the following entries: (if there)

    O4 - HKCU\..\Run: [qoppnlsys] rundll32.exe "c:\users\sirife~1\appdata\local\temp\iiiijj.dll",s
    O4 - HKCU\..\Run: [drvxslek32k] C:\Users\Siri Fevang Ekenes\AppData\Roaming\drvxslek32k\drvxslek55k.exe
    O4 - HKCU\..\Run: [awwxvsaudio] rundll32.exe "c:\users\sirife~1\appdata\local\temp\awurst.dll",s


    Important: Close all open windows except for HijackThis and then click Fix checked.

    Once completed, exit HijackThis.
    *********************************************
    Download Security Check by screen317 from one of the following links and save it to your desktop.

    Link 1
    Link 2

    * Unzip SecurityCheck.zip and a folder named Security Check should appear.
    * Open the Security Check folder and double-click Security Check.bat
    * Follow the on-screen instructions inside of the black box.
    * A Notepad document should open automatically called checkup.txt
    * Post the contents of that document in your next reply.

    Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.
    **************************************************
    Download ComboFix by sUBs from one of the below links.  Be sure to save it to the Desktop.

    link # 1
    Link # 2
    If you are using Firefox, make sure that your download settings are as follows:

    * Tools->Options->Main tab
    * Set to "Always ask me where to Save the files".

    Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    Right-click combofix.exe and select Run as Administrator and follow the prompts.
    When finished, ComboFix will produce a log for you.
    Post the ComboFix log and a new HijackThis log in your next reply.

    NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.
    Windows 8 and Windows 10 dual boot with two SSD's

    smyers0013

      Topic Starter


      Greenhorn

      • Experience: Beginner
      • OS: Unknown
      Re: help with malware removal
      « Reply #2 on: February 09, 2011, 10:49:36 AM »
      Hi Dave,

      thas for offering your assistance, it's really appreciated.

      here are my logs:

      =============================================

      Security Check:

       Results of screen317's Security Check version 0.99.8 
       Windows Vista Service Pack 2 (UAC is enabled)
       Internet Explorer 8 
      ``````````````````````````````
      Antivirus/Firewall Check:

       Norton AntiVirus     
       Norton Internet Security (Symantec Corporation) 
       Norton Internet Security   
       WMI entry may not exist for antivirus; attempting automatic update.
      ```````````````````````````````
      Anti-malware/Other Utilities Check:

       SUPERAntiSpyware     
       CCleaner     
       Java(TM) 6 Update 23 
       Java(TM) SE Runtime Environment 6
       Adobe Flash Player 10.0.12.36 
      Adobe Reader 9.3 - Norsk
      Out of date Adobe Reader installed!
      ````````````````````````````````
      Process Check: 
      objlist.exe by Laurent

       Norton ccSvcHst.exe
      ``````````End of Log````````````





      ====================================================


      ComboFix:

      ComboFix 11-02-08.05 - Siri Fevang Ekenes 09.02.2011  18:14:03.1.2 - x86
      Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.47.1044.18.1917.1194 [GMT 1:00]
      Kjører fra: c:\users\Siri Fevang Ekenes\Desktop\ComboFix.exe
      SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
      .

      (((((((((((((((((((((((((((((((((((((((   Andre slettinger   )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      c:\programdata\Local
      c:\programdata\Microsoft\Network\Downloader\qmgr0.dat
      c:\programdata\Microsoft\Network\Downloader\qmgr1.dat
      c:\users\Siri Fevang Ekenes\AppData\Local\Temp\awurst.dll
      c:\users\Siri Fevang Ekenes\AppData\Roaming\drvxslek32k
      c:\users\Siri Fevang Ekenes\AppData\Roaming\drvxslek32k\config.ini
      c:\users\Siri Fevang Ekenes\AppData\Roaming\drvxslek32k\drvxslek55k.exe
      c:\users\Siri Fevang Ekenes\drvxslek55k.exe
      c:\users\SIRIFE~1\AppData\Local\Temp\awurst.dll

      ----- BITS: Mulige infiserte sider -----

      hxxp://buy-download.norton.com
      .
      (((((((((((((((((((((((((((   Filer Opprettet Fra 2011-01-09 til 2011-02-09  )))))))))))))))))))))))))))))))))
      .

