OTL log:
OTL logfile created on: 15-04-2012 14:36:56 - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000406 | Country: Danmark | Language: DAN | Date Format: dd-MM-yyyy
2,00 Gb Total Physical Memory | 1,71 Gb Available Physical Memory | 85,74% Memory free
3,85 Gb Paging File | 3,75 Gb Available in Paging File | 97,56% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 291,34 Gb Total Space | 240,42 Gb Free Space | 82,52% Space Free | Partition Type: NTFS
Computer Name: LUNDSTRØM | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012-04-15 14:33:56 | 000,593,920 |——| M] (OldTimer Tools)—C:\Documents and Settings\Administrator\Desktop\OTL.exe
PRC - [2011-08-12 01:38:07 | 000,116,608 |——| M] (SUPERAntiSpyware.com)—C:\Program Files\SUPERAntiSpyware\SASCore.exe
PRC - [2008-04-14 02:12:19 | 001,033,728 |——| M] (Microsoft Corporation)—C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped]—C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe—(Automatisk LiveUpdate-planlægning)
SRV - [2012-04-04 15:56:40 | 000,654,408 |——| M] (Malwarebytes Corporation) [Auto | Stopped]—C:\Program Files\Malwarebytes’ Anti-Malware\mbamservice.exe—(MBAMService)
SRV - [2012-03-07 01:15:14 | 000,044,768 |——| M] (AVAST Software) [Auto | Stopped]—C:\Program Files\AVAST Software\Avast\AvastSvc.exe—(avast! Antivirus)
SRV - [2012-02-24 10:36:06 | 001,117,624 |——| M] (PC Tools) [Auto | Stopped]—C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe—(sdCoreService)
SRV - [2012-02-24 09:16:12 | 000,402,336 |——| M] (PC Tools) [Auto | Stopped]—C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe—(sdAuxService)
SRV - [2012-02-17 15:08:16 | 000,550,864 |——| M] (Threat Expert Ltd.) [Auto | Stopped]—C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe—(Browser Defender Update Service)
SRV - [2012-01-18 06:21:52 | 000,737,184 |——| M] (Enigma Software Group USA, LLC.) [Auto | Stopped]—C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe—(SpyHunter 4 Service)
SRV - [2011-09-22 02:40:11 | 000,117,648 | R—- | M] (Symantec Corporation) [Auto | Stopped]—C:\Program Files\Norton 360\Engine\3.8.3.6\ccSvcHst.exe—(N360)
SRV - [2011-08-12 01:38:07 | 000,116,608 |——| M] (SUPERAntiSpyware.com) [Auto | Running]—C:\Program Files\SUPERAntiSpyware\SASCore.exe—(!SASCORE)
SRV - [2006-06-01 17:25:00 | 000,180,224 |——| M] (Intel Corporation) [Auto | Stopped]—C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\ELService.exe—(ELService) Intel(R)
SRV - [2006-05-11 12:46:54 | 000,090,112 |——| M] (Intel Corporation) [Auto | Stopped]—C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe—(IAANTMON) Intel(R)
SRV - [2005-03-14 13:05:02 | 000,069,632 |——| M] (HP) [Auto | Stopped]—C:\WINDOWS\system32\HPZipm12.exe—(Pml Driver HPZ12)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped]——(WDICA)
DRV - File not found [Kernel | On_Demand | Stopped]—C:\WINDOWS\System32\Drivers\N360\0308000.029\SYMNDIS.SYS—(SYMNDIS)
DRV - File not found [Kernel | On_Demand | Stopped]—C:\WINDOWS\System32\Drivers\N360\0308000.029\SYMIDS.SYS—(SYMIDS)
DRV - File not found [Kernel | On_Demand | Stopped]—C:\WINDOWS\System32\Drivers\N360\0308000.029\SYMFW.SYS—(SYMFW)
DRV - File not found [Kernel | On_Demand | Stopped]——(PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped]——(PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped]——(PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped]——(PDCOMP)
DRV - File not found [Kernel | System | Stopped]——(PCIDump)
DRV - File not found [Kernel | System | Stopped]——(lbrtfdc)
DRV - File not found [Kernel | System | Stopped]——(Changer)
DRV - [2012-04-04 15:56:40 | 000,022,344 |——| M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\mbam.sys—(MBAMProtector)
