OTL logfile created on: 27-08-2010 06:57:41 - Run 2 OTL by OldTimer - Version 3.2.10.0 Folder = C:\Users\BrugerAdmin\Desktop Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000406 | Country: Danmark | Language: DAN | Date Format: dd-MM-yyyy 3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 52,00% Memory free 6,00 Gb Paging File | 5,00 Gb Available in Paging File | 82,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 290,77 Gb Total Space | 93,13 Gb Free Space | 32,03% Space Free | Partition Type: NTFS Drive D: | 7,32 Gb Total Space | 1,53 Gb Free Space | 20,86% Space Free | Partition Type: NTFS Drive E: | 298,09 Gb Total Space | 297,56 Gb Free Space | 99,82% Space Free | Partition Type: NTFS F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: FARS-PC Current User Name: BrugerAdmin Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Standard [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2010-08-24 16:03:26 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\BrugerAdmin\Desktop\OTL.exe PRC - [2010-08-10 13:48:12 | 000,231,888 | ---- | M] (Adobe Systems, Inc.) -- C:\WINDOWS\System32\Macromed\Flash\FlashUtil10h_ActiveX.exe PRC - [2010-07-21 14:23:35 | 002,048,352 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programmer\AVG\AVG8\avgtray.exe PRC - [2010-01-14 19:04:52 | 000,041,984 | ---- | M] (David Becher) -- C:\Programmer\WC3 Quickstarter\WC3 Quickstarter.exe PRC - [2009-08-28 14:50:35 | 000,486,680 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programmer\AVG\AVG8\avgrsx.exe PRC - [2009-08-28 14:50:21 | 000,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Programmer\AVG\AVG8\avgwdsvc.exe PRC - [2009-05-07 14:59:00 | 000,098,304 | ---- | M] (Wireless Service) -- C:\Programmer\ANI\ANIWZCS2 Service\WZCSLDR2.exe PRC - [2009-03-08 23:09:24 | 000,638,816 | ---- | M] (Microsoft Corporation) -- C:\Programmer\Internet Explorer\iexplore.exe PRC - [2009-02-26 13:46:40 | 000,147,456 | ---- | M] () -- C:\WINDOWS\System32\ANIWConnService.exe PRC - [2008-12-02 23:15:58 | 000,054,680 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\jureg.exe PRC - [2008-10-29 08:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2008-02-29 20:36:50 | 001,232,896 | ---- | M] (Microsoft Corporation) -- C:\Programmer\Windows Sidebar\sidebar.exe PRC - [2007-12-18 23:24:48 | 000,385,024 | R--- | M] (Nalpeiron Ltd.) -- C:\WINDOWS\System32\AstSrv.exe PRC - [2007-09-13 21:42:36 | 001,006,264 | ---- | M] (Microsoft Corporation) -- C:\Programmer\Windows Defender\MSASCui.exe PRC - [2007-07-06 13:06:52 | 004,669,440 | ---- | M] (Realtek Semiconductor) -- C:\WINDOWS\RtHDVCpl.exe PRC - [2007-05-29 17:19:08 | 000,198,240 | ---- | M] () -- c:\hp\HPEZBTN\HPBtnSrv.exe PRC - [2007-04-18 17:01:34 | 000,065,536 | ---- | M] (Hewlett-Packard Company) -- C:\hp\support\hpsysdrv.exe PRC - [2007-02-15 13:59:00 | 000,118,784 | ---- | M] (OsdMaestro) -- C:\Programmer\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe PRC - [2006-11-02 14:36:04 | 000,895,488 | ---- | M] (Microsoft Corporation) -- C:\Programmer\Windows Media Player\wmpnetwk.exe PRC - [2006-11-02 11:45:39 | 000,150,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\schtasks.exe PRC - [2006-11-02 11:44:59 | 000,068,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\conime.exe PRC - [2006-10-26 13:40:34 | 000,335,872 | ---- | M] (Microsoft Corporation) -- C:\Programmer\Common Files\microsoft shared\VS7DEBUG\mdm.exe PRC - [2006-09-03 10:32:28 | 000,208,896 | ---- | M] () -- C:\Programmer\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [color=#E56717]========== Modules (SafeList) ==========[/color] MOD - [2010-08-24 16:03:26 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\BrugerAdmin\Desktop\OTL.exe MOD - [2009-08-28 14:50:35 | 000,011,952 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll MOD - [2006-11-02 11:44:49 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msscript.ocx MOD - [2006-11-02 11:38:57 | 001,648,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - [2010-07-29 16:32:33 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2009-08-28 14:50:21 | 000,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Programmer\AVG\AVG8\avgwdsvc.exe -- (avg8wd) SRV - [2009-02-26 13:46:40 | 000,147,456 | ---- | M] () [Auto | Running] -- C:\WINDOWS\System32\ANIWConnService.exe -- (ANIWConnService) SRV - [2008-04-07 15:06:47 | 000,069,120 | ---- | M] (BOONTY) [On_Demand | Stopped] -- C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe -- (Boonty Games) SRV - [2007-12-18 23:24:48 | 000,385,024 | R--- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\WINDOWS\System32\AstSrv.exe -- (astcc) SRV - [2007-09-13 21:42:36 | 000,265,912 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programmer\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2007-05-29 17:19:08 | 000,198,240 | ---- | M] () [Auto | Running] -- c:\hp\HPEZBTN\HPBtnSrv.exe -- (HPBtnSrv) SRV - [2007-01-19 11:49:26 | 000,049,152 | ---- | M] (Wireless Service) [Auto | Stopped] -- C:\Programmer\ANI\ANIWZCS2 Service\ANIWZCSdS.exe -- (ANIWZCSdService) SRV - [2006-09-11 16:02:44 | 000,544,256 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe -- (Remote UI Service) Intel(R) SRV - [2006-09-11 16:01:04 | 000,167,936 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe -- (MCLServiceATL) Intel(R) SRV - [2006-09-11 15:56:32 | 000,075,264 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe -- (ISSM) Intel(R) SRV - [2006-09-11 15:56:20 | 000,188,416 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\IntelDH\CCU\AlertService.exe -- (AlertService) Intel(R) SRV - [2006-09-03 10:32:28 | 000,208,896 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe -- (DQLWinService) SRV - [2006-08-31 23:47:56 | 000,026,624 | ---- | M] () [On_Demand | Stopped] -- C:\Programmer\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe -- (M1 Server) Intel(R) Viiv(TM) SRV - [2006-05-10 09:13:52 | 000,029,696 | R--- | M] (Intel(R) Corporation) [Auto | Stopped] -- C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe -- (IntelDHSvcConf) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\ipinip.sys -- (IpInIp) DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\blbdrive.sys -- (blbdrive) DRV - [2009-08-28 14:50:35 | 000,335,240 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\Drivers\avgldx86.sys -- (AvgLdx86) DRV - [2009-08-28 14:50:35 | 000,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\Drivers\avgmfx86.sys -- (AvgMfx86) DRV - [2009-04-17 11:27:10 | 000,722,944 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\netr28u.sys -- (netr28u) DRV - [2009-03-06 18:09:52 | 000,012,800 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\anodlwf.sys -- (anodlwf) DRV - [2008-05-02 11:58:28 | 000,008,064 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt) DRV - [2008-05-02 11:58:14 | 000,020,864 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\ccdcmbo.sys -- (nmwcdc) DRV - [2008-05-02 10:58:14 | 000,008,064 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\usbser_lowerflt.sys -- (upperdev) DRV - [2008-05-02 10:58:12 | 000,017,536 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\ccdcmb.sys -- (nmwcd) DRV - [2007-07-11 12:21:00 | 001,793,880 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2007-07-06 15:15:00 | 007,568,832 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2007-06-11 11:49:22 | 000,968,064 | ---- | M] (Hauppauge Computer Works) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\HCW85BDA.sys -- (HCW85BDA) DRV - [2007-05-30 17:40:42 | 000,735,232 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\athr.sys -- (athr) DRV - [2007-04-13 15:22:56 | 000,228,224 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\e1e6032.sys -- (e1express) Intel(R) DRV - [2006-11-02 11:51:45 | 000,900,712 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300) DRV - [2006-11-02 11:51:38 | 000,420,968 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx) DRV - [2006-11-02 11:51:34 | 000,316,520 | ---- | M] (Emulex) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor) DRV - [2006-11-02 11:51:32 | 000,297,576 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci) DRV - [2006-11-02 11:51:25 | 000,235,112 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci) DRV - [2006-11-02 11:51:25 | 000,232,040 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV) DRV - [2006-11-02 