      2011-02-09 17:24 . 2011-02-09 17:24   --------   d-----w-   c:\programdata\Local
      2011-02-09 17:22 . 2011-02-09 17:22   --------   d-----w-   c:\users\Default\AppData\Local\temp
      2011-02-08 12:06 . 2011-01-13 09:41   5890896   ----a-w-   c:\programdata\Microsoft\Windows Defender\Definition Updates\{3FCC4C4D-9F0B-4B28-8F3F-BA152E4227BD}\mpengine.dll
      2011-02-07 19:15 . 2011-02-08 20:51   111616   ----a-w-   c:\users\Siri Fevang Ekenes\pod312.exe
      2011-02-06 23:58 . 2011-02-06 23:58   388096   ----a-r-   c:\users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
      2011-02-06 23:58 . 2011-02-06 23:58   --------   d-----w-   c:\program files\Trend Micro
      2011-02-06 23:43 . 2011-02-06 23:43   --------   d-----w-   c:\program files\CCleaner
      2011-02-06 23:33 . 2011-02-06 23:32   472808   ----a-w-   c:\windows\system32\deployJava1.dll
      2011-02-06 20:32 . 2011-02-06 20:33   --------   d-----w-   c:\program files\SUPERAntiSpyware
      2011-02-05 14:10 . 2011-02-05 14:10   --------   d-----w-   c:\users\Siri Fevang Ekenes\AppData\Roaming\Malwarebytes
      2011-02-05 14:08 . 2011-02-05 14:08   --------   d-----w-   c:\programdata\Malwarebytes
      2011-02-05 02:06 . 2011-02-05 02:06   --------   d-----w-   c:\users\Siri Fevang Ekenes\AppData\Roaming\SUPERAntiSpyware.com
      2011-02-05 02:06 . 2011-02-05 02:06   --------   d-----w-   c:\programdata\SUPERAntiSpyware.com
      2011-02-04 18:54 . 2011-02-04 21:56   --------   d-----w-   c:\users\Siri Fevang Ekenes\AppData\Local\CrashDumps
      2011-02-03 17:23 . 2011-02-03 17:23   --------   d-----w-   c:\program files\Norton AntiVirus
      2011-02-03 17:16 . 2011-02-03 17:16   --------   d-----w-   c:\programdata\PCSettings
      2011-02-03 17:14 . 2011-02-03 17:14   --------   d-----w-   c:\program files\NortonInstaller
      2011-02-03 17:11 . 2011-02-03 17:30   --------   d-----w-   c:\programdata\Norton
      2011-01-26 03:33 . 2011-01-26 03:33   --------   d-----w-   c:\users\Siri Fevang Ekenes\AppData\Roaming\Sync App Settings
      2011-01-26 03:32 . 2011-01-26 03:32   --------   d-----w-   c:\programdata\Sync App Settings
      2011-01-26 03:31 . 2011-01-26 03:31   115200   ----a-w-   c:\users\Siri Fevang Ekenes\pod552.exe
      2011-01-14 14:34 . 2011-01-14 14:35   --------   d-----w-   c:\program files\Iomega
      2011-01-12 10:18 . 2010-12-28 15:55   413696   ----a-w-   c:\windows\system32\odbc32.dll
      2011-01-12 10:18 . 2010-12-28 15:53   253952   ----a-w-   c:\program files\Common Files\System\ado\msadox.dll
      2011-01-12 10:18 . 2010-12-28 15:53   708608   ----a-w-   c:\program files\Common Files\System\ado\msado15.dll
      2011-01-12 10:18 . 2010-12-28 15:53   241664   ----a-w-   c:\program files\Common Files\System\ado\msadomd.dll
      2011-01-12 10:18 . 2010-12-28 15:53   57344   ----a-w-   c:\program files\Common Files\System\msadc\msadcs.dll
      2011-01-12 10:18 . 2010-12-28 15:53   180224   ----a-w-   c:\program files\Common Files\System\msadc\msadco.dll
      2011-01-12 10:18 . 2010-12-14 14:49   1169408   ----a-w-   c:\windows\system32\sdclt.exe

      .
      ((((((((((((((((((((((((((((((((((((((((   Find3M Rapport   ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .

      ((((((((((((((((((((((((((((((((   Oppstartspunkter I Registeret   )))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Merk* tomme oppføringer & gyldige standardoppføringer vises ikke 
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-25 39408]
      "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
      "RegistryMechanic"="c:\program files\Registry Mechanic\RMTray.exe" [2010-04-08 292824]
      "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
      "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-28 857648]
      "OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-05-10 36864]
      "SigmatelSysTrayApp"="sttray.exe" [2007-03-06 303104]
      "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
      "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
      "SSDMonitor"="c:\program files\Common Files\PC Tools\sMonitor\SSDMonitor.exe" [2010-04-08 104408]
      "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
      "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
      "Iomega Home Storage Manager"="c:\program files\Iomega\Home Storage Manager\Iomega Discovery.exe" [2009-10-27 152936]
      "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

      c:\users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
      OneNote 2007 Screen Clipper og Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
      "EnableUIADesktopToggle"= 0 (0x0)

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
      "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
      "mixer"=wdmaud.drv

      [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^BTTray.lnk]
      backup=c:\windows\pss\BTTray.lnk.CommonStartup
      backupExtension=.CommonStartup

