Computer Hope

Software => Computer viruses and spyware => Virus and spyware removal => Topic started by: smyers0013 on February 06, 2011, 05:22:14 PM

Title: help with malware removal
Post by: smyers0013 on February 06, 2011, 05:22:14 PM
hi,

i've followed the 'malware removal' steps in the 'Read this before requesting malware removal help' topic, and now I am posting my logs so that I can hopefully get some help.

A couple of things first though -- I couldn't run malarebytes' antimalware program. I don't know why -- I installed it and when i clicked the desktop shortcut a screen for downloading unpdates popped up and disappeared within a split second. I tried downloading updates from the website by following the links in the topic, but the links were dead.

so, I scanned using SAS and HijackThis. Here are my logs. Thanks in advance to whoever (qualified) helps me!

also, I forgot to run ccleaner before running SAS, but I'm hoping it's not essential. I DID run it before running HJT though.


===============================================


SAS LOG:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/06/2011 at 11:45 PM

Application Version : 4.48.1000

Core Rules Database Version : 6343
Trace Rules Database Version: 4155

Scan type       : Complete Scan
Total Scan Time : 02:09:29

Memory items scanned      : 655
Memory threats detected   : 1
Registry items scanned    : 8496
Registry threats detected : 0
File items scanned        : 148853
File threats detected     : 23

Rogue.Disk-Cleanup
   C:\USERS\SIRIFE~1\APPDATA\LOCAL\TEMP\WINBDM.DLL
   C:\USERS\SIRIFE~1\APPDATA\LOCAL\TEMP\WINBDM.DLL
   C:\USERS\SIRI FEVANG EKENES\APPDATA\LOCAL\TEMP\WINBDM.DLL

Trojan.Agent/Gen-FakeAlert
   C:\USERS\SIRI FEVANG EKENES\APPDATA\LOCAL\TEMP\LOW\0.9854071332668755.EXE
   C:\USERS\SIRI FEVANG EKENES\APPDATA\LOCAL\TEMP\LOW\CYYJETMYH\BVTBDVASJMO.EXE

Adware.Tracking Cookie
   C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@adform[2].txt
   C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@adtech[1].txt
   C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@adviva[1].txt
   C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@adxpose[1].txt
   C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@apmebf[1].txt
   C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][3].txt
   C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@doubleclick[1].txt
   C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@mediaplex[2].txt
   C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@revsci[2].txt
   C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@serving-sys[1].txt
   C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@specificclick[1].txt
   C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@statcounter[2].txt
   C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@tribalfusion[2].txt
   C:\Users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Cookies\Low\siri_fevang_ekenes@zanox[1].txt




===============================================



HijackThis LOG:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 01:03:37, on 07.02.2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18999)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\OEM02Mon.exe
C:\Windows\sttray.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Iomega\Home Storage Manager\Iomega Discovery.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Registry Mechanic\RMTray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\rundll32.exe
C:\Users\Siri Fevang Ekenes\AppData\Roaming\drvxslek32k\drvxslek55k.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Windows\system32\conime.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe
C:\Program Files\Trend Micro\HiJackThis\Sniper.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sol.no/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.no/ig/dell?hl=no&client=dell-row&channel=no&ibd=3070927
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer levert av Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton-verktøylinjen - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SSDMonitor] C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Iomega Home Storage Manager] C:\Program Files\Iomega\Home Storage Manager\Iomega Discovery.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RMTray.exe /H
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [CTF Products Updater] rundll32.exe "C:\Users\SIRIFE~1\AppData\Local\Temp\winbdm.dll", DepCmd
O4 - HKCU\..\Run: [qoppnlsys] rundll32.exe "c:\users\sirife~1\appdata\local\temp\iiiijj.dll",s
O4 - HKCU\..\Run: [drvxslek32k] C:\Users\Siri Fevang Ekenes\AppData\Roaming\drvxslek32k\drvxslek55k.exe
O4 - HKCU\..\Run: [awwxvsaudio] rundll32.exe "c:\users\sirife~1\appdata\local\temp\awurst.dll",s
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETTVERKSTJENESTE')
O4 - Startup: OneNote 2007 Screen Clipper og Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Automatisk LiveUpdate-planlegging - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GTMM Device Service - Option nv - C:\Program Files\Telenor\Mobile Broadband\GtmmDeviceService.exe
O23 - Service: Googles oppdateringstjeneste (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Sesam Control Service (SesamService) - Swisscom - C:\Program Files\Telenor\Mobile Broadband\Sesam\BIN\SecMIPService.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 12002 bytes


=================================================


regards, smyers0013
Title: Re: help with malware removal
Post by: SuperDave on February 07, 2011, 04:41:53 PM
Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
**************************************************
Registry cleaners are extremely powerful applications and their potential for harming your OS far outweighs any small potential for improving your computer's performance.
Registry Mechanic
There are a number of them available and some are more safe than others. Keep in mind that no two registry cleaners work entirely the same way. Each vendor uses different criteria as to what constitutes a "bad" entry. One cleaner may find entries on your system that will not cause a problem when removed, another may not find the same entries, and still another may want to remove entries required for a program to work. Without research into what the registry entry selected for deletion is, a registry cleaner can end up being an automated method to cause problems with the registry.

