Malwarebytes Anti-Malware 1.60.0.1800
http://www.malwarebytes.org
Database version: v2012.01.15.01
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Marianne :: MARIANNE-BDD3A4 [administrator]
15-01-2012 10:13:05
mbam-log-2012-01-15 (10-13-05).txt
Skanningstype: Hurtig skanning
Skanningsmuligheder valgt: Hukommelse | Opstart | Registreringsdatabasen | Filsystem | Heuristics/Ekstra | Heuristics/Shuriken | PUP | PUM
Skanningsmuligheder som er deaktiverede: P2P
Objekter skannet: 168340
Tid gået: 7 minut(ter), 11 sekund(er)
Hukommelses Processorer Inficeret: 0
(Ingen skadelige objekter blev fundet)
Hukommelses Moduler Inficeret: 0
(Ingen skadelige objekter blev fundet)
Registreringsdatabasenøgler Inficeret: 0
(Ingen skadelige objekter blev fundet)
Registreringsdatabaseværdier Inficeret: 0
(Ingen skadelige objekter blev fundet)
Registreringsdatabasedata Objekter Inficeret: 0
(Ingen skadelige objekter blev fundet)
Inficerede Mapper: 0
(Ingen skadelige objekter blev fundet)
Inficerede Filer: 0
(Ingen skadelige objekter blev fundet)
(færdig)
OTL logfile created on: 15-01-2012 11:05:32 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Marianne\Skrivebord
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000406 | Country: Danmark | Language: DAN | Date Format: dd-MM-yyyy
2,00 Gb Total Physical Memory | 1,38 Gb Available Physical Memory | 69,05% Memory free
3,85 Gb Paging File | 3,08 Gb Available in Paging File | 80,13% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmer
Drive C: | 39,06 Gb Total Space | 17,53 Gb Free Space | 44,88% Space Free | Partition Type: NTFS
Drive D: | 194,69 Gb Total Space | 192,04 Gb Free Space | 98,64% Space Free | Partition Type: NTFS
Drive F: | 14,92 Gb Total Space | 6,89 Gb Free Space | 46,21% Space Free | Partition Type: FAT32
Computer Name: MARIANNE-BDD3A4 | User Name: Marianne | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012-01-15 11:04:16 | 000,584,192 |——| M] (OldTimer Tools)—C:\Documents and Settings\Marianne\Skrivebord\OTL.exe
PRC - [2011-12-20 12:41:52 | 000,215,688 |——| M] (SPAMfighter ApS)—C:\Programmer\Fighters\SPAMfighter\sfus.exe
PRC - [2011-12-20 12:41:48 | 001,197,704 |——| M] (SPAMfighter ApS)—C:\Programmer\Fighters\SPAMfighter\sfagent.exe
PRC - [2011-12-13 16:08:44 | 001,324,680 |——| M] (SPAMfighter ApS)—C:\Programmer\Fighters\FighterSuiteService.exe
PRC - [2011-12-13 15:35:08 | 001,450,120 |——| M] (SPAMfighter ApS)—C:\Programmer\Fighters\Tray\FightersTray.exe
PRC - [2011-12-08 01:36:42 | 000,421,736 |——| M] (Apple Inc.)—D:\iTunesHelper.exe
PRC - [2011-12-06 10:06:50 | 001,088,280 |——| M] (Mischel Internet Security)—C:\Programmer\TrojanHunter 5.5\THGuard.exe
PRC - [2011-11-02 16:51:54 | 003,508,624 |——| M] (Samsung Electronics Co., Ltd.)—C:\Programmer\Samsung\Kies\KiesTrayAgent.exe
PRC - [2011-10-26 10:20:48 | 000,273,528 |——| M] (RealNetworks, Inc.)—C:\Programmer\Real\RealPlayer\Update\realsched.exe
PRC - [2011-10-24 21:32:00 | 000,055,144 |——| M] (Apple Inc.)—C:\Programmer\Fælles filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2011-09-23 18:08:19 | 000,086,224 |——| M] (Avira Operations GmbH & Co. KG)—C:\Programmer\Avira\AntiVir Desktop\sched.exe
PRC - [2011-09-23 18:01:09 | 000,110,032 |——| M] (Avira Operations GmbH & Co. KG)—C:\Programmer\Avira\AntiVir Desktop\avguard.exe
PRC - [2011-09-23 11:38:21 | 000,258,512 |——| M] (Avira Operations GmbH & Co. KG)—C:\Programmer\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011-09-16 02:34:43 | 000,080,336 |——| M] (Avira Operations GmbH & Co. KG)—C:\Programmer\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011-05-25 10:36:45 | 000,830,808 |——| M] (Preventon Technologies Limited)—C:\Programmer\Fælles filer\Common Toolkit Suite\AVEngine\AVScanningService.exe
PRC - [2011-05-25 10:36:45 | 000,142,768 |——| M] (Preventon Technologies Limited)—C:\Programmer\Fælles filer\Common Toolkit Suite\AVEngine\AVWatchService.exe
PRC - [2011-01-10 15:24:20 | 000,993,848 |——| M] (Secunia)—D:\PSI\psia.exe
PRC - [2011-01-10 15:24:20 | 000,399,416 |——| M] (Secunia)—D:\PSI\sua.exe
PRC - [2011-01-10 15:24:20 | 000,291,896 |——| M] (Secunia)—D:\PSI\psi_tray.exe
PRC - [2009-02-10 08:01:49 | 000,116,104 |——| M] ()—C:\Programmer\Canon\IJPLM\ijplmsvc.exe
PRC - [2008-04-14 17:05:49 | 001,034,752 |——| M] (Microsoft Corporation)—C:\WINDOWS\explorer.exe
PRC - [2008-03-09 11:20:26 | 000,071,096 |——| M] ()—C:\Programmer\CDBurnerXP\NMSAccessU.exe
PRC - [2008-02-29 16:03:46 | 001,481,968 |——| M] (SUPERAntiSpyware.com)—C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
PRC - [2006-01-21 13:31:46 | 000,118,784 |——| M] (Rainy)—C:\Programmer\Rainlendar\Rainlendar.exe
PRC - [2004-07-29 03:02:34 | 001,269,760 |——| M] (Symantec Corporation)—C:\Programmer\Symantec\Norton Ghost\Agent\PQV2iSvc.exe
PRC - [2004-07-29 01:53:58 | 000,053,248 |——| M] (GEAR Software)—C:\WINDOWS\system32\gearsec.exe
PRC - [2003-06-19 23:25:00 | 000,322,120 |——| M] (Microsoft Corporation)—C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