      [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Digital Line Detect.lnk]
      backup=c:\windows\pss\Digital Line Detect.lnk.CommonStartup
      backupExtension=.CommonStartup

      [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickSet.lnk]
      backup=c:\windows\pss\QuickSet.lnk.CommonStartup
      backupExtension=.CommonStartup
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
      %ProgramFiles%\Windows Defender\MSASCui.exe -hide [X]

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
      2007-03-21 19:33   1548288   ----a-w-   c:\windows\System32\WLTRAY.EXE

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
      2007-01-24 23:03   107112   ----a-w-   c:\program files\Common Files\Symantec Shared\ccApp.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ECenter]
      2007-03-16 10:50   17920   ----a-w-   c:\dell\E-Center\EULALauncher.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
      2008-01-19 07:33   125952   ----a-w-   c:\windows\ehome\ehtray.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
      2007-09-27 15:38   1862144   ----a-w-   c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
      2006-10-03 10:37   81920   ----a-w-   c:\program files\Common Files\InstallShield\UpdateService\issch.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
      2010-04-28 13:06   142120   ----a-w-   c:\program files\iTunes\iTunesHelper.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEM02Mon.exe]
      2007-05-10 09:01   36864   ----a-w-   c:\windows\OEM02Mon.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
      2008-04-01 01:54   507904   ----a-w-   c:\program files\Winamp Remote\bin\OrbTray.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
      2007-01-24 23:01   22696   ----a-w-   c:\program files\Norton Internet Security\osCheck.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
      2007-04-16 15:10   184320   ------w-   c:\program files\Dell\MediaDirect\PCMService.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
      2010-03-17 19:53   421888   ----a-w-   c:\program files\QuickTime\QTTask.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
      2006-11-05 10:22   221184   ----a-w-   c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
      2009-04-11 06:28   1233920   ----a-w-   c:\program files\Windows Sidebar\sidebar.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
      2007-03-06 20:37   303104   ----a-w-   c:\windows\sttray.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
      2007-09-27 15:01   77824   ----a-w-   c:\program files\Java\jre1.6.0\bin\jusched.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng]
      2008-01-29 15:38   583048   ----a-w-   c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
      2007-04-28 00:35   857648   ----a-w-   c:\program files\Synaptics\SynTP\SynTPEnh.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
      2009-03-09 15:49   37888   ----a-w-   c:\program files\Winamp\winampa.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
      2008-01-19 07:33   202240   ----a-w-   c:\program files\Windows Media Player\wmpnscfg.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
      "DisableMonitoring"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
      "DisableMonitoring"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
      "DisableMonitoring"=dword:00000001

      R2 gupdate;Googles oppdateringstjeneste (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 135664]
      R3 GT72NDISIPXP;GT 72 IP NDIS;c:\windows\system32\DRIVERS\Gt51Ip.sys [2007-07-09 95744]
      R3 GT72UBUS;GT 72 U BUS;c:\windows\system32\DRIVERS\gt72ubus.sys [2007-06-26 51968]
      R3 GTMM Device Service;GTMM Device Service;c:\program files\Telenor\Mobile Broadband\GtmmDeviceService.exe [2008-07-02 106496]
      R3 SYMNDISV;SYMNDISV;c:\windows\System32\Drivers\SYMNDISV.SYS [2007-01-24 37008]
      S1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\idsdefs\20101113.002\IDSvix86.sys [2010-09-15 287792]
      S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
      S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
      S2 Automatisk LiveUpdate-planlegging;Automatisk LiveUpdate-planlegging;c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2007-09-26 554352]
      S2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [2010-04-08 632792]
      S2 SesamService;Sesam Control Service;c:\program files\Telenor\Mobile Broadband\Sesam\BIN\SecMIPService.exe [2008-05-09 1216296]
      S3 wtsmpadap;Sesam Virtual Adapter;c:\windows\system32\DRIVERS\wtsmpadap.sys [2008-04-29 39720]
      S3 WtSmpFlt;Sesam Adapter;c:\windows\system32\DRIVERS\wtsmpflt.sys [2008-04-29 272424]


      --- Andre tjenester/drivere lastet i minnet ---

      *NewlyCreated* - COMHOST

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
      bthsvcs   REG_MULTI_SZ      BthServ
      LocalServiceAndNoImpersonation   REG_MULTI_SZ      FontCache
      .
      Innholdet i mappen 'Scheduled Tasks' (planlagte oppgaver)

      2011-02-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
      - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 14:02]

      2011-02-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
      - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 14:02]

