OTL logfile created on: 18-06-2012 15:01:31 - Run 1
OTL by OldTimer - Version 3.2.49.0 Folder = C:\Documents and Settings\kdp.DOMAIN\Skrivebord
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000406 | Country: Danmark | Language: DAN | Date Format: dd-MM-yyyy
3,50 Gb Total Physical Memory | 2,41 Gb Available Physical Memory | 68,94% Memory free
5,34 Gb Paging File | 4,45 Gb Available in Paging File | 83,39% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmer
Drive C: | 465,76 Gb Total Space | 226,68 Gb Free Space | 48,67% Space Free | Partition Type: NTFS
Drive K: | 1024,00 Gb Total Space | 114,94 Gb Free Space | 11,22% Space Free | Partition Type: NTFS
Drive L: | 1024,00 Gb Total Space | 114,94 Gb Free Space | 11,22% Space Free | Partition Type: NTFS
Drive N: | 1024,00 Gb Total Space | 114,94 Gb Free Space | 11,22% Space Free | Partition Type: NTFS
Drive P: | 1024,00 Gb Total Space | 114,94 Gb Free Space | 11,22% Space Free | Partition Type: NTFS
Drive Q: | 1024,00 Gb Total Space | 114,94 Gb Free Space | 11,22% Space Free | Partition Type: NTFS
Drive R: | 1024,00 Gb Total Space | 114,94 Gb Free Space | 11,22% Space Free | Partition Type: NTFS
Drive X: | 1024,00 Gb Total Space | 114,94 Gb Free Space | 11,22% Space Free | Partition Type: NTFS
Drive Z: | 1024,00 Gb Total Space | 114,94 Gb Free Space | 11,22% Space Free | Partition Type: NTFS
Computer Name: KURT01 | User Name: kdp | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012-06-17 17:50:49 | 000,595,968 |——| M] (OldTimer Tools)—C:\Documents and Settings\kdp.DOMAIN\Skrivebord\OTL.exe
PRC - [2012-06-08 15:12:13 | 000,488,104 |——| M] (F-Secure Corporation)—C:\Programmer\F-Secure\Anti-Virus\fsav32.exe
PRC - [2012-06-08 15:11:52 | 000,061,088 |——| M] (F-Secure Corporation)—C:\Programmer\F-Secure\ORSP Client\fsorsp.exe
PRC - [2012-06-08 15:10:58 | 001,028,776 |——| M] (F-Secure Corporation)—C:\Programmer\F-Secure\Anti-Virus\fssm32.exe
PRC - [2012-06-08 15:10:58 | 000,561,832 |——| M] (F-Secure Corporation)—C:\Programmer\F-Secure\Anti-Virus\fsgk32.exe
PRC - [2012-05-31 18:20:02 | 000,296,056 |——| M] (RealNetworks, Inc.)—C:\Programmer\Real\RealPlayer\Update\realsched.exe
PRC - [2012-05-30 13:56:52 | 003,048,136 |——| M] (Skype Technologies S.A.)—C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2012-05-15 15:46:35 | 000,779,264 |——| M] (PTC)—C:\Programmer\proeWildfire 5.0\i486_nt\nms\nmsd.exe
PRC - [2012-04-04 15:56:40 | 000,654,408 |——| M] (Malwarebytes Corporation)—C:\Programmer\Malwarebytes’ Anti-Malware\mbamservice.exe
PRC - [2012-02-27 01:15:42 | 000,055,144 |——| M] (Apple Inc.)—C:\Programmer\Fælles filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2011-12-05 21:17:44 | 024,242,056 |——| M] (Dropbox, Inc.)—C:\Documents and Settings\kdp\Application Data\Dropbox\bin\Dropbox.exe
PRC - [2011-10-07 11:40:42 | 001,387,288 |——| M] (Logitech, Inc.)—C:\Programmer\Logitech\SetPointP\SetPoint.exe
PRC - [2011-09-27 21:05:24 | 000,149,784 |——| M] (Logitech, Inc.)—C:\Programmer\Fælles filer\LogiShrd\KHAL3\KHALMNPR.exe
PRC - [2010-03-16 10:22:44 | 000,475,136 |——| M] ()—C:\Programmer\Fælles filer\Materialise\LicenseFiles\LicSrv52.exe
PRC - [2010-03-16 10:22:44 | 000,036,864 |——| M] ()—C:\Programmer\Fælles filer\Materialise\LicenseFiles\LicSrv50.exe
PRC - [2010-03-04 23:38:00 | 000,071,096 |——| M] ()—C:\Programmer\CDBurnerXP\NMSAccessU.exe
PRC - [2010-03-03 10:36:46 | 000,082,432 |——| M] (PTC)—C:\Programmer\PTC\WindchillSharePointProducts\ClientManager\ProductPointService.exe
PRC - [2009-11-26 11:36:42 | 000,166,512 |——| M] (F-Secure Corporation)—C:\Programmer\F-Secure\common\FNRB32.exe
PRC - [2009-11-26 11:36:42 | 000,129,648 |——| M] (F-Secure Corporation)—C:\Programmer\F-Secure\common\FIH32.exe
PRC - [2009-11-26 11:36:38 | 000,186,992 |——| M] (F-Secure Corporation)—C:\Programmer\F-Secure\common\FSMA32.EXE
PRC - [2009-11-26 11:36:36 | 000,301,680 |——| M] (F-Secure Corporation)—C:\Programmer\F-Secure\common\FSM32.EXE
PRC - [2009-11-26 11:36:36 | 000,088,688 |——| M] (F-Secure Corporation)—C:\Programmer\F-Secure\common\FSHDLL32.EXE
PRC - [2009-11-26 11:35:58 | 000,522,864 |——| M] (F-Secure Corporation)—C:\Programmer\F-Secure\FWES\program\fsdfwd.exe
PRC - [2009-11-26 11:35:14 | 000,219,760 |——| M] (F-Secure Corporation)—C:\Programmer\F-Secure\Anti-Virus\fsgk32st.exe
PRC - [2009-11-03 15:48:54 | 000,874,768 |——| M] (Intel(R) Corporation)—C:\Programmer\Intel\WiFi\bin\EvtEng.exe
PRC - [2009-11-03 15:45:52 | 000,348,160 |——| M] (Intel(R) Corporation)—C:\Programmer\Intel\WiFi\bin\WLKEEPER.exe
PRC - [2009-11-03 15:45:48 | 001,372,160 |——| M] (Intel(R) Corporation)—C:\Programmer\Intel\WiFi\bin\ZCfgSvc.exe
PRC - [2009-11-03 15:42:00 | 000,909,312 |——| M] (Intel(R) Corporation)—C:\Programmer\Intel\WiFi\bin\S24EvMon.exe
PRC - [2009-11-03 15:35:14 | 001,202,448 |——| M] (Intel(R) Corporation)—C:\Programmer\Fælles filer\Intel\WirelessCommon\iFrmewrk.exe
PRC - [2009-11-03 15:33:48 | 000,473,360 |——| M] (Intel(R) Corporation)—C:\Programmer\Fælles filer\Intel\WirelessCommon\RegSrvc.exe
PRC - [2009-03-06 10:40:10 | 000,656,696 |——| M] (Wave Systems Corp.)—C:\Programmer\Wave Systems Corp\SecureUpgrade.exe
PRC - [2009-03-06 10:39:10 | 000,145,408 |——| M] (Wave Systems Corp.)—C:\Programmer\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe
PRC - [2009-02-18 14:10:14 | 000,991,232 |——| M] (Wave Systems Corp.)—C:\Programmer\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
PRC - [2008-04-14 18:05:49 | 001,034,752 |——| M] (Microsoft Corporation)—C:\WINDOWS\explorer.exe
PRC - [2008-04-14 18:05:45 | 000,391,680 |——| M] (Microsoft Corporation)—C:\WINDOWS\system32\cmd.exe
PRC - [2008-03-20 08:25:43 | 000,025,256 |——| M] ()—C:\Programmer\Lexmark 3600-4600 Series\lxdxmsdmon.exe
PRC - [2008-03-20 08:25:42 | 000,668,328 |——| M] ()—C:\Programmer\Lexmark 3600-4600 Series\lxdxmon.exe
PRC - [2008-02-28 02:53:25 | 000,594,600 |——| M] ( )—C:\WINDOWS\system32\lxdxcoms.exe
PRC - [2007-06-20 14:30:18 | 000,079,168 |——| M] (Broadcom Corporation)—C:\Programmer\Broadcom\ASFIPMon\AsfIpMon.exe
PRC - [2007-05-10 10:22:32 | 000,405,504 |——| M] (SigmaTel, Inc.)—C:\Programmer\SigmaTel\C-Major Audio\WDM\stsystra.exe
PRC - [2007-01-11 20:43:46 | 002,150,400 |——| M] (TOSHIBA CORPORATION.)—C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