========== Modules (No Company Name) ==========
MOD - [2012-01-14 09:12:52 | 002,019,976 |——| M] ()—C:\Programmer\Fighters\SPAMfighter\sfse.dll
MOD - [2011-12-20 12:42:14 | 000,549,512 |——| M] ()—C:\Programmer\Fighters\SPAMfighter\sfsg.dll
MOD - [2011-09-16 02:05:58 | 000,398,288 |——| M] ()—C:\Programmer\Avira\AntiVir Desktop\sqlite3.dll
MOD - [2011-09-05 18:05:00 | 000,300,544 |——| M] ()—C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\PDFShell.DAN
MOD - [2011-06-24 21:56:36 | 000,087,328 |——| M] ()—C:\Programmer\Fælles filer\Apple\Apple Application Support\zlib1.dll
MOD - [2011-06-24 21:56:14 | 001,241,888 |——| M] ()—C:\Programmer\Fælles filer\Apple\Apple Application Support\libxml2.dll
MOD - [2011-05-25 10:36:45 | 002,121,728 |——| M] ()—C:\Programmer\Fælles filer\Common Toolkit Suite\AVEngine\QtCore4.dll
MOD - [2011-05-25 10:36:45 | 000,909,312 |——| M] ()—C:\Programmer\Fælles filer\Common Toolkit Suite\AVEngine\QtNetwork4.dll
MOD - [2011-05-25 10:36:45 | 000,344,064 |——| M] ()—C:\Programmer\Fælles filer\Common Toolkit Suite\AVEngine\QtXml4.dll
MOD - [2009-02-10 08:01:49 | 000,116,104 |——| M] ()—C:\Programmer\Canon\IJPLM\ijplmsvc.exe
MOD - [2008-03-09 11:20:26 | 000,071,096 |——| M] ()—C:\Programmer\CDBurnerXP\NMSAccessU.exe
MOD - [2008-03-01 06:10:49 | 000,008,704 |——| M] ()—C:\Programmer\Unlocker\UnlockerCOM.dll
MOD - [2006-01-21 13:31:46 | 000,176,128 |——| M] ()—C:\Programmer\Rainlendar\Plugins\iCalPlugin.dll
MOD - [2006-01-21 13:31:46 | 000,065,536 |——| M] ()—C:\Programmer\Rainlendar\Plugins\IniFormatPlugin.dll
MOD - [2006-01-21 13:31:46 | 000,053,248 |——| M] ()—C:\Programmer\Rainlendar\Plugins\OutlookPlugin.dll
MOD - [2006-01-21 13:31:46 | 000,045,056 |——| M] ()—C:\Programmer\Rainlendar\Plugins\ServerPlugin.dll
MOD - [2006-01-21 13:31:44 | 000,573,440 |——| M] ()—C:\Programmer\Rainlendar\Rainlendar.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped]——(Olympus DVR Service)
SRV - File not found [On_Demand | Stopped]——(AppMgmt)
SRV - [2011-12-20 12:41:52 | 000,215,688 |——| M] (SPAMfighter ApS) [Auto | Running]—C:\Programmer\Fighters\SPAMfighter\sfus.exe—(SPAMfighter Update Service)
SRV - [2011-12-13 16:08:44 | 001,324,680 |——| M] (SPAMfighter ApS) [Auto | Running]—C:\Programmer\Fighters\FighterSuiteService.exe—(Suite Service)
SRV - [2011-10-24 21:32:00 | 000,055,144 |——| M] (Apple Inc.) [Auto | Running]—C:\Programmer\Fælles filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe—(Apple Mobile Device)
SRV - [2011-09-23 18:08:19 | 000,086,224 |——| M] (Avira Operations GmbH & Co. KG) [Auto | Running]—C:\Programmer\Avira\AntiVir Desktop\sched.exe—(AntiVirSchedulerService)
SRV - [2011-09-23 18:01:09 | 000,110,032 |——| M] (Avira Operations GmbH & Co. KG) [Auto | Running]—C:\Programmer\Avira\AntiVir Desktop\avguard.exe—(AntiVirService)
SRV - [2011-05-25 10:36:45 | 000,830,808 |——| M] () [Auto | Running]—C:/Programmer/Fælles filer/Common Toolkit Suite/AVEngine/AVScanningService.exe—(AV Engine Scanning Service)
SRV - [2011-05-25 10:36:45 | 000,142,768 |——| M] () [Auto | Running]—C:/Programmer/Fælles filer/Common Toolkit Suite/AVEngine/AVWatchService.exe—(AV Watch Service)
SRV - [2011-01-10 15:24:20 | 000,993,848 |——| M] (Secunia) [Auto | Running]—D:\PSI\PSIA.exe—(Secunia PSI Agent)
SRV - [2011-01-10 15:24:20 | 000,399,416 |——| M] (Secunia) [Auto | Running]—D:\PSI\sua.exe—(Secunia Update Agent)
SRV - [2010-01-15 13:49:20 | 000,227,232 |——| M] (McAfee, Inc.) [On_Demand | Stopped]—C:\Programmer\McAfee Security Scan\2.0.181\McCHSvc.exe—(McComponentHostService)
SRV - [2009-07-20 12:28:10 | 000,121,360 |——| M] (Logitech, Inc.) [On_Demand | Stopped]—C:\Programmer\Fælles filer\Logishrd\Bluetooth\LBTServ.exe—(LBTServ)
SRV - [2009-02-19 21:10:54 | 000,238,968 |——| M] (Symantec Corporation) [Disabled | Stopped]—C:\Programmer\Symantec\LiveUpdate\AluSchedulerSvc.exe—(Automatic LiveUpdate Scheduler)
SRV - [2009-02-19 21:09:53 | 003,220,856 |——| M] (Symantec Corporation) [On_Demand | Stopped]—C:\Programmer\Symantec\LiveUpdate\LuComServer_3_4.EXE—(LiveUpdate)
SRV - [2009-02-10 08:01:49 | 000,116,104 |——| M] () [Auto | Running]—C:\Programmer\Canon\IJPLM\ijplmsvc.exe—(IJPLMSVC)
SRV - [2008-03-09 11:20:26 | 000,071,096 |——| M] () [Auto | Running]—C:\Programmer\CDBurnerXP\NMSAccessU.exe—(NMSAccessU)
SRV - [2004-07-29 03:02:34 | 001,269,760 |——| M] (Symantec Corporation) [Auto | Running]—C:\Programmer\Symantec\Norton Ghost\Agent\PQV2iSvc.exe—(Norton Ghost)
SRV - [2004-07-29 01:53:58 | 000,053,248 |——| M] (GEAR Software) [Auto | Running]—C:\WINDOWS\system32\gearsec.exe—(GEARSecurity)
SRV - [2003-06-19 23:25:00 | 000,322,120 |——| M] (Microsoft Corporation) [Auto | Running]—C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE—(MDM)
========== Driver Services (SafeList) ==========
DRV - [2012-01-14 07:10:57 | 000,134,856 |——| M] (Avira GmbH) [Kernel | System | Running]—C:\WINDOWS\system32\drivers\avipbb.sys—(avipbb)
DRV - [2011-09-15 23:55:04 | 000,036,000 |——| M] (Avira GmbH) [Kernel | System | Running]—C:\WINDOWS\system32\drivers\avkmgr.sys—(avkmgr)