For routine use by those not familiar with the registry, the benefits to your computer are negligible while the potential risks are great.

Further reading: XP Fixes Myth #1: Registry Cleaners (http://www.windowsbbs.com/showthread.php?t=61015)
*****************************************************
Open HijackThis and select Do a system scan only

Place a check mark next to the following entries: (if there)

O4 - HKCU\..\Run: [qoppnlsys] rundll32.exe "c:\users\sirife~1\appdata\local\temp\iiiijj.dll",s
O4 - HKCU\..\Run: [drvxslek32k] C:\Users\Siri Fevang Ekenes\AppData\Roaming\drvxslek32k\drvxslek55k.exe
O4 - HKCU\..\Run: [awwxvsaudio] rundll32.exe "c:\users\sirife~1\appdata\local\temp\awurst.dll",s


Important: Close all open windows except for HijackThis and then click Fix checked.

Once completed, exit HijackThis.
*********************************************
Download Security Check by screen317 from one of the following links and save it to your desktop.

Link 1 (http://screen317.spywareinfoforum.org/SecurityCheck.exe)
Link 2 (http://screen317.changelog.fr/SecurityCheck.exe)

* Unzip SecurityCheck.zip and a folder named Security Check should appear.
* Open the Security Check folder and double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.
**************************************************
Download ComboFix by sUBs from one of the below links.  Be sure to save it to the Desktop.

link # 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link # 2 (http://subs.geekstogo.com/ComboFix.exe)
If you are using Firefox, make sure that your download settings are as follows:

* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".

Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link (http://www.bleepingcomputer.com/forums/topic114351.html) to see a list of security programs that should be disabled and how to disable them.

Right-click combofix.exe and select Run as Administrator and follow the prompts.
When finished, ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next reply.

NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.
Title: Re: help with malware removal
Post by: smyers0013 on February 09, 2011, 10:49:36 AM
Hi Dave,

thas for offering your assistance, it's really appreciated.

here are my logs:

=============================================

Security Check:

 Results of screen317's Security Check version 0.99.8 
 Windows Vista Service Pack 2 (UAC is enabled)
 Internet Explorer 8 
``````````````````````````````
Antivirus/Firewall Check:

 Norton AntiVirus     
 Norton Internet Security (Symantec Corporation) 
 Norton Internet Security   
 WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:

 SUPERAntiSpyware     
 CCleaner     
 Java(TM) 6 Update 23 
 Java(TM) SE Runtime Environment 6
 Adobe Flash Player 10.0.12.36 
Adobe Reader 9.3 - Norsk
Out of date Adobe Reader installed!
````````````````````````````````
Process Check: 
objlist.exe by Laurent