PRC - [2006-12-18 15:22:14 | 000,278,528 |——| M] (TOSHIBA CORPORATION.)—C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
PRC - [2006-12-15 11:41:30 | 002,170,880 |——| M] (TOSHIBA CORPORATION.)—C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
PRC - [2006-11-03 11:01:16 | 000,319,488 |——| M] (PixArt Imaging Incorporation)—C:\WINDOWS\PixArt\Pac7302\Monitor.exe
PRC - [2006-10-27 20:13:48 | 000,270,336 |——| M] (TOSHIBA CORPORATION.)—C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
PRC - [2006-02-06 23:00:20 | 000,311,296 |——| M] (TOSHIBA CORPORATION.)—C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosOBEX.exe
PRC - [2006-01-23 23:14:10 | 000,069,632 |——| M] (TOSHIBA CORPORATION.)—C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
PRC - [2004-02-11 09:00:00 | 000,118,784 |——| M] (WinZip Computing, Inc.)—C:\Programmer\WinZip\WZQKPICK.EXE
========== Modules (No Company Name) ==========
MOD - [2012-06-13 03:20:54 | 000,212,992 |——| M] ()—C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8b84bb74d7724e147a642a1d5358feb7\System.ServiceProcess.ni.dll
MOD - [2012-06-13 03:20:52 | 011,817,472 |——| M] ()—C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\dbc413807cb7360b3e26ef3ca1d54f9a\System.Web.ni.dll
MOD - [2012-06-13 03:19:18 | 012,433,920 |——| M] ()—C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\01abbadafaf265d9f4ac9bbb247acb98\System.Windows.Forms.ni.dll
MOD - [2012-06-13 03:19:07 | 001,592,320 |——| M] ()—C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d86f2038209a4cf0d0f5b30f6375c9b2\System.Drawing.ni.dll
MOD - [2012-06-13 03:17:04 | 000,372,736 |——| M] ()—C:\WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
MOD - [2012-06-08 15:12:04 | 000,030,888 |——| M] ()—C:\Programmer\F-Secure\Anti-Virus\minifilter\hashlib_x86.dll
MOD - [2012-06-08 15:10:58 | 000,768,712 |——| M] ()—C:\Programmer\F-Secure\Anti-Virus\fm4av.dll
MOD - [2012-05-14 09:04:19 | 001,706,496 |——| M] ()—C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\97d635f5c656ae43d94b55e67fc4ab50\System.ServiceModel.Web.ni.dll
MOD - [2012-05-14 09:03:26 | 000,256,000 |——| M] ()—C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\660c4d6dd69ef22bc05587e1998cd135\SMDiagnostics.ni.dll
MOD - [2012-05-14 09:03:18 | 017,403,904 |——| M] ()—C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\bc254d2fa26664898ae21d45643bc194\System.ServiceModel.ni.dll
MOD - [2012-05-14 09:03:03 | 002,345,472 |——| M] ()—C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\505e12638acd6fdb22e1fd2d4c6fc232\System.Runtime.Serialization.ni.dll
MOD - [2012-05-14 09:02:27 | 000,971,264 |——| M] ()—C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d5b7368bde0f65aa15d9f46b498cc89\System.Configuration.ni.dll
MOD - [2012-05-14 08:48:03 | 005,450,752 |——| M] ()—C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\3bba1b8b0b5ef0be238b011cc7a0575e\System.Xml.ni.dll
MOD - [2012-05-14 08:46:03 | 007,953,408 |——| M] ()—C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll
MOD - [2012-05-14 08:45:55 | 011,492,352 |——| M] ()—C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll
MOD - [2012-04-04 07:54:00 | 000,300,544 |——| M] ()—C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\PDFShell.DAN
MOD - [2012-01-08 15:41:12 | 000,093,696 |——| M] ()—C:\Programmer\FileZilla FTP Client\fzshellext.dll
MOD - [2011-10-07 11:41:16 | 000,879,896 |——| M] ()—C:\Programmer\Logitech\SetPointP\Macros\MacroCore.dll
MOD - [2011-06-24 22:56:36 | 000,087,328 |——| M] ()—C:\Programmer\Fælles filer\Apple\Apple Application Support\zlib1.dll
MOD - [2011-06-24 22:56:14 | 001,241,888 |——| M] ()—C:\Programmer\Fælles filer\Apple\Apple Application Support\libxml2.dll
MOD - [2011-02-24 02:57:18 | 000,555,112 |——| M] ()—C:\Programmer\NVIDIA Corporation\nView\nvShell.dll
MOD - [2010-11-01 22:33:24 | 000,048,936 |——| M] ()—C:\WINDOWS\system32\pdf995mon.dll
MOD - [2010-03-16 10:22:44 | 000,475,136 |——| M] ()—C:\Programmer\Fælles filer\Materialise\LicenseFiles\LicSrv52.exe
MOD - [2010-03-16 10:22:44 | 000,036,864 |——| M] ()—C:\Programmer\Fælles filer\Materialise\LicenseFiles\LicSrv50.exe
MOD - [2010-03-16 10:17:16 | 000,319,488 |——| M] ()—C:\Programmer\Fælles filer\Materialise\LicenseFiles\MatSAX.14.00.dll
MOD - [2010-03-16 10:17:02 | 000,339,968 |——| M] ()—C:\Programmer\Fælles filer\Materialise\LicenseFiles\MatBase.14.00.dll
MOD - [2010-03-16 10:15:36 | 000,102,400 |——| M] ()—C:\Programmer\Fælles filer\Materialise\LicenseFiles\MatResString.14.01.dll
MOD - [2010-03-16 10:13:50 | 000,061,440 |——| M] ()—C:\Programmer\Fælles filer\Materialise\LicenseFiles\_MatDll.14.00.dll
MOD - [2010-03-04 23:38:00 | 000,071,096 |——| M] ()—C:\Programmer\CDBurnerXP\NMSAccessU.exe
MOD - [2010-02-04 00:28:27 | 000,589,824 |——| M] ()—C:\Programmer\Lexmark 3600-4600 Series\lxdxdatr.dll
MOD - [2009-11-26 11:36:38 | 000,088,688 |——| M] ()—C:\Programmer\F-Secure\common\OnDemandInstallWatcher.dll
MOD - [2009-11-26 11:36:28 | 000,236,144 |——| M] ()—\\?\c:\programmer\f-secure\hips\fsumi.dll
MOD - [2009-11-26 11:35:44 | 000,086,016 |——| M] ()—C:\Programmer\F-Secure\FSGUI\strres.eng
MOD - [2009-11-26 11:35:40 | 000,551,536 |——| M] ()—C:\Programmer\F-Secure\FSGUI\gres.dll
MOD - [2009-11-26 11:35:36 | 000,045,056 |——| M] ()—C:\Programmer\F-Secure\FSGUI\fsavures.eng
MOD - [2009-11-26 11:35:34 | 000,143,360 |——| M] ()—C:\Programmer\F-Secure\FSGUI\flyerres.eng
MOD - [2009-11-26 11:35:30 | 000,440,944 |——| M] ()—C:\Programmer\F-Secure\FSGUI\about.dll
MOD - [2009-11-26 11:35:30 | 000,088,688 |——| M] ()—C:\Programmer\F-Secure\FSGUI\aboutres.dll
MOD - [2009-11-26 11:35:12 | 000,036,864 |——| M] ()—C:\Programmer\F-Secure\Anti-Virus\fsavhres.eng
MOD - [2009-11-03 15:35:46 | 000,200,704 |——| M] ()—C:\Programmer\Intel\WiFi\bin\iWMSProv.dll
MOD - [2009-10-16 13:12:44 | 000,147,968 |——| M] ()—C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdxdrpp.dll
MOD - [2009-03-06 10:39:10 | 000,249,856 |——| M] ()—C:\WINDOWS\system32\wxvault.dll
MOD - [2008-03-20 08:25:43 | 000,025,256 |——| M] ()—C:\Programmer\Lexmark 3600-4600 Series\lxdxmsdmon.exe
MOD - [2008-03-20 08:25:42 | 000,668,328 |——| M] ()—C:\Programmer\Lexmark 3600-4600 Series\lxdxmon.exe