DRV - [2012-03-07 01:03:51 | 000,612,184 |——| M] (AVAST Software) [File_System | System | Stopped]—C:\WINDOWS\System32\drivers\aswSnx.sys—(aswSnx)
DRV - [2012-03-07 01:03:38 | 000,337,880 |——| M] (AVAST Software) [Kernel | System | Stopped]—C:\WINDOWS\System32\drivers\aswSP.sys—(aswSP)
DRV - [2012-03-07 01:02:00 | 000,035,672 |——| M] (AVAST Software) [Kernel | System | Running]—C:\WINDOWS\System32\drivers\aswRdr.sys—(AswRdr)
DRV - [2012-03-07 01:01:53 | 000,053,848 |——| M] (AVAST Software) [Kernel | System | Stopped]—C:\WINDOWS\System32\drivers\aswTdi.sys—(aswTdi)
DRV - [2012-03-07 01:01:39 | 000,095,704 |——| M] (AVAST Software) [File_System | Auto | Stopped]—C:\WINDOWS\System32\drivers\aswmon2.sys—(aswMon2)
DRV - [2012-03-07 01:01:30 | 000,020,696 |——| M] (AVAST Software) [File_System | Auto | Stopped]—C:\WINDOWS\System32\drivers\aswFsBlk.sys—(aswFsBlk)
DRV - [2012-03-07 00:58:29 | 000,024,920 |——| M] (AVAST Software) [Kernel | System | Stopped]—C:\WINDOWS\System32\drivers\aavmker4.sys—(Aavmker4)
DRV - [2012-02-24 10:36:44 | 000,185,560 |——| M] (PC Tools) [Kernel | System | Stopped]—C:\WINDOWS\system32\drivers\PCTSD.sys—(PCTSD)
DRV - [2012-01-04 16:28:36 | 000,016,128 |——| M] (Windows (R) Win 7 DDK provider) [File_System | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\gtkdrv.sys—(TrojanKillerDriver)
DRV - [2011-12-01 16:07:06 | 000,909,728 |——| M] (PC Tools) [File_System | Boot | Running]—C:\WINDOWS\system32\drivers\pctEFA.sys—(pctEFA)
DRV - [2011-12-01 16:07:06 | 000,342,168 |——| M] (PC Tools) [Kernel | Boot | Running]—C:\WINDOWS\system32\drivers\pctDS.sys—(pctDS)
DRV - [2011-11-14 15:12:26 | 000,331,880 |——| M] (PC Tools) [Kernel | Boot | Running]—C:\WINDOWS\system32\drivers\PCTCore.sys—(PCTCore)
DRV - [2011-09-28 13:14:02 | 000,056,840 |——| M] (PC Tools) [Kernel | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\PCTBD.sys—(PCTBD)
DRV - [2011-09-22 02:40:13 | 000,467,592 |——| M] (Symantec Corporation) [Kernel | System | Stopped]—C:\WINDOWS\system32\drivers\N360\0308030.006\cchpx86.sys—(ccHP)
DRV - [2011-09-22 02:40:13 | 000,217,464 |——| M] (Symantec Corporation) [Kernel | System | Stopped]—C:\WINDOWS\system32\drivers\N360\0308030.006\symtdi.sys—(SYMTDI)
DRV - [2011-08-23 00:17:32 | 000,356,280 |——| M] (Symantec Corporation) [Kernel | System | Stopped]—C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20111006.030\IDSXpx86.sys—(IDSxpx86)
DRV - [2011-08-05 10:00:00 | 001,576,312 |——| M] (Symantec Corporation) [Kernel | On_Demand | Stopped]—C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20111006.032\NAVEX15.SYS—(NAVEX15)
DRV - [2011-08-05 10:00:00 | 000,086,136 |——| M] (Symantec Corporation) [Kernel | On_Demand | Stopped]—C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20111006.032\NAVENG.SYS—(NAVENG)
DRV - [2011-07-29 10:00:00 | 000,374,392 |——| M] (Symantec Corporation) [Kernel | System | Stopped]—C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys—(eeCtrl)
DRV - [2011-07-22 18:27:02 | 000,012,880 |——| M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Stopped]—C:\Program Files\SUPERAntiSpyware\sasdifsv.sys—(SASDIFSV)
DRV - [2011-07-12 23:55:22 | 000,067,664 |——| M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Stopped]—C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS—(SASKUTIL)
DRV - [2011-05-06 15:57:10 | 000,013,904 |——| M] () [Kernel | On_Demand | Stopped]—C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys—(esgiguard)
DRV - [2010-10-06 23:14:58 | 000,124,976 |——| M] (Symantec Corporation) [Kernel | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\SYMEVENT.SYS—(SymEvent)
DRV - [2010-10-06 23:14:43 | 000,310,320 |——| M] (Symantec Corporation) [File_System | Boot | Running]—C:\WINDOWS\system32\drivers\N360\0308030.006\SymEFA.sys—(SymEFA)
