[code] OTScanIt2 logfile created on: 06.04.2009 09:48:53 - Run 1 OTScanIt2 by OldTimer - Version 1.0.12.0 Folder = C:\Documents and Settings\Ole\Skrivebord\OTScanIt2 Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000414 | Country: Norge | Language: NOR | Date Format: dd.MM.yyyy 1,50 Gb Total Physical Memory | 1,03 Gb Available Physical Memory | 68,70% Memory free 3,35 Gb Paging File | 2,72 Gb Available in Paging File | 81,24% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programfiler Drive C: | 68,94 Gb Total Space | 50,80 Gb Free Space | 73,69% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded Drive F: | 111,78 Gb Total Space | 95,04 Gb Free Space | 85,02% Space Free | Partition Type: NTFS Drive G: | 465,76 Gb Total Space | 360,70 Gb Free Space | 77,44% Space Free | Partition Type: NTFS H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: DATAROM Current User Name: Ole Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Whitelist: On File Age = 30 Days [Processes - Safe List] ati2evxx.exe -> %SystemRoot%\system32\Ati2evxx.exe -> [2007.09.14 15:55:02 | 00,483,328 | ---- | M] (ATI Technologies Inc.) ati2evxx.exe -> %SystemRoot%\system32\Ati2evxx.exe -> [2007.09.14 15:55:02 | 00,483,328 | ---- | M] (ATI Technologies Inc.) ccc.exe -> %ProgramFiles%\ATI Technologies\ATI.ACE\Core-Static\ccc.exe -> [2007.07.17 11:13:34 | 00,049,152 | ---- | M] (ATI Technologies Inc.) ccsvchst.exe -> %ProgramFiles%\Norton 360\Engine\3.0.0.135\ccSvcHst.exe -> [2009.03.18 18:05:21 | 00,115,560 | R--- | M] (Symantec Corporation) ccsvchst.exe -> %ProgramFiles%\Norton 360\Engine\3.0.0.135\ccSvcHst.exe -> [2009.03.18 18:05:21 | 00,115,560 | R--- | M] (Symantec Corporation) explorer.exe -> %SystemRoot%\Explorer.EXE -> [2008.04.14 18:22:49 | 01,033,728 | ---- | M] (Microsoft Corporation) hasplms.exe -> %SystemRoot%\system32\hasplms.exe -> [2007.03.15 14:48:26 | 00,535,807 | ---- | M] (Aladdin Knowledge Systems Ltd.) jqs.exe -> %ProgramFiles%\Java\jre6\bin\jqs.exe -> [2009.03.09 05:19:15 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) jusched.exe -> %ProgramFiles%\Java\jre6\bin\jusched.exe -> [2009.03.09 05:19:17 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) mdm.exe -> %CommonProgramFiles%\Microsoft Shared\VS7DEBUG\MDM.EXE -> [2003.06.19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) mdnsresponder.exe -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> [2008.08.29 10:18:44 | 00,238,888 | ---- | M] (Apple Inc.) mom.exe -> %ProgramFiles%\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE -> [2007.07.17 11:13:56 | 00,049,152 | ---- | M] (Advanced Micro Devices Inc.) otscanit2.exe -> %UserProfile%\Skrivebord\OTScanIt2\OTScanIt2.exe -> [2009.04.05 15:56:10 | 00,493,568 | ---- | M] (OldTimer Tools) [Win32 Services - Safe List] (Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Stopped] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008.11.07 15:28:16 | 00,132,424 | ---- | M] (Apple Inc.) (aspnet_state) Statustjeneste for ASP.NET [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2007.10.24 01:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) (Ati HotKey Poller) Ati HotKey Poller [Win32_Own | Auto | Running] -> %SystemRoot%\system32\Ati2evxx.exe -> [2007.09.14 15:55:02 | 00,483,328 | ---- | M] (ATI Technologies Inc.) (ATI Smart) ATI Smart [Win32_Own | Auto | Stopped] -> %SystemRoot%\system32\ati2sgag.exe -> [2007.09.14 21:05:00 | 00,593,920 | ---- | M] () (Bonjour Service) Bonjour-tjeneste [Win32_Own | Auto | Running] -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> [2008.08.29 10:18:44 | 00,238,888 | ---- | M] (Apple Inc.) (clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2007.10.24 01:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) (FontCache3.0.0.0) Windows Presentation Foundation Font Cache 3.0.0.0 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -> [2007.10.09 12:58:12 | 00,036,864 | ---- | M] (Microsoft Corporation) (hasplms) HASP License Manager [Win32_Own | Auto | Running] -> %SystemRoot%\system32\hasplms.exe -> [2007.03.15 14:48:26 | 00,535,807 | ---- | M] (Aladdin Knowledge Systems Ltd.) (helpsvc) Help and Support [Win32_Shared | Auto | Running] -> %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2008.04.14 18:22:17 | 00,038,400 | ---- | M] (Microsoft Corporation) (idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -> [2007.10.11 09:55:10 | 00,864,256 | ---- | M] (Microsoft Corporation) (iPod Service) iPod-tjeneste [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2008.11.20 14:20:44 | 00,536,872 | ---- | M] (Apple Inc.) (Irmon) Infrarød overvåking [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\irmon.dll -> [2008.04.14 18:22:04 | 00,028,160 | ---- | M] (Microsoft Corporation) (JavaQuickStarterService) Java Quick Starter [Win32_Own | Auto | Running] -> %ProgramFiles%\Java\jre6\bin\jqs.exe -> [2009.03.09 05:19:15 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) (MDM) Machine Debug Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Microsoft Shared\VS7DEBUG\MDM.EXE -> [2003.06.19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) (N360) Norton 360 [Win32_Own | Auto | Running] -> %ProgramFiles%\Norton 360\Engine\3.0.0.135\ccSvcHst.exe -> [2009.03.18 18:05:21 | 00,115,560 | R--- | M] (Symantec Corporation) (NetTcpPortSharing) Net.Tcp Port Sharing Service [Win32_Shared | Disabled | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -> [2007.10.11 09:55:14 | 00,122,880 | ---- | M] (Microsoft Corporation) (ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\Source Engine\OSE.EXE -> [2003.07.28 20:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) (ServiceLayer) ServiceLayer [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\PC Connectivity Solution\ServiceLayer.exe -> [2008.11.11 10:38:06 | 00,620,544 | ---- | M] (Nokia.) (usnjsvc) Messenger Sharing Folders USN Journal Reader-tjeneste [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Live\Messenger\usnsvc.exe -> [2007.10.18 11:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) (WLSetupSvc) Windows Live Setup Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Live\installer\WLSetupSvc.exe -> [2007.10.25 15:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) (WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Media Player\WMPNetwk.exe -> [2006.11.15 10:46:18 | 00,914,944 | ---- | M] (Microsoft Corporation) [Driver Services - Safe List] (26b68cb4) 26b68cb4 [Kernel | System | Stopped] -> %SystemRoot%\System32\drivers\26b68cb4.sys -> [2009.02.04 20:12:37 | 00,000,000 | ---- | M] () (aksfridge) aksfridge [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\aksfridge.sys -> [2007.03.12 20:48:56 | 00,351,744 | ---- | M] (Aladdin Knowledge Systems Ltd.) (ati2mtag) ati2mtag [Kernel | On_Demand | Running] -> %SystemRoot%\System32\DRIVERS\ati2mtag.sys -> [2007.09.14 16:04:46 | 02,455,040 | ---- | M] (ATI Technologies Inc.) (BHDrvx86) Symantec Heuristics Driver [Kernel | System | Running] -> %SystemRoot%\system32\drivers\N360\0300000.087\BHDrvx86.sys -> [2009.03.18 18:05:22 | 00,258,608 | ---- | M] (Symantec Corporation) (CamDrL) Logitech QuickCam Pro 3000(CamDrl) [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\DRIVERS\Camdrl.sys -> [2007.02.03 10:25:56 | 01,075,360 | ---- | M] (Logitech Inc.) (ccHP) Symantec Hash Provider [Kernel | System | Running] -> %SystemRoot%\system32\drivers\N360\0300000.087\ccHPx86.sys -> [2009.03.18 18:05:22 | 00,482,352 | ---- | M] (Symantec Corporation) (cvspydr2) ColorVision Spyder 2 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\cvspydr2.sys -> [2002.04.02 17:30:16 | 00,033,024 | ---- | M] (Colorvision Inc) (dmxfire) DMX6fire WDM Audio [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\dmx6fire.sys -> [2003.08.29 09:30:16 | 00,148,724 | ---- | M] (Terratec Electronic GmbH) (dmxsens) dmxsens [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\dmxsens.sys -> [2003.07.22 