MOD - [2008-03-20 07:24:19 | 000,081,920 |——| M] ()—C:\Programmer\Lexmark 3600-4600 Series\lxdxcaps.dll
MOD - [2008-03-20 07:24:12 | 000,380,928 |——| M] ()—C:\Programmer\Lexmark 3600-4600 Series\lxdxscw.dll
MOD - [2008-03-20 07:24:11 | 000,782,336 |——| M] ()—C:\Programmer\Lexmark 3600-4600 Series\lxdxdrs.dll
MOD - [2008-03-20 07:17:07 | 000,069,632 |——| M] ()—C:\Programmer\Lexmark 3600-4600 Series\lxdxcnv4.dll
MOD - [2008-02-28 01:40:55 | 000,036,864 |——| M] ()—C:\Programmer\Lexmark 3600-4600 Series\app4r.monitor.core.dll
MOD - [2008-02-28 01:40:54 | 000,028,672 |——| M] ()—C:\Programmer\Lexmark 3600-4600 Series\app4r.monitor.common.dll
MOD - [2008-02-28 01:40:02 | 000,061,440 |——| M] ()—C:\Programmer\Lexmark 3600-4600 Series\app4r.devmons.mcmdevmon.dll
MOD - [2007-11-22 18:55:48 | 000,011,776 |——| M] ()—C:\Programmer\Lexmark 3600-4600 Series\app4r.devmons.mcmdevmon.autoplayutil.dll
MOD - [2007-09-20 18:34:58 | 000,129,024 |——| M] ()—C:\Programmer\WinRAR\RarExt.dll
MOD - [2005-07-22 21:30:20 | 000,065,536 |——| M] ()—C:\WINDOWS\system32\TosCommAPI.dll
MOD - [2005-05-07 15:14:56 | 000,090,112 |——| M] ()—C:\WINDOWS\system32\custmon2k.dll
MOD - [2004-10-14 10:18:24 | 000,040,960 |——| M] ()—C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosBtAfh.dll
MOD - [2004-07-20 17:04:02 | 000,094,208 |——| M] ()—C:\WINDOWS\system32\TosBtHcrpAPI.dll
========== Win32 Services (SafeList) ==========
SRV - [2012-06-08 15:11:52 | 000,061,088 |——| M] (F-Secure Corporation) [On_Demand | Running]—C:\Programmer\F-Secure\ORSP Client\fsorsp.exe—(FSORSPClient)
SRV - [2012-05-30 13:56:52 | 003,048,136 |——| M] (Skype Technologies S.A.) [Auto | Running]—C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe—(Skype C2C Service)
SRV - [2012-05-08 09:40:49 | 000,257,696 |——| M] (Adobe Systems Incorporated) [On_Demand | Stopped]—C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe—(AdobeFlashPlayerUpdateSvc)
SRV - [2012-04-04 15:56:40 | 000,654,408 |——| M] (Malwarebytes Corporation) [Auto | Running]—C:\Programmer\Malwarebytes’ Anti-Malware\mbamservice.exe—(MBAMService)
SRV - [2012-02-27 01:15:42 | 000,055,144 |——| M] (Apple Inc.) [Auto | Running]—C:\Programmer\Fælles filer\Apple\Mobile Device Support\AppleMobileDeviceService.exe—(Apple Mobile Device)
SRV - [2011-09-27 21:03:28 | 000,295,192 |——| M] (Logitech, Inc.) [On_Demand | Stopped]—C:\Programmer\Fælles filer\LogiShrd\Bluetooth\LBTServ.exe—(LBTServ)
SRV - [2011-07-20 05:18:24 | 000,440,696 |——| M] (Microsoft Corporation) [On_Demand | Stopped]—C:\Programmer\Fælles filer\Microsoft Shared\OFFICE12\ODSERV.EXE—(odserv)
SRV - [2011-05-30 11:21:41 | 000,079,360 |——| M] (SolidWorks) [On_Demand | Stopped]—C:\Programmer\Fælles filer\SolidWorks Shared\Service\SolidWorksLicensing.exe—(SolidWorks Licensing Service)
SRV - [2010-03-16 10:22:44 | 000,475,136 |——| M] () [Auto | Running]—C:\Programmer\Fælles filer\Materialise\LicenseFiles\LicSrv52.exe—(MatLocalLicenceServer52)
SRV - [2010-03-16 10:22:44 | 000,036,864 |——| M] () [Auto | Running]—C:\Programmer\Fælles filer\Materialise\LicenseFiles\LicSrv50.exe—(MatLocalLicenceServer50)
SRV - [2010-03-04 23:38:00 | 000,071,096 |——| M] () [Auto | Running]—C:\Programmer\CDBurnerXP\NMSAccessU.exe—(NMSAccess)
SRV - [2009-11-26 11:36:42 | 000,166,512 |——| M] (F-Secure Corporation) [On_Demand | Running]—C:\Programmer\F-Secure\common\FNRB32.exe—(F-Secure Network Request Broker)
SRV - [2009-11-26 11:36:38 | 000,186,992 |——| M] (F-Secure Corporation) [Auto | Running]—C:\Programmer\F-Secure\common\FSMA32.EXE—(FSMA)
SRV - [2009-11-26 11:35:58 | 000,522,864 |——| M] (F-Secure Corporation) [On_Demand | Running]—C:\Programmer\F-Secure\FWES\program\fsdfwd.exe—(FSDFWD)
SRV - [2009-11-26 11:35:14 | 000,219,760 |——| M] (F-Secure Corporation) [Auto | Running]—C:\Programmer\F-Secure\Anti-Virus\fsgk32st.exe—(F-Secure Gatekeeper Handler Starter)
SRV - [2009-11-03 15:48:54 | 000,874,768 |——| M] (Intel(R) Corporation) [Auto | Running]—C:\Programmer\Intel\WiFi\bin\EvtEng.exe—(EvtEng) Intel(R)
SRV - [2009-11-03 15:45:52 | 000,348,160 |——| M] (Intel(R) Corporation) [Auto | Running]—C:\Programmer\Intel\WiFi\bin\WLKEEPER.exe—(WLANKEEPER) Intel(R)
SRV - [2009-11-03 15:42:00 | 000,909,312 |——| M] (Intel(R) Corporation) [Auto | Running]—C:\Programmer\Intel\WiFi\bin\S24EvMon.exe—(S24EventMonitor) Intel(R)
SRV - [2009-11-03 15:33:48 | 000,473,360 |——| M] (Intel(R) Corporation) [Auto | Running]—C:\Programmer\Fælles filer\Intel\WirelessCommon\RegSrvc.exe—(RegSrvc) Intel(R)
SRV - [2009-10-16 13:00:50 | 000,094,208 |——| M] () [Auto | Stopped]—C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdxserv.exe—(lxdxCATSCustConnectService)
SRV - [2009-05-06 15:32:02 | 000,249,856 |——| M] (SMServer) [On_Demand | Stopped]—C:\WINDOWS\system32\snmvtsvc.exe—(SMServer)
SRV - [2009-02-18 14:10:14 | 000,991,232 |——| M] (Wave Systems Corp.) [Auto | Running]—C:\Programmer\Wave Systems Corp\Trusted Drive Manager\TdmService.exe—(TdmService)
SRV - [2008-12-12 09:54:00 | 000,638,976 |——| M] (Wave Systems Corp.) [On_Demand | Stopped]—C:\Programmer\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe—(SecureStorageService)
SRV - [2008-11-12 13:25:48 | 001,273,856 |——| M] () [Auto | Stopped]—C:\Programmer\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe—(tcsd_win32.exe)
SRV - [2008-02-28 02:53:25 | 000,594,600 |——| M] ( ) [Auto | Running]—C:\WINDOWS\system32\lxdxcoms.exe—(lxdx_device)
SRV - [2007-06-20 14:30:18 | 000,079,168 |——| M] (Broadcom Corporation) [Auto | Running]—C:\Programmer\Broadcom\ASFIPMon\AsfIpMon.exe—(ASFIPmon)
SRV - [2006-10-26 14:03:08 | 000,145,184 |——| M] (Microsoft Corporation) [On_Demand | Stopped]—C:\Programmer\Fælles filer\Microsoft Shared\Source Engine\OSE.EXE—(ose)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped]——(WDICA)
DRV - File not found [Kernel | System | Stopped]—C:\WINDOWS\system32\drivers\SBREdrv.sys—(SBRE)
DRV - File not found [Kernel | On_Demand | Stopped]——(PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped]——(PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped]——(PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped]——(PDCOMP)
DRV - File not found [Kernel | System | Stopped]——(PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped]—system32\DRIVERS\pccsmcfd.sys—(pccsmcfd)