DRV - [2010-10-06 23:14:43 | 000,308,272 |——| M] (Symantec Corporation) [File_System | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\N360\0308030.006\srtsp.sys—(SRTSP)
DRV - [2010-10-06 23:14:43 | 000,043,696 |——| M] (Symantec Corporation) [Kernel | System | Stopped]—C:\WINDOWS\system32\drivers\N360\0308030.006\srtspx.sys—(SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2010-10-06 23:14:43 | 000,036,400 |——| M] (Symantec Corporation) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\SymIM.sys—(SymIMMP)
DRV - [2010-10-06 23:14:43 | 000,036,400 |——| M] (Symantec Corporation) [Kernel | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\SymIM.sys—(SymIM)
DRV - [2010-10-06 23:14:42 | 000,259,632 |——| M] (Symantec Corporation) [Kernel | System | Stopped]—C:\WINDOWS\system32\drivers\N360\0308030.006\BHDrvx86.sys—(BHDrvx86)
DRV - [2008-11-24 10:54:12 | 000,495,104 |——| M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\rt61.sys—(RT61)
DRV - [2008-04-13 20:46:22 | 000,015,232 |——| M] (Microsoft Corporation) [Kernel | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\mpe.sys—(MPE)
DRV - [2006-10-11 19:44:00 | 000,009,984 |——| M] (Conexant Systems, Inc.) [Kernel | System | Stopped]—C:\WINDOWS\system32\drivers\pvavsaud.sys—(CXAVSAUD)
DRV - [2006-08-23 03:53:14 | 001,723,904 |——| M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\ati2mtag.sys—(ati2mtag)
DRV - [2006-06-27 13:38:00 | 000,016,768 |——| M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\pvavsts.sys—(pvavSTS)
DRV - [2006-06-01 03:27:00 | 000,104,320 |——| M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\PVBDAtun.sys—(PVBDATUNE)
DRV - [2006-06-01 03:27:00 | 000,032,256 |——| M] (Conexant Systems, Inc.) [Kernel | Auto | Stopped]—C:\WINDOWS\system32\drivers\pv88tune.sys—(PVTUNE)
DRV - [2006-06-01 03:26:00 | 000,011,520 |——| M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\pvavxbar.sys—(pvavXBAR)
DRV - [2006-06-01 03:23:00 | 000,244,352 |——| M] (Conexant Systems, Inc.) [Kernel | Auto | Stopped]—C:\WINDOWS\system32\drivers\pv88vid.sys—(CX23880)
DRV - [2006-05-09 16:36:44 | 000,009,728 |——| M] (Intel Corporation) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\ELacpi.sys—(ELacpi)
DRV - [2006-05-09 16:36:42 | 000,007,040 |——| M] (Intel Corporation) [Kernel | System | Stopped]—C:\WINDOWS\system32\drivers\Elmon.sys—(ELmon)
DRV - [2006-05-09 16:36:22 | 000,006,912 |——| M] (Intel Corporation) [Kernel | System | Running]—C:\WINDOWS\system32\drivers\Elkbd.sys—(ELkbd)
DRV - [2006-05-09 16:36:20 | 000,006,400 |——| M] (Intel Corporation) [Kernel | System | Running]—C:\WINDOWS\system32\drivers\Elmou.sys—(ELmou)
DRV - [2006-05-09 16:36:18 | 000,010,112 |——| M] (Intel Corporation) [Kernel | System | Running]—C:\WINDOWS\system32\drivers\Elhid.sys—(ELhid)
DRV - [2005-09-23 18:56:28 | 003,966,976 |——| M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\RtkHDAud.sys—(IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2001-08-17 16:00:04 | 000,002,944 |——| M] (Microsoft Corporation) [Kernel | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\msmpu401.sys—(ms_mpu401)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: “URL” = http://search.live.com/results.aspx?q={searchTerms}&src;={referrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: “URL” = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&sourceid=ie7
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: “URL” = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: “URL” = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&sourceid=ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\ [2011-10-12 09:28:40 | 000,000,000 |—-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools\PC Tools Security\BDT\Firefox\ [2012-04-14 21:24:46 | 000,000,000 |—-D | M]