      2010-12-16 c:\windows\Tasks\User_Feed_Synchronization-{633CEE21-2C47-4221-89BB-2BBA14BB3F47}.job
      - c:\windows\system32\msfeedssync.exe [2010-12-15 04:25]
      .
      .
      ------- Tilleggsskanning -------
      .
      uStart Page = hxxp://www.sol.no/
      uInternet Settings,ProxyOverride = *.local
      IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
      IE: Google Sidewiki - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
      IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
      IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
      IE: StumbleUpon PhotoBlog It! - StumbleUponIEBar.dll/blogimage
      .
      - - - - TOMME PEKERE FJERNET - - - -

      HKCU-Run-efdeffaudio - c:\users\sirife~1\appdata\local\temp\awurst.dll
      MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
      AddRemove-Allway Sync_is1 - f:\program files\Allway Sync\unins000.exe



      **************************************************************************

      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2011-02-09 18:27
      Windows 6.0.6002 Service Pack 2 NTFS

      skanner skjulte prosesser ... 

      skanner skjulte autostart-oppføringer ...

      skanner skjulte filer ... 

      skanning vellykket
      skjulte filer: 0

      **************************************************************************
      .
      --------------------- LÅSTE REGISTERNØKLER ---------------------

      [HKEY_USERS\S-1-5-21-199706739-3402135902-50689569-1000\Software\SecuROM\License information*]
      "datasecu"=hex:21,9b,ca,5d,2b,94,2f,e8,15,df,46,0f,ee,bb,e5,ab,27,2b,be,13,45,
         45,65,a0,36,af,f8,57,36,f3,42,49,0e,de,ec,d8,f3,21,e5,08,38,c5,ee,b5,bc,9b,\
      "rkeysecu"=hex:04,a5,5a,62,06,53,6b,16,6f,c8,3e,47,1f,30,de,24

      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
      @Denied: (A 2) (Everyone)
      @="FlashBroker"
      "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
      "Enabled"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
      @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
      @Denied: (A 2) (Everyone)
      @="IFlashBroker4"

      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
      @="{00020424-0000-0000-C000-000000000046}"

      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
      "Version"="1.0"

      [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
      @Denied: (A) (Users)
      @Denied: (A) (Everyone)
      @Allowed: (B 1 2 3 4 5) (S-1-5-20)
      "BlindDial"=dword:00000000

      [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
      @Denied: (A) (Users)
      @Denied: (A) (Everyone)
      @Allowed: (B 1 2 3 4 5) (S-1-5-20)
      "BlindDial"=dword:00000000

      [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
      @Denied: (A) (Users)
      @Denied: (A) (Everyone)
      @Allowed: (B 1 2 3 4 5) (S-1-5-20)
      "BlindDial"=dword:00000000

      [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
      @Denied: (A) (Users)
      @Denied: (A) (Everyone)
      @Allowed: (B 1 2 3 4 5) (S-1-5-20)
      "BlindDial"=dword:00000000
      .
      --------------------- DLL'er Lastet Av Kjørende Prosesser ---------------------

      - - - - - - - > 'Explorer.exe'(4064)
      c:\windows\system32\btncopy.dll
      .
      ------------------------ Andre Kjørende Prosesser ------------------------
      .
      c:\windows\system32\Ati2evxx.exe
      c:\windows\system32\Ati2evxx.exe
      c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
      c:\program files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
      c:\windows\System32\WLTRYSVC.EXE
      c:\windows\System32\bcmwltry.exe
      c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
      c:\program files\Bonjour\mDNSResponder.exe
      c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
      c:\windows\system32\STacSV.exe
      c:\windows\system32\DRIVERS\xaudio.exe
      c:\windows\system32\conime.exe
      c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
      c:\windows\ehome\ehmsas.exe
      c:\program files\Windows Media Player\wmpnetwk.exe
      c:\program files\iPod\bin\iPodService.exe
      c:\windows\servicing\TrustedInstaller.exe
      .
      **************************************************************************
      .
      Tidspunkt ferdig: 2011-02-09  18:34:10 - maskinen ble startet på nytt
      ComboFix-quarantined-files.txt  2011-02-09 17:34

      Pre-Run: 53 712 781 312 byte ledig
      Post-Run: 53 659 262 976 byte ledig

      - - End Of File - - 0D0A1E30C5BDF001D8F71345D6A30E57





      ==============================================================================


      HijackThis:

      Logfile of Trend Micro HijackThis v2.0.4
      Scan saved at 18:42:20, on 09.02.2011
      Platform: Windows Vista SP2 (WinNT 6.00.1906)
      MSIE: Internet Explorer v8.00 (8.00.6001.18999)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\conime.exe
      C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Windows\OEM02Mon.exe
      C:\Windows\sttray.exe
      C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
      C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Iomega\Home Storage Manager\Iomega Discovery.exe
      C:\Program Files\Common Files\Java\Java Update\jusched.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Registry Mechanic\RMTray.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Windows\system32\wuauclt.exe
      C:\Windows\Explorer.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Program Files\Trend Micro\HiJackThis\Sniper.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sol.no/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
      O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
      O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O3 - Toolbar: Norton-verktøylinjen - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
      O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
      O4 - HKLM\..\Run: [SSDMonitor] C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [Iomega Home Storage Manager] C:\Program Files\Iomega\Home Storage Manager\Iomega Discovery.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
      O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RMTray.exe /H
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - Startup: OneNote 2007 Screen Clipper og Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
      O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: Google Sidewiki - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
      O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
      O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
      O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
      O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
      O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
      O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
      O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
      O23 - Service: Automatisk LiveUpdate-planlegging - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
      O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      O23 - Service: GTMM Device Service - Option nv - C:\Program Files\Telenor\Mobile Broadband\GtmmDeviceService.exe
      O23 - Service: Googles oppdateringstjeneste (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
      O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
      O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
      O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
      O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
      O23 - Service: Sesam Control Service (SesamService) - Swisscom - C:\Program Files\Telenor\Mobile Broadband\Sesam\BIN\SecMIPService.exe
      O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
      O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
      O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
      O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
      O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

      --
      End of file - 10676 bytes



      =======================================================================


      Thanks again!
      smyers0013

      SuperDave

      • Malware Removal Specialist


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: help with malware removal
      « Reply #3 on: February 09, 2011, 05:13:50 PM »
      Please download the newest version of Adobe Acrobat Reader from Adobe.com

      Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
      Go to the Control Panel and enter Add or Remove Programs.
      Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

      Once old versions are gone, please install the newest version.
      **************************************************
      SysProt Antirootkit

      Download
      SysProt Antirootkit from the link below (you will find it at the bottom
      of the page under attachments, or you can get it from one of the
      mirrors).

      http://sites.google.com/site/sysprotantirootkit/

      Unzip it into a folder on your desktop.
      • Double click Sysprot.exe to start the program.
      • Click on the Log tab.
      • In the Write to log box select the following items.
        • Process << Selected
        • Kernel Modules << Selected
        • SSDT << Selected
        • Kernel Hooks << Selected
        • IRP Hooks << NOT Selected
        • Ports << NOT Selected
        • Hidden Files << Selected
      • At the bottom of the page
        • Hidden Objects Only << Selected
      • Click on the Create Log button on the bottom right.
      • After a few seconds a new window should appear.
      • Select Scan Root Drive. Click on the Start button.
      • When it is complete a new window will appear to indicate that the scan is finished.
      • The

      log will be saved automatically in the same folder Sysprot.exe was
      extracted to. Open the text file and copy/paste the log here.
      [/list]
      Windows 8 and Windows 10 dual boot with two SSD's

      smyers0013

        Topic Starter


        Greenhorn

        • Experience: Beginner
        • OS: Unknown
        Re: help with malware removal
        « Reply #4 on: February 09, 2011, 06:32:34 PM »
        SysProt Log:

        SysProt AntiRootkit v1.0.1.0
        by swatkat

        ******************************************************************************************
        ******************************************************************************************

        No Hidden Processes found

        ******************************************************************************************
        ******************************************************************************************
        Kernel Modules:
        Module Name: \SystemRoot\System32\Drivers\dump_dumpata.sys
        Service Name: ---
        Module Base: 8DEBB000
        Module End: 8DEC6000
        Hidden: Yes

        Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
        Service Name: ---
        Module Base: 8DEC6000
        Module End: 8DECE000
        Hidden: Yes

        ******************************************************************************************
        ******************************************************************************************
        SSDT:
        Function Name: ZwConnectPort
        Address: 8622AE18
        Driver Base: 0
        Driver End: 0
        Driver Name: _unknown_

        ******************************************************************************************
        ******************************************************************************************
        No Kernel Hooks found

        ******************************************************************************************
        ******************************************************************************************
        Hidden files/folders:
        Object: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\SRTSP\SrtETmp\A5EEBA5F.TMP
        Status: Access denied

        Object: C:\ProgramData\Symantec\SRTSP\Quarantine\AP589EC956.mp3
        Status: Access denied

        Object: C:\Qoobox\BackEnv\AppData.folder.dat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\Cache.folder.dat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\Cookies.folder.dat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\Desktop.folder.dat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\Favorites.folder.dat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\History.folder.dat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\LocalAppData.folder.dat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\LocalSettings.folder.dat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\Music.folder.dat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\NetHood.folder.dat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\Personal.folder.dat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\Pictures.folder.dat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\PrintHood.folder.dat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\Profiles.Folder.dat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\Profiles.Folder.folder.dat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\Programs.folder.dat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\Recent.folder.dat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\SendTo.folder.dat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\SetPath.bat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\StartMenu.folder.dat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\StartUp.folder.dat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\SysPath.dat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\Templates.folder.dat
        Status: Access denied