DRV - File not found [Kernel | System | Stopped]—C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS—(OMCI)
DRV - File not found [Kernel | System | Stopped]——(lbrtfdc)
DRV - File not found [Kernel | System | Stopped]——(i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped]—system32\DRIVERS\ewusbfake.sys—(hwusbfake)
DRV - File not found [Kernel | On_Demand | Stopped]—system32\DRIVERS\ewusbmdm.sys—(hwdatacard)
DRV - File not found [Kernel | System | Stopped]——(Changer)
DRV - [2012-06-08 15:14:26 | 000,044,184 |——| M] () [Kernel | Boot | Running]—C:\WINDOWS\system32\drivers\fsbts.sys—(fsbts)
DRV - [2012-06-08 15:12:05 | 000,149,672 |——| M] () [Kernel | On_Demand | Running]—C:\Programmer\F-Secure\Anti-Virus\minifilter\fsgk.sys—(F-Secure Gatekeeper)
DRV - [2012-04-04 15:56:40 | 000,022,344 |——| M] (Malwarebytes Corporation) [File_System | On_Demand | Running]—C:\WINDOWS\system32\drivers\mbam.sys—(MBAMProtector)
DRV - [2011-12-16 17:53:00 | 000,025,088 |——| M] (TeamViewer GmbH) [Kernel | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\teamviewervpn.sys—(teamviewervpn)
DRV - [2011-09-02 08:31:28 | 000,039,192 |——| M] (Logitech, Inc.) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\LMouFilt.Sys—(LMouFilt)
DRV - [2011-09-02 08:31:28 | 000,030,360 |——| M] (Logitech, Inc.) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\LUsbFilt.sys—(LUsbFilt)
DRV - [2011-09-02 08:31:20 | 000,041,240 |——| M] (Logitech, Inc.) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\LHidFilt.Sys—(LHidFilt)
DRV - [2011-09-02 08:31:10 | 000,042,648 |——| M] (Logitech, Inc.) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\LEqdUsb.sys—(LEqdUsb)
DRV - [2011-09-02 08:31:10 | 000,012,184 |——| M] (Logitech, Inc.) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\LHidEqd.sys—(LHidEqd)
DRV - [2011-09-02 08:30:58 | 000,012,184 |——| M] (Logitech, Inc.) [Kernel | Auto | Running]—C:\WINDOWS\system32\drivers\LBeepKE.sys—(LBeepKE)
DRV - [2011-05-10 08:06:14 | 000,018,432 |——| M] (Apple Inc.) [Kernel | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\netaapl.sys—(Netaapl)
DRV - [2009-12-07 17:12:36 | 000,078,336 |——| M] (PC Dynamics, Inc.) [Kernel | System | Running]—C:\WINDOWS\system32\drivers\SafDskNT.sys—(SafDskNT)
DRV - [2009-11-26 11:36:28 | 000,068,080 |——| M] (F-Secure Corporation) [Kernel | System | Running]—C:\Programmer\F-Secure\HIPS\drivers\fshs.sys—(F-Secure HIPS)
DRV - [2009-11-26 11:35:58 | 000,080,016 |——| M] (F-Secure Corporation) [Kernel | Boot | Running]—C:\WINDOWS\system32\drivers\fsdfw.sys—(FSFW)
DRV - [2009-11-26 11:35:16 | 000,039,792 |——| M] () [Kernel | Disabled | Stopped]—C:\Programmer\F-Secure\Anti-Virus\win2k\fsfilter.sys—(F-Secure Filter)
DRV - [2009-11-26 11:35:16 | 000,025,200 |——| M] () [Kernel | Disabled | Stopped]—C:\Programmer\F-Secure\Anti-Virus\win2k\fsrec.sys—(F-Secure Recognizer)
DRV - [2009-11-12 14:48:56 | 000,005,504 |——| M] () [File_System | Auto | Running]—C:\WINDOWS\System32\drivers\StarOpen.sys—(StarOpen)
DRV - [2009-10-26 05:47:30 | 004,221,952 |——| M] (Intel Corporation) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\NETw5x32.sys—(NETw5x32) Intel(R)
DRV - [2009-05-06 13:11:22 | 000,023,096 |——| M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\SndTAudio.sys—(SndTAudio)
DRV - [2009-03-11 17:51:00 | 000,050,448 |——| M] (Basler AG) [Kernel | Auto | Running]—C:\WINDOWS\system32\drivers\pynwagnt.sys—(PYNWAGNT)
DRV - [2009-03-06 10:39:10 | 000,208,824 |——| M] (Wave Systems Corp.) [File_System | Auto | Running]—C:\WINDOWS\system32\drivers\WavxDMgr.sys—(WavxDMgr)
DRV - [2009-03-06 10:39:00 | 000,026,608 |——| M] (Dell Inc) [Kernel | Boot | Running]—C:\WINDOWS\system32\drivers\PBADRV.sys—(PBADRV)
DRV - [2009-02-03 19:13:30 | 000,049,552 |——| M] (Basler AG) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\pynwflt.sys—(PyNwFlt)
DRV - [2008-08-13 16:23:56 | 000,011,904 |——| M] (Intel Corporation) [Kernel | Auto | Running]—C:\WINDOWS\system32\drivers\s24trans.sys—(s24trans)
DRV - [2007-12-23 17:18:48 | 000,068,696 |——| M] (O2Micro) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\oz776.sys—(guardian2)
DRV - [2007-08-02 17:35:12 | 000,989,952 | R—- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\HSF_DPV.sys—(HSF_DPV)
DRV - [2007-08-02 17:34:30 | 000,211,200 | R—- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\HSFHWAZL.sys—(HSFHWAZL)
DRV - [2007-08-02 17:34:26 | 000,731,136 | R—- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\HSF_CNXT.sys—(winachsf)
DRV - [2007-06-20 14:30:20 | 000,010,480 |——| M] (Broadcom Corporation) [Kernel | Auto | Running]—C:\Programmer\Broadcom\ASFIPMon\BASFND.sys—(BASFND)
DRV - [2007-06-14 15:29:08 | 000,457,856 |——| M] (PixArt Imaging Inc.) [Kernel | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\PAC7302.SYS—(PAC7302)
DRV - [2007-06-06 12:51:04 | 000,161,792 |——| M] (Broadcom Corporation) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\b57xp32.sys—(b57w2k)
DRV - [2007-05-10 10:24:34 | 001,222,840 |——| M] (SigmaTel, Inc.) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\sthda.sys—(STHDA)
DRV - [2007-04-23 16:39:00 | 000,113,920 |——| M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\tosrfbd.sys—(tosrfbd)
DRV - [2007-04-10 20:29:42 | 000,041,856 |——| M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\tosrfusb.sys—(Tosrfusb)
DRV - [2007-03-21 22:02:04 | 000,037,376 |——| M] (REDC) [Kernel | Auto | Running]—C:\WINDOWS\system32\drivers\rixdptsk.sys—(rismxdp)
DRV - [2007-02-24 14:42:22 | 000,039,936 |——| M] (REDC) [Kernel | Auto | Running]—C:\WINDOWS\system32\drivers\rimmptsk.sys—(rimmptsk)
DRV - [2007-01-23 16:40:20 | 000,042,496 |——| M] (REDC) [Kernel | Auto | Running]—C:\WINDOWS\system32\drivers\rimsptsk.sys—(rimsptsk)
DRV - [2007-01-16 10:22:00 | 000,031,744 |——| M] (CSR, plc) [Kernel | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\csrbcxp.sys—(CSRBC)
DRV - [2006-11-22 16:09:22 | 000,053,504 |——| M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\TosRfSnd.sys—(TosRfSnd)
DRV - [2006-11-22 06:20:00 | 000,072,704 |——| M] (WIBU-SYSTEMS AG) [Kernel | Auto | Running]—C:\WINDOWS\system32\drivers\WibuKey.sys—(WIBUKEY)
DRV - [2006-11-20 17:55:16 | 000,036,480 |——| M] (TOSHIBA Corporation) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\tosrfbnp.sys—(tosrfbnp)