DRV - [2011-09-15 23:55:03 | 000,074,640 |——| M] (Avira GmbH) [File_System | Auto | Running]—C:\WINDOWS\system32\drivers\avgntflt.sys—(avgntflt)
DRV - [2010-12-24 13:45:10 | 000,010,264 |——| M] () [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\avfsfilter.sys—(AVFSFilter)
DRV - [2010-11-09 14:35:30 | 000,021,992 |——| M] (CPUID) [Kernel | Auto | Running]—C:\WINDOWS\system32\drivers\cpuz135_x32.sys—(cpuz135)
DRV - [2010-09-01 09:30:58 | 000,015,544 |——| M] (Secunia) [File_System | On_Demand | Running]—C:\WINDOWS\system32\drivers\psi_mf.sys—(PSI)
DRV - [2010-06-17 15:14:27 | 000,028,520 |——| M] (Avira GmbH) [Kernel | System | Running]—C:\WINDOWS\system32\drivers\ssmdrv.sys—(ssmdrv)
DRV - [2009-06-17 17:56:32 | 000,028,560 |——| M] (Logitech, Inc.) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\LUsbFilt.sys—(LUsbFilt)
DRV - [2009-06-17 17:56:24 | 000,079,248 |——| M] (Logitech, Inc.) [Kernel | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\LMouKE.Sys—(LMouKE)
DRV - [2009-06-17 17:56:16 | 000,037,392 |——| M] (Logitech, Inc.) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\LMouFilt.Sys—(LMouFilt)
DRV - [2009-06-17 17:56:06 | 000,035,472 |——| M] (Logitech, Inc.) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\LHidFilt.Sys—(LHidFilt)
DRV - [2009-06-17 17:55:34 | 000,010,384 |——| M] (Logitech, Inc.) [Kernel | Auto | Running]—C:\WINDOWS\system32\drivers\LBeepKE.sys—(LBeepKE)
DRV - [2009-06-17 17:55:26 | 000,063,248 |——| M] (Logitech, Inc.) [Kernel | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\L8042mou.Sys—(L8042mou)
DRV - [2009-06-17 17:55:18 | 000,020,240 |——| M] (Logitech, Inc.) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\L8042Kbd.sys—(L8042Kbd)
DRV - [2008-04-14 19:57:10 | 000,009,760 |——| M] () [Kernel | System | Running]—C:\Programmer\i-Menu\hugoio.sys—(hugoio)
DRV - [2008-04-13 19:45:29 | 000,010,624 |——| M] (Microsoft Corporation) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\gameenum.sys—(gameenum)
DRV - [2008-02-29 16:03:48 | 000,008,944 |——| M] () [Kernel | System | Running]—C:\Programmer\SUPERAntiSpyware\sasdifsv.sys—(SASDIFSV)
DRV - [2008-02-29 16:03:46 | 000,051,440 |——| M] () [Kernel | System | Running]—C:\Programmer\SUPERAntiSpyware\SASKUTIL.SYS—(SASKUTIL)
DRV - [2006-07-02 12:39:40 | 000,036,864 |——| M] (Advanced Micro Devices) [Kernel | System | Running]—C:\WINDOWS\system32\drivers\AmdK8.sys—(AmdK8)
DRV - [2006-04-17 09:31:26 | 004,262,912 | R—- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\RtkHDAud.Sys—(IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006-02-16 16:51:08 | 000,004,096 | R—- | M] (SuperAdBlocker, Inc.) [Kernel | On_Demand | Running]—C:\Programmer\SUPERAntiSpyware\SASENUM.SYS—(SASENUM)
DRV - [2005-03-22 20:36:40 | 000,028,672 |——| M] (ULi Electronics Inc.) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\ULILAN51.SYS—(ULI5261XP)
DRV - [2004-07-29 03:13:28 | 000,046,779 |——| M] (PowerQuest Corporation) [Kernel | System | Running]—C:\WINDOWS\System32\drivers\PQIMount.sys—(PQIMount)
DRV - [2004-07-29 02:33:08 | 000,138,780 |——| M] (StorageCraft) [File_System | Boot | Running]—C:\WINDOWS\System32\drivers\PQV2i.sys—(PQV2i)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0
IE - HKU\S-1-5-21-1078081533-1425521274-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
IE - HKU\S-1-5-21-1078081533-1425521274-839522115-1004\..\URLSearchHook: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - No CLSID value found
IE - HKU\S-1-5-21-1078081533-1425521274-839522115-1004\..\URLSearchHook: {f999a48b-1950-4d81-9971-79018f807b4b} - No CLSID value found
IE - HKU\S-1-5-21-1078081533-1425521274-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0
IE - HKU\S-1-5-21-1078081533-1425521274-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyOverride” = *.local
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Programmer\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Programmer\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programmer\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Programmer\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.669: c:\programmer\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.669: c:\programmer\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.669: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.669: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.669: c:\programmer\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programmer\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programmer\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programmer\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011-10-26 10:21:24 | 000,000,000 |—-D | M]