        Object: C:\Qoobox\BackEnv\VikPev00
        Status: Access denied

        Object: C:\Users\All Users\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\SRTSP\SrtETmp\A5EEBA5F.TMP
        Status: Access denied

        Object: C:\Users\All Users\Symantec\SRTSP\Quarantine\AP589EC956.mp3
        Status: Access denied

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\00\200-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v200-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\01\201-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v201-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\01\520-{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}-v1-{C2DD0587-D460-43F9-8B4B-D3CE35765
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\02\202-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v202-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\03\203-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v203-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\04\204-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v204-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\05\205-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v205-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\06\206-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v206-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\07\207-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v207-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\08\208-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v208-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\09\209-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v209-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\10\210-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v210-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\11\211-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v211-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\12\212-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v212-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\13\213-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v213-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\14\214-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v214-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\15\215-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v215-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\16\216-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v216-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\17\217-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v217-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\18\218-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v218-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\19\219-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v219-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\20\220-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v220-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\21\221-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v221-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\22\222-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v222-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\23\223-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v223-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\24\243-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v224-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\25\244-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v225-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\26\245-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v226-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\27\246-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v227-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\28\247-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v228-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\29\248-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v229-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\30\249-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v230-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\31\250-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v231-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\32\251-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v232-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\33\252-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v233-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\34\253-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v234-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\35\235-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v235-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\36\236-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v236-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\37\237-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v237-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\38\238-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v238-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\39\239-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v239-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\40\240-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v240-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\41\241-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v241-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\42\242-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v242-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\74\174-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v174-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\75\175-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v175-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\76\176-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v176-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\77\177-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v177-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\78\178-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v178-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\79\179-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v179-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\80\180-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v180-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\81\181-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v181-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\82\182-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v182-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\83\183-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v183-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\84\184-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v184-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\85\185-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v185-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\86\186-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v186-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\87\187-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v187-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\88\188-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v188-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\89\189-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v189-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\90\190-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v190-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\91\191-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v191-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\92\192-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v192-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\93\193-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v193-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\94\194-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v194-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\95\195-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v195-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\96\196-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v196-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\97\197-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v197-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\98\198-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v198-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\99\199-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v199-{446D13BA-76A0-474E-BA7C-2D768EC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\00\100-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v100-{3B3128C8-965C-4097-A222-75A8
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\01\101-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v101-{3B3128C8-965C-4097-A222-75A8
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\01\11-{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}-v1-{C2DD0587-D460-43F9-8B4B-D3CE357
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\02\102-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v102-{3B3128C8-965C-4097-A222-75A8
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\03\103-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v103-{3B3128C8-965C-4097-A222-75A8
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\04\104-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v104-{3B3128C8-965C-4097-A222-75A8
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\49\358-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v49-{317B1412-4A0A-4491-89FE-18B76
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\59\59-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v59-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\60\60-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v60-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\61\61-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v61-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\62\62-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v62-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\63\63-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v63-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\64\64-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v64-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\65\65-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v65-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\66\66-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v66-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\67\67-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v67-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\68\68-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v68-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\69\69-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v69-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\70\70-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v70-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\71\71-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v71-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\72\72-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v72-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\73\73-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v73-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\74\74-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v74-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\75\75-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v75-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\76\76-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v76-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\77\77-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v77-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\78\78-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v78-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\79\79-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v79-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\81\81-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v81-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\82\82-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v82-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\83\83-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v83-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\84\84-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v84-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\85\85-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v85-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\86\86-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v86-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\87\87-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v87-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\88\88-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v88-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\89\89-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v89-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\90\90-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v90-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\91\91-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v91-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\92\92-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v92-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\94\94-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v94-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\95\95-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v95-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\96\96-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v96-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\97\97-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v97-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\98\98-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v98-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\99\99-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v99-{3B3128C8-965C-4097-A222-75A8AC