DRV - [2006-11-09 06:20:00 | 000,016,384 |——| M] (WIBU-SYSTEMS AG) [Kernel | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\Wibukey2.sys—(Wibukey2)
DRV - [2006-10-10 19:33:00 | 000,041,600 |——| M] (TOSHIBA Corporation) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\tosporte.sys—(tosporte)
DRV - [2006-10-05 16:07:46 | 000,073,600 |——| M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\Tosrfhid.sys—(Tosrfhid)
DRV - [2005-08-12 16:50:46 | 000,016,128 |——| M] (Dell Inc) [Kernel | System | Running]—C:\WINDOWS\system32\drivers\APPDRV.SYS—(APPDRV)
DRV - [2005-08-01 16:45:00 | 000,064,896 |——| M] (TOSHIBA Corporation) [Kernel | System | Running]—C:\WINDOWS\system32\drivers\tosrfcom.sys—(Tosrfcom)
DRV - [2005-01-06 13:42:00 | 000,018,612 |——| M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\tosrfnds.sys—(tosrfnds)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: “URL” = http://search.live.com/results.aspx?q={searchTerms}&src;={referrer:source?}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0
IE - HKU\S-1-5-21-2585336296-2683178579-560321132-1125\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://mit.tdc.dk/
IE - HKU\S-1-5-21-2585336296-2683178579-560321132-1125\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://dk.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-2585336296-2683178579-560321132-1125\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = da
IE - HKU\S-1-5-21-2585336296-2683178579-560321132-1125\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 26 6D 9D 9D 91 D6 CC 01 [binary data]
IE - HKU\S-1-5-21-2585336296-2683178579-560321132-1125\..\SearchScopes,DefaultScope = {9FDEE07F-1220-4EC1-A5E9-D5C11F9FF3E0}
IE - HKU\S-1-5-21-2585336296-2683178579-560321132-1125\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: “URL” = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-2585336296-2683178579-560321132-1125\..\SearchScopes\{9FDEE07F-1220-4EC1-A5E9-D5C11F9FF3E0}: “URL” = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie;={inputEncoding?}&oe;={outputEncoding?}
IE - HKU\S-1-5-21-2585336296-2683178579-560321132-1125\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0
IE - HKU\S-1-5-21-2585336296-2683178579-560321132-1125\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyOverride” = <local>
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Programmer\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Programmer\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Programmer\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Programmer\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@ptc.com/ProductViewLite: C:\Programmer\Fælles filer\PTC\np6_pvapplite9.dll (PTC)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.4.53: c:\programmer\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.4.53: c:\programmer\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.4.53: c:\programmer\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programmer\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programmer\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programmer\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012-05-31 18:22:37 | 000,000,000 |—-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\litmus-ff@f-secure.com: C:\Programmer\F-Secure\NRS\litmus-ff@f-secure.com [2012-06-08 15:11:54 | 000,000,000 |—-D | M]
[2011-12-09 21:22:56 | 000,002,047 |——| M] ()—C:\Programmer\mozilla firefox\searchplugins\fcmdSrch.xml
O1 HOSTS File: ([2012-05-31 17:43:02 | 000,000,355 |——| M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programmer\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Browsing Protection Class) - {C6867EB7-8350-4856-877F-93CF8AE3DC9C} - C:\Programmer\F-Secure\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O3 - HKLM\..\Toolbar: (Browsing Protection Toolbar) - {265EEE8E-3228-44D3-AEA5-F7FDF5860049} - C:\Programmer\F-Secure\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-2585336296-2683178579-560321132-1125\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.
O4 - HKLM..\Run: [Adobe ARM] C:\Programmer\Fælles filer\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Programmer\Fælles filer\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Programmer\Fælles filer\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ChangeTPMAuth] C:\Programmer\Wave Systems Corp\Common\ChangeTPMAuth.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [EmbassySecurityCheck] C:\Programmer\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [EvtMgr6] C:\Programmer\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [F-Secure Manager] C:\Programmer\F-Secure\Common\FSM32.EXE (F-Secure Corporation)
O4 - HKLM..\Run: [F-Secure TNB] C:\Programmer\F-Secure\FSGUI\TNBUtil.exe (F-Secure Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Programmer\Fælles filer\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Programmer\Intel\WiFi\bin\ZCfgSvc.exe (Intel(R) Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [lxdxamon] C:\Programmer\Lexmark 3600-4600 Series\lxdxamon.exe ()
O4 - HKLM..\Run: [lxdxmon.exe] C:\Programmer\Lexmark 3600-4600 Series\lxdxmon.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Programmer\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\Pac7302\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [SecureUpgrade] C:\Programmer\Wave Systems Corp\SecureUpgrade.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Programmer\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\programmer\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [WavXMgr] C:\Programmer\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe (Wave Systems Corp.)
O4 - Startup: C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Bluetooth Manager.lnk = C:\Programmer\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
O4 - Startup: C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Windchill ProductPoint Client Manager.lnk = C:\WINDOWS\Installer\{129024FF-A6C9-4696-91BC-570C6C05193A}\_F5BCEE176F60B4DABC6DF8.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\WinZip Quick Pick.lnk = C:\Programmer\WinZip\WZQKPICK.EXE (WinZip Computing, Inc.)