O1 HOSTS File: ([2011-09-26 07:07:30 | 000,000,723 |——| M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Programmer\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Fravalg af annonceringscookie) - {8E425EB4-ADBD-4816-B1E8-49BB9DECF034} - C:\Programmer\Google\Advertising Cookie Opt-out\opt_out.dll (Google Inc)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O2 - BHO: (Sammsoft Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programmer\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Programmer\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (Sammsoft Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programmer\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-21-1078081533-1425521274-839522115-1004\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Programmer\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKU\S-1-5-21-1078081533-1425521274-839522115-1004\..\Toolbar\WebBrowser: (Sammsoft Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programmer\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [APSDaemon] C:\Programmer\Fælles filer\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Programmer\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [CommonToolkitTray] C:\Programmer\Fighters\Tray\FightersTray.exe (SPAMfighter ApS)
O4 - HKLM..\Run: [iTunesHelper] D:\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [KiesHelper] C:\Programmer\Samsung\Kies\KiesHelper.exe (Samsung)
O4 - HKLM..\Run: [KiesTrayAgent] C:\Programmer\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [sfagent] C:\Programmer\Fighters\SPAMfighter\sfagent.exe (SPAMfighter ApS)
O4 - HKLM..\Run: [StartupDelayer] C:\Programmer\r2 Studios\Startup Delayer\Startup Launcher.exe (r2 Studios)
O4 - HKLM..\Run: [THGuard] C:\Programmer\TrojanHunter 5.5\THGuard.exe (Mischel Internet Security)
O4 - HKLM..\Run: [TkBellExe] C:\programmer\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-1078081533-1425521274-839522115-1004..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Secunia PSI Tray.lnk = D:\PSI\psi_tray.exe (Secunia)
O4 - Startup: C:\Documents and Settings\Marianne\Menuen Start\Programmer\Start\Rainlendar.lnk = C:\Programmer\Rainlendar\Rainlendar.exe (Rainy)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1078081533-1425521274-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&ksporter; til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programmer\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-1078081533-1425521274-839522115-1004\..Trusted Domains: spks.dk ([]https in Websteder, du har tillid til)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1263033202874 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1263565151968 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/win/ActiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.3.0/GarminAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 193.162.153.164 194.239.134.83
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C438D674-B1EB-40CF-BAAD-21B722C01AE1}: DhcpNameServer = 193.162.153.164 194.239.134.83
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Programmer\SUPERAntiSpyware\SASWINLO.dll) - C:\Programmer\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\programmer\fælles filer\logishrd\bluetooth\LBTWlgn.dll) - c:\Programmer\Fælles filer\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop Components:0 (Min aktuelle startside) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Marianne\Lokale indstillinger\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Marianne\Lokale indstillinger\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Programmer\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O30 - LSA: Authentication Packages - (ows\s) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010-01-09 11:13:43 | 000,000,000 |——| M] () - C:\AUTOEXEC.BAT—[ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open]—“%1” %*
O35 - HKLM\..exefile [open]—“%1” %*
O37 - HKLM\...com [@ = comfile]—“%1” %*
O37 - HKLM\...exe [@ = exefile]—“%1” %*
========== Files/Folders - Created Within 30 Days ==========
[2012-01-15 11:04:13 | 000,584,192 |——| C] (OldTimer Tools)—C:\Documents and Settings\Marianne\Skrivebord\OTL.exe
[2012-01-14 18:43:30 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Menuen Start\Programmer\r2 Studios
[2012-01-14 18:43:29 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\r2 Studios
[2012-01-14 18:42:42 | 000,000,000 |—-D | C]—C:\Programmer\r2 Studios
[2012-01-14 18:36:34 | 005,044,592 |——| C] (Auslogics Software Pty Ltd )—C:\Documents and Settings\Marianne\Skrivebord\disk-defrag-setup.exe
[2012-01-14 12:28:50 | 000,000,000 |—-D | C]—C:\WINDOWS\System32\NtmsData
[2012-01-14 09:10:41 | 002,455,384 |——| C] (SPAMfighter ApS)—C:\Documents and Settings\Marianne\Skrivebord\spamfighter_web.exe
[2012-01-13 13:42:48 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2012-01-13 13:42:44 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Menuen Start\Programmer\SUPERAntiSpyware
[2012-01-13 13:42:42 | 000,000,000 |—-D | C]—C:\Programmer\SUPERAntiSpyware
[2012-01-13 13:42:41 | 000,000,000 |—-D | C]—C:\Documents and Settings\Marianne\Application Data\SUPERAntiSpyware.com
[2012-01-13 13:42:16 | 000,000,000 |—-D | C]—C:\Programmer\Fælles filer\Wise Installation Wizard