O1 HOSTS File: ([2004-08-11 05:00:00 | 000,000,734 |——| M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PC Tools Browser Defender BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\3.8.3.6\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\3.8.3.6\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\3.8.3.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [ISTray] C:\Program Files\PC Tools\PC Tools Security\pctsGui.exe (PC Tools)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes’ Anti-Malware] C:\Program Files\Malwarebytes’ Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [SkyTel] SkyTel.EXE File not found
O4 - HKLM..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe (Enigma Software Group USA, LLC.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [Power2GoExpress] “C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe” /Startup File not found
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil11g_ActiveX.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Philips Media Manager.lnk = File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Hurtigstart.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FreeventsSchedule.lnk = C:\Philips\FreeventsSchedule.exe ( )
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Hurtig start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra ‘Tools’ menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} http://downol.dr.dk/download/netradio/Rawflow.cab (Rawflow ICD Client)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab (e-Safekey)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 82.143.192.20 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{07ECF843-7984-41E3-A457-C88CD58891CB}: DhcpNameServer = 82.143.192.20 192.168.0.1
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files\Norton 360\Engine\3.8.3.6\CoIEPlg.dll (Symantec Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005-10-20 00:29:26 | 000,000,000 |——| M] () - C:\AUTOEXEC.BAT—[ NTFS ]
O33 - MountPoints2\{09a62921-40b3-11da-9e60-806d6172696f}\Shell - “” = AutoRun
O33 - MountPoints2\{09a62921-40b3-11da-9e60-806d6172696f}\Shell\AutoRun\command - “” = E:\Launch.exe
O33 - MountPoints2\Z\Shell - “” = AutoRun
O33 - MountPoints2\Z\Shell\AutoRun\command - “” = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open]—“%1” %*
O35 - HKLM\..exefile [open]—“%1” %*
O37 - HKLM\...com [@ = comfile]—“%1” %*
O37 - HKLM\...exe [@ = exefile]—“%1” %*
========== Files/Folders - Created Within 30 Days ==========
[2012-04-15 14:33:56 | 000,593,920 |——| C] (OldTimer Tools)—C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2012-04-15 14:25:07 | 000,000,000 | RH-D | C]—C:\Documents and Settings\Administrator\Recent
[2012-04-15 14:20:53 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2012-04-15 14:20:52 | 000,000,000 |—-D | C]—C:\Program Files\CCleaner
[2012-04-15 11:57:54 | 000,000,000 |—-D | C]—C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
[2012-04-15 11:57:39 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
[2012-04-15 11:57:36 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2012-04-15 11:57:36 | 000,000,000 |—-D | C]—C:\Program Files\SUPERAntiSpyware
[2012-04-15 11:22:22 | 000,000,000 |—-D | C]—C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2012-04-15 11:22:00 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes’ Anti-Malware
[2012-04-15 11:21:57 | 000,022,344 |——| C] (Malwarebytes Corporation)—C:\WINDOWS\System32\drivers\mbam.sys
[2012-04-15 11:21:57 | 000,000,000 |—-D | C]—C:\Program Files\Malwarebytes’ Anti-Malware