O4 - Startup: C:\Documents and Settings\kdp\Menuen Start\Programmer\Start\GoogleCalendarSync.exe (Google)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2585336296-2683178579-560321132-1125\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html File not found
O9 - Extra Button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Programmer\SoundTaxi\YouTubeRipper.dll ()
O9 - Extra ‘Tools’ menuitem : Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Programmer\SoundTaxi\YouTubeRipper.dll ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmer\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra ‘Tools’ menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmer\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Programmer\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {1ED48504-8834-11D5-AC75-0008C73FD642} file:///C:/Programmer/proeWildfire 3.0/i486_nt/obj/pvx_install.exe (ProductView Express)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bitdefender.com/qsax/qsax.cab (Bitdefender QuickScan Control)
O16 - DPF: {640373B0-6978-4FA5-A9FC-420ECBBC61C7} http://www.3d-sd.dk/general/3dmodels/TCC/Plan12/Komplet 3D-model - 12102009/dll/zkitlib.dll (Web Viewer Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1287304315765 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8BBDC81D-81B3-49EE-87E8-47B7A707FAE8} https://www2.gotomeeting.com/default/applets/g2mdlax.cab (GoToMeeting Web Starter)
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} http://ax.emsisoft.com/asquared.cab (a-squared Scanner)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.euro.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx (CRLDownloadWrapper Class)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/4.0.1.0/GarminAxControl_32.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.30 10.0.0.31
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Domain.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0AFBA613-A5B8-4D51-95D0-414234000AA9}: DhcpNameServer = 10.0.0.30 10.0.0.31
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{47068BAE-2166-4969-AC51-F95631FA372C}: DhcpNameServer = 10.0.0.30 10.0.0.31
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D7F3BAC3-B40C-4D72-922E-C9BA7A0F3CF0}: DhcpNameServer = 62.44.166.69 62.44.166.197
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programmer\Fælles filer\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programmer\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programmer\Fælles filer\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\programmer\fælles filer\logishrd\bluetooth\LBTWlgn.dll) - c:\Programmer\Fælles filer\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programmer\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (wvauth) - C:\WINDOWS\System32\wvauth.dll (Wave Systems Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012-05-09 14:48:32 | 000,000,000 |—-D | M] - C:\Autodesk—[ NTFS ]
O32 - AutoRun File - [2010-10-15 23:32:08 | 000,000,000 |——| M] () - C:\AUTOEXEC.BAT—[ NTFS ]
O32 - AutoRun File - [1999-05-25 10:35:16 | 000,001,788 |——| M] () - N:\AUTORUN.INF—[ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open]—“%1” %*
O35 - HKLM\..exefile [open]—“%1” %*
O37 - HKLM\...com [@ = comfile]—“%1” %*
O37 - HKLM\...exe [@ = exefile]—“%1” %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Sharedaccess - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
System Restore Service not available.
========== Files/Folders - Created Within 30 Days ==========
[2012-06-18 13:29:01 | 000,000,000 |—-D | C]—C:\Documents and Settings\kdp.DOMAIN\Skrivebord\novo foto
[2012-06-17 17:50:40 | 000,595,968 |——| C] (OldTimer Tools)—C:\Documents and Settings\kdp.DOMAIN\Skrivebord\OTL.exe
[2012-06-17 16:55:03 | 000,000,000 |—-D | C]—C:\Programmer\Trend Micro
[2012-06-17 16:55:03 | 000,000,000 |—-D | C]—C:\Documents and Settings\kdp.DOMAIN\Menuen Start\Programmer\HiJackThis
[2012-06-16 13:10:58 | 000,000,000 |—-D | C]—C:\Documents and Settings\kdp.DOMAIN\Dokumenter\Ny mappe (2)
[2012-06-16 13:10:57 | 000,000,000 |—-D | C]—C:\Documents and Settings\kdp.DOMAIN\Dokumenter\Dell
[2012-06-16 13:10:11 | 000,000,000 |—-D | C]—C:\Documents and Settings\kdp.DOMAIN\Menuen Start\Programmer\Dell Inc
[2012-06-16 12:49:17 | 000,000,000 |—-D | C]—C:\Documents and Settings\kdp.DOMAIN\Skrivebord\backups
[2012-06-16 12:36:13 | 000,000,000 | RH-D | C]—C:\Documents and Settings\kdp.DOMAIN\Recent
[2012-06-16 11:52:44 | 000,000,000 |—-D | C]—C:\Programmer\Desktop
[2012-06-13 22:15:25 | 000,000,000 |—-D | C]—C:\Documents and Settings\kdp.DOMAIN\Lokale indstillinger\Application Data\Secunia PSI
[2012-06-13 22:15:02 | 000,000,000 |—-D | C]—C:\Programmer\Secunia
[2012-06-12 21:37:36 | 000,000,000 |—-D | C]—C:\Programmer\ESET
[2012-06-11 14:45:29 | 000,000,000 |—-D | C]—C:\Programmer\Fælles filer\DESIGNER
[2012-06-11 14:44:31 | 000,000,000 |—-D | C]—C:\Programmer\Microsoft Visual Studio
[2012-06-08 15:06:22 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Menuen Start\Programmer\F-Secure Client Security
[2012-06-08 14:25:32 | 000,000,000 |—-D | C]—C:\Documents and Settings\NetworkService\Lokale indstillinger\Application Data\F-Secure
[2012-06-08 14:24:55 | 000,080,016 |——| C] (F-Secure Corporation)—C:\WINDOWS\System32\drivers\fsdfw.sys
[2012-06-08 14:18:26 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\fssg
[2012-06-08 14:17:34 | 000,000,000 |—-D | C]—C:\Programmer\F-Secure
[2012-06-08 14:16:44 | 000,000,000 |—-D | C]—C:\Documents and Settings\kdp.DOMAIN\Skrivebord\Fsecure
[2012-06-06 21:18:53 | 000,000,000 |—-D | C]—C:\Documents and Settings\kdp.DOMAIN\Lokale indstillinger\Application Data\Deployment
[2012-06-06 18:59:01 | 000,000,000 |—-D | C]—C:\Documents and Settings\kdp.DOMAIN\Dokumenter\Sommerferie
[2012-06-04 10:24:48 | 000,000,000 |—-D | C]—C:\adobeTemp
[2012-06-01 06:43:13 | 000,000,000 |—-D | C]—C:\Documents and Settings\kdp.DOMAIN\Application Data\Malwarebytes
[2012-06-01 06:43:03 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Menuen Start\Programmer\Malwarebytes’ Anti-Malware
[2012-06-01 06:43:00 | 000,022,344 |——| C] (Malwarebytes Corporation)—C:\WINDOWS\System32\drivers\mbam.sys
[2012-06-01 06:43:00 | 000,000,000 |—-D | C]—C:\Programmer\Malwarebytes’ Anti-Malware
[2012-06-01 06:43:00 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012-05-31 21:56:46 | 000,000,000 |—-D | C]—C:\Documents and Settings\kdp.DOMAIN\Application Data\QuickScan