[2012-01-12 23:06:48 | 000,000,000 |—-D | C]—C:\Documents and Settings\Marianne\Application Data\Malwarebytes
[2012-01-12 23:06:30 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Menuen Start\Programmer\Malwarebytes’ Anti-Malware
[2012-01-12 23:06:25 | 000,020,464 |——| C] (Malwarebytes Corporation)—C:\WINDOWS\System32\drivers\mbam.sys
[2012-01-12 23:06:25 | 000,000,000 |—-D | C]—C:\Programmer\Malwarebytes’ Anti-Malware
[2012-01-12 23:06:25 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012-01-12 19:08:26 | 000,000,000 |—-D | C]—C:\Programmer\ESET
[2012-01-12 19:02:03 | 000,000,000 |—-D | C]—C:\Documents and Settings\Marianne\Application Data\Avira
[2012-01-12 19:01:42 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Menuen Start\Programmer\Avira
[2012-01-12 19:01:29 | 000,028,520 |——| C] (Avira GmbH)—C:\WINDOWS\System32\drivers\ssmdrv.sys
[2012-01-12 19:01:26 | 000,036,000 |——| C] (Avira GmbH)—C:\WINDOWS\System32\drivers\avkmgr.sys
[2012-01-12 19:01:25 | 000,134,856 |——| C] (Avira GmbH)—C:\WINDOWS\System32\drivers\avipbb.sys
[2012-01-12 19:01:25 | 000,074,640 |——| C] (Avira GmbH)—C:\WINDOWS\System32\drivers\avgntflt.sys
[2012-01-12 19:01:22 | 000,000,000 |—-D | C]—C:\Programmer\Avira
[2012-01-12 19:01:22 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\Avira
[2012-01-12 19:00:13 | 000,000,000 | RH-D | C]—C:\Documents and Settings\Marianne\Recent
[2012-01-12 18:58:41 | 000,000,000 |—-D | C]—C:\Programmer\CCleaner
[2012-01-12 18:38:28 | 000,000,000 |—-D | C]—C:\Documents and Settings\Marianne\Skrivebord\Spywarefri forum
[2012-01-06 18:22:47 | 000,000,000 |—-D | C]—C:\Documents and Settings\Marianne\Dokumenter\Mail_20120106
[2012-01-05 18:46:32 | 000,000,000 |—-D | C]—C:\Programmer\Uniblue(2)
[2012-01-05 12:04:50 | 000,000,000 |—-D | C]—C:\Documents and Settings\Marianne\Application Data\licenses
[2012-01-05 12:04:47 | 000,000,000 |—-D | C]—C:\Documents and Settings\Marianne\Application Data\PCMM2009
[2012-01-05 12:04:40 | 000,000,000 |—-D | C]—C:\Documents and Settings\Marianne\Application Data\PCMM2011
[2012-01-05 09:35:04 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
[2012-01-04 16:46:33 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Menuen Start\Programmer\BurnAware Free
[2012-01-04 16:45:54 | 000,000,000 |—-D | C]—C:\Documents and Settings\Marianne\Lokale indstillinger\Application Data\AskToolbar(2)
[2012-01-04 16:12:35 | 000,000,000 |—-D | C]—C:\Documents and Settings\Marianne\Dokumenter\help
[2012-01-03 18:47:58 | 000,000,000 |—-D | C]—C:\Documents and Settings\Marianne\Dokumenter\Songs
[2012-01-03 18:47:58 | 000,000,000 |—-D | C]—C:\Documents and Settings\Marianne\Dokumenter\Settings
[2012-01-03 18:47:58 | 000,000,000 |—-D | C]—C:\Documents and Settings\Marianne\Dokumenter\Sets
[2012-01-03 18:47:58 | 000,000,000 |—-D | C]—C:\Documents and Settings\Marianne\Dokumenter\Backgrounds
[2012-01-03 18:47:40 | 000,000,000 |—-D | C]—C:\Documents and Settings\Marianne\Application Data\OpenSong
[2011-12-26 16:25:31 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\{553764F8-6599-495D-B99E-4797D3DFC558}
[2011-12-22 18:44:52 | 000,000,000 |—-D | C]—C:\Documents and Settings\Marianne\Dokumenter\HØJTIDER
[2011-12-21 16:34:10 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Menuen Start\Programmer\iTunes
[2011-12-21 16:33:22 | 000,000,000 |—-D | C]—C:\Programmer\iPod
[2011-12-20 18:17:01 | 000,000,000 |—-D | C]—C:\Documents and Settings\Marianne\Application Data\AVG
[2011-12-20 18:16:00 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\TEMP
[2011-12-20 18:15:50 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Menuen Start\Programmer\AVG PC Tuneup 2011
[2011-12-18 09:56:43 | 000,000,000 |—-D | C]—C:\Documents and Settings\Marianne\Application Data\TrojanHunter
[2011-12-18 09:44:57 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Menuen Start\Programmer\TrojanHunter
[2011-12-18 09:44:56 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\TrojanHunter
[2011-12-18 09:44:49 | 000,000,000 |—-D | C]—C:\Programmer\TrojanHunter 5.5
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012-01-15 11:06:00 | 000,000,234 |——| M] ()—C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2012-01-15 11:04:16 | 000,584,192 |——| M] (OldTimer Tools)—C:\Documents and Settings\Marianne\Skrivebord\OTL.exe
[2012-01-15 10:57:00 | 000,000,918 |——| M] ()—C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012-01-15 10:02:16 | 000,000,914 |——| M] ()—C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012-01-15 10:02:15 | 000,000,264 |——| M] ()—C:\WINDOWS\tasks\RegistryBooster.job
[2012-01-15 10:01:46 | 000,002,048 |—S- | M] ()—C:\WINDOWS\bootstat.dat
[2012-01-15 10:00:14 | 000,000,763 |——| M] ()—C:\Documents and Settings\All Users\Skrivebord\Malwarebytes Anti-Malware.lnk
[2012-01-15 07:43:18 | 000,000,420 | -H—| M] ()—C:\WINDOWS\tasks\User_Feed_Synchronization-{E707ECCA-F45E-4547-9AEB-9D53B738D977}.job