14:07:50 | 00,403,968 | ---- | M] (Sensaura Ltd) (E1000) Intel(R) PRO/1000 Adapter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\System32\DRIVERS\e1000325.sys -> [2004.06.22 14:18:46 | 00,169,984 | ---- | M] (Intel Corporation) (eeCtrl) Symantec Eraser Control driver [Kernel | System | Running] -> %CommonProgramFiles%\Symantec Shared\EENGINE\eeCtrl.sys -> [2009.03.18 18:05:22 | 00,371,248 | ---- | M] (Symantec Corporation) (EraserUtilRebootDrv) EraserUtilRebootDrv [Kernel | On_Demand | Running] -> %CommonProgramFiles%\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -> [2009.03.18 18:05:22 | 00,101,936 | ---- | M] (Symantec Corporation) (GEARAspiWDM) GEAR ASPI Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\GEARAspiWDM.sys -> [2009.01.15 13:19:36 | 00,023,848 | ---- | M] (GEAR Software Inc.) (Hardlock) Hardlock [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\hardlock.sys -> [2007.03.06 21:39:20 | 00,694,272 | ---- | M] (Aladdin Knowledge Systems Ltd.) (IDSxpx86) IDSxpx86 [Kernel | System | Running] -> %AllUsersProfile%\Programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090331.007\IDSxpx86.sys -> [2009.03.18 18:05:22 | 00,276,344 | ---- | M] (Symantec Corporation) (iTurns) iTurns [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\iTurnsDriver.sys -> [2008.09.16 15:03:40 | 00,005,632 | ---- | M] (DVD neXt COPY) (LVUSBSta) Logitech USB Monitor Filter [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\LVUSBSta.sys -> [2007.02.03 10:32:36 | 00,041,504 | ---- | M] (Logitech Inc.) (NAVENG) NAVENG [Kernel | On_Demand | Running] -> %AllUsersProfile%\Programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090405.020\NAVENG.SYS -> [2009.03.18 18:05:22 | 00,089,104 | ---- | M] (Symantec Corporation) (NAVEX15) NAVEX15 [Kernel | On_Demand | Running] -> %AllUsersProfile%\Programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090405.020\NAVEX15.SYS -> [2009.03.18 18:05:22 | 00,876,144 | ---- | M] (Symantec Corporation) (nmwcdnsu) Nokia USB Flashing Phone Parent [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\nmwcdnsu.sys -> [2008.02.01 16:17:12 | 00,138,112 | ---- | M] (Nokia) (nmwcdnsuc) Nokia USB Flashing Generic [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\nmwcdnsuc.sys -> [2008.02.01 16:17:06 | 00,008,320 | ---- | M] (Nokia) (pavboot) pavboot [File_System | Boot | Running] -> %SystemRoot%\system32\drivers\pavboot.sys -> [2008.06.19 16:24:30 | 00,028,544 | ---- | M] (Panda Security, S.L.) (pccsmcfd) PCCS Mode Change Filter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\pccsmcfd.sys -> [2008.08.26 10:26:12 | 00,018,816 | ---- | M] (Nokia) (PolarUSB) Polar USB Interface [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\PolarUSB.sys -> [2001.07.12 15:49:44 | 00,017,343 | ---- | M] (Polar Electro) (Ptilink) Direkte parallell koblingsdriver [Kernel | On_Demand | Running] -> %SystemRoot%\System32\DRIVERS\ptilink.sys -> [2003.04.25 14:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) (PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\System32\Drivers\PxHelp20.sys -> [2008.07.09 05:05:48 | 00,043,872 | ---- | M] (Sonic Solutions) (Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\DRIVERS\secdrv.sys -> [2008.04.13 18:39:16 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) (si3114r) SiI-3114 SATARaid Controller [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\si3114r.sys -> [2007.10.04 20:27:24 | 00,116,776 | ---- | M] (Silicon Image, Inc) (SiFilter) SATALink driver accelerator [Kernel | Boot | Running] -> %SystemRoot%\System32\DRIVERS\SiWinAcc.sys -> [2007.10.04 20:27:26 | 00,019,240 | ---- | M] (Silicon Image, Inc) (SiWinAcc) SiWinAcc [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\SiWinAcc.sys -> [2007.10.04 20:27:26 | 00,019,240 | ---- | M] (Silicon Image, Inc) (sptd) sptd [Kernel | Boot | Running] -> %SystemRoot%\System32\Drivers\sptd.sys -> [2008.10.04 20:10:42 | 00,717,296 | ---- | M] () (SRTSP) Symantec Real Time Storage Protection [File_System | On_Demand | Running] -> %SystemRoot%\system32\drivers\N360\0300000.087\SRTSP.SYS -> [2009.03.18 18:05:22 | 00,307,760 | ---- | M] (Symantec Corporation) (SRTSPX) Symantec Real Time Storage Protection (PEL) [Kernel | System | Running] -> %SystemRoot%\system32\drivers\N360\0300000.087\SRTSPX.SYS -> [2009.03.18 18:05:22 | 00,043,696 | ---- | M] (Symantec Corporation) (stusb2ir) USB 2.0 IrDA Bridge [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\stusb2ir.sys -> [2006.09.22 11:09:12 | 00,040,856 | R--- | M] (SigmaTel, Inc.) (SymEFA) Symantec Extended File Attributes [File_System | Boot | Running] -> %SystemRoot%\system32\drivers\N360\0300000.087\SYMEFA.SYS -> [2009.03.18 18:05:22 | 00,310,320 | ---- | M] (Symantec Corporation) (SymEvent) SymEvent [Kernel | On_Demand | Running] -> %SystemRoot%\system32\Drivers\SYMEVENT.SYS -> [2009.03.18 18:05:28 | 00,124,464 | ---- | M] (Symantec Corporation) (SYMFW) Symantec Network Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\N360\0300000.087\SYMFW.SYS -> [2009.03.18 18:05:22 | 00,089,776 | ---- | M] (Symantec Corporation) (SYMIDS) Symantec Network Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\N360\0300000.087\SYMIDS.SYS -> [2009.03.18 18:05:22 | 00,034,736 | ---- | M] (Symantec Corporation) (SymIM) Symantec Network Security Intermediate Filter Service [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\SymIM.sys -> [2009.03.18 18:05:22 | 00,036,400 | R--- | M] (Symantec Corporation) (SymIMMP) SymIMMP [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\SymIM.sys -> [2009.03.18 18:05:22 | 00,036,400 | R--- | M] (Symantec Corporation) (SYMNDIS) Symantec Network Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\N360\0300000.087\SYMNDIS.SYS -> [2009.03.18 18:05:22 | 00,037,296 | ---- | M] (Symantec Corporation) (SYMTDI) Symantec Network Dispatch Driver [Kernel | System | Running] -> %SystemRoot%\system32\drivers\N360\0300000.087\SYMTDI.SYS -> [2009.03.18 18:05:22 | 00,217,392 | ---- | M] (Symantec Corporation) (USBAAPL) Apple Mobile USB Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\Drivers\usbaapl.sys -> [2008.10.01 13:01:28 | 00,032,000 | ---- | M] (Apple, Inc.) (usbaudio) USB-lyddriver (WDM) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\usbaudio.sys -> [2008.04.13 20:45:12 | 00,060,032 | ---- | M] (Microsoft Corporation) (WIBUKEY) WIBU-KEY Kernel Driver [Kernel | Auto | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\WibuKey.sys -> [2008.07.18 12:00:00 | 00,072,704 | ---- | M] (WIBU-SYSTEMS AG) (wimfltr) wimfltr [File_System | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\wimfltr.sys -> [2008.01.19 00:43:20 | 00,131,000 | ---- | M] (Microsoft Corporation) [Registry - Safe List] < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> Reg Error: Invalid data type. -> HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons -> HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm -> HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk -> HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> < Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> HKEY_USERS\S-1-5-19\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> HKEY_USERS\S-1-5-20\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\] > -> -> HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm -> HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\: Main\\"Start Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome -> HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\: "ProxyEnable" -> 0 -> HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\: "ProxyOverride" -> *.local -> < FireFox Settings [Prefs.js] > -> C:\Documents and Settings\Ole\Programdata\Mozilla\FireFox\Profiles\y5uimci6.default\prefs.js -> browser.startup.homepage -> "http://www.dinside.no" -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10 -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11 -> extensions.enabledItems -> {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13 -> extensions.enabledItems -> [removed]:1.0 -> extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8 -> < FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla HKLM\software\mozilla\Firefox\extensions -> -> HKLM\software\mozilla\Firefox\extensions\\[removed] -> %ProgramFiles%\NOKIA\NOKIA PC SUITE 7\BKMRKSYNC [C:\PROGRAMFILER\NOKIA\NOKIA PC SUITE 7\BKMRKSYNC\] -> [2009.01.16 19:30:21 | 00,000,000 | ---D | M] HKLM\software\mozilla\Firefox\extensions\\[removed] -> %ProgramFiles%\JAVA\JRE6\LIB\DEPLOY\JQS\FF [C:\PROGRAMFILER\JAVA\JRE6\LIB\DEPLOY\JQS\FF] -> [2008.11.24 17:11:16 | 00,000,000 | ---D | M] HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions -> -> HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components -> %ProgramFiles%\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAMFILER\MOZILLA FIREFOX\COMPONENTS] -> [2009.03.29 21:32:12 | 00,000,000 | ---D | M] HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins -> %ProgramFiles%\MOZILLA FIREFOX\PLUGINS [C:\PROGRAMFILER\MOZILLA FIREFOX\PLUGINS] -> [2009.03.29 21:32:12 | 00,000,000 | ---D | M] < FireFox Extensions [User Folders] > -> -> C:\Documents and Settings\Ole\Programdata\mozilla\Extensions -> [2008.10.04 09:53:04 | 00,000,000 | ---D | M] -> C:\Documents and Settings\Ole\Programdata\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} -> [2008.10.04 09:53:04 | 00,000,000 | ---D | M] -> C:\Documents and Settings\Ole\Programdata\mozilla\Firefox\Profiles\y5uimci6.default\extensions -> [2009.04.02 21:42:03 | 00,096,267 | ---- | M] () < FireFox Extensions [Program Folders] > -> -> C:\PROGRAMFILER\MOZILLA FIREFOX\extensions -> [2009.03.29 21:32:12 | 09,732,600 | ---- | M] (Mozilla Foundation) -> C:\PROGRAMFILER\MOZILLA FIREFOX\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} -> [2009.03.29 21:32:12 | 09,732,600 | ---- | M] (Mozilla Foundation) -> C:\PROGRAMFILER\MOZILLA FIREFOX\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} -> [2009.03.29 21:32:12 | 09,732,600 | ---- | M] (Mozilla Foundation) -> C:\PROGRAMFILER\MOZILLA FIREFOX\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} -> [2009.03.29 21:32:12 | 09,732,600 | ---- | M] (Mozilla Foundation) -> C:\PROGRAMFILER\MOZILLA FIREFOX\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} -> [2009.03.29 21:32:12 | 09,732,600 | ---- | M] (Mozilla Foundation) < FireFox Components [Program Folders] > -> C:\PROGRAMFILER\MOZILLA FIREFOX\components\ -> C:\PROGRAMFILER\MOZILLA FIREFOX\components -> [2009.03.29 21:32:12 | 00,000,000 | ---D | M] browserdirprovider.dll -> C:\PROGRAMFILER\MOZILLA FIREFOX\components\browserdirprovider.dll -> [2009.03.29 21:32:10 | 00,023,032 | ---- | M] (Mozilla Foundation) brwsrcmp.dll -> C:\PROGRAMFILER\MOZILLA FIREFOX\components\brwsrcmp.dll -> [2009.03.29 21:32:10 | 00,134,648 | ---- | M] (Mozilla Foundation) < FireFox Plugins [Program Folders] > -> C:\PROGRAMFILER\MOZILLA FIREFOX\plugins\ -> C:\PROGRAMFILER\MOZILLA FIREFOX\plugins -> [2009.03.29 21:32:12 | 00,000,000 | ---D | M] np32dsw.dll -> C:\PROGRAMFILER\MOZILLA FIREFOX\plugins\np32dsw.dll -> [2008.11.24 15:35:00 | 00,114,688 | ---- | M] (Adobe Systems, Inc.) npdeploytk.dll -> C:\PROGRAMFILER\MOZILLA FIREFOX\plugins\npdeploytk.dll -> [2009.03.09 05:19:09 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) npnul32.dll -> C:\PROGRAMFILER\MOZILLA FIREFOX\plugins\npnul32.dll -> [2009.03.29 21:32:10 | 00,065,528 | ---- | M] (mozilla.org) nppdf32.dll -> C:\PROGRAMFILER\MOZILLA FIREFOX\plugins\nppdf32.dll -> [2009.02.27 13:13:42 | 00,103,792 | ---- | M] (Adobe Systems Inc.) npqtplugin.dll -> C:\PROGRAMFILER\MOZILLA FIREFOX\plugins\npqtplugin.dll -> [2008.11.21 21:16:03 | 00,143,360 | ---- | M] (Apple Inc.) npqtplugin2.dll -> C:\PROGRAMFILER\MOZILLA FIREFOX\plugins\npqtplugin2.dll -> [2008.11.21 21:16:04 | 00,143,360 | ---- | M] (Apple Inc.) npqtplugin3.dll -> C:\PROGRAMFILER\MOZILLA FIREFOX\plugins\npqtplugin3.dll -> [2008.11.21 21:16:04 | 00,143,360 | ---- | M] (Apple Inc.) npqtplugin4.dll -> C:\PROGRAMFILER\MOZILLA FIREFOX\plugins\npqtplugin4.dll -> [2008.11.21 21:16:04 | 00,143,360 | ---- | M] (Apple Inc.) npqtplugin5.dll -> C:\PROGRAMFILER\MOZILLA FIREFOX\plugins\npqtplugin5.dll -> [2008.11.21 21:16:04 | 00,143,360 | ---- | M] (Apple Inc.) npqtplugin6.dll -> C:\PROGRAMFILER\MOZILLA FIREFOX\plugins\npqtplugin6.dll -> [2008.11.21 21:16:04 | 00,143,360 | ---- | M] (Apple Inc.) npqtplugin7.dll -> C:\PROGRAMFILER\MOZILLA FIREFOX\plugins\npqtplugin7.dll -> [2008.11.21 21:16:04 | 00,143,360 | ---- | M] (Apple Inc.) QuickTimePlugin.class -> C:\PROGRAMFILER\MOZILLA FIREFOX\plugins\QuickTimePlugin.cla -> [2008.11.21 21:16:03 | 00,004,208 | ---- | M] () ShockwavePlugin.class -> C:\PROGRAMFILER\MOZILLA FIREFOX\plugins\ShockwavePlugin.cla -> [2008.11.24 15:05:16 | 00,001,144 | ---- | M] () < FireFox SearchPlugins [Program Folders] > -> C:\PROGRAMFILER\MOZILLA FIREFOX\searchplugins\ -> C:\PROGRAMFILER\MOZILLA FIREFOX\searchplugins -> [2009.03.25 08:34:11 | 00,000,000 | ---D | M] amazon-en-GB.xml -> C:\PROGRAMFILER\MOZILLA FIREFOX\searchplugins\amazon-en-GB.xml -> [2009.03.25 08:34:05 | 00,001,525 | ---- | M] () bok-NO.xml -> C:\PROGRAMFILER\MOZILLA FIREFOX\searchplugins\bok-NO.xml -> [2009.03.25 08:34:05 | 00,000,955 | ---- | M] () google.xml -> C:\PROGRAMFILER\MOZILLA FIREFOX\searchplugins\google.xml -> [2009.03.25 08:34:05 | 00,001,706 | ---- | M] () qxl-NO.xml -> C:\PROGRAMFILER\MOZILLA FIREFOX\searchplugins\qxl-NO.xml -> [2009.03.25 08:34:05 | 00,000,968 | ---- | M] () telefonkatalogen-NO.xml -> C:\PROGRAMFILER\MOZILLA FIREFOX\searchplugins\telefonkatalogen-NO.xml -> [2009.03.25 08:34:05 | 00,001,203 | ---- | M] () wikipedia-NO.xml -> C:\PROGRAMFILER\MOZILLA FIREFOX\searchplugins\wikipedia-NO.xml -> [2009.03.25 08:34:05 | 00,001,176 | ---- | M] () yahoo-NO.xml -> C:\PROGRAMFILER\MOZILLA FIREFOX\searchplugins\yahoo-NO.xml -> [2009.03.25 08:34:05 | 00,000,888 | ---- | M] () < HOSTS File > (686 bytes and 19 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts -> Reset Hosts 127.0.0.1 localhost < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} [HKLM] -> %CommonProgramFiles%\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [Adobe PDF Link Helper] -> [2009.02.27 13:07:26 | 00,075,128 | ---- | M] (Adobe Systems Incorporated) {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} [HKLM] -> %ProgramFiles%\Norton 360\Engine\3.0.0.135\coIEPlg.dll [Symantec NCO BHO] -> [2009.03.18 18:05:16 | 00,372,592 | R--- | M] (Symantec Corporation) {6D53EC84-6AAE-4787-AEEE-F4628F01010C} [HKLM] -> %ProgramFiles%\Norton 360\Engine\3.0.0.135\IPSBHO.DLL [Symantec Intrusion Prevention] -> [2009.03.18 18:05:18 | 00,107,896 | R--- | M] (Symantec Corporation) {9030D464-4C02-4ABF-8ECC-5164760863C6} [HKLM] -> %CommonProgramFiles%\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [Påloggingshjelp for Windows Live] -> [2009.02.17 17:11:04 | 00,408,440 | ---- | M] (Microsoft Corporation) {DBC80044-A445-435b-BC74-9C25C1C588A9} [HKLM] -> %ProgramFiles%\Java\jre6\bin\jp2ssv.dll [Java(tm) Plug-In 2 SSV Helper] -> [2009.03.09 05:18:50 | 00,035,840 | ---- | M] (Sun Microsystems, Inc.) {E7E6F031-17CE-4C07-BC86-EABFE594F69C} [HKLM] -> %ProgramFiles%\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [JQSIEStartDetectorImpl Class] -> [2009.03.09 05:18:52 | 00,073,728 | ---- | M] (Sun Microsystems, Inc.) < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> "{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" [HKLM] -> %ProgramFiles%\Norton 360\Engine\3.0.0.135\coIEPlg.dll [Norton Toolbar] -> [2009.03.18 18:05:16 | 00,372,592 | R--- | M] (Symantec Corporation) < Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\] > -> HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\Software\Microsoft\Internet Explorer\Toolbar\ -> WebBrowser\\"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" [HKLM] -> %ProgramFiles%\Norton 