[2012-05-31 21:08:06 | 000,000,000 |—-D | C]—C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2012-05-31 20:46:19 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\GFI Software
[2012-05-31 18:30:15 | 000,000,000 |—-D | C]—C:\Documents and Settings\kdp.DOMAIN\Application Data\Ad-Aware Antivirus
[2012-05-31 18:27:59 | 000,000,000 |—-D | C]—C:\Documents and Settings\NetworkService\Application Data\Ad-Aware Antivirus
[2012-05-31 18:23:21 | 000,000,000 |—-D | C]—C:\Programmer\Fælles filer\xing shared
[2012-05-31 18:23:17 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\Lavasoft
[2012-05-31 18:23:16 | 000,000,000 |—-D | C]—C:\Programmer\Ad-Aware Antivirus
[2012-05-31 18:20:07 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Menuen Start\Programmer\RealNetworks
[2012-05-31 17:32:08 | 000,000,000 |—-D | C]—C:\Documents and Settings\kdp.DOMAIN\Application Data\f-secure
[2012-05-31 17:31:49 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\F-Secure
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012-06-18 15:08:00 | 000,000,410 | -H—| M] ()—C:\WINDOWS\tasks\User_Feed_Synchronization-{1BA29A02-51F6-4C03-99DF-E445CA6AF43E}.job
[2012-06-18 15:07:00 | 000,000,410 | -H—| M] ()—C:\WINDOWS\tasks\User_Feed_Synchronization-{AA14B53C-C34E-4453-AD51-5FFC7D7EB41B}.job
[2012-06-18 15:07:00 | 000,000,410 | -H—| M] ()—C:\WINDOWS\tasks\User_Feed_Synchronization-{7FC6C589-A425-49F0-9FD5-1ACBF095F1C7}.job
[2012-06-18 14:41:00 | 000,000,914 |——| M] ()—C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA1cc240fc5b0f11e.job
[2012-06-18 14:36:00 | 000,000,830 |——| M] ()—C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012-06-18 14:08:45 | 000,000,982 |——| M] ()—C:\Documents and Settings\kdp.DOMAIN\Skrivebord\Genvej til Dropbox.exe.lnk
[2012-06-18 11:15:00 | 000,000,964 |——| M] ()—C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-746137067-879983540-725345543-1003Core.job
[2012-06-18 10:55:10 | 000,002,585 |——| M] ()—C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Windchill ProductPoint Client Manager.lnk
[2012-06-18 10:54:45 | 000,000,000 |——| M] ()—C:\Documents and Settings\kdp.DOMAIN\Lokale indstillinger\Application Data\WavXMapDrive.bat
[2012-06-18 10:54:21 | 000,002,206 |——| M] ()—C:\WINDOWS\System32\wpa.dbl
[2012-06-18 10:54:19 | 000,000,910 |——| M] ()—C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cc240fc539bb8a.job
[2012-06-18 10:54:17 | 000,000,422 |——| M] ()—C:\WINDOWS\tasks\SyncToy 2.job
[2012-06-18 10:54:17 | 000,000,268 |——| M] ()—C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-746137067-879983540-725345543-1003.job
[2012-06-18 10:54:17 | 000,000,268 |——| M] ()—C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2585336296-2683178579-560321132-1125.job
[2012-06-18 10:54:17 | 000,000,268 |——| M] ()—C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1275210071-1614895754-839522115-1175.job
[2012-06-18 10:45:49 | 000,002,048 |—S- | M] ()—C:\WINDOWS\bootstat.dat
[2012-06-17 22:17:05 | 000,076,933 |——| M] ()—C:\Documents and Settings\kdp.DOMAIN\Skrivebord\screen.jpg
[2012-06-17 22:13:06 | 002,073,654 |——| M] ()—C:\Documents and Settings\kdp.DOMAIN\Skrivebord\screen.bmp
[2012-06-17 17:50:49 | 000,595,968 |——| M] (OldTimer Tools)—C:\Documents and Settings\kdp.DOMAIN\Skrivebord\OTL.exe
[2012-06-17 16:55:27 | 000,002,439 |——| M] ()—C:\Documents and Settings\kdp.DOMAIN\Skrivebord\HiJackThis.lnk
[2012-06-17 16:42:17 | 000,002,535 |——| M] ()—C:\Documents and Settings\kdp.DOMAIN\Skrivebord\Microsoft Office Word 2007.lnk
[2012-06-16 12:47:01 | 000,002,187 |——| M] ()—C:\Documents and Settings\kdp.DOMAIN\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2012-06-15 10:09:52 | 000,000,301 |——| M] ()—C:\WINDOWS\AllegroClient.INI
[2012-06-13 12:50:24 | 000,001,824 | -H—| M] ()—C:\Documents and Settings\kdp.DOMAIN\Dokumenter\Default.rdp
[2012-06-13 03:35:39 | 003,646,344 |——| M] ()—C:\WINDOWS\System32\FNTCACHE.DAT
[2012-06-13 03:17:26 | 000,543,802 |——| M] ()—C:\WINDOWS\System32\perfh006.dat
[2012-06-13 03:17:26 | 000,504,494 |——| M] ()—C:\WINDOWS\System32\perfh009.dat
[2012-06-13 03:17:26 | 000,110,374 |——| M] ()—C:\WINDOWS\System32\perfc006.dat
[2012-06-13 03:17:26 | 000,089,094 |——| M] ()—C:\WINDOWS\System32\perfc009.dat
[2012-06-12 21:04:19 | 000,000,276 |——| M] ()—C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2585336296-2683178579-560321132-1125.job
[2012-06-12 17:41:04 | 000,000,276 |——| M] ()—C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1275210071-1614895754-839522115-1175.job
[2012-06-12 13:23:23 | 000,073,176 | -H—| M] ()—C:\WINDOWS\System32\mlfcache.dat
[2012-06-12 12:01:00 | 000,000,272 |——| M] ()—C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012-06-11 15:01:56 | 000,000,777 |——| M] ()—C:\Documents and Settings\kdp.DOMAIN\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2012-06-11 08:10:07 | 000,002,329 |——| M] ()—C:\Documents and Settings\All Users\Skrivebord\Axon 2.lnk
[2012-06-08 15:14:26 | 000,044,184 |——| M] ()—C:\WINDOWS\System32\drivers\fsbts.sys
[2012-06-06 15:46:55 | 000,009,728 |——| M] ()—C:\Documents and Settings\kdp.DOMAIN\Lokale indstillinger\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012-06-05 20:00:04 | 000,060,304 |——| M] ()—C:\Documents and Settings\kdp.DOMAIN\g2mdlhlpx.exe
[2012-06-05 13:54:38 | 017,748,594 |——| M] ()—C:\Documents and Settings\kdp.DOMAIN\Dokumenter\tv manual.pdf
[2012-06-04 21:50:00 | 000,000,276 |——| M] ()—C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-746137067-879983540-725345543-1003.job
[2012-06-04 13:55:08 | 000,000,763 |——| M] ()—C:\Documents and Settings\All Users\Skrivebord\Malwarebytes Anti-Malware.lnk
[2012-05-31 21:00:17 | 000,000,664 |——| M] ()—C:\WINDOWS\System32\d3d9caps.dat
[2012-05-31 18:32:04 | 000,000,940 |——| M] ()—C:\WINDOWS\tasks\Ad-Aware Antivirus Scheduled Scan.job
[2012-05-31 18:23:51 | 000,000,733 |——| M] ()—C:\Documents and Settings\kdp.DOMAIN\Skrivebord\RealPlayer.lnk
[2012-05-31 18:20:06 | 000,272,896 |——| M] (Progressive Networks)—C:\WINDOWS\System32\pncrt.dll
[2012-05-31 18:17:37 | 000,000,211 | -HS- | M] ()—C:\boot.ini
[2012-05-31 17:43:02 | 000,000,355 |——| M] ()—C:\WINDOWS\System32\drivers\etc\hosts
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012-06-18 14:08:45 | 000,000,982 |——| C] ()—C:\Documents and Settings\kdp.DOMAIN\Skrivebord\Genvej til Dropbox.exe.lnk