[2012-01-14 18:40:41 | 000,466,164 |——| M] ()—C:\Documents and Settings\Marianne\Skrivebord\keykeep1 husker passwords.exe
[2012-01-14 18:36:47 | 005,044,592 |——| M] (Auslogics Software Pty Ltd )—C:\Documents and Settings\Marianne\Skrivebord\disk-defrag-setup.exe
[2012-01-14 09:10:47 | 002,455,384 |——| M] (SPAMfighter ApS)—C:\Documents and Settings\Marianne\Skrivebord\spamfighter_web.exe
[2012-01-14 07:10:57 | 000,134,856 |——| M] (Avira GmbH)—C:\WINDOWS\System32\drivers\avipbb.sys
[2012-01-13 18:46:13 | 000,013,646 |——| M] ()—C:\WINDOWS\System32\wpa.dbl
[2012-01-13 18:45:09 | 000,000,287 |——| M] ()—C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Secunia PSI Tray.lnk
[2012-01-13 18:26:06 | 000,565,010 |——| M] ()—C:\WINDOWS\System32\perfh006.dat
[2012-01-13 18:26:06 | 000,547,700 |——| M] ()—C:\WINDOWS\System32\perfh009.dat
[2012-01-13 18:26:06 | 000,114,940 |——| M] ()—C:\WINDOWS\System32\perfc006.dat
[2012-01-13 18:26:06 | 000,100,030 |——| M] ()—C:\WINDOWS\System32\perfc009.dat
[2012-01-07 17:11:31 | 000,003,751 |——| M] ()—C:\Documents and Settings\Marianne\Dokumenter\harmonika ensemble Godt Nytår fra JP.eml
[2012-01-06 19:27:57 | 000,160,605 |——| M] ()—C:\Documents and Settings\Marianne\Dokumenter\Google Oversæt# pen 2.mht
[2012-01-06 16:32:07 | 000,010,583 |——| M] ()—C:\Documents and Settings\Marianne\Dokumenter\Your RegistryBooster’s ActiveProtection payment is due.eml
[2012-01-05 18:26:06 | 000,289,296 |——| M] ()—C:\WINDOWS\System32\FNTCACHE.DAT
[2011-12-21 14:20:06 | 000,000,278 |——| M] ()—C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011-12-18 09:45:02 | 000,059,392 | R—- | M] ()—C:\WINDOWS\System32\streamhlp.dll
[2011-12-18 09:45:01 | 000,000,757 |——| M] ()—C:\Documents and Settings\Marianne\Application Data\Microsoft\Internet Explorer\Quick Launch\TrojanHunter Scanner.lnk
[2011-12-16 19:00:01 | 000,000,302 |——| M] ()—C:\WINDOWS\tasks\tempoperfectShakeIcon.job
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012-01-15 10:00:14 | 000,000,763 |——| C] ()—C:\Documents and Settings\All Users\Skrivebord\Malwarebytes Anti-Malware.lnk
[2012-01-14 18:40:40 | 000,466,164 |——| C] ()—C:\Documents and Settings\Marianne\Skrivebord\keykeep1 husker passwords.exe
[2012-01-13 18:45:09 | 000,000,287 |——| C] ()—C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Secunia PSI Tray.lnk
[2012-01-07 17:11:31 | 000,003,751 |——| C] ()—C:\Documents and Settings\Marianne\Dokumenter\harmonika ensemble Godt Nytår fra JP.eml
[2012-01-06 19:27:55 | 000,160,605 |——| C] ()—C:\Documents and Settings\Marianne\Dokumenter\Google Oversæt# pen 2.mht
[2012-01-06 16:32:07 | 000,010,583 |——| C] ()—C:\Documents and Settings\Marianne\Dokumenter\Your RegistryBooster’s ActiveProtection payment is due.eml
[2012-01-05 18:46:52 | 000,000,264 |——| C] ()—C:\WINDOWS\tasks\RegistryBooster.job
[2012-01-04 16:46:27 | 000,000,234 |——| C] ()—C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011-12-18 09:45:01 | 000,000,757 |——| C] ()—C:\Documents and Settings\Marianne\Application Data\Microsoft\Internet Explorer\Quick Launch\TrojanHunter Scanner.lnk
[2011-12-18 09:44:49 | 000,059,392 | R—- | C] ()—C:\WINDOWS\System32\streamhlp.dll
[2011-12-04 19:37:31 | 000,631,264 |——| C] ()—C:\Documents and Settings\LocalService\Lokale indstillinger\Application Data\FontCache3.0.0.0.dat
[2011-10-31 11:22:42 | 000,030,568 |——| C] ()—C:\WINDOWS\MusiccityDownload.exe
[2011-10-31 11:22:40 | 000,081,920 |——| C] ()—C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2011-10-31 11:22:40 | 000,065,536 |——| C] ()—C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2011-10-31 11:22:40 | 000,057,344 |——| C] ()—C:\WINDOWS\System32\issacapi_se-2.3.dll
[2011-10-31 11:22:38 | 000,974,848 |——| C] ()—C:\WINDOWS\System32\cis-2.4.dll
[2011-09-20 09:30:19 | 000,000,754 |——| C] ()—C:\WINDOWS\WORDPAD.INI
[2011-08-26 15:34:58 | 000,009,760 |——| C] ()—C:\WINDOWS\System32\drivers\hugoio.sys
[2011-06-22 10:02:20 | 000,000,128 | -H—| C] ()—C:\Documents and Settings\Marianne\Application Data\lakerda1967.sys
[2011-06-22 10:01:49 | 000,010,584 |——| C] ()—C:\Documents and Settings\Marianne\Application Data\docXConverter (3).ini
[2011-04-29 14:20:29 | 000,000,222 |——| C] ()—C:\WINDOWS\Support.ini
[2011-04-16 18:04:55 | 000,252,080 |——| C] ()—C:\WINDOWS\System32\nvdrsdb0.bin
[2011-04-16 18:04:51 | 000,252,080 |——| C] ()—C:\WINDOWS\System32\nvdrsdb1.bin
[2011-04-16 18:04:51 | 000,000,001 |——| C] ()—C:\WINDOWS\System32\nvdrssel.bin
[2011-04-02 17:55:04 | 000,000,000 |——| C] ()—C:\WINDOWS\nsreg.dat
[2011-03-17 11:53:55 | 000,007,680 |——| C] ()—C:\Documents and Settings\Marianne\Lokale indstillinger\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011-03-06 18:20:19 | 000,000,000 |——| C] ()—C:\WINDOWS\Powertxt.INI
[2011-03-03 08:28:43 | 000,000,137 |——| C] ()—C:\Documents and Settings\Marianne\Lokale indstillinger\Application Data\fusioncache.dat
[2011-02-27 19:43:36 | 000,583,026 |——| C] ()—C:\Documents and Settings\LocalService\Lokale indstillinger\Application Data\WPFFontCache_v0400-S-1-5-21-1078081533-1425521274-839522115-1004-0.dat