11:51:00 | 000,147,048 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320) DRV - [2006-11-02 11:50:45 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2) DRV - [2006-11-02 11:50:41 | 000,112,232 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid) DRV - [2006-11-02 11:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx) DRV - [2006-11-02 11:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata) DRV - [2006-11-02 11:50:35 | 000,098,408 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m) DRV - [2006-11-02 11:50:24 | 000,088,680 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid) DRV - [2006-11-02 11:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960) DRV - [2006-11-02 11:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp) DRV - [2006-11-02 11:50:16 | 000,071,784 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4) DRV - [2006-11-02 11:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor) DRV - [2006-11-02 11:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx) DRV - [2006-11-02 11:50:10 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas) DRV - [2006-11-02 11:50:10 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI) DRV - [2006-11-02 11:50:10 | 000,038,504 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid2.sys -- (SiSRaid2) DRV - [2006-11-02 11:50:10 | 000,037,480 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs) DRV - [2006-11-02 11:50:09 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arc.sys -- (arc) DRV - [2006-11-02 11:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid) DRV - [2006-11-02 11:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi) DRV - [2006-11-02 11:50:05 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS) DRV - [2006-11-02 11:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx) DRV - [2006-11-02 11:50:04 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC) DRV - [2006-11-02 11:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3) DRV - [2006-11-02 11:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x) DRV - [2006-11-02 11:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi) DRV - [2006-11-02 11:49:53 | 000,028,776 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasas.sys -- (megasas) DRV - [2006-11-02 11:49:30 | 000,017,512 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide) DRV - [2006-11-02 11:49:28 | 000,016,488 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide) DRV - [2006-11-02 11:49:20 | 000,014,952 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide) DRV - [2006-11-02 10:55:16 | 000,040,448 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\avc.sys -- (Avc) DRV - [2006-11-02 10:55:15 | 000,045,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\61883.sys -- (61883) DRV - [2006-11-02 10:55:12 | 000,052,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\msdv.sys -- (MSDV) DRV - [2006-11-02 10:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM) DRV - [2006-11-02 10:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer) DRV - [2006-11-02 10:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp) DRV - [2006-11-02 10:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo) DRV - [2006-11-02 10:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm) DRV - [2006-11-02 10:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm) DRV - [2006-11-02 09:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi) DRV - [2006-11-02 09:30:54 | 000,117,760 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\E1G60I32.sys -- (E1G60) Intel(R) DRV - [2005-12-12 19:27:00 | 000,019,072 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\PS2.sys -- (Ps2) DRV - [2005-02-23 17:59:54 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DA_DK&c=74&bd=Pavilion&pf=desktop IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DA_DK&c=74&bd=Pavilion&pf=desktop IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3851498605-421253736-3578957769-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = IE - HKU\S-1-5-21-3851498605-421253736-3578957769-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/ IE - HKU\S-1-5-21-3851498605-421253736-3578957769-1001\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\S-1-5-21-3851498605-421253736-3578957769-1001\..