 Norton ccSvcHst.exe
``````````End of Log````````````





====================================================


ComboFix:

ComboFix 11-02-08.05 - Siri Fevang Ekenes 09.02.2011  18:14:03.1.2 - x86
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.47.1044.18.1917.1194 [GMT 1:00]
Kjører fra: c:\users\Siri Fevang Ekenes\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.

(((((((((((((((((((((((((((((((((((((((   Andre slettinger   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\programdata\Local
c:\programdata\Microsoft\Network\Downloader\qmgr0.dat
c:\programdata\Microsoft\Network\Downloader\qmgr1.dat
c:\users\Siri Fevang Ekenes\AppData\Local\Temp\awurst.dll
c:\users\Siri Fevang Ekenes\AppData\Roaming\drvxslek32k
c:\users\Siri Fevang Ekenes\AppData\Roaming\drvxslek32k\config.ini
c:\users\Siri Fevang Ekenes\AppData\Roaming\drvxslek32k\drvxslek55k.exe
c:\users\Siri Fevang Ekenes\drvxslek55k.exe
c:\users\SIRIFE~1\AppData\Local\Temp\awurst.dll

----- BITS: Mulige infiserte sider -----

hxxp://buy-download.norton.com
.
(((((((((((((((((((((((((((   Filer Opprettet Fra 2011-01-09 til 2011-02-09  )))))))))))))))))))))))))))))))))
.

2011-02-09 17:24 . 2011-02-09 17:24   --------   d-----w-   c:\programdata\Local
2011-02-09 17:22 . 2011-02-09 17:22   --------   d-----w-   c:\users\Default\AppData\Local\temp
2011-02-08 12:06 . 2011-01-13 09:41   5890896   ----a-w-   c:\programdata\Microsoft\Windows Defender\Definition Updates\{3FCC4C4D-9F0B-4B28-8F3F-BA152E4227BD}\mpengine.dll
2011-02-07 19:15 . 2011-02-08 20:51   111616   ----a-w-   c:\users\Siri Fevang Ekenes\pod312.exe
2011-02-06 23:58 . 2011-02-06 23:58   388096   ----a-r-   c:\users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-02-06 23:58 . 2011-02-06 23:58   --------   d-----w-   c:\program files\Trend Micro
2011-02-06 23:43 . 2011-02-06 23:43   --------   d-----w-   c:\program files\CCleaner
2011-02-06 23:33 . 2011-02-06 23:32   472808   ----a-w-   c:\windows\system32\deployJava1.dll
2011-02-06 20:32 . 2011-02-06 20:33   --------   d-----w-   c:\program files\SUPERAntiSpyware
2011-02-05 14:10 . 2011-02-05 14:10   --------   d-----w-   c:\users\Siri Fevang Ekenes\AppData\Roaming\Malwarebytes
2011-02-05 14:08 . 2011-02-05 14:08   --------   d-----w-   c:\programdata\Malwarebytes
2011-02-05 02:06 . 2011-02-05 02:06   --------   d-----w-   c:\users\Siri Fevang Ekenes\AppData\Roaming\SUPERAntiSpyware.com
2011-02-05 02:06 . 2011-02-05 02:06   --------   d-----w-   c:\programdata\SUPERAntiSpyware.com
2011-02-04 18:54 . 2011-02-04 21:56   --------   d-----w-   c:\users\Siri Fevang Ekenes\AppData\Local\CrashDumps
2011-02-03 17:23 . 2011-02-03 17:23   --------   d-----w-   c:\program files\Norton AntiVirus
2011-02-03 17:16 . 2011-02-03 17:16   --------   d-----w-   c:\programdata\PCSettings
2011-02-03 17:14 . 2011-02-03 17:14   --------   d-----w-   c:\program files\NortonInstaller
2011-02-03 17:11 . 2011-02-03 17:30   --------   d-----w-   c:\programdata\Norton
2011-01-26 03:33 . 2011-01-26 03:33   --------   d-----w-   c:\users\Siri Fevang Ekenes\AppData\Roaming\Sync App Settings
2011-01-26 03:32 . 2011-01-26 03:32   --------   d-----w-   c:\programdata\Sync App Settings
2011-01-26 03:31 . 2011-01-26 03:31   115200   ----a-w-   c:\users\Siri Fevang Ekenes\pod552.exe
2011-01-14 14:34 . 2011-01-14 14:35   --------   d-----w-   c:\program files\Iomega
2011-01-12 10:18 . 2010-12-28 15:55   413696   ----a-w-   c:\windows\system32\odbc32.dll
2011-01-12 10:18 . 2010-12-28 15:53   253952   ----a-w-   c:\program files\Common Files\System\ado\msadox.dll
2011-01-12 10:18 . 2010-12-28 15:53   708608   ----a-w-   c:\program files\Common Files\System\ado\msado15.dll
2011-01-12 10:18 . 2010-12-28 15:53   241664   ----a-w-   c:\program files\Common Files\System\ado\msadomd.dll
2011-01-12 10:18 . 2010-12-28 15:53   57344   ----a-w-   c:\program files\Common Files\System\msadc\msadcs.dll
2011-01-12 10:18 . 2010-12-28 15:53   180224   ----a-w-   c:\program files\Common Files\System\msadc\msadco.dll
2011-01-12 10:18 . 2010-12-14 14:49   1169408   ----a-w-   c:\windows\system32\sdclt.exe

.
((((((((((((((((((((((((((((((((((((((((   Find3M Rapport   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.

((((((((((((((((((((((((((((((((   Oppstartspunkter I Registeret   )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Merk* tomme oppføringer & gyldige standardoppføringer vises ikke 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-25 39408]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"RegistryMechanic"="c:\program files\Registry Mechanic\RMTray.exe" [2010-04-08 292824]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-28 857648]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-05-10 36864]
"SigmatelSysTrayApp"="sttray.exe" [2007-03-06 303104]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SSDMonitor"="c:\program files\Common Files\PC Tools\sMonitor\SSDMonitor.exe" [2010-04-08 104408]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"Iomega Home Storage Manager"="c:\program files\Iomega\Home Storage Manager\Iomega Discovery.exe" [2009-10-27 152936]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

c:\users\Siri Fevang Ekenes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper og Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^BTTray.lnk]
backup=c:\windows\pss\BTTray.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Digital Line Detect.lnk]
backup=c:\windows\pss\Digital Line Detect.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickSet.lnk]
backup=c:\windows\pss\QuickSet.lnk.CommonStartup
backupExtension=.CommonStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
%ProgramFiles%\Windows Defender\MSASCui.exe -hide [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
2007-03-21 19:33   1548288   ----a-w-   c:\windows\System32\WLTRAY.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
2007-01-24 23:03   107112   ----a-w-   c:\program files\Common Files\Symantec Shared\ccApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ECenter]
2007-03-16 10:50   17920   ----a-w-   c:\dell\E-Center\EULALauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-19 07:33   125952   ----a-w-   c:\windows\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2007-09-27 15:38   1862144   ----a-w-   c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2006-10-03 10:37   81920   ----a-w-   c:\program files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-04-28 13:06   142120   ----a-w-   c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEM02Mon.exe]
2007-05-10 09:01   36864   ----a-w-   c:\windows\OEM02Mon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
2008-04-01 01:54   507904   ----a-w-   c:\program files\Winamp Remote\bin\OrbTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
2007-01-24 23:01   22696   ----a-w-   c:\program files\Norton Internet Security\osCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2007-04-16 15:10   184320   ------w-   c:\program files\Dell\MediaDirect\PCMService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-17 19:53   421888   ----a-w-   c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
2006-11-05 10:22   221184   ----a-w-   c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28   1233920   ----a-w-   c:\program files\Windows Sidebar\sidebar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2007-03-06 20:37   303104   ----a-w-   c:\windows\sttray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-09-27 15:01   77824   ----a-w-   c:\program files\Java\jre1.6.0\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng]
2008-01-29 15:38   583048   ----a-w-   c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2007-04-28 00:35   857648   ----a-w-   c:\program files\Synaptics\SynTP\SynTPEnh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2009-03-09 15:49   37888   ----a-w-   c:\program files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-19 07:33   202240   ----a-w-   c:\program files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

R2 gupdate;Googles oppdateringstjeneste (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 135664]
R3 GT72NDISIPXP;GT 72 IP NDIS;c:\windows\system32\DRIVERS\Gt51Ip.sys [2007-07-09 95744]
R3 GT72UBUS;GT 72 U BUS;c:\windows\system32\DRIVERS\gt72ubus.sys [2007-06-26 51968]
R3 GTMM Device Service;GTMM Device Service;c:\program files\Telenor\Mobile Broadband\GtmmDeviceService.exe [2008-07-02 106496]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\Drivers\SYMNDISV.SYS [2007-01-24 37008]