360\Engine\3.0.0.135\coIEPlg.dll [Norton Toolbar] -> [2009.03.18 18:05:16 | 00,372,592 | R--- | M] (Symantec Corporation) < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "Adobe Reader Speed Launcher" -> %ProgramFiles%\Adobe\Reader 9.0\Reader\Reader_sl.exe ["C:\Programfiler\Adobe\Reader 9.0\Reader\Reader_sl.exe"] -> [2009.02.27 18:10:28 | 00,035,696 | ---- | M] (Adobe Systems Incorporated) "StartCCC" -> %ProgramFiles%\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ["C:\Programfiler\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"] -> [2006.11.10 12:35:24 | 00,090,112 | ---- | M] () "SunJavaUpdateSched" -> %ProgramFiles%\Java\jre6\bin\jusched.exe ["C:\Programfiler\Java\jre6\bin\jusched.exe"] -> [2009.03.09 05:19:17 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) < RunOnce [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce -> "WUAppSetup" -> %CommonProgramFiles%\logishrd\WUApp32.exe -v 0x046d -p 0x08b5 -f video -m logitech -d 10.5.1.2023 [C:\Programfiler\Fellesfiler\logishrd\WUApp32.exe -v 0x046d -p 0x08b5 -f video -m logitech -d 10.5.1.2023] -> File not found < RunOnce [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce -> "WUAppSetup" -> %CommonProgramFiles%\logishrd\WUApp32.exe -v 0x046d -p 0x08b5 -f video -m logitech -d 10.5.1.2023 [C:\Programfiler\Fellesfiler\logishrd\WUApp32.exe -v 0x046d -p 0x08b5 -f video -m logitech -d 10.5.1.2023] -> File not found < Run [HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\] > -> HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "MsnMsgr" -> %ProgramFiles%\Windows Live\Messenger\MsnMsgr.Exe ["C:\Programfiler\Windows Live\Messenger\MsnMsgr.Exe" /background] -> [2007.10.18 11:34:28 | 05,724,184 | ---- | M] (Microsoft Corporation) < All Users Startup Folder > -> C:\Documents and Settings\All Users\Start-meny\Programmer\Oppstart -> %AllUsersProfile%\Start-meny\Programmer\Oppstart\ColorVisionStartup.lnk -> %ProgramFiles%\ColorVision\Utility\ColorVisionStartup.exe -> [2006.01.31 18:48:52 | 00,385,024 | ---- | M] (ColorVision Inc.) %AllUsersProfile%\Start-meny\Programmer\Oppstart\DMX 6fire 2496 ControlPanel.lnk -> %ProgramFiles%\TerraTec\DMX 6fire\DMX6Fire.exe -> [2003.08.29 09:30:28 | 00,335,872 | ---- | M] (TerraTec Electronic GmbH) < Default User Startup Folder > -> C:\Documents and Settings\Default User\Start-meny\Programmer\Oppstart -> < Ole Startup Folder > -> C:\Documents and Settings\Ole\Start-meny\Programmer\Oppstart -> < Software Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer -> < Software Policy Settings [HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003] > -> HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\SOFTWARE\Policies\Microsoft\Internet Explorer -> < CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"HonorAutoRunSetting" -> [1] -> File not found < CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System \\"dontdisplaylastusername" -> [0] -> File not found \\"legalnoticecaption" -> [] -> File not found \\"legalnoticetext" -> [] -> File not found \\"shutdownwithoutlogon" -> [1] -> File not found \\"undockwithoutlogon" -> [1] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [91 00 00 00 [binary data]] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [91 00 00 00 [binary data]] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [145] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [145] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003] > -> HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003] > -> HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> < Internet Explorer Menu Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\MenuExt\ -> E&ksporter til Microsoft Excel -> %ProgramFiles%\Microsoft Office\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000] -> [2008.10.13 12:29:28 | 10,351,944 | ---- | M] (Microsoft Corporation) < Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\MenuExt\ -> E&ksporter til Microsoft Excel -> %ProgramFiles%\Microsoft Office\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000] -> [2008.10.13 12:29:28 | 10,351,944 | ---- | M] (Microsoft Corporation) < Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\] > -> HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\Software\Microsoft\Internet Explorer\MenuExt\ -> E&ksporter til Microsoft Excel -> %ProgramFiles%\Microsoft Office\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000] -> [2008.10.13 12:29:28 | 10,351,944 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Button: Oppslag] -> [2007.04.19 14:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation) {e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> %SystemRoot%\Network Diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2008.04.13 20:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Button: Messenger] -> [2008.04.14 18:23:00 | 01,695,232 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2008.04.14 18:23:00 | 01,695,232 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{e2e2dd38-d088-4134-82b7-f2ba38496583}" [HKLM] -> %SystemRoot%\Network Diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008.04.13 20:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008.04.14 18:23:00 | 01,695,232 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{e2e2dd38-d088-4134-82b7-f2ba38496583}" [HKLM] -> %SystemRoot%\Network Diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008.04.13 20:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008.04.14 18:23:00 | 01,695,232 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\] > -> HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Oppslag] -> [2007.04.19 14:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation) CmdMapping\\"{e2e2dd38-d088-4134-82b7-f2ba38496583}" [HKLM] -> %SystemRoot%\Network Diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008.04.13 20:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008.04.14 18:23:00 | 01,695,232 | ---- | M] (Microsoft Corporation) < Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> < Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix "" -> http:// < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 1 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\] > -> HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\] > -> HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-21-343818398-1647877149-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} [HKLM] -> http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1222703448984 [MUWebControl Class] -> {8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab [Java Plug-in 1.6.0_13] -> {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} [HKLM] -> http://support.f-secure.com/ols/fscax.cab [F-Secure Online Scanner 3.3] -> {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab [Java Plug-in 1.6.0_13] -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab [Java Plug-in 1.6.0_13] -> < DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {ABD9E0D4-CFBF-451E-ACD8-A26ED0071AF6} -> (1394-nettverkskort) -> {C6A48251-3F06-404F-894D-8F129F2D9430} -> (Intel(R) PRO/1000 CT Network Connection) -> {EF62D353-A5EF-45AD-ADE7-ACBA501340C6} -> () -> < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> *Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> Explorer.exe -> %SystemRoot%\Explorer.exe -> [2008.04.14 18:22:49 | 01,033,728 | ---- | M] (Microsoft Corporation) *MultiFile Done* -> -> < Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> AtiExtEvent -> %SystemRoot%\system32\Ati2evxx.dll -> [2007.09.14 15:56:22 | 00,122,880 | ---- | M] (ATI Technologies Inc.) < Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List -> "%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008.04.13 20:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) "%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008.04.14 18:23:10 | 00,140,800 | ---- | M] (Microsoft Corporation) "C:\Programfiler\Windows