\URLSearchHook: {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - Reg Error: Key error. File not found IE - HKU\S-1-5-21-3851498605-421253736-3578957769-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 O1 HOSTS File: ([2006-09-18 23:41:30 | 000,000,761 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (no name) - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - No CLSID value found. O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmer\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No CLSID value found. O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Programmer\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - No CLSID value found. O3 - HKU\S-1-5-21-3851498605-421253736-3578957769-1001\..\Toolbar\WebBrowser: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found. O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [ANIWZCS2Service] C:\Programmer\ANI\ANIWZCS2 Service\WZCSLDR2.exe (Wireless Service) O4 - HKLM..\Run: [AVG8_TRAY] C:\Programmer\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [CCUTRAYICON] File not found O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Programmer\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard) O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company) O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe () O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [OsdMaestro] C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (OsdMaestro) O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [SunJavaUpdateReg] C:\Windows\System32\jureg.exe (Sun Microsystems, Inc.) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-21-3851498605-421253736-3578957769-1001..\Run: [wc3quickstarter] C:\Programmer\WC3 Quickstarter\WC3 Quickstarter.exe (David Becher) O4 - Startup: C:\Users\Henrik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip () O7 - HKU\S-1-5-21-3851498605-421253736-3578957769-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-3851498605-421253736-3578957769-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2 O7 - HKU\S-1-5-21-3851498605-421253736-3578957769-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1 O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programmer\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: HP Smart markering - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Programmer\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) O13 - gopher Prefix: missing O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.) O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmer\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programmer\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programmer\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programmer\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\awave.jpg O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\awave.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2007-09-13 12:24:37 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2010-08-26 23:41:07 | 000,000,000 | ---D | C] -- C:\Programmer\ESET [2010-08-25 20:25:23 | 000,000,000 | ---D | C] -- C:\Users\BrugerAdmin\AppData\Roaming\Malwarebytes [2010-08-25 20:25:12 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2010-08-25 20:25:11 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2010-08-25 20:25:11 | 000,000,000 | ---D | C] -- C:\Programmer\Malwarebytes' Anti-Malware [2010-08-25 20:25:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2010-08-25 20:23:42 | 006,153,352 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\BrugerAdmin\Desktop\mbam-setup-1.46.exe [2010-08-24 16:03:17 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\BrugerAdmin\Desktop\OTL.exe [2010-08-17 20:52:07 | 000,000,000 | ---D | C] -- C:\Programmer\Trend Micro [2010-08-17 20:42:09 | 000,000,000 | ---D | C] -- C:\Windows\pss [2010-08-17 20:34:24 | 000,000,000 | ---D | C] -- C:\Programmer\CCleaner [2010-08-12 19:03:28 | 000,000,000 | ---D | C] -- C:\Temp [2010-08-02 21:45:58 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2010-08-02 21:45:58 | 000,156,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll [2010-08-02 21:45:58 | 000,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll [2010-08-02 21:45:58 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll [2010-08-02 21:45:58 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll [2010-08-02 21:45:58 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll [2010-08-02 21:45:58 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2010-08-02 21:45:58 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\corpol.dll [2010-08-02 21:45:57 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2010-08-02 21:45:57 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll [2010-08-02 21:45:57 | 000,229,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll [2010-08-02 21:45:57 | 000,216,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll [2010-08-02 21:45:57 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll [2010-08-02 21:45:57 | 000,183,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll [2010-08-02 21:45:57 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll [2010-08-02 21:45:57 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll [2010-08-02 21:45:57 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll [2010-08-02 21:45:57 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll [2010-08-02 21:45:57 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll [2010-08-02 21:45:56 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll [2010-08-02 21:45:56 | 000,611,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll [2010-08-02 21:45:56 | 000,594,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2010-08-02 21:45:56 | 000,445,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll [2010-08-02 21:45:56 | 000,420,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll [2010-08-02 21:45:56 | 000,208,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WinFXDocObj.exe [2010-08-02 21:45:56 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll [2010-08-02 21:45:56 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe [2010-08-02 21:45:56 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll [2010-08-02 21:45:56 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe [2010-08-02 21:45:55 | 003,698,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat [2010-08-02 21:45:55 | 000,391,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll [2010-08-02 21:45:55 | 000,385,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec [2010-08-02 21:45:55 | 000,169,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe [2010-08-02 21:45:55 | 000,132,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2010-08-02 21:45:55 | 000,109,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PDMSetup.exe [2010-08-02 21:45:55 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll [2010-08-02 21:45:55 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe [2010-08-02 21:45:55 | 000,107,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe [2010-08-02 21:45:55 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll [2010-08-02 21:45:54 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl [2010-08-02 21:45:54 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe [3 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2010-08-27 06:56:38 | 002,359,296 | -HS- | M] () -- C:\Users\BrugerAdmin\NTUSER.DAT [2010-08-27 06:35:55 | 000,003,456 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2010-08-27 06:35:55 | 000,003,456 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2010-08-27 06:28:00 | 000,000,920 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2010-08-26 23:36:08 | 000,000,007 | ---- | M] () -- C:\Windows\System32\ANIWZCSUSERNAME [2010-08-26 23:36:05 | 000,000,916 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2010-08-26 23:36:05 | 000,000,254 | ---- | M] () -- C:\Windows\tasks\PersSecurity.job [2010-08-26 23:35:56 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2010-08-26 23:35:54 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010-08-26 19:37:36 | 000,000,836 | ---- | M] () -- C:\Users\Public\Desktop\World of Warcraft.lnk [2010-08-26 17:09:45 | 000,609,944 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2010-08-26 17:09:45 | 