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\01\724-{BFB9603C-6379-257F-3100-66D68993F7D4}-v1-{C2DD0587-D460-43F9-8B4B-D
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\01\802-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v801-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\03\804-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v803-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\05\806-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v805-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\07\808-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v807-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\09\810-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v809-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\11\11-{71924945-5F04-4E9C-AB34-4383CBF6339F}-v11-{71924945-5F04-4E9C-AB34-4
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\11\812-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v811-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\12\12-{71924945-5F04-4E9C-AB34-4383CBF6339F}-v12-{71924945-5F04-4E9C-AB34-4
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\13\814-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v813-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\15\816-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v815-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\17\818-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v817-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\19\820-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v819-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\21\822-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v821-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\23\824-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v823-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\25\725-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v725-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\25\826-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v825-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\26\726-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v726-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\27\727-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v727-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\28\728-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v728-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\29\729-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v729-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\30\730-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v730-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\31\731-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v731-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\32\732-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v732-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\33\733-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v733-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\34\734-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v734-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\35\735-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v735-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\36\736-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v736-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\37\737-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v737-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\38\738-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v738-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\39\739-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v739-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\40\740-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v740-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\41\741-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v741-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\42\742-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v742-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\43\743-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v743-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\44\744-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v744-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\65\786-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v765-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\66\766-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v766-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\67\767-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v767-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\68\768-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v768-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\69\769-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v769-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\70\770-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v770-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\71\771-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v771-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\72\772-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v772-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\73\773-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v773-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\74\774-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v774-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\75\775-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v775-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\76\776-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v776-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\77\777-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v777-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\78\778-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v778-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\79\779-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v779-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\80\780-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v780-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\81\781-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v781-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\82\782-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v782-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\83\783-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v783-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\84\784-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v784-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\85\785-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v785-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\87\788-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v787-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\89\790-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v789-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\91\792-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v791-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\93\794-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v793-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\95\796-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v795-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\97\798-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v797-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\99\800-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v799-{C2DD0587-D460-43F9-8B4B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\01\704-{6A9313F1-CDB2-6309-8834-73A2A42B0757}-v1-{C2DD0587-D460-43F9-8B
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\05\705-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v705-{C2DD0587-D460-43F9-
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\06\706-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v706-{C2DD0587-D460-43F9-
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\07\707-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v707-{C2DD0587-D460-43F9-
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\08\708-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v708-{C2DD0587-D460-43F9-
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\09\709-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v709-{C2DD0587-D460-43F9-
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\10\710-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v710-{C2DD0587-D460-43F9-
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\11\711-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v711-{C2DD0587-D460-43F9-
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\12\712-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v712-{C2DD0587-D460-43F9-
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\13\713-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v713-{C2DD0587-D460-43F9-
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\14\714-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v714-{C2DD0587-D460-43F9-
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\15\715-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v715-{C2DD0587-D460-43F9-
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\16\716-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v716-{C2DD0587-D460-43F9-
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\17\717-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v717-{C2DD0587-D460-43F9-
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\18\718-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v718-{C2DD0587-D460-43F9-
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\19\719-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v719-{C2DD0587-D460-43F9-
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\20\720-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v720-{C2DD0587-D460-43F9-
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{98F86564-8D69-F4C3-5DC3-48B13DE6068E}\00\900-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v900-{C2DD0587-D460-43F9-8B4B-D3C
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{98F86564-8D69-F4C3-5DC3-48B13DE6068E}\01\892-{98F86564-8D69-F4C3-5DC3-48B13DE6068E}-v1-{C2DD0587-D460-43F9-8B4B-D3CE3
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{98F86564-8D69-F4C3-5DC3-48B13DE6068E}\01\901-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v901-{C2DD0587-D460-43F9-8B4B-D3C
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{98F86564-8D69-F4C3-5DC3-48B13DE6068E}\02\902-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v902-{C2DD0587-D460-43F9-8B4B-D3C
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{98F86564-8D69-F4C3-5DC3-48B13DE6068E}\03\903-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v903-{C2DD0587-D460-43F9-8B4B-D3C
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{98F86564-8D69-F4C3-5DC3-48B13DE6068E}\04\904-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v904-{C2DD0587-D460-43F9-8B4B-D3C
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{98F86564-8D69-F4C3-5DC3-48B13DE6068E}\05\905-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v905-{C2DD0587-D460-43F9-8B4B-D3C
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{98F86564-8D69-F4C3-5DC3-48B13DE6068E}\06\906-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v906-{C2DD0587-D460-43F9-8B4B-D3C
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{98F86564-8D69-F4C3-5DC3-48B13DE6068E}\07\907-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v907-{C2DD0587-D460-43F9-8B4B-D3C
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{98F86564-8D69-F4C3-5DC3-48B13DE6068E}\08\908-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v908-{C2DD0587-D460-43F9-8B4B-D3C
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{98F86564-8D69-F4C3-5DC3-48B13DE6068E}\09\909-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v909-{C2DD0587-D460-43F9-8B4B-D3C
        Status: Hidden

        Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\mi

        SuperDave

        • Malware Removal Specialist


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: help with malware removal
        « Reply #5 on: February 10, 2011, 01:43:22 PM »
        I'd like to scan your machine with ESET OnlineScan

        •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
        ESET OnlineScan
        •Click the button.
        •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
        • Click on to download the ESET Smart Installer. Save it to your desktop.
        • Double click on the icon on your desktop.
        •Check
        •Click the button.
        •Accept any security warnings from your browser.
        •Check
        •Push the Start button.
        •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
        •When the scan completes, push
        •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
        •Push the button.
        •Push
        A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
        Windows 8 and Windows 10 dual boot with two SSD's

        smyers0013

          Topic Starter


          Greenhorn

          • Experience: Beginner
          • OS: Unknown
          Re: help with malware removal
          « Reply #6 on: February 11, 2011, 04:33:20 AM »
          C:\Qoobox\Quarantine\C\Users\Siri Fevang Ekenes\drvxslek55k.exe.vir   Win32/Autoit.NGV trojan   cleaned by deleting - quarantined
          C:\Qoobox\Quarantine\C\Users\Siri Fevang Ekenes\AppData\Local\Temp\awurst.dll.vir   a variant of Win32/Kryptik.JYO trojan   cleaned by deleting - quarantined
          C:\Qoobox\Quarantine\C\Users\Siri Fevang Ekenes\AppData\Local\Temp\_awurst_.dll.zip   a variant of Win32/Kryptik.JYO trojan   deleted - quarantined
          C:\Qoobox\Quarantine\C\Users\Siri Fevang Ekenes\AppData\Roaming\drvxslek32k\drvxslek55k.exe.vir   Win32/Autoit.NGV trojan   cleaned by deleting - quarantined
          C:\Users\Siri Fevang Ekenes\pod312.exe   a variant of Win32/Adware.Virtumonde.NHB application   cleaned by deleting - quarantined
          C:\Users\Siri Fevang Ekenes\pod552.exe   a variant of Win32/Kryptik.JYO trojan   cleaned by deleting - quarantined
          C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1\5bb2f041-5b9b55b6   multiple threats   deleted - quarantined
          C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1\75ae1601-1fa9c8fc   multiple threats   deleted - quarantined
          C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\7ea4908c-182fc273   multiple threats   deleted - quarantined
          C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\23648212-5168a807   multiple threats   deleted - quarantined
          C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\5f94f754-71eb59bc   multiple threats   deleted - quarantined
          C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\6b8b5d-5f0dd2a4   multiple threats   deleted - quarantined
          C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\899bde0-4ec2ac69   multiple threats   deleted - quarantined
          C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\d46a9e8-73ea8974   multiple threats   deleted - quarantined
          C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\de78db2-5764013a   multiple threats   deleted - quarantined
          C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\78d32ff3-1dbe6471   Java/Agent.X trojan   deleted - quarantined
          C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\78d32ff3-4eaa834a   Java/Agent.X trojan   deleted - quarantined
          C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\78d32ff3-6879eb57   Java/Agent.X trojan   deleted - quarantined
          C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\78d32ff3-7a0fcf2f   Java/Agent.X trojan   deleted - quarantined
          C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\656cf636-26624949   multiple threats   deleted - quarantined
          C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61\7e5ebafd-1f216e6b   multiple threats   deleted - quarantined
          C:\Windows\System32\opinstaller.msi   multiple threats   deleted - quarantined

          SuperDave

          • Malware Removal Specialist


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: help with malware removal
          « Reply #7 on: February 11, 2011, 04:41:55 PM »
          That looks good. If there are no other issues, it's time for some cleanup.

          To uninstall ComboFix

          • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
          • In the field, type in ComboFix /uninstall


          (Note: Make sure there's a space between the word ComboFix and the forward-slash.)

          • Then, press Enter, or click OK.
          • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
          ********************************************************
          Clean out your temporary internet files and temp files.

          Download TFC by OldTimer to your desktop.

          Double-click TFC.exe to run it.

          Note: If you are running on Vista, right-click on the file and choose Run As Administrator

          TFC will close all programs when run, so make sure you have saved all your work before you begin.

          * Click the Start button to begin the cleaning process.
          * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
          * Please let TFC run uninterrupted until it is finished.

          Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
          **************************************************
          Looking over your log it seems you don't have any evidence of a third party firewall.

          Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

          Remember only install ONE firewall

          1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
          2) Online Armor
          3) Agnitum Outpost
          4) PC Tools Firewall Plus

          If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
          *************************************************************
          Use the Secunia Software Inspector to check for out of date software.

          •Click Start Now

          •Check the box next to Enable thorough system inspection.

          •Click Start

          •Allow the scan to finish and scroll down to see if any updates are needed.
          •Update anything listed.
          .
          ----------

          Go to Microsoft Windows Update and get all critical updates.

          ----------

          I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

          SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
          * Using SpywareBlaster to protect your computer from Spyware and Malware
          * If you don't know what ActiveX controls are, see here

          Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

          Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

          Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
          Safe Surfing!
          Windows 8 and Windows 10 dual boot with two SSD's

          smyers0013

            Topic Starter


            Greenhorn

            • Experience: Beginner
            • OS: Unknown
            Re: help with malware removal
            « Reply #8 on: February 11, 2011, 08:22:13 PM »
            Thanks a million SuperDave!

            SuperDave

            • Malware Removal Specialist


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
            Re: help with malware removal
            « Reply #9 on: February 12, 2011, 11:56:06 AM »
            You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
            Windows 8 and Windows 10 dual boot with two SSD's