[2012-04-15 11:21:57 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012-04-14 21:41:37 | 000,337,880 |——| C] (AVAST Software)—C:\WINDOWS\System32\drivers\aswSP.sys
[2012-04-14 21:41:37 | 000,020,696 |——| C] (AVAST Software)—C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2012-04-14 21:41:37 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2012-04-14 21:41:36 | 000,612,184 |——| C] (AVAST Software)—C:\WINDOWS\System32\drivers\aswSnx.sys
[2012-04-14 21:41:36 | 000,095,704 |——| C] (AVAST Software)—C:\WINDOWS\System32\drivers\aswmon2.sys
[2012-04-14 21:41:36 | 000,089,048 |——| C] (AVAST Software)—C:\WINDOWS\System32\drivers\aswmon.sys
[2012-04-14 21:41:36 | 000,053,848 |——| C] (AVAST Software)—C:\WINDOWS\System32\drivers\aswTdi.sys
[2012-04-14 21:41:36 | 000,035,672 |——| C] (AVAST Software)—C:\WINDOWS\System32\drivers\aswRdr.sys
[2012-04-14 21:41:35 | 000,024,920 |——| C] (AVAST Software)—C:\WINDOWS\System32\drivers\aavmker4.sys
[2012-04-14 21:41:23 | 000,041,184 |——| C] (AVAST Software)—C:\WINDOWS\avastSS.scr
[2012-04-14 21:41:22 | 000,201,352 |——| C] (AVAST Software)—C:\WINDOWS\System32\aswBoot.exe
[2012-04-14 21:41:11 | 000,000,000 |—-D | C]—C:\Program Files\AVAST Software
[2012-04-14 21:41:11 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\AVAST Software
[2012-04-14 21:29:44 | 000,000,000 |—-D | C]—C:\Program Files\ESET
[2012-04-14 21:24:45 | 000,056,840 |——| C] (PC Tools)—C:\WINDOWS\System32\drivers\PCTBD.sys
[2012-04-14 21:24:44 | 002,250,704 |——| C] (Threat Expert Ltd.)—C:\WINDOWS\PCTBDCore.dll
[2012-04-14 21:24:44 | 001,681,360 |——| C] (Threat Expert Ltd.)—C:\WINDOWS\PCTBDRes.dll
[2012-04-14 21:24:44 | 000,149,456 |——| C] (PC Tools)—C:\WINDOWS\SGDetectionTool.dll
[2012-04-14 21:23:56 | 000,253,352 |——| C] (PC Tools)—C:\WINDOWS\System32\drivers\pctgntdi.sys
[2012-04-14 21:23:49 | 000,017,848 |——| C] (PC Tools)—C:\WINDOWS\System32\drivers\pctBTFix.sys
[2012-04-14 21:23:49 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Start Menu\Programs\PC Tools Security
[2012-04-14 21:23:46 | 000,070,536 |——| C] (PC Tools)—C:\WINDOWS\System32\drivers\pctplsg.sys
[2012-04-14 21:23:40 | 000,000,000 |—-D | C]—C:\Program Files\PC Tools
[2012-04-14 21:21:11 | 000,909,728 |——| C] (PC Tools)—C:\WINDOWS\System32\drivers\pctEFA.sys
[2012-04-14 21:21:10 | 000,342,168 |——| C] (PC Tools)—C:\WINDOWS\System32\drivers\pctDS.sys
[2012-04-14 21:21:09 | 000,331,880 |——| C] (PC Tools)—C:\WINDOWS\System32\drivers\PCTCore.sys
[2012-04-14 21:21:09 | 000,162,584 |——| C] (PC Tools)—C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2012-04-14 21:21:07 | 000,185,560 |——| C] (PC Tools)—C:\WINDOWS\System32\drivers\PCTSD.sys
[2012-04-14 21:21:07 | 000,000,000 |—-D | C]—C:\Program Files\Common Files\PC Tools
[2012-04-14 21:20:52 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\TEMP
[2012-04-14 21:20:50 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\PC Tools
[2012-04-14 21:05:14 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Start Menu\Programs\GridinSoft Trojan Killer
[2012-04-14 21:05:09 | 000,000,000 |—-D | C]—C:\Program Files\GridinSoft Trojan Killer
[2012-04-14 20:43:45 | 000,000,000 |—-D | C]—C:\sh4ldr
[2012-04-14 20:43:44 | 000,000,000 |—-D | C]—C:\Program Files\Enigma Software Group
[2012-04-11 18:47:49 | 000,000,000 | -HSD | C]—C:\Documents and Settings\Administrator\PrivacIE
[2012-04-11 18:47:44 | 000,000,000 | -HSD | C]—C:\Documents and Settings\Administrator\IETldCache
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012-04-15 14:33:56 | 000,593,920 |——| M] (OldTimer Tools)—C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2012-04-15 14:20:53 | 000,000,682 |——| M] ()—C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2012-04-15 13:02:42 | 000,001,158 |——| M] ()—C:\WINDOWS\System32\wpa.dbl