Live\Messenger\livecall.exe" -> C:\Programfiler\Windows Live\Messenger\livecall.exe [C:\Programfiler\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)] -> [2007.10.02 17:18:24 | 00,304,488 | ---- | M] (Microsoft Corporation) "C:\Programfiler\Windows Live\Messenger\msnmsgr.exe" -> C:\Programfiler\Windows Live\Messenger\msnmsgr.exe [C:\Programfiler\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger] -> [2007.10.18 11:34:28 | 05,724,184 | ---- | M] (Microsoft Corporation) < Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> "%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008.04.13 20:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) "%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008.04.14 18:23:10 | 00,140,800 | ---- | M] (Microsoft Corporation) "C:\Programfiler\Bonjour\mDNSResponder.exe" -> C:\Programfiler\Bonjour\mDNSResponder.exe [C:\Programfiler\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour] -> [2008.08.29 10:18:44 | 00,238,888 | ---- | M] (Apple Inc.) "C:\Programfiler\iTunes\iTunes.exe" -> C:\Programfiler\iTunes\iTunes.exe [C:\Programfiler\iTunes\iTunes.exe:*:Enabled:iTunes] -> [2008.11.20 14:20:48 | 14,294,824 | ---- | M] (Apple Inc.) "C:\Programfiler\TwonkyMedia\TwonkyMedia.exe" -> C:\Programfiler\TwonkyMedia\TwonkyMedia.exe [C:\Programfiler\TwonkyMedia\TwonkyMedia.exe:*:Enabled:TwonkyMedia] -> [2008.10.02 14:15:28 | 00,106,496 | ---- | M] (PacketVideo) "C:\Programfiler\TwonkyMedia\TwonkyMediaServer.exe" -> C:\Programfiler\TwonkyMedia\TwonkyMediaServer.exe [C:\Programfiler\TwonkyMedia\TwonkyMediaServer.exe:*:Enabled:TwonkyMediaServer] -> [2008.10.02 14:16:22 | 00,446,464 | ---- | M] () "C:\Programfiler\Vuze\Azureus.exe" -> C:\Programfiler\Vuze\Azureus.exe [C:\Programfiler\Vuze\Azureus.exe:*:Enabled:Azureus] -> File not found "C:\Programfiler\Windows Live\Messenger\livecall.exe" -> C:\Programfiler\Windows Live\Messenger\livecall.exe [C:\Programfiler\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)] -> [2007.10.02 17:18:24 | 00,304,488 | ---- | M] (Microsoft Corporation) "C:\Programfiler\Windows Live\Messenger\msnmsgr.exe" -> C:\Programfiler\Windows Live\Messenger\msnmsgr.exe [C:\Programfiler\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger] -> [2007.10.18 11:34:28 | 05,724,184 | ---- | M] (Microsoft Corporation) < SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> "AlternateShell" -> cmd.exe -> < CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom -> "AutoRun" -> 1 -> "DisplayName" -> CD-ROM-driver -> "ImagePath" -> %SystemRoot%\System32\DRIVERS\cdrom.sys [System32\DRIVERS\cdrom.sys] -> [2008.04.13 20:40:46 | 00,062,976 | ---- | M] (Microsoft Corporation) < Drives with AutoRun files > -> -> C:\AUTOEXEC.BAT [] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ] -> [2008.09.29 16:51:01 | 00,000,000 | ---- | M] () F:\AutoPlay Menu Builder 4.2.zip [PK | ] -> F:\AutoPlay Menu Builder 4.2.zip [ NTFS ] -> [2005.04.30 10:04:06 | 02,008,422 | ---- | M] () < MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> \{5b610186-e3f3-11dd-8a55-00508df3c34d} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5b610186-e3f3-11dd-8a55-00508df3c34d}\shell\autorun\command \{5b610186-e3f3-11dd-8a55-00508df3c34d}\shell\autorun\command\\"" -> J:\StartCD.exe [J:\StartCD.exe] -> File not found [Files/Folders - Created Within 30 Days] 4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> OTScanIt2 -> %UserProfile%\Skrivebord\OTScanIt2 -> [2009.04.06 09:46:40 | 00,000,000 | ---D | C] OTScanIt2.exe -> %UserProfile%\Skrivebord\OTScanIt2.exe -> [2009.04.06 09:44:31 | 00,664,709 | ---- | C] () _OTMoveIt -> %SystemDrive%\_OTMoveIt -> [2009.04.02 21:35:57 | 00,000,000 | ---D | C] OTMoveIt3.exe -> %UserProfile%\Skrivebord\OTMoveIt3.exe -> [2009.04.02 21:34:25 | 00,389,632 | ---- | C] (OldTimer Tools) Malwarebytes -> %AppData%\Malwarebytes -> [2009.04.02 16:32:37 | 00,000,000 | ---D | C] 20090401-003-v5i32.exe -> %UserProfile%\Skrivebord\20090401-003-v5i32.exe -> [2009.04.01 23:48:29 | 39,603,232 | ---- | C] () rsit -> %SystemDrive%\rsit -> [2009.04.01 23:38:46 | 00,000,000 | ---D | C] RSIT.exe -> %UserProfile%\Skrivebord\RSIT.exe -> [2009.04.01 23:38:14 | 00,781,909 | ---- | C] () user32.dll -> %SystemRoot%\System32\dllcache\user32.dll -> [2009.04.01 22:26:53 | 00,578,560 | ---- | C] (Microsoft Corporation) ERUNT -> %SystemRoot%\ERUNT -> [2009.04.01 22:20:21 | 00,000,000 | ---D | C] SDFix -> %SystemDrive%\SDFix -> [2009.04.01 21:45:21 | 00,000,000 | ---D | C] SDFix.exe -> %UserProfile%\Skrivebord\SDFix.exe -> [2009.04.01 21:38:30 | 01,529,241 | ---- | C] () ComboFix.exe -> %UserProfile%\Skrivebord\ComboFix.exe -> [2009.04.01 17:10:36 | 03,062,142 | ---- | C] () CF17185.exe -> %SystemRoot%\System32\CF17185.exe -> [2009.03.31 21:05:39 | 00,388,608 | ---- | C] (Microsoft Corporation) Qoobox -> %SystemDrive%\Qoobox -> [2009.03.31 21:05:31 | 00,000,000 | ---D | C] pavboot.sys -> %SystemRoot%\System32\drivers\pavboot.sys -> [2009.03.31 15:52:30 | 00,028,544 | ---- | C] (Panda Security, S.L.) Panda Security -> %ProgramFiles%\Panda Security -> [2009.03.31 15:51:57 | 00,000,000 | ---D | C] HijackThis.lnk -> %UserProfile%\Skrivebord\HijackThis.lnk -> [2009.03.24 14:31:50 | 00,001,725 | ---- | C] () Adobe Reader 9.lnk -> %AllUsersProfile%\Skrivebord\Adobe Reader 9.lnk -> [2009.03.24 11:33:44 | 00,001,724 | ---- | C] () sqmdata16.sqm -> %SystemDrive%\sqmdata16.sqm -> [2009.03.24 10:52:56 | 00,000,268 | -H-- | C] () sqmnoopt16.sqm -> %SystemDrive%\sqmnoopt16.sqm -> [2009.03.24 10:52:56 | 00,000,244 | -H-- | C] () sqmdata15.sqm -> %SystemDrive%\sqmdata15.sqm -> [2009.03.24 10:50:09 | 00,000,268 | -H-- | C] () sqmnoopt15.sqm -> %SystemDrive%\sqmnoopt15.sqm -> [2009.03.24 10:50:09 | 00,000,244 | -H-- | C] () sqmdata14.sqm -> %SystemDrive%\sqmdata14.sqm -> [2009.03.24 10:44:22 | 00,000,268 | -H-- | C] () sqmnoopt14.sqm -> %SystemDrive%\sqmnoopt14.sqm -> [2009.03.24 10:44:22 | 00,000,244 | -H-- | C] () GetRightToGo -> %AppData%\GetRightToGo -> [2009.03.23 22:06:40 | 00,000,000 | ---D | C] sqmdata13.sqm -> %SystemDrive%\sqmdata13.sqm -> [2009.03.23 21:13:44 | 00,000,268 | -H-- | C] () sqmnoopt13.sqm -> %SystemDrive%\sqmnoopt13.sqm -> [2009.03.23 21:13:44 | 00,000,244 | -H-- | C] () fsaua.data -> %SystemDrive%\fsaua.data -> [2009.03.23 17:58:28 | 00,000,000 | ---D | C] sqmdata12.sqm -> %SystemDrive%\sqmdata12.sqm -> [2009.03.23 17:51:05 | 00,000,268 | -H-- | C] () sqmnoopt12.sqm -> %SystemDrive%\sqmnoopt12.sqm -> [2009.03.23 17:51:05 | 00,000,244 | -H-- | C] () sqmdata11.sqm -> %SystemDrive%\sqmdata11.sqm -> [2009.03.23 00:14:04 | 00,000,268 | -H-- | C] () sqmnoopt11.sqm -> %SystemDrive%\sqmnoopt11.sqm -> [2009.03.23 00:14:04 | 00,000,244 | -H-- | C] () sqmdata10.sqm -> %SystemDrive%\sqmdata10.sqm -> [2009.03.22 22:49:32 | 00,000,268 | -H-- | C] () sqmnoopt10.sqm -> %SystemDrive%\sqmnoopt10.sqm -> [2009.03.22 22:49:32 | 00,000,244 | -H-- | C] () mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2009.03.22 22:45:37 | 00,015,504 | ---- | C] (Malwarebytes Corporation) Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Skrivebord\Malwarebytes' Anti-Malware.lnk -> [2009.03.22 22:45:37 | 00,000,691 | ---- | C] () mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2009.03.22 22:45:35 | 00,038,496 | ---- | C] (Malwarebytes Corporation) Malwarebytes' Anti-Malware -> %ProgramFiles%\Malwarebytes' Anti-Malware -> [2009.03.22 22:45:34 | 00,000,000 | ---D | C] Malwarebytes -> %AllUsersProfile%\Programdata\Malwarebytes -> [2009.03.22 22:45:34 | 00,000,000 | ---D | C] sqmdata09.sqm -> %SystemDrive%\sqmdata09.sqm -> [2009.03.19 07:29:24 | 00,000,268 | -H-- | C] () sqmnoopt09.sqm -> %SystemDrive%\sqmnoopt09.sqm -> [2009.03.19 07:29:24 | 00,000,244 | -H-- | C] () N360_BACKUP -> %SystemRoot%\System32\N360_BACKUP -> [2009.03.18 23:27:53 | 00,000,000 | ---D | C] sqmdata08.sqm -> %SystemDrive%\sqmdata08.sqm -> [2009.03.18 23:16:14 | 00,000,268 | -H-- | C] () sqmnoopt08.sqm -> %SystemDrive%\sqmnoopt08.sqm -> [2009.03.18 23:16:14 | 00,000,244 | -H-- | C] () sqmdata07.sqm -> %SystemDrive%\sqmdata07.sqm -> [2009.03.18 22:36:03 | 00,000,268 | -H-- | C] () sqmnoopt07.sqm -> %SystemDrive%\sqmnoopt07.sqm -> [2009.03.18 22:36:03 | 00,000,244 | -H-- | C] () pss -> %SystemRoot%\pss -> [2009.03.18 22:34:57 | 00,000,000 | ---D | C] sqmdata06.sqm -> %SystemDrive%\sqmdata06.sqm -> [2009.03.18 22:23:24 | 00,000,268 | -H-- | C] () sqmnoopt06.sqm -> %SystemDrive%\sqmnoopt06.sqm -> [2009.03.18 22:23:24 | 00,000,244 | -H-- | C] () sqmdata05.sqm -> %SystemDrive%\sqmdata05.sqm -> [2009.03.18 22:15:30 | 00,000,268 | -H-- | C] () sqmnoopt05.sqm -> %SystemDrive%\sqmnoopt05.sqm -> [2009.03.18 22:15:30 | 00,000,244 | -H-- | C] () sqmdata04.sqm -> %SystemDrive%\sqmdata04.sqm -> [2009.03.18 20:26:52 | 00,000,268 | -H-- | C] () sqmnoopt04.sqm -> %SystemDrive%\sqmnoopt04.sqm -> [2009.03.18 20:26:52 | 00,000,244 | -H-- | C] () Norton Support -> %ProgramFiles%\Norton Support -> [2009.03.18 18:45:22 | 00,000,000 | R--D | C] Symantec -> %UserProfile%\Lokale innstillinger\Programdata\Symantec -> [2009.03.18 18:45:12 | 00,000,000 | ---D | C] sqmdata03.sqm -> %SystemDrive%\sqmdata03.sqm -> [2009.03.18 18:27:05 | 00,000,268 | -H-- | C] () sqmnoopt03.sqm -> %SystemDrive%\sqmnoopt03.sqm -> [2009.03.18 18:27:05 | 00,000,244 | -H-- | C] () sqmdata02.sqm -> %SystemDrive%\sqmdata02.sqm -> [2009.03.18 18:14:23 | 00,000,268 | -H-- | C] () sqmnoopt02.sqm -> %SystemDrive%\sqmnoopt02.sqm -> [2009.03.18 18:14:23 | 00,000,244 | -H-- | C] () Symantec -> F:\Symantec -> [2009.03.18 18:06:26 | 00,000,000 | ---D | C] Cat.DB -> %SystemRoot%\System32\drivers\N360\0300000.087\Cat.DB -> [2009.03.18 18:05:39 | 00,614,204 | ---- | C] () {7B6BA59A-FB0E-4499-8536-A7420338BF3B} -> %AllUsersProfile%\Programdata\{7B6BA59A-FB0E-4499-8536-A7420338BF3B} -> [2009.03.18 18:05:39 | 00,000,000 | ---D | C] Downloaded Installations -> %UserProfile%\Lokale innstillinger\Programdata\Downloaded Installations -> [2009.03.18 18:05:35 | 00,000,000 | ---D | C] SymIM.sys -> %SystemRoot%\System32\drivers\SymIM.sys -> [2009.03.18 18:05:30 | 00,036,400 | R--- | C] (Symantec Corporation) SYMEVENT.SYS -> %SystemRoot%\System32\drivers\SYMEVENT.SYS -> [2009.03.18 18:05:28 | 00,124,464 | ---- | C] (Symantec Corporation) S32EVNT1.DLL -> %SystemRoot%\System32\S32EVNT1.DLL -> [2009.03.18 18:05:28 | 00,060,808 | ---- | C] (Symantec Corporation) SYMEVENT.CAT -> %SystemRoot%\System32\drivers\SYMEVENT.CAT -> [2009.03.18 18:05:28 | 00,007,386 | ---- | C] () SYMEVENT.INF -> %SystemRoot%\System32\drivers\SYMEVENT.INF -> [2009.03.18 18:05:28 | 00,000,805 | ---- | C] () Symantec -> %ProgramFiles%\Symantec -> [2009.03.18 18:05:28 | 00,000,000 | ---D | C] Norton 360.LNK -> %AllUsersProfile%\Skrivebord\Norton 360.LNK -> [2009.03.18 18:05:23 | 00,001,900 | ---- | C] () cchpx86.sys -> %SystemRoot%\System32\drivers\N360\0300000.087\cchpx86.sys -> [2009.03.18 18:05:22 | 00,482,352 | ---- | C] (Symantec Corporation) SymEFA.sys -> %SystemRoot%\System32\drivers\N360\0300000.087\SymEFA.sys -> [2009.03.18 18:05:22 | 00,310,320 | ---- | C] (Symantec Corporation) srtsp.sys -> %SystemRoot%\System32\drivers\N360\0300000.087\srtsp.sys -> [2009.03.18 18:05:22 | 00,307,760 | ---- | C] (Symantec Corporation) BHDrvx86.sys -> %SystemRoot%\System32\drivers\N360\0300000.087\BHDrvx86.sys -> [2009.03.18 18:05:22 | 00,258,608 | ---- | C] (Symantec Corporation) symtdi.sys -> %SystemRoot%\System32\drivers\N360\0300000.087\symtdi.sys -> [2009.03.18 18:05:22 | 00,217,392 | ---- | C] (Symantec Corporation) symfw.sys -> %SystemRoot%\System32\drivers\N360\0300000.087\symfw.sys -> [2009.03.18 18:05:22 | 00,089,776 | ---- | C] (Symantec Corporation) srtspx.sys -> %SystemRoot%\System32\drivers\N360\0300000.087\srtspx.sys -> [2009.03.18 18:05:22 | 00,043,696 | ---- | C] (Symantec Corporation) symndisv.sys -> %SystemRoot%\System32\drivers\N360\0300000.087\symndisv.sys -> [2009.03.18 18:05:22 | 00,039,984 | ---- | C] (Symantec Corporation) symndis.sys -> %SystemRoot%\System32\drivers\N360\0300000.087\symndis.sys -> [2009.03.18 18:05:22 | 00,037,296 | ---- | C] (Symantec Corporation) symids.sys -> %SystemRoot%\System32\drivers\N360\0300000.087\symids.sys -> [2009.03.18 18:05:22 | 00,034,736 | ---- | C] (Symantec Corporation) SymEFA.inf -> %SystemRoot%\System32\drivers\N360\0300000.087\SymEFA.inf -> [2009.03.18 18:05:13 | 00,003,373 | ---- | C] () ccHPx86.inf -> %SystemRoot%\System32\drivers\N360\0300000.087\ccHPx86.inf -> [2009.03.18 18:05:13 | 00,001,753 | ---- | C] () SymNet.inf -> %SystemRoot%\System32\drivers\N360\0300000.087\SymNet.inf -> [2009.03.18 18:05:13 | 00,001,528 | ---- | C] () srtspx.inf -> %SystemRoot%\System32\drivers\N360\0300000.087\srtspx.inf -> [2009.03.18 18:05:13 | 00,001,389 | ---- | C] () srtsp.inf -> %SystemRoot%\System32\drivers\N360\0300000.087\srtsp.inf -> [2009.03.18 18:05:13 | 00,001,383 | ---- | C] () BHDrvx86.inf -> %SystemRoot%\System32\drivers\N360\0300000.087\BHDrvx86.inf -> [2009.03.18 18:05:13 | 00,000,640 | ---- | C] () isolate.ini -> %SystemRoot%\System32\drivers\N360\0300000.087\isolate.ini -> [2009.03.18 18:05:13 | 00,000,172 | ---- | C] () SymNet.cat -> %SystemRoot%\System32\drivers\N360\0300000.087\SymNet.cat -> [2009.03.18 18:05:05 | 00,009,423 | ---- | C] () SymEFA.cat -> %SystemRoot%\System32\drivers\N360\0300000.087\SymEFA.cat -> [2009.03.18 18:05:05 | 00,007,410 | ---- | C] () srtspx.cat -> %SystemRoot%\System32\drivers\N360\0300000.087\srtspx.cat -> [2009.03.18 18:05:05 | 00,007,372 | ---- | C] () BHDrvx86.CAT -> %SystemRoot%\System32\drivers\N360\0300000.087\BHDrvx86.CAT -> [2009.03.18 18:05:05 | 00,007,364 | ---- | C] () srtsp.cat -> %SystemRoot%\System32\drivers\N360\0300000.087\srtsp.cat -> [2009.03.18 18:05:05 | 00,007,355 | ---- | C] () ccHPx86.cat -> %SystemRoot%\System32\drivers\N360\0300000.087\ccHPx86.cat -> [2009.03.18 18:05:05 | 00,007,347 | ---- | C] () N360 -> %SystemRoot%\System32\drivers\N360 -> [2009.03.18 18:05:05 | 00,000,000 | ---D | C] 0300000.087 -> %SystemRoot%\System32\drivers\N360\0300000.087 -> [2009.03.18 18:05:05 | 00,000,000 | ---D | C] Windows Sidebar -> %ProgramFiles%\Windows Sidebar -> [2009.03.18 18:05:03 | 00,000,000 | ---D | C] Symantec -> %AllUsersProfile%\Programdata\Symantec -> [2009.03.18 18:05:03 | 00,000,000 | ---D | C] Norton 360 -> %ProgramFiles%\Norton 360 -> [2009.03.18 18:05:03 | 00,000,000 | ---D | C] Norton -> %AllUsersProfile%\Programdata\Norton -> [2009.03.18 18:03:49 | 00,000,000 | ---D | C] NortonInstaller -> %ProgramFiles%\NortonInstaller -> [2009.03.18 18:03:46 | 00,000,000 | ---D | C] NortonInstaller -> %AllUsersProfile%\Programdata\NortonInstaller -> [2009.03.18 18:03:46 | 00,000,000 | ---D | C] Symantec Temporary Files -> %AllUsersProfile%\Symantec Temporary Files -> [2009.03.18 18:00:42 | 00,000,000 | ---D | C] Symantec Shared -> %CommonProgramFiles%\Symantec Shared -> [2009.03.18 17:46:16 | 00,000,000 | ---D | C] Norton Security Scan -> %ProgramFiles%\Norton Security Scan -> [2009.03.18 17:46:13 | 00,000,000 | ---D | C] DCEBOOT.CFG -> %SystemRoot%\DCEBOOT.CFG -> [2009.03.18 01:07:45 | 00,002,388 | ---- | C] () sqmdata01.sqm -> %SystemDrive%\sqmdata01.sqm -> [2009.03.17 19:46:54 | 00,000,268 | -H-- | C] () sqmnoopt01.sqm -> %SystemDrive%\sqmnoopt01.sqm -> [2009.03.17 19:46:54 | 00,000,244 | -H-- | C] () Office Genuine Advantage -> %AllUsersProfile%\Programdata\Office Genuine Advantage -> [2009.03.16 23:19:22 | 00,000,000 | ---D | C] sqmdata00.sqm -> %SystemDrive%\sqmdata00.sqm -> [2009.03.16 23:17:13 | 00,000,268 | -H-- | C] () sqmnoopt00.sqm -> %SystemDrive%\sqmnoopt00.sqm -> [2009.03.16 23:17:13 | 00,000,244 | -H-- | C] () microsoft -> %AllUsersProfile%\Dokumenter\microsoft -> [2009.03.16 23:17:09 | 00,000,000 | ---D | C] OGADaily.job -> %SystemRoot%\tasks\OGADaily.job -> [2009.03.16 23:15:33 | 00,000,264 | ---- | C] () OGALogon.job -> %SystemRoot%\tasks\OGALogon.job -> [2009.03.16 23:15:32 | 00,000,264 | ---- | C] () wmpns.dll -> %SystemRoot%\System32\wmpns.dll -> [2009.03.16 23:15:22 | 00,221,184 | ---- | C] (Microsoft Corporation) log -> %SystemRoot%\System32\log -> [2009.03.16 18:01:40 | 00,000,000 | ---D | C] 26b68cb4.sys -> %SystemRoot%\System32\drivers\26b68cb4.sys -> [2009.01.18 23:15:38 | 00,000,000 | ---- | C] () OGACheckControl.dll -> %SystemRoot%\System32\OGACheckControl.dll -> [2008.12.31 18:04:42 | 00,691,560 | ---- | C] () CDPlayer.ini -> %SystemRoot%\CDPlayer.ini -> [2008.12.25 21:55:10 | 00,003,463 | ---- | C] () psisdecd.dll -> %SystemRoot%\System32\psisdecd.dll -> [2008.10.18 18:41:33 | 00,354,816 | ---- | C] () sptd.sys -> %SystemRoot%\System32\drivers\sptd.sys -> [2008.10.04 20:10:42 | 00,717,296 | ---- | C] () CNMVS5n.DLL -> %SystemRoot%\System32\CNMVS5n.DLL -> [2008.10.04 20:00:18 | 00,006,656 | ---- | C] () ODBC.INI -> %SystemRoot%\ODBC.INI -> [2008.09.29 21:43:45 | 00,000,382 | ---- | C] () CddbCdda.dll -> %SystemRoot%\System32\CddbCdda.dll -> [2007.03.29 23:00:40 | 00,203,264 | ---- | C] () lvcoinst.ini -> %SystemRoot%\System32\lvcoinst.ini -> [2007.02.03 08:59:04 | 00,050,127 | ---- | C] () CoInst.dll -> %SystemRoot%\System32\CoInst.dll -> [2003.08.12 17:16:44 | 00,049,152 | ---- | C] () win.ini -> %SystemRoot%\win.ini -> [2003.04.25 14:00:00 | 00,000,613 | ---- | C] () system.ini -> %SystemRoot%\system.ini -> [2003.04.25 14:00:00 | 00,000,227 | ---- | C] () OUTLPERF.INI -> %SystemRoot%\System32\OUTLPERF.INI -> [2003.04.02 10:59:50 | 00,005,263 | ---- | C] () [Files/Folders - Modified Within 30 Days] 4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 2 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> OTScanIt2.exe -> %UserProfile%\Skrivebord\OTScanIt2.exe -> [2009.04.06 09:44:35 | 00,664,709 | ---- | M] () wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [2009.04.05 22:15:01 | 00,013,646 | ---- | M] () OGADaily.job -> %SystemRoot%\tasks\OGADaily.job -> [2009.04.05 22:15:01 | 00,000,264 | ---- | M] () kosglue-7.0.25.0.dll -> %UserProfile%\Lokale innstillinger\Temp\jkos-Ole\binaries\kosglue-7.0.25.0.dll -> [2009.04.05 22:00:48 | 00,729,152 | ---- | M] (Kaspersky Lab) msvcr80.dll -> %UserProfile%\Lokale innstillinger\Temp\jkos-Ole\binaries\msvcr80.dll -> [2009.04.05 22:00:47 | 00,626,688 | ---- | M] (Microsoft Corporation) msvcp80.dll -> %UserProfile%\Lokale innstillinger\Temp\jkos-Ole\binaries\msvcp80.dll -> [2009.04.05 22:00:47 | 00,548,864 | ---- | M] (Microsoft Corporation) kave.dll -> %UserProfile%\Lokale innstillinger\Temp\jkos-Ole\binaries\kave.dll -> [2009.04.05 22:00:47 | 00,282,624 | ---- | M] (Kaspersky Lab.) prLoader.dll -> %UserProfile%\Lokale innstillinger\Temp\jkos-Ole\binaries\prLoader.dll -> [2009.04.05 22:00:47 | 00,184,320 | ---- | M] (Kaspersky Lab) ScanningProcess.exe -> %UserProfile%\Lokale innstillinger\Temp\jkos-Ole\binaries\ScanningProcess.exe -> [2009.04.05 22:00:47 | 00,139,264 | ---- | M] (Kaspersky Lab.) prremote.dll -> %UserProfile%\Lokale innstillinger\Temp\jkos-Ole\binaries\prremote.dll -> [2009.04.05 22:00:47 | 00,090,112 | ---- | M] (Kaspersky Lab) ikave.dll -> %UserProfile%\Lokale innstillinger\Temp\jkos-Ole\binaries\ikave.dll -> [2009.04.05 22:00:47 | 00,065,536 | ---- | M] () FSSync.dll -> %UserProfile%\Lokale innstillinger\Temp\jkos-Ole\binaries\FSSync.dll -> [2009.04.05 22:00:47 | 00,038,400 | ---- | M] (Kaspersky Lab) msvcm80.dll -> %UserProfile%\Lokale innstillinger\Temp\jkos-Ole\binaries\msvcm80.dll -> [2009.04.05 22:00:46 | 00,479,232 | ---- | M] (Microsoft Corporation) index.dat -> %SystemRoot%\Temp\Temporary Internet Files\Content.IE5\index.dat -> [2009.04.02 22:39:03 | 00,032,768 | -HS- | M] () index.dat -> %SystemRoot%\Temp\History\History.IE5\index.dat -> [2009.04.02 22:39:03 | 00,016,384 | -HS- | M] () index.dat -> %SystemRoot%\Temp\Cookies\index.dat -> [2009.04.02 22:39:03 | 00,016,384 | -HS- | M] () AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job -> [2009.04.02 22:39:03 | 00,000,282 | ---- | M] () sfdb.dat -> %UserProfile%\Lokale innstillinger\Temp\jkos-Ole\engine\bases\sfdb.dat -> [2009.04.02 21:58:28 | 00,000,084 | ---- | M] () Perflib_Perfdata_468.dat -> %SystemRoot%\Temp\Perflib_Perfdata_468.dat -> [2009.04.02 21:41:44 | 00,016,384 | ---- | M] () qmgr1.dat -> %AllUsersProfile%\Programdata\Microsoft\Network\Downloader\qmgr1.dat -> [2009.04.02 21:41:20 | 00,010,336 | ---- | M] () qmgr0.dat -> %AllUsersProfile%\Programdata\Microsoft\Network\Downloader\qmgr0.dat -> [2009.04.02 21:41:20 | 00,010,336 | ---- | M] () GDIPFONTCACHEV1.DAT -> %UserProfile%\Lokale innstillinger\Programdata\GDIPFONTCACHEV1.DAT -> [2009.04.02 21:41:18 | 00,022,648 | ---- | M] () OGALogon.job -> %SystemRoot%\tasks\OGALogon.job -> [2009.04.02 21:40:36 | 00,000,264 | ---- | M] () Perflib_Perfdata_6dc.dat -> %SystemRoot%\Temp\Perflib_Perfdata_6dc.dat -> [2009.04.02 21:40:30 | 00,016,384 | ---- | M] () SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [2009.04.02 21:40:17 | 00,000,006 | -H-- | M] () bootstat.dat -> %SystemRoot%\bootstat.dat -> [2009.04.02 21:40:15 | 00,002,048 | --S- | M] () ntuser.ini -> %UserProfile%\ntuser.ini -> [2009.04.02 21:38:20 | 00,000,286 | -HS- | M] () NTUSER.DAT -> %UserProfile%\NTUSER.DAT -> [2009.04.02 21:38:19 | 04,194,304 | -H-- | M] () OTMoveIt3.exe -> %UserProfile%\Skrivebord\OTMoveIt3.exe -> [2009.04.02 21:34:29 | 00,389,632 | ---- | M] (OldTimer Tools) Mine delte mapper.lnk -> F:\Mine delte mapper.lnk -> [2009.04.02 17:43:42 | 00,000,384 | ---- | M] () 20090401-003-v5i32.exe -> %UserProfile%\Skrivebord\20090401-003-v5i32.exe -> [2009.04.01 23:48:30 | 39,603,232 | ---- | M] () RSIT.exe -> %UserProfile%\Skrivebord\RSIT.exe -> [2009.04.01 23:38:18 | 00,781,909 | ---- | M] () HOSTS -> %SystemRoot%\System32\drivers\etc\HOSTS -> [2009.04.01 22:30:54 | 00,000,686 | ---- | M] () user32.dll -> %SystemRoot%\System32\dllcache\user32.dll -> [2009.04.01 22:26:53 | 00,578,560 | ---- | M] (Microsoft Corporation) win.ini -> %SystemRoot%\win.ini -> [2009.04.01 22:08:20 | 00,000,613 | ---- | M] () boot.ini -> %SystemDrive%\boot.ini -> [2009.04.01 22:08:20 | 00,000,229 | RHS- | M] () system.ini -> %SystemRoot%\system.ini -> [2009.04.01 22:08:20 | 00,000,227 | ---- | M] () SDFix.exe -> %UserProfile%\Skrivebord\SDFix.exe -> [2009.04.01 21:38:42 | 01,529,241 | ---- | M] () ComboFix.exe -> %UserProfile%\Skrivebord\ComboFix.exe -> [2009.04.01 17:10:47 | 03,062,142 | ---- | M] () CF17185.exe -> %SystemRoot%\System32\CF17185.exe -> [2009.03.31 21:05:28 | 00,388,608 | ---- | M] (Microsoft Corporation) PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI -> [2009.03.30 21:36:11 | 01,059,846 | ---- | M] () perfh014.dat -> %SystemRoot%\System32\perfh014.dat -> [2009.03.30 21:36:11 | 00,447,134 | ---- | M] () perfh009.dat -> %SystemRoot%\System32\perfh009.dat -> [2009.03.30 21:36:11 | 00,444,528 | ---- | M] () perfc014.dat -> %SystemRoot%\System32\perfc014.dat -> [2009.03.30 21:36:11 | 00,080,868 | ---- | M] () perfc009.dat -> %SystemRoot%\System32\perfc009.dat -> [2009.03.30 21:36:11 | 00,072,152 | ---- | M] () DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Lokale innstillinger\Programdata\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2009.03.29 19:00:08 | 00,122,368 | ---- | M] () mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2009.03.26 16:49:56 | 00,038,496 | ---- | M] (Malwarebytes Corporation) mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2009.03.26 16:49:50 | 00,015,504 | ---- | M] (Malwarebytes Corporation) HijackThis.lnk -> %UserProfile%\Skrivebord\HijackThis.lnk -> [2009.03.24 14:31:50 | 00,001,725 | ---- | M] () Adobe Reader 9.lnk -> %AllUsersProfile%\Skrivebord\Adobe Reader 9.lnk -> [2009.03.24 11:33:45 | 00,001,724 | ---- | M] () sqmdata16.sqm -> %SystemDrive%\sqmdata16.sqm -> [2009.03.24 10:52:56 | 00,000,268 | -H-- | M] () sqmnoopt16.sqm -> %SystemDrive%\sqmnoopt16.sqm -> [2009.03.24 