000,485,362 | ---- | M] () -- C:\Windows\System32\perfh006.dat [2010-08-26 17:09:45 | 000,103,726 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2010-08-26 17:09:45 | 000,080,082 | ---- | M] () -- C:\Windows\System32\perfc006.dat [2010-08-26 17:09:43 | 001,270,178 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI [2010-08-26 16:20:07 | 063,903,826 | ---- | M] () -- C:\Windows\System32\drivers\Avg\incavi.avm [2010-08-25 23:21:12 | 002,101,436 | -H-- | M] () -- C:\Users\BrugerAdmin\AppData\Local\IconCache.db [2010-08-25 20:25:15 | 000,000,820 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010-08-25 20:23:55 | 006,153,352 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\BrugerAdmin\Desktop\mbam-setup-1.46.exe [2010-08-25 13:01:55 | 253,666,607 | ---- | M] () -- C:\Windows\MEMORY.DMP [2010-08-24 16:03:26 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\BrugerAdmin\Desktop\OTL.exe [2010-08-23 20:30:52 | 000,133,632 | ---- | M] () -- C:\Users\BrugerAdmin\Desktop\RKUnhookerLE.EXE [2010-08-23 20:21:14 | 000,794,408 | ---- | M] () -- C:\Windows\System32\pbsvc.exe [2010-08-17 21:35:54 | 000,003,584 | ---- | M] () -- C:\Users\BrugerAdmin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010-08-17 21:26:28 | 000,002,535 | ---- | M] () -- C:\Users\BrugerAdmin\Desktop\HiJackThis.lnk [2010-08-17 20:34:25 | 000,000,806 | ---- | M] () -- C:\Users\BrugerAdmin\Desktop\CCleaner.lnk [2010-08-12 18:59:38 | 000,452,272 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2010-08-03 10:08:52 | 000,000,945 | ---- | M] () -- C:\Users\BrugerAdmin\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [3 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2010-08-25 20:25:15 | 000,000,820 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2010-08-25 13:01:27 | 253,666,607 | ---- | C] () -- C:\Windows\MEMORY.DMP [2010-08-23 20:30:41 | 000,133,632 | ---- | C] () -- C:\Users\BrugerAdmin\Desktop\RKUnhookerLE.EXE [2010-08-23 20:21:14 | 000,794,408 | ---- | C] () -- C:\Windows\System32\pbsvc.exe [2010-08-17 20:52:07 | 000,002,535 | ---- | C] () -- C:\Users\BrugerAdmin\Desktop\HiJackThis.lnk [2010-08-17 20:34:25 | 000,000,806 | ---- | C] () -- C:\Users\BrugerAdmin\Desktop\CCleaner.lnk [2010-08-02 21:45:56 | 000,057,667 | ---- | C] () -- C:\Windows\System32\ieuinit.inf [2010-06-07 20:51:40 | 000,003,284 | ---- | C] () -- C:\Users\BrugerAdmin\AppData\Roaming\ANIWZCS{675E32AB-FCA0-451D-9FFF-7170DA93B73B} [2010-06-07 20:49:00 | 000,315,392 | ---- | C] () -- C:\Windows\System32\ANIOApi.dll [2010-06-07 20:48:52 | 000,258,048 | ---- | C] () -- C:\Windows\System32\wlanapp.dll [2010-06-07 20:48:52 | 000,204,800 | ---- | C] () -- C:\Windows\System32\aIPH.dll [2010-06-07 20:48:52 | 000,049,152 | ---- | C] () -- C:\Windows\System32\JJAKEn.dll [2010-06-07 20:48:52 | 000,049,152 | ---- | C] () -- C:\Windows\System32\AQCKGen.dll [2010-06-07 20:48:52 | 000,045,115 | ---- | C] () -- C:\Windows\System32\ANICtl.dll [2010-06-07 20:48:46 | 000,724,992 | ---- | C] () -- C:\Windows\System32\ANIOWPS.dll [2010-06-07 20:47:31 | 000,012,800 | ---- | C] () -- C:\Windows\System32\drivers\anodlwf.sys [2010-05-05 16:07:14 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2010-04-21 15:30:38 | 000,000,118 | ---- | C] () -- C:\Windows\System32\MRT.INI [2010-03-12 00:08:32 | 000,000,596 | ---- | C] () -- C:\Windows\wininit.ini [2009-06-05 22:02:19 | 000,000,000 | ---- | C] () -- C:\Users\BrugerAdmin\AppData\Local\rx_image.Cache [2008-07-21 11:05:49 | 000,032,768 | ---- | C] () -- C:\Windows\unvise32.dll [2008-05-13 12:39:14 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll [2008-05-13 12:38:01 | 000,021,840 | ---- | C] () -- C:\Windows\System32\SIntfNT.dll [2008-05-13 12:38:01 | 000,017,212 | ---- | C] () -- C:\Windows\System32\SIntf32.dll [2008-05-13 12:38:01 | 000,012,067 | ---- | C] () -- C:\Windows\System32\SIntf16.dll [2008-02-29 22:40:03 | 000,003,584 | ---- | C] () -- C:\Users\BrugerAdmin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2007-09-13 12:17:52 | 000,001,525 | ---- | C] () -- C:\ProgramData\hpzinstall.log [2007-09-13 12:12:51 | 000,003,758 | ---- | C] () -- C:\Windows\HCWPNP.INI [2007-09-13 12:12:32 | 000,066,048 | ---- | C] () -- C:\Windows\System32\hcwxds.dll [2007-09-13 12:04:27 | 000,327,680 | ---- | C] () -- C:\Windows\System32\pythoncom25.dll [2007-09-13 12:04:27 | 000,102,400 | ---- | C] () -- C:\Windows\System32\pywintypes25.dll [2007-07-19 17:07:52 | 000,000,000 | ---- | C] () -- C:\Windows\System32\px.ini [2006-12-13 23:01:36 | 000,520,192 | ---- | C] () -- C:\Windows\System32\CddbPlaylist2Roxio.dll [2006-12-13 23:01:36 | 000,204,800 | ---- | C] () -- C:\Windows\System32\CddbFileTaggerRoxio.dll [2006-11-02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006-11-02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006-06-23 10:09:34 | 000,019,968 | R--- | C] () -- C:\Windows\System32\cpuinf32.dll [color=#E56717]========== LOP Check ==========[/color] [2008-10-03 15:32:06 | 000,000,000 | ---D | M] -- C:\Users\BrugerAdmin\AppData\Roaming\Any Video Converter [2009-01-16 14:21:48 | 000,000,000 | ---D | M] -- C:\Users\BrugerAdmin\AppData\Roaming\DriverCure [2010-06-23 13:58:15 | 000,000,000 | ---D | M] -- C:\Users\BrugerAdmin\AppData\Roaming\DVDVideoSoftIEHelpers [2008-12-23 18:37:55 | 000,000,000 | ---D | M] -- C:\Users\BrugerAdmin\AppData\Roaming\FrostWire [2008-12-27 20:43:27 | 000,000,000 | ---D | M] -- C:\Users\BrugerAdmin\AppData\Roaming\GHISLER [2008-02-29 22:49:35 | 000,000,000 | ---D | M] -- C:\Users\BrugerAdmin\AppData\Roaming\Grisoft [2009-02-07 12:14:13 | 000,000,000 | ---D | M] -- C:\Users\BrugerAdmin\AppData\Roaming\LEGO Company [2008-10-03 15:47:37 | 000,000,000 | ---D | M] -- C:\Users\BrugerAdmin\AppData\Roaming\LimeWire [2009-11-11 00:05:01 | 000,000,000 | ---D | M] -- C:\Users\BrugerAdmin\AppData\Roaming\NCH Swift Sound [2008-12-25 13:00:17 | 000,000,000 | ---D | M] -- C:\Users\BrugerAdmin\AppData\Roaming\Serif [2009-12-06 19:29:48 | 000,000,000 | ---D | M] -- C:\Users\BrugerAdmin\AppData\Roaming\Texas Instruments [2009-01-10 13:18:05 | 000,000,000 | ---D | M] -- C:\Users\BrugerAdmin\AppData\Roaming\uTorrent [2010-01-31 18:37:48 | 000,000,000 | ---D | M] -- C:\Users\Henrik\AppData\Roaming\FrostWire [2008-03-02 12:58:27 | 000,000,000 | ---D | M] -- C:\Users\Henrik\AppData\Roaming\Grisoft [2010-08-16 21:58:13 | 000,000,000 | ---D | M] -- C:\Users\Henrik\AppData\Roaming\gtk-2.0 [2008-10-04 13:18:38 | 000,000,000 | ---D | M] -- C:\Users\Henrik\AppData\Roaming\LimeWire [2009-11-11 00:04:44 | 000,000,000 | ---D | M] -- C:\Users\Henrik\AppData\Roaming\NCH Swift Sound [2010-06-09 12:25:39 | 000,000,000 | ---D | M] -- C:\Users\Henrik\AppData\Roaming\Politiken [2009-12-06 19:35:59 | 000,000,000 | ---D | M] -- C:\Users\Henrik\AppData\Roaming\Texas Instruments [2009-12-06 19:36:10 | 000,000,000 | ---D | M] -- C:\Users\Henrik\AppData\Roaming\TI-Nspire [2010-02-28 21:03:45 | 000,000,000 | ---D | M] -- C:\Users\Henrik\AppData\Roaming\Ubisoft [2010-01-16 22:44:28 | 000,000,000 | ---D | M] -- C:\Users\Henrik\AppData\Roaming\uTorrent [2008-03-16 22:44:54 | 000,000,000 | ---D | M] -- C:\Users\Preben\AppData\Roaming\Grisoft [2010-04-25 21:42:58 | 000,000,000 | ---D | M] -- C:\Users\Preben\AppData\Roaming\Serif [2008-10-03 15:27:35 | 000,000,000 | ---D | M] -- C:\Users\Søren\AppData\Roaming\Any Video Converter [2009-08-13 15:25:00 | 000,000,000 | ---D | M] -- C:\Users\Søren\AppData\Roaming\FrostWire [2008-03-04 15:54:05 | 000,000,000 | ---D | M] -- C:\Users\Søren\AppData\Roaming\Grisoft [2009-02-07 12:14:26 | 000,000,000 | ---D | M] -- C:\Users\Søren\AppData\Roaming\LEGO Company [2008-10-03 16:26:37 | 000,000,000 | ---D | M] -- C:\Users\Søren\AppData\Roaming\LimeWire [2009-04-01 13:46:35 | 000,000,000 | ---D | M] -- C:\Users\Søren\AppData\Roaming\PeerNetworking [2008-10-01 14:20:10 | 000,000,000 | ---D | M] -- C:\Users\Søren\AppData\Roaming\Three Rings Design [2010-03-02 18:06:10 | 000,000,000 | ---D | M] -- C:\Users\Søren\AppData\Roaming\Ubisoft [2010-07-21 14:21:16 | 000,000,376 | ---- | M] () -- C:\WINDOWS\Tasks\Install_NSS.job [2010-08-26 23:36:05 | 000,000,254 | ---- | M] () -- C:\WINDOWS\Tasks\PersSecurity.job [2010-08-26 23:24:10 | 000,032,658 | ---- | M] () -- C:\WINDOWS\Tasks\SCHEDLGU.TXT [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:DFC5A2B2 @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8 < End of report >