[2012-04-15 13:02:15 | 000,002,048 |——| M] ()—C:\WINDOWS\bootstat.dat
[2012-04-15 12:55:50 | 000,000,920 |——| M] ()—C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012-04-15 12:50:00 | 000,000,916 |——| M] ()—C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012-04-15 11:57:39 | 000,001,678 |——| M] ()—C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012-04-15 11:23:10 | 000,000,784 |——| M] ()—C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012-04-14 21:41:37 | 000,001,689 |——| M] ()—C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012-04-14 21:41:36 | 000,002,625 |——| M] ()—C:\WINDOWS\System32\CONFIG.NT
[2012-04-14 21:23:50 | 000,001,843 |——| M] ()—C:\Documents and Settings\All Users\Desktop\PC Tools Spyware Doctor with AntiVirus.lnk
[2012-04-14 21:21:31 | 000,648,393 |——| M] ()—C:\WINDOWS\System32\drivers\Cat.DB
[2012-04-14 20:40:02 | 000,000,466 |——| M] ()—C:\WINDOWS\tasks\At2.job
[2012-04-12 17:28:14 | 000,000,129 |——| M] ()—C:\WINDOWS\System32\MRT.INI
[2012-04-11 18:59:02 | 000,165,403 |——| M] ()—C:\Documents and Settings\Administrator\Local Settings\Application Data\census.cache
[2012-04-11 18:58:59 | 000,171,555 |——| M] ()—C:\Documents and Settings\Administrator\Local Settings\Application Data\ars.cache
[2012-04-11 16:40:20 | 000,000,160 |——| M] ()—C:\Documents and Settings\All Users\Application Data\-3rA3WI7LGLNRPir
[2012-04-11 16:40:20 | 000,000,000 |——| M] ()—C:\Documents and Settings\All Users\Application Data\-3rA3WI7LGLNRPi
[2012-04-11 16:40:15 | 000,000,256 |——| M] ()—C:\Documents and Settings\All Users\Application Data\3rA3WI7LGLNRPi
[2012-04-11 14:26:01 | 000,000,284 |——| M] ()—C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012-04-11 14:00:00 | 000,000,466 |——| M] ()—C:\WINDOWS\tasks\At4.job
[2012-04-11 10:10:01 | 000,000,466 |——| M] ()—C:\WINDOWS\tasks\At1.job
[2012-04-10 16:08:00 | 000,000,466 |——| M] ()—C:\WINDOWS\tasks\At3.job
[2012-04-09 20:00:00 | 000,000,644 |——| M] ()—C:\WINDOWS\tasks\Norton Internet Security - Kør fuld systemskanning - Lundstrøm.job
[2012-04-08 22:16:39 | 000,002,265 |——| M] ()—C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2012-04-04 15:56:40 | 000,022,344 |——| M] (Malwarebytes Corporation)—C:\WINDOWS\System32\drivers\mbam.sys
[2012-03-25 15:11:30 | 000,444,600 |——| M] ()—C:\WINDOWS\System32\perfh009.dat
[2012-03-25 15:11:30 | 000,072,476 |——| M] ()—C:\WINDOWS\System32\perfc009.dat
[2012-03-19 22:09:55 | 000,000,611 |——| M] ()—C:\Documents and Settings\All Users\Desktop\Dolby Axon.lnk
[2012-03-16 22:53:17 | 000,192,184 |——| M] ()—C:\WINDOWS\System32\FNTCACHE.DAT
[2012-03-16 22:10:36 | 000,414,368 |——| M] (Adobe Systems Incorporated)—C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012-04-15 14:20:53 | 000,000,682 |——| C] ()—C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2012-04-15 11:57:39 | 000,001,678 |——| C] ()—C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012-04-15 11:23:10 | 000,000,784 |——| C] ()—C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012-04-14 21:41:37 | 000,001,689 |——| C] ()—C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012-04-14 21:24:44 | 000,767,952 |——| C] ()—C:\WINDOWS\BDTSupport.dll
[2012-04-14 21:24:44 | 000,003,488 |——| C] ()—C:\WINDOWS\UDB.zip
[2012-04-14 21:24:44 | 000,000,882 |——| C] ()—C:\WINDOWS\RegSDImport.xml
[2012-04-14 21:24:44 | 000,000,879 |——| C] ()—C:\WINDOWS\RegISSImport.xml
[2012-04-14 21:24:44 | 000,000,131 |——| C] ()—C:\WINDOWS\IDB.zip
[2012-04-14 21:23:50 | 000,001,843 |——| C] ()—C:\Documents and Settings\All Users\Desktop\PC Tools Spyware Doctor with AntiVirus.lnk