10:52:56 | 00,000,244 | -H-- | M] () sqmdata15.sqm -> %SystemDrive%\sqmdata15.sqm -> [2009.03.24 10:50:09 | 00,000,268 | -H-- | M] () sqmnoopt15.sqm -> %SystemDrive%\sqmnoopt15.sqm -> [2009.03.24 10:50:09 | 00,000,244 | -H-- | M] () sqmdata14.sqm -> %SystemDrive%\sqmdata14.sqm -> [2009.03.24 10:44:22 | 00,000,268 | -H-- | M] () sqmnoopt14.sqm -> %SystemDrive%\sqmnoopt14.sqm -> [2009.03.24 10:44:22 | 00,000,244 | -H-- | M] () sqmdata13.sqm -> %SystemDrive%\sqmdata13.sqm -> [2009.03.23 21:13:44 | 00,000,268 | -H-- | M] () sqmnoopt13.sqm -> %SystemDrive%\sqmnoopt13.sqm -> [2009.03.23 21:13:44 | 00,000,244 | -H-- | M] () sqmdata12.sqm -> %SystemDrive%\sqmdata12.sqm -> [2009.03.23 17:51:05 | 00,000,268 | -H-- | M] () sqmnoopt12.sqm -> %SystemDrive%\sqmnoopt12.sqm -> [2009.03.23 17:51:05 | 00,000,244 | -H-- | M] () sqmdata11.sqm -> %SystemDrive%\sqmdata11.sqm -> [2009.03.23 00:14:04 | 00,000,268 | -H-- | M] () sqmnoopt11.sqm -> %SystemDrive%\sqmnoopt11.sqm -> [2009.03.23 00:14:04 | 00,000,244 | -H-- | M] () Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Skrivebord\Malwarebytes' Anti-Malware.lnk -> [2009.03.22 23:12:36 | 00,000,691 | ---- | M] () sqmdata10.sqm -> %SystemDrive%\sqmdata10.sqm -> [2009.03.22 22:49:32 | 00,000,268 | -H-- | M] () sqmnoopt10.sqm -> %SystemDrive%\sqmnoopt10.sqm -> [2009.03.22 22:49:32 | 00,000,244 | -H-- | M] () sqmdata09.sqm -> %SystemDrive%\sqmdata09.sqm -> [2009.03.19 07:29:24 | 00,000,268 | -H-- | M] () sqmnoopt09.sqm -> %SystemDrive%\sqmnoopt09.sqm -> [2009.03.19 07:29:24 | 00,000,244 | -H-- | M] () sqmdata08.sqm -> %SystemDrive%\sqmdata08.sqm -> [2009.03.18 23:16:14 | 00,000,268 | -H-- | M] () sqmnoopt08.sqm -> %SystemDrive%\sqmnoopt08.sqm -> [2009.03.18 23:16:14 | 00,000,244 | -H-- | M] () sqmdata07.sqm -> %SystemDrive%\sqmdata07.sqm -> [2009.03.18 22:36:03 | 00,000,268 | -H-- | M] () sqmnoopt07.sqm -> %SystemDrive%\sqmnoopt07.sqm -> [2009.03.18 22:36:03 | 00,000,244 | -H-- | M] () sqmdata06.sqm -> %SystemDrive%\sqmdata06.sqm -> [2009.03.18 22:23:24 | 00,000,268 | -H-- | M] () sqmnoopt06.sqm -> %SystemDrive%\sqmnoopt06.sqm -> [2009.03.18 22:23:24 | 00,000,244 | -H-- | M] () sqmdata05.sqm -> %SystemDrive%\sqmdata05.sqm -> [2009.03.18 22:15:30 | 00,000,268 | -H-- | M] () sqmnoopt05.sqm -> %SystemDrive%\sqmnoopt05.sqm -> [2009.03.18 22:15:30 | 00,000,244 | -H-- | M] () intlname.ols -> %UserProfile%\intlname.ols -> [2009.03.18 21:18:47 | 00,002,789 | ---- | M] () sqmdata04.sqm -> %SystemDrive%\sqmdata04.sqm -> [2009.03.18 20:26:52 | 00,000,268 | -H-- | M] () sqmnoopt04.sqm -> %SystemDrive%\sqmnoopt04.sqm -> [2009.03.18 20:26:52 | 00,000,244 | -H-- | M] () sqmdata03.sqm -> %SystemDrive%\sqmdata03.sqm -> [2009.03.18 18:27:05 | 00,000,268 | -H-- | M] () sqmnoopt03.sqm -> %SystemDrive%\sqmnoopt03.sqm -> [2009.03.18 18:27:05 | 00,000,244 | -H-- | M] () Cat.DB -> %SystemRoot%\System32\drivers\N360\0300000.087\Cat.DB -> [2009.03.18 18:16:26 | 00,614,204 | ---- | M] () sqmdata02.sqm -> %SystemDrive%\sqmdata02.sqm -> [2009.03.18 18:14:23 | 00,000,268 | -H-- | M] () sqmnoopt02.sqm -> %SystemDrive%\sqmnoopt02.sqm -> [2009.03.18 18:14:23 | 00,000,244 | -H-- | M] () SYMEVENT.SYS -> %SystemRoot%\System32\drivers\SYMEVENT.SYS -> [2009.03.18 18:05:28 | 00,124,464 | ---- | M] (Symantec Corporation) S32EVNT1.DLL -> %SystemRoot%\System32\S32EVNT1.DLL -> [2009.03.18 18:05:28 | 00,060,808 | ---- | M] (Symantec Corporation) SYMEVENT.CAT -> %SystemRoot%\System32\drivers\SYMEVENT.CAT -> [2009.03.18 18:05:28 | 00,007,386 | ---- | M] () SYMEVENT.INF -> %SystemRoot%\System32\drivers\SYMEVENT.INF -> [2009.03.18 18:05:28 | 00,000,805 | ---- | M] () Norton 360.LNK -> %AllUsersProfile%\Skrivebord\Norton 360.LNK -> [2009.03.18 18:05:23 | 00,001,900 | ---- | M] () cchpx86.sys -> %SystemRoot%\System32\drivers\N360\0300000.087\cchpx86.sys -> [2009.03.18 18:05:22 | 00,482,352 | ---- | M] (Symantec Corporation) SymEFA.sys -> %SystemRoot%\System32\drivers\N360\0300000.087\SymEFA.sys -> [2009.03.18 18:05:22 | 00,310,320 | ---- | M] (Symantec Corporation) srtsp.sys -> %SystemRoot%\System32\drivers\N360\0300000.087\srtsp.sys -> [2009.03.18 18:05:22 | 00,307,760 | ---- | M] (Symantec Corporation) BHDrvx86.sys -> %SystemRoot%\System32\drivers\N360\0300000.087\BHDrvx86.sys -> [2009.03.18 18:05:22 | 00,258,608 | ---- | M] (Symantec Corporation) symtdi.sys -> %SystemRoot%\System32\drivers\N360\0300000.087\symtdi.sys -> [2009.03.18 18:05:22 | 00,217,392 | ---- | M] (Symantec Corporation) symfw.sys -> %SystemRoot%\System32\drivers\N360\0300000.087\symfw.sys -> [2009.03.18 18:05:22 | 00,089,776 | ---- | M] (Symantec Corporation) srtspx.sys -> %SystemRoot%\System32\drivers\N360\0300000.087\srtspx.sys -> [2009.03.18 18:05:22 | 00,043,696 | ---- | M] (Symantec Corporation) symndisv.sys -> %SystemRoot%\System32\drivers\N360\0300000.087\symndisv.sys -> [2009.03.18 18:05:22 | 00,039,984 | ---- | M] (Symantec Corporation) symndis.sys -> %SystemRoot%\System32\drivers\N360\0300000.087\symndis.sys -> [2009.03.18 18:05:22 | 00,037,296 | ---- | M] (Symantec Corporation) SymIM.sys -> %SystemRoot%\System32\drivers\SymIM.sys -> [2009.03.18 18:05:22 | 00,036,400 | R--- | M] (Symantec Corporation) symids.sys -> %SystemRoot%\System32\drivers\N360\0300000.087\symids.sys -> [2009.03.18 18:05:22 | 00,034,736 | ---- | M] (Symantec Corporation) SymEFA.inf -> %SystemRoot%\System32\drivers\N360\0300000.087\SymEFA.inf -> [2009.03.18 18:05:13 | 00,003,373 | ---- | M] () ccHPx86.inf -> %SystemRoot%\System32\drivers\N360\0300000.087\ccHPx86.inf -> [2009.03.18 18:05:13 | 00,001,753 | ---- | M] () SymNet.inf -> %SystemRoot%\System32\drivers\N360\0300000.087\SymNet.inf -> [2009.03.18 18:05:13 | 00,001,528 | ---- | M] () srtspx.inf -> %SystemRoot%\System32\drivers\N360\0300000.087\srtspx.inf -> [2009.03.18 18:05:13 | 00,001,389 | ---- | M] () srtsp.inf -> %SystemRoot%\System32\drivers\N360\0300000.087\srtsp.inf -> [2009.03.18 18:05:13 | 00,001,383 | ---- | M] () BHDrvx86.inf -> %SystemRoot%\System32\drivers\N360\0300000.087\BHDrvx86.inf -> [2009.03.18 18:05:13 | 00,000,640 | ---- | M] () isolate.ini -> %SystemRoot%\System32\drivers\N360\0300000.087\isolate.ini -> [2009.03.18 18:05:13 | 00,000,172 | ---- | M] () SymNet.cat -> %SystemRoot%\System32\drivers\N360\0300000.087\SymNet.cat -> [2009.03.18 18:05:05 | 00,009,423 | ---- | M] () SymEFA.cat -> %SystemRoot%\System32\drivers\N360\0300000.087\SymEFA.cat -> [2009.03.18 18:05:05 | 00,007,410 | ---- | M] () srtspx.cat -> %SystemRoot%\System32\drivers\N360\0300000.087\srtspx.cat -> [2009.03.18 18:05:05 | 00,007,372 | ---- | M] () BHDrvx86.CAT -> %SystemRoot%\System32\drivers\N360\0300000.087\BHDrvx86.CAT -> [2009.03.18 18:05:05 | 00,007,364 | ---- | M] () srtsp.cat -> %SystemRoot%\System32\drivers\N360\0300000.087\srtsp.cat -> [2009.03.18 18:05:05 | 00,007,355 | ---- | M] () ccHPx86.cat -> %SystemRoot%\System32\drivers\N360\0300000.087\ccHPx86.cat -> [2009.03.18 18:05:05 | 00,007,347 | ---- | M] () DCEBOOT.CFG -> %SystemRoot%\DCEBOOT.CFG -> [2009.03.18 01:07:45 | 00,002,388 | ---- | M] () sqmdata01.sqm -> %SystemDrive%\sqmdata01.sqm -> [2009.03.17 19:46:54 | 00,000,268 | -H-- | M] () sqmnoopt01.sqm -> %SystemDrive%\sqmnoopt01.sqm -> [2009.03.17 19:46:54 | 00,000,244 | -H-- | M] () FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [2009.03.16 23:18:48 | 00,124,520 | ---- | M] () sqmdata00.sqm -> %SystemDrive%\sqmdata00.sqm -> [2009.03.16 23:17:13 | 00,000,268 | -H-- | M] () sqmnoopt00.sqm -> %SystemDrive%\sqmnoopt00.sqm -> [2009.03.16 23:17:13 | 00,000,244 | -H-- | M] () imsins.BAK -> %SystemRoot%\imsins.BAK -> [2009.03.16 23:15:29 | 00,001,374 | ---- | M] () opa11.dat -> %AllUsersProfile%\Programdata\Microsoft\OFFICE\DATA\opa11.dat -> [2008.10.04 21:16:28 | 00,011,088 | ---- | M] () [Alternate Data Streams] @Alternate Data Stream - 0 bytes -> %UserProfile%\Skrivebord\Thumbs.db:encryptable @Alternate Data Stream - 0 bytes -> F:\Thumbs.db:encryptable < End of report > [/code]