S1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\idsdefs\20101113.002\IDSvix86.sys [2010-09-15 287792]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 Automatisk LiveUpdate-planlegging;Automatisk LiveUpdate-planlegging;c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2007-09-26 554352]
S2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [2010-04-08 632792]
S2 SesamService;Sesam Control Service;c:\program files\Telenor\Mobile Broadband\Sesam\BIN\SecMIPService.exe [2008-05-09 1216296]
S3 wtsmpadap;Sesam Virtual Adapter;c:\windows\system32\DRIVERS\wtsmpadap.sys [2008-04-29 39720]
S3 WtSmpFlt;Sesam Adapter;c:\windows\system32\DRIVERS\wtsmpflt.sys [2008-04-29 272424]


--- Andre tjenester/drivere lastet i minnet ---

*NewlyCreated* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs   REG_MULTI_SZ      BthServ
LocalServiceAndNoImpersonation   REG_MULTI_SZ      FontCache
.
Innholdet i mappen 'Scheduled Tasks' (planlagte oppgaver)

2011-02-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 14:02]

2011-02-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 14:02]

2010-12-16 c:\windows\Tasks\User_Feed_Synchronization-{633CEE21-2C47-4221-89BB-2BBA14BB3F47}.job
- c:\windows\system32\msfeedssync.exe [2010-12-15 04:25]
.
.
------- Tilleggsskanning -------
.
uStart Page = hxxp://www.sol.no/
uInternet Settings,ProxyOverride = *.local
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: StumbleUpon PhotoBlog It! - StumbleUponIEBar.dll/blogimage
.
- - - - TOMME PEKERE FJERNET - - - -

HKCU-Run-efdeffaudio - c:\users\sirife~1\appdata\local\temp\awurst.dll
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
AddRemove-Allway Sync_is1 - f:\program files\Allway Sync\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-09 18:27
Windows 6.0.6002 Service Pack 2 NTFS

skanner skjulte prosesser ... 

skanner skjulte autostart-oppføringer ...

skanner skjulte filer ... 

skanning vellykket
skjulte filer: 0

**************************************************************************
.
--------------------- LÅSTE REGISTERNØKLER ---------------------

[HKEY_USERS\S-1-5-21-199706739-3402135902-50689569-1000\Software\SecuROM\License information*]
"datasecu"=hex:21,9b,ca,5d,2b,94,2f,e8,15,df,46,0f,ee,bb,e5,ab,27,2b,be,13,45,
   45,65,a0,36,af,f8,57,36,f3,42,49,0e,de,ec,d8,f3,21,e5,08,38,c5,ee,b5,bc,9b,\
"rkeysecu"=hex:04,a5,5a,62,06,53,6b,16,6f,c8,3e,47,1f,30,de,24

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLL'er Lastet Av Kjørende Prosesser ---------------------

- - - - - - - > 'Explorer.exe'(4064)
c:\windows\system32\btncopy.dll
.
------------------------ Andre Kjørende Prosesser ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\program files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\windows\system32\STacSV.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\system32\conime.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Tidspunkt ferdig: 2011-02-09  18:34:10 - maskinen ble startet på nytt
ComboFix-quarantined-files.txt  2011-02-09 17:34

Pre-Run: 53 712 781 312 byte ledig
Post-Run: 53 659 262 976 byte ledig

- - End Of File - - 0D0A1E30C5BDF001D8F71345D6A30E57





==============================================================================


HijackThis:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:42:20, on 09.02.2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18999)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\conime.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\OEM02Mon.exe
C:\Windows\sttray.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Iomega\Home Storage Manager\Iomega Discovery.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Registry Mechanic\RMTray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\Explorer.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HiJackThis\Sniper.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sol.no/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton-verktøylinjen - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SSDMonitor] C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Iomega Home Storage Manager] C:\Program Files\Iomega\Home Storage Manager\Iomega Discovery.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RMTray.exe /H
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OneNote 2007 Screen Clipper og Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Automatisk LiveUpdate-planlegging - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GTMM Device Service - Option nv - C:\Program Files\Telenor\Mobile Broadband\GtmmDeviceService.exe
O23 - Service: Googles oppdateringstjeneste (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Sesam Control Service (SesamService) - Swisscom - C:\Program Files\Telenor\Mobile Broadband\Sesam\BIN\SecMIPService.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 10676 bytes



=======================================================================


Thanks again!
smyers0013
Title: Re: help with malware removal
Post by: SuperDave on February 09, 2011, 05:13:50 PM
Please download the newest version of Adobe Acrobat Reader from Adobe.com (http://www.adobe.com/products/acrobat/readstep2.html)

Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs.
Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

Once old versions are gone, please install the newest version.
**************************************************
SysProt Antirootkit

Download
SysProt Antirootkit from the link below (you will find it at the bottom
of the page under attachments, or you can get it from one of the
mirrors).

http://sites.google.com/site/sysprotantirootkit/ (http://sites.google.com/site/sysprotantirootkit/)

Unzip it into a folder on your desktop.

log will be saved automatically in the same folder Sysprot.exe was
extracted to. Open the text file and copy/paste the log here.
[/list]
Title: Re: help with malware removal
Post by: smyers0013 on February 09, 2011, 06:32:34 PM
SysProt Log:

SysProt AntiRootkit v1.0.1.0
by swatkat

******************************************************************************************
******************************************************************************************

No Hidden Processes found

******************************************************************************************
******************************************************************************************
Kernel Modules:
Module Name: \SystemRoot\System32\Drivers\dump_dumpata.sys
Service Name: ---
Module Base: 8DEBB000
Module End: 8DEC6000
Hidden: Yes

Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
Service Name: ---
Module Base: 8DEC6000
Module End: 8DECE000
Hidden: Yes

******************************************************************************************
******************************************************************************************
SSDT:
Function Name: ZwConnectPort
Address: 8622AE18
Driver Base: 0
Driver End: 0
Driver Name: _unknown_

******************************************************************************************
******************************************************************************************
No Kernel Hooks found

******************************************************************************************
******************************************************************************************
Hidden files/folders:
Object: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\SRTSP\SrtETmp\A5EEBA5F.TMP
Status: Access denied

Object: C:\ProgramData\Symantec\SRTSP\Quarantine\AP589EC956.mp3
Status: Access denied

Object: C:\Qoobox\BackEnv\AppData.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Cache.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Cookies.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Desktop.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Favorites.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\History.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\LocalAppData.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\LocalSettings.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Music.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\NetHood.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Personal.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Pictures.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\PrintHood.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Profiles.Folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Profiles.Folder.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Programs.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Recent.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SendTo.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SetPath.bat