[2011-02-27 19:43:35 | 000,291,754 |——| C] ()—C:\Documents and Settings\LocalService\Lokale indstillinger\Application Data\WPFFontCache_v0400-System.dat
[2011-01-30 19:04:23 | 000,000,214 |——| C] ()—C:\Documents and Settings\Marianne\Application Data\burnaware.ini
[2011-01-26 15:00:06 | 000,255,344 |——| C] ()—C:\WINDOWS\System32\imagxpr3.dll
[2011-01-26 15:00:06 | 000,065,536 |——| C] ()—C:\WINDOWS\System32\Eztw32.dll
[2011-01-23 18:59:34 | 000,000,164 |——| C] ()—C:\WINDOWS\install.dat
[2010-12-24 13:45:10 | 000,010,264 |——| C] ()—C:\WINDOWS\System32\drivers\avfsfilter.sys
[2010-01-27 10:01:39 | 000,055,484 | -H—| C] ()—C:\WINDOWS\System32\mlfcache.dat
[2010-01-13 16:23:38 | 000,000,079 |——| C] ()—C:\WINDOWS\KDatabase.ini
[2010-01-09 20:57:26 | 000,000,376 |——| C] ()—C:\WINDOWS\ODBC.INI
[2010-01-09 20:26:47 | 002,292,678 |——| C] ()—C:\WINDOWS\System32\nvdata.bin
[2010-01-09 20:23:15 | 000,000,664 |——| C] ()—C:\WINDOWS\System32\d3d9caps.dat
[2010-01-09 20:23:14 | 000,000,552 |——| C] ()—C:\WINDOWS\System32\d3d8caps.dat
[2010-01-09 20:19:23 | 000,135,168 | R—- | C] ()—C:\WINDOWS\System32\RtlCPAPI.dll
[2010-01-09 20:19:23 | 000,040,960 | R—- | C] ()—C:\WINDOWS\System32\ChCfg.exe
[2010-01-09 12:03:33 | 000,004,161 |——| C] ()—C:\WINDOWS\ODBCINST.INI
[2010-01-09 12:02:26 | 000,289,296 |——| C] ()—C:\WINDOWS\System32\FNTCACHE.DAT
[2010-01-09 11:25:52 | 000,028,672 |——| C] ()—C:\WINDOWS\System32\UnLAN.exe
[2010-01-09 11:25:36 | 000,004,463 |——| C] ()—C:\WINDOWS\Ascd_tmp.ini
[2010-01-09 11:25:35 | 000,005,824 |——| C] ()—C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010-01-09 11:15:15 | 000,002,048 |—S- | C] ()—C:\WINDOWS\bootstat.dat
[2010-01-09 11:11:20 | 000,021,644 |——| C] ()—C:\WINDOWS\System32\emptyregdb.dat
[2004-08-27 13:00:00 | 013,107,200 |——| C] ()—C:\WINDOWS\System32\oembios.bin
[2004-08-27 13:00:00 | 000,673,088 |——| C] ()—C:\WINDOWS\System32\mlang.dat
[2004-08-27 13:00:00 | 000,565,010 |——| C] ()—C:\WINDOWS\System32\perfh006.dat
[2004-08-27 13:00:00 | 000,547,700 |——| C] ()—C:\WINDOWS\System32\perfh009.dat
[2004-08-27 13:00:00 | 000,284,912 |——| C] ()—C:\WINDOWS\System32\perfi006.dat
[2004-08-27 13:00:00 | 000,272,128 |——| C] ()—C:\WINDOWS\System32\perfi009.dat
[2004-08-27 13:00:00 | 000,218,003 |——| C] ()—C:\WINDOWS\System32\dssec.dat
[2004-08-27 13:00:00 | 000,114,940 |——| C] ()—C:\WINDOWS\System32\perfc006.dat
[2004-08-27 13:00:00 | 000,100,030 |——| C] ()—C:\WINDOWS\System32\perfc009.dat
[2004-08-27 13:00:00 | 000,046,258 |——| C] ()—C:\WINDOWS\System32\mib.bin
[2004-08-27 13:00:00 | 000,034,026 |——| C] ()—C:\WINDOWS\System32\perfd006.dat
[2004-08-27 13:00:00 | 000,028,626 |——| C] ()—C:\WINDOWS\System32\perfd009.dat
[2004-08-27 13:00:00 | 000,004,569 |——| C] ()—C:\WINDOWS\System32\secupd.dat
[2004-08-27 13:00:00 | 000,004,461 |——| C] ()—C:\WINDOWS\System32\oembios.dat
[2004-08-27 13:00:00 | 000,001,804 |——| C] ()—C:\WINDOWS\System32\dcache.bin
[2004-08-27 13:00:00 | 000,000,741 |——| C] ()—C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2011-02-27 15:54:02 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\ashampoo
[2010-01-11 11:43:59 | 000,000,000 | -H-D | M]—C:\Documents and Settings\All Users\Application Data\CanonBJ
[2012-01-11 20:07:21 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\CanonIJ
[2010-01-11 16:21:01 | 000,000,000 | -H-D | M]—C:\Documents and Settings\All Users\Application Data\CanonIJEGV
[2011-03-10 16:40:49 | 000,000,000 | -H-D | M]—C:\Documents and Settings\All Users\Application Data\CanonIJEPPEX
[2011-01-24 16:14:20 | 000,000,000 | -H-D | M]—C:\Documents and Settings\All Users\Application Data\CanonIJMyPrinter
[2012-01-06 18:48:32 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2010-01-11 11:59:55 | 000,000,000 | -H-D | M]—C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2011-01-24 16:14:23 | 000,000,000 | -H-D | M]—C:\Documents and Settings\All Users\Application Data\CanonIJSolutionMenu
[2011-10-14 11:21:14 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\Cloudmark
[2011-11-01 07:56:42 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\clp
[2011-09-09 17:34:16 | 000,000,000 | -H-D | M]—C:\Documents and Settings\All Users\Application Data\Common Files
[2011-02-08 09:25:52 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\Common Toolkit Suite
[2011-02-09 19:17:21 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\eMachineShop
[2010-01-20 11:30:33 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\explauncher
[2011-02-01 19:12:46 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\F-Secure
[2011-10-22 17:51:15 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\Fighters
[2012-01-12 18:45:28 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\MFAData
[2011-03-03 16:35:29 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2011-09-22 15:53:25 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2012-01-14 18:43:29 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\r2 Studios