[2012-04-14 21:21:11 | 000,648,393 |——| C] ()—C:\WINDOWS\System32\drivers\Cat.DB
[2012-04-14 21:07:59 | 000,001,808 |——| C] ()—C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2012-04-14 21:07:59 | 000,001,757 |——| C] ()—C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Hurtigstart.lnk
[2012-04-14 21:07:59 | 000,001,726 |——| C] ()—C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2012-04-14 21:07:59 | 000,000,798 |——| C] ()—C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Hurtig start.lnk
[2012-04-14 21:07:59 | 000,000,526 |——| C] ()—C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FreeventsSchedule.lnk
[2012-04-14 21:07:58 | 000,000,786 |——| C] ()—C:\Documents and Settings\All Users\Start Menu\Programs\Windows Movie Maker.lnk
[2012-04-14 21:07:57 | 000,002,491 |——| C] ()—C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Excel.lnk
[2012-04-14 21:07:57 | 000,002,479 |——| C] ()—C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Word.lnk
[2012-04-14 21:07:57 | 000,002,471 |——| C] ()—C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft PowerPoint.lnk
[2012-04-14 21:07:57 | 000,002,469 |——| C] ()—C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Access.lnk
[2012-04-14 21:07:57 | 000,002,068 |——| C] ()—C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Outlook.lnk
[2012-04-14 21:07:57 | 000,001,830 |——| C] ()—C:\Documents and Settings\All Users\Start Menu\Programs\Apple Software Update.lnk
[2012-04-14 21:07:57 | 000,001,810 |——| C] ()—C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 7.0.lnk
[2012-04-14 21:07:57 | 000,001,783 |——| C] ()—C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office PowerPoint Viewer 2003.lnk
[2012-04-14 21:07:57 | 000,001,693 |——| C] ()—C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Works Opgavestarter.lnk
[2012-04-14 21:07:57 | 000,001,466 |——| C] ()—C:\Documents and Settings\All Users\Start Menu\Programs\Media Center.lnk
[2012-04-14 21:07:57 | 000,001,077 |——| C] ()—C:\Documents and Settings\All Users\Start Menu\Programs\Windows Live ID.lnk
[2012-04-14 21:07:57 | 000,000,725 |——| C] ()—C:\Documents and Settings\All Users\Start Menu\Programs\I.R.I.S. OCR-registrering.lnk
[2012-04-12 17:28:14 | 000,000,129 |——| C] ()—C:\WINDOWS\System32\MRT.INI
[2012-04-11 18:59:02 | 000,165,403 |——| C] ()—C:\Documents and Settings\Administrator\Local Settings\Application Data\census.cache
[2012-04-11 18:58:59 | 000,171,555 |——| C] ()—C:\Documents and Settings\Administrator\Local Settings\Application Data\ars.cache
[2012-04-11 16:40:20 | 000,000,160 |——| C] ()—C:\Documents and Settings\All Users\Application Data\-3rA3WI7LGLNRPir
[2012-04-11 16:40:20 | 000,000,000 |——| C] ()—C:\Documents and Settings\All Users\Application Data\-3rA3WI7LGLNRPi
[2012-04-11 16:40:11 | 000,000,256 |——| C] ()—C:\Documents and Settings\All Users\Application Data\3rA3WI7LGLNRPi
[2012-02-16 12:18:59 | 000,003,072 |——| C] ()—C:\WINDOWS\System32\iacenc.dll
[2011-10-02 14:51:46 | 000,000,000 |——| C] ()—C:\WINDOWS\ativpsrm.bin
[2011-02-20 17:53:28 | 000,000,036 |——| C] ()—C:\Documents and Settings\Administrator\Local Settings\Application Data\housecall.guid.cache
[2010-10-26 00:07:32 | 000,005,232 |——| C] ()—C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
========== Custom Scans ==========
< HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones >
“” =
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4]
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones >
“” =
“SelfHealCount” = 1
“SecuritySafe” = 1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4]
========== Alternate Data Streams ==========
@Alternate Data Stream - 166 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84
< End of report >