Status: Access denied

Object: C:\Qoobox\BackEnv\StartMenu.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\StartUp.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SysPath.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Templates.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\VikPev00
Status: Access denied

Object: C:\Users\All Users\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\SRTSP\SrtETmp\A5EEBA5F.TMP
Status: Access denied

Object: C:\Users\All Users\Symantec\SRTSP\Quarantine\AP589EC956.mp3
Status: Access denied

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\00\200-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v200-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\01\201-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v201-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\01\520-{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}-v1-{C2DD0587-D460-43F9-8B4B-D3CE35765
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\02\202-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v202-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\03\203-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v203-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\04\204-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v204-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\05\205-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v205-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\06\206-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v206-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\07\207-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v207-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\08\208-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v208-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\09\209-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v209-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\10\210-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v210-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\11\211-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v211-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\12\212-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v212-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\13\213-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v213-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\14\214-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v214-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\15\215-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v215-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\16\216-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v216-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\17\217-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v217-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\18\218-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v218-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\19\219-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v219-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\20\220-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v220-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\21\221-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v221-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\22\222-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v222-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\23\223-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v223-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\24\243-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v224-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\25\244-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v225-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\26\245-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v226-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\27\246-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v227-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\28\247-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v228-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\29\248-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v229-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\30\249-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v230-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\31\250-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v231-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\32\251-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v232-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\33\252-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v233-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\34\253-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v234-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\35\235-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v235-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\36\236-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v236-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\37\237-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v237-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\38\238-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v238-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\39\239-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v239-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\40\240-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v240-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\41\241-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v241-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\42\242-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v242-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\74\174-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v174-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\75\175-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v175-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\76\176-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v176-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\77\177-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v177-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\78\178-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v178-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\79\179-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v179-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\80\180-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v180-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\81\181-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v181-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\82\182-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v182-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\83\183-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v183-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\84\184-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v184-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\85\185-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v185-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\86\186-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v186-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\87\187-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v187-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\88\188-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v188-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\89\189-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v189-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\90\190-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v190-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\91\191-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v191-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\92\192-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v192-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\93\193-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v193-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\94\194-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v194-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\95\195-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v195-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\96\196-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v196-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\97\197-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v197-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\98\198-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v198-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{4C9377C0-B16C-F99F-CDD4-9FCA1CCE3D63}\99\199-{446D13BA-76A0-474E-BA7C-2D768EC3FBEE}-v199-{446D13BA-76A0-474E-BA7C-2D768EC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\00\100-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v100-{3B3128C8-965C-4097-A222-75A8