[2011-12-04 18:40:58 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\Samsung
[2011-12-21 19:26:25 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\TEMP
[2011-12-18 09:51:32 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\TrojanHunter
[2011-02-21 15:46:20 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012-01-11 20:08:48 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\{553764F8-6599-495D-B99E-4797D3DFC558}
[2012-01-11 20:08:09 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
[2011-07-05 17:21:19 | 000,000,000 | -H-D | M]—C:\Documents and Settings\All Users\Application Data\{E07F9938-EC07-44EC-B4EC-8A92DCF004BB}
[2011-01-23 14:15:44 | 000,000,000 |—-D | M]—C:\Documents and Settings\LocalService\Application Data\Fighters
[2011-01-30 18:27:31 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\AnvSoft
[2011-02-27 16:07:51 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\Ashampoo
[2011-02-06 16:00:53 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\Audacity
[2011-12-20 19:33:29 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\AVG
[2011-09-02 18:00:44 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\Canneverbe_Limited
[2012-01-06 19:07:30 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\Canon
[2011-01-24 16:12:57 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\Canon Easy-WebPrint EX
[2011-01-26 14:51:29 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\CD-LabelPrint
[2011-01-26 10:51:30 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\CDBurnerXP_Soft
[2011-05-05 17:47:46 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\com.aspiro.wimp.dk.25F5C0086CDE1F22CA0B92A487729991CA6CD013.1
[2011-04-13 17:53:29 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\DriverCure
[2011-02-08 18:23:12 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\eMachineShop
[2011-02-01 19:12:59 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\f-secure
[2011-10-22 17:51:39 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\Fighters
[2011-01-30 18:56:26 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\FinalMediaPlayer
[2011-02-27 19:01:15 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\GARMIN
[2011-02-06 16:12:35 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\Get from YouTube
[2010-01-14 18:13:34 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\GoodSync
[2011-03-06 19:19:05 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\GST
[2011-01-25 18:23:57 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\IsolatedStorage
[2011-09-17 08:47:36 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\JAM Software
[2010-01-11 11:35:27 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\Leadertech
[2012-01-05 12:04:50 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\licenses
[2010-01-21 15:55:38 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\NCH Swift Sound
[2011-05-12 12:24:47 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\Notepad++
[2010-01-16 19:07:05 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\OpenOffice.org
[2012-01-03 18:50:35 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\OpenSong
[2011-04-13 17:53:29 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\ParetoLogic
[2012-01-05 12:06:35 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\PCMM2009
[2012-01-05 12:04:40 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\PCMM2011
[2011-05-13 09:58:26 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\PeaZip
[2011-01-30 16:16:55 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\PGP
[2011-02-07 19:23:53 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\Power Sound Editor Free
[2011-02-06 16:47:19 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\PriceGong
[2011-03-06 19:12:31 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\Publisher4
[2010-01-11 18:58:05 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\Rainlendar
[2011-02-04 15:23:25 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\REAPER
[2011-04-02 17:34:49 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\Sammsoft
[2011-12-04 18:39:02 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\Samsung
[2011-01-30 18:56:31 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\SmartDraw
[2011-01-23 11:49:06 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\TeamViewer
[2011-12-18 09:56:43 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\TrojanHunter
[2012-01-05 09:35:10 | 000,000,000 |—-D | M]—C:\Documents and Settings\Marianne\Application Data\Uniblue
[2012-01-15 10:02:15 | 000,000,264 |——| M] ()—C:\WINDOWS\Tasks\RegistryBooster.job
[2012-01-15 11:06:00 | 000,000,234 |——| M] ()—C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
[2011-12-16 19:00:01 | 000,000,302 |——| M] ()—C:\WINDOWS\Tasks\tempoperfectShakeIcon.job
[2012-01-15 07:43:18 | 000,000,420 | -H—| M] ()—C:\WINDOWS\Tasks\User_Feed_Synchronization-{E707ECCA-F45E-4547-9AEB-9D53B738D977}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
< End of report >