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\01\101-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v101-{3B3128C8-965C-4097-A222-75A8
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\01\11-{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}-v1-{C2DD0587-D460-43F9-8B4B-D3CE357
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\02\102-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v102-{3B3128C8-965C-4097-A222-75A8
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\03\103-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v103-{3B3128C8-965C-4097-A222-75A8
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\04\104-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v104-{3B3128C8-965C-4097-A222-75A8
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\49\358-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v49-{317B1412-4A0A-4491-89FE-18B76
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\59\59-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v59-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\60\60-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v60-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\61\61-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v61-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\62\62-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v62-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\63\63-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v63-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\64\64-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v64-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\65\65-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v65-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\66\66-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v66-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\67\67-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v67-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\68\68-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v68-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\69\69-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v69-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\70\70-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v70-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\71\71-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v71-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\72\72-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v72-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\73\73-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v73-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\74\74-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v74-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\75\75-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v75-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\76\76-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v76-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\77\77-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v77-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\78\78-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v78-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\79\79-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v79-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\81\81-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v81-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\82\82-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v82-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\83\83-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v83-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\84\84-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v84-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\85\85-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v85-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\86\86-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v86-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\87\87-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v87-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\88\88-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v88-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\89\89-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v89-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\90\90-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v90-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\91\91-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v91-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\92\92-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v92-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\94\94-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v94-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\95\95-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v95-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\96\96-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v96-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\97\97-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v97-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\98\98-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v98-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{A9A17939-4E77-9C71-03AF-FEE9CE576D9D}\99\99-{3B3128C8-965C-4097-A222-75A8AC0635CD}-v99-{3B3128C8-965C-4097-A222-75A8AC
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\01\724-{BFB9603C-6379-257F-3100-66D68993F7D4}-v1-{C2DD0587-D460-43F9-8B4B-D
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\01\802-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v801-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\03\804-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v803-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\05\806-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v805-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\07\808-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v807-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\09\810-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v809-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\11\11-{71924945-5F04-4E9C-AB34-4383CBF6339F}-v11-{71924945-5F04-4E9C-AB34-4
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\11\812-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v811-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\12\12-{71924945-5F04-4E9C-AB34-4383CBF6339F}-v12-{71924945-5F04-4E9C-AB34-4
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\13\814-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v813-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\15\816-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v815-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\17\818-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v817-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\19\820-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v819-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\21\822-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v821-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\23\824-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v823-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\25\725-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v725-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\25\826-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v825-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\26\726-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v726-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\27\727-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v727-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\28\728-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v728-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\29\729-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v729-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\30\730-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v730-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\31\731-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v731-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\32\732-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v732-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\33\733-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v733-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\34\734-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v734-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\35\735-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v735-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\36\736-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v736-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\37\737-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v737-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\38\738-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v738-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\39\739-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v739-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\40\740-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v740-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\41\741-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v741-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\42\742-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v742-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\43\743-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v743-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\44\744-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v744-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\65\786-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v765-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\66\766-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v766-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\67\767-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v767-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\68\768-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v768-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\69\769-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v769-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\70\770-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v770-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\71\771-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v771-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\72\772-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v772-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\73\773-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v773-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\74\774-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v774-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\75\775-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v775-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\76\776-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v776-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\77\777-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v777-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\78\778-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v778-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\79\779-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v779-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\80\780-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v780-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\81\781-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v781-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\82\782-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v782-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\83\783-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v783-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\84\784-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v784-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\85\785-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v785-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\87\788-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v787-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\89\790-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v789-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\91\792-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v791-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\93\794-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v793-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\95\796-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v795-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\97\798-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v797-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{BFB9603C-6379-257F-3100-66D68993F7D4}\99\800-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v799-{C2DD0587-D460-43F9-8B4B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\01\704-{6A9313F1-CDB2-6309-8834-73A2A42B0757}-v1-{C2DD0587-D460-43F9-8B
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\05\705-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v705-{C2DD0587-D460-43F9-
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\06\706-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v706-{C2DD0587-D460-43F9-
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\07\707-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v707-{C2DD0587-D460-43F9-
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\08\708-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v708-{C2DD0587-D460-43F9-
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\09\709-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v709-{C2DD0587-D460-43F9-
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\10\710-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v710-{C2DD0587-D460-43F9-
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\11\711-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v711-{C2DD0587-D460-43F9-
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\12\712-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v712-{C2DD0587-D460-43F9-
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\13\713-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v713-{C2DD0587-D460-43F9-
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\14\714-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v714-{C2DD0587-D460-43F9-
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\15\715-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v715-{C2DD0587-D460-43F9-
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\16\716-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v716-{C2DD0587-D460-43F9-
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\17\717-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v717-{C2DD0587-D460-43F9-
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\18\718-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v718-{C2DD0587-D460-43F9-
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\19\719-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v719-{C2DD0587-D460-43F9-
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{6A9313F1-CDB2-6309-8834-73A2A42B0757}\20\720-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v720-{C2DD0587-D460-43F9-
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{98F86564-8D69-F4C3-5DC3-48B13DE6068E}\00\900-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v900-{C2DD0587-D460-43F9-8B4B-D3C
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{98F86564-8D69-F4C3-5DC3-48B13DE6068E}\01\892-{98F86564-8D69-F4C3-5DC3-48B13DE6068E}-v1-{C2DD0587-D460-43F9-8B4B-D3CE3
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{98F86564-8D69-F4C3-5DC3-48B13DE6068E}\01\901-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v901-{C2DD0587-D460-43F9-8B4B-D3C
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{98F86564-8D69-F4C3-5DC3-48B13DE6068E}\02\902-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v902-{C2DD0587-D460-43F9-8B4B-D3C
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{98F86564-8D69-F4C3-5DC3-48B13DE6068E}\03\903-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v903-{C2DD0587-D460-43F9-8B4B-D3C
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{98F86564-8D69-F4C3-5DC3-48B13DE6068E}\04\904-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v904-{C2DD0587-D460-43F9-8B4B-D3C
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{98F86564-8D69-F4C3-5DC3-48B13DE6068E}\05\905-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v905-{C2DD0587-D460-43F9-8B4B-D3C
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{98F86564-8D69-F4C3-5DC3-48B13DE6068E}\06\906-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v906-{C2DD0587-D460-43F9-8B4B-D3C
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{98F86564-8D69-F4C3-5DC3-48B13DE6068E}\07\907-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v907-{C2DD0587-D460-43F9-8B4B-D3C
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{98F86564-8D69-F4C3-5DC3-48B13DE6068E}\08\908-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v908-{C2DD0587-D460-43F9-8B4B-D3C
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DFSR\Staging\CS{98F86564-8D69-F4C3-5DC3-48B13DE6068E}\09\909-{C2DD0587-D460-43F9-8B4B-D3CE35765EA0}-v909-{C2DD0587-D460-43F9-8B4B-D3C
Status: Hidden

Object: C:\Users\Siri Fevang Ekenes\AppData\Local\Microsoft\Messenger\mi
Title: Re: help with malware removal
Post by: SuperDave on February 10, 2011, 01:43:22 PM
I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
 ESET OnlineScan (http://eset.com/onlinescan)
•Click the (http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetOnline.png) button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Check (http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetAcceptTerms.png)
•Click the (http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetStart.png) button.
•Accept any security warnings from your browser.
•Check (http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetScanArchives.png)
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push (http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetListThreats.png)
•Push (http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetExport.png), and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the (http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetBack.png) button.
•Push (http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetFinish.png)
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
Title: Re: help with malware removal
Post by: smyers0013 on February 11, 2011, 04:33:20 AM
C:\Qoobox\Quarantine\C\Users\Siri Fevang Ekenes\drvxslek55k.exe.vir   Win32/Autoit.NGV trojan   cleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\Users\Siri Fevang Ekenes\AppData\Local\Temp\awurst.dll.vir   a variant of Win32/Kryptik.JYO trojan   cleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\Users\Siri Fevang Ekenes\AppData\Local\Temp\_awurst_.dll.zip   a variant of Win32/Kryptik.JYO trojan   deleted - quarantined
C:\Qoobox\Quarantine\C\Users\Siri Fevang Ekenes\AppData\Roaming\drvxslek32k\drvxslek55k.exe.vir   Win32/Autoit.NGV trojan   cleaned by deleting - quarantined
C:\Users\Siri Fevang Ekenes\pod312.exe   a variant of Win32/Adware.Virtumonde.NHB application   cleaned by deleting - quarantined
C:\Users\Siri Fevang Ekenes\pod552.exe   a variant of Win32/Kryptik.JYO trojan   cleaned by deleting - quarantined
C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1\5bb2f041-5b9b55b6   multiple threats   deleted - quarantined
C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1\75ae1601-1fa9c8fc   multiple threats   deleted - quarantined
C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\7ea4908c-182fc273   multiple threats   deleted - quarantined
C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\23648212-5168a807   multiple threats   deleted - quarantined
C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\5f94f754-71eb59bc   multiple threats   deleted - quarantined
C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\6b8b5d-5f0dd2a4   multiple threats   deleted - quarantined
C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\899bde0-4ec2ac69   multiple threats   deleted - quarantined
C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\d46a9e8-73ea8974   multiple threats   deleted - quarantined
C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\de78db2-5764013a   multiple threats   deleted - quarantined
C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\78d32ff3-1dbe6471   Java/Agent.X trojan   deleted - quarantined
C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\78d32ff3-4eaa834a   Java/Agent.X trojan   deleted - quarantined
C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\78d32ff3-6879eb57   Java/Agent.X trojan   deleted - quarantined
C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\78d32ff3-7a0fcf2f   Java/Agent.X trojan   deleted - quarantined
C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\656cf636-26624949   multiple threats   deleted - quarantined
C:\Users\Siri Fevang Ekenes\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61\7e5ebafd-1f216e6b   multiple threats   deleted - quarantined
C:\Windows\System32\opinstaller.msi   multiple threats   deleted - quarantined
Title: Re: help with malware removal
Post by: SuperDave on February 11, 2011, 04:41:55 PM
That looks good. If there are no other issues, it's time for some cleanup.

To uninstall ComboFix

(http://i582.photobucket.com/albums/ss269/Cat_Byte/Combofix_uninstall_image.jpg)

(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

********************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer (http://oldtimer.geekstogo.com/TFC.exe) to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
**************************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (http://www.majorgeeks.com/Comodo_Personal_Firewall_d5033.html) (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor (http://www.majorgeeks.com/Online_Armor_Free_d4872.html)
3) Agnitum Outpost (http://www.majorgeeks.com/Outpost_Firewall_Free_d1056.html)
4) PC Tools Firewall Plus (http://www.majorgeeks.com/PC_Tools_Firewall_Plus_d5470.html)

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
*************************************************************
Use the Secunia Software Inspector (http://secunia.com/software_inspector) to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update (http://windowsupdate.microsoft.com/) and get all critical updates.

----------

I suggest using WOT - Web of Trust (http://www.mywot.com/). WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster (http://www.javacoolsoftware.com/spywareblaster.html)- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer (http://www.bleepingcomputer.com/forums/tutorial49.html) from Spyware and Malware
* If you don't know what ActiveX controls are, see here (http://www.webopedia.com/TERM/A/ActiveX_control.html)

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. (http://www.safer-networking.org/en/spybotsd/index.html) Guide: Use Spybot's Immunize Feature (http://www.bleepingcomputer.com/tutorials/tutorial43.html#immunize) to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ (http://www.safer-networking.org/en/faq/index.html)

Check out Keeping Yourself Safe On The Web  (http://evilfantasy.wordpress.com/2008/05/20/keeping-yourself-safe-on-the-web/) for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware (http://evilfantasy.wordpress.com/2008/05/24/slow-computer-it-may-not-be-malware/) for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
Title: Re: help with malware removal
Post by: smyers0013 on February 11, 2011, 08:22:13 PM
Thanks a million SuperDave!
Title: Re: help with malware removal
Post by: SuperDave on February 12, 2011, 11:56:06 AM
You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.