[2012-06-17 22:16:41 | 000,076,933 |——| C] ()—C:\Documents and Settings\kdp.DOMAIN\Skrivebord\screen.jpg
[2012-06-17 22:13:03 | 002,073,654 |——| C] ()—C:\Documents and Settings\kdp.DOMAIN\Skrivebord\screen.bmp
[2012-06-17 16:55:03 | 000,002,439 |——| C] ()—C:\Documents and Settings\kdp.DOMAIN\Skrivebord\HiJackThis.lnk
[2012-06-08 14:25:16 | 000,044,184 |——| C] ()—C:\WINDOWS\System32\drivers\fsbts.sys
[2012-06-06 22:05:20 | 002,344,352 |——| C] ()—C:\Documents and Settings\LocalService\Lokale indstillinger\Application Data\FontCache3.0.0.0.dat
[2012-06-06 21:49:34 | 000,000,268 |——| C] ()—C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2585336296-2683178579-560321132-1125.job
[2012-06-05 13:54:39 | 017,748,594 |——| C] ()—C:\Documents and Settings\kdp.DOMAIN\Dokumenter\tv manual.pdf
[2012-06-05 13:03:36 | 000,002,303 |——| C] ()—C:\Documents and Settings\All Users\Menuen Start\Programmer\Adobe Reader X.lnk
[2012-06-04 13:55:08 | 000,000,763 |——| C] ()—C:\Documents and Settings\All Users\Skrivebord\Malwarebytes Anti-Malware.lnk
[2012-05-31 18:32:04 | 000,000,940 |——| C] ()—C:\WINDOWS\tasks\Ad-Aware Antivirus Scheduled Scan.job
[2012-05-31 18:23:51 | 000,000,733 |——| C] ()—C:\Documents and Settings\kdp.DOMAIN\Skrivebord\RealPlayer.lnk
[2012-05-09 14:27:33 | 000,000,566 |——| C] ()—C:\WINDOWS\System32\SP7302.INI
[2012-03-10 18:03:59 | 000,000,552 |——| C] ()—C:\WINDOWS\System32\d3d8caps.dat
[2012-02-16 18:56:46 | 000,003,072 |——| C] ()—C:\WINDOWS\System32\iacenc.dll
[2012-01-23 14:35:04 | 000,009,728 |——| C] ()—C:\Documents and Settings\kdp.DOMAIN\Lokale indstillinger\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012-01-18 18:27:53 | 001,829,618 |——| C] ()—C:\Documents and Settings\LocalService\Lokale indstillinger\Application Data\WPFFontCache_v0400-S-1-5-21-2585336296-2683178579-560321132-1125-0.dat
[2012-01-18 18:27:53 | 000,418,254 |——| C] ()—C:\Documents and Settings\LocalService\Lokale indstillinger\Application Data\WPFFontCache_v0400-S-1-5-21-2585336296-2683178579-560321132-500-0.dat
[2012-01-18 17:16:59 | 000,000,000 |——| C] ()—C:\Documents and Settings\kdp.DOMAIN\Lokale indstillinger\Application Data\WavXMapDrive.bat
[2012-01-18 16:34:00 | 000,418,254 |——| C] ()—C:\Documents and Settings\LocalService\Lokale indstillinger\Application Data\WPFFontCache_v0400-S-1-5-21-746137067-879983540-725345543-500-0.dat
[2011-05-30 16:34:09 | 001,204,974 |——| C] ()—C:\Documents and Settings\LocalService\Lokale indstillinger\Application Data\WPFFontCache_v0400-S-1-5-21-746137067-879983540-725345543-1003-0.dat
[2011-05-30 16:34:08 | 000,412,738 |——| C] ()—C:\Documents and Settings\LocalService\Lokale indstillinger\Application Data\WPFFontCache_v0400-System.dat
[2011-05-30 11:21:41 | 000,000,000 |——| C] ()—C:\WINDOWS\eDrawingOfficeAutomator.INI
[2011-05-10 08:49:05 | 000,260,808 |——| C] ()—C:\WINDOWS\System32\nvdrsdb1.bin
[2011-05-10 08:49:05 | 000,260,808 |——| C] ()—C:\WINDOWS\System32\nvdrsdb0.bin
[2011-05-10 08:49:05 | 000,000,001 |——| C] ()—C:\WINDOWS\System32\nvdrssel.bin
[2011-05-10 08:48:42 | 002,116,894 |——| C] ()—C:\WINDOWS\System32\nvdata.bin
[2011-05-04 13:13:05 | 000,073,176 | -H—| C] ()—C:\WINDOWS\System32\mlfcache.dat
[2011-03-01 10:43:45 | 000,005,504 |——| C] ()—C:\WINDOWS\System32\drivers\StarOpen.sys
[2011-02-28 14:32:33 | 000,090,112 |——| C] ()—C:\WINDOWS\System32\custmon2k.dll
[2011-02-28 14:32:33 | 000,053,248 |——| C] ()—C:\WINDOWS\System32\uninstpw.exe
[2010-12-27 03:33:31 | 000,000,664 |——| C] ()—C:\WINDOWS\System32\d3d9caps.dat
[2010-11-30 12:24:46 | 000,000,099 |——| C] ()—C:\WINDOWS\WirelessFTP.INI
[2010-11-24 15:31:20 | 000,053,248 |——| C] ()—C:\WINDOWS\System32\ZLIB.DLL
[2010-11-19 14:53:53 | 000,000,043 |——| C] ()—C:\WINDOWS\gswin32.ini
[2010-11-19 14:05:19 | 000,000,032 |——| C] ()—C:\WINDOWS\PrintPreview.INI
[2010-11-15 13:03:10 | 000,057,552 |——| C] ()—C:\WINDOWS\System32\WkDos.exe
[2010-11-04 09:50:04 | 000,000,144 |——| C] ()—C:\WINDOWS\VCVI_vui.ini
[2010-11-04 09:50:04 | 000,000,000 |——| C] ()—C:\WINDOWS\VCVI_vui_ftb.ini
[2010-11-02 15:56:33 | 000,000,056 | -H—| C] ()—C:\WINDOWS\System32\ezsidmv.dat
[2010-11-01 22:33:25 | 000,127,026 |——| C] ()—C:\WINDOWS\System32\pdfmona.dll
[2010-11-01 22:33:24 | 000,048,936 |——| C] ()—C:\WINDOWS\System32\pdf995mon.dll
[2010-11-01 21:18:55 | 000,000,000 |——| C] ()—C:\WINDOWS\communicator_NextDay.ini
[2010-10-31 12:36:27 | 000,000,044 |——| C] ()—C:\WINDOWS\System32\lxdxrwrd.ini
[2010-10-25 21:40:11 | 000,040,960 |——| C] ()—C:\WINDOWS\System32\lxdxvs.dll
[2010-10-25 21:40:10 | 000,409,600 |——| C] ( )—C:\WINDOWS\System32\lxdxcoin.dll
[2010-10-25 21:39:51 | 000,782,336 |——| C] ()—C:\WINDOWS\System32\lxdxdrs.dll
[2010-10-25 21:39:51 | 000,081,920 |——| C] ()—C:\WINDOWS\System32\lxdxcaps.dll
[2010-10-25 21:39:51 | 000,069,632 |——| C] ()—C:\WINDOWS\System32\lxdxcnv4.dll
[2010-10-25 21:39:28 | 001,105,920 |——| C] ( )—C:\WINDOWS\System32\lxdxserv.dll
[2010-10-25 21:39:28 | 000,843,776 |——| C] ( )—C:\WINDOWS\System32\lxdxusb1.dll
[2010-10-25 21:39:28 | 000,663,552 |——| C] ( )—C:\WINDOWS\System32\lxdxhbn3.dll
[2010-10-25 21:39:28 | 000,647,168 |——| C] ( )—C:\WINDOWS\System32\lxdxpmui.dll
[2010-10-25 21:39:28 | 000,569,344 |——| C] ( )—C:\WINDOWS\System32\lxdxlmpm.dll
[2010-10-25 21:39:28 | 000,438,272 |——| C] ( )—C:\WINDOWS\System32\LXDXhcp.dll
[2010-10-25 21:39:28 | 000,364,544 |——| C] ( )—C:\WINDOWS\System32\lxdxinpa.dll
[2010-10-25 21:39:28 | 000,348,160 |——| C] ()—C:\WINDOWS\System32\LXDXinst.dll
[2010-10-25 21:39:28 | 000,339,968 |——| C] ( )—C:\WINDOWS\System32\lxdxiesc.dll
[2010-10-25 21:39:28 | 000,320,168 |——| C] ( )—C:\WINDOWS\System32\lxdxih.exe
[2010-10-25 21:39:28 | 000,208,896 |——| C] ()—C:\WINDOWS\System32\lxdxgrd.dll
[2010-10-25 21:39:28 | 000,106,496 |——| C] ()—C:\WINDOWS\System32\lxdxinsr.dll
[2010-10-25 21:39:28 | 000,053,248 |——| C] ( )—C:\WINDOWS\System32\lxdxprox.dll
[2010-10-25 21:39:27 | 000,851,968 |——| C] ( )—C:\WINDOWS\System32\lxdxcomc.dll
[2010-10-25 21:39:27 | 000,594,600 |——| C] ( )—C:\WINDOWS\System32\lxdxcoms.exe
[2010-10-25 21:39:27 | 000,376,832 |——| C] ( )—C:\WINDOWS\System32\lxdxcomm.dll
[2010-10-25 21:39:27 | 000,365,224 |——| C] ( )—C:\WINDOWS\System32\lxdxcfg.exe
[2010-10-25 09:20:10 | 000,000,301 |——| C] ()—C:\WINDOWS\AllegroClient.INI
[2010-10-24 17:00:05 | 000,000,352 |——| C] ()—C:\WINDOWS\modelcheck.INI
[2010-10-18 15:17:07 | 000,000,000 |——| C] ()—C:\WINDOWS\vpc32.INI
[2010-10-17 09:29:14 | 000,000,376 |——| C] ()—C:\WINDOWS\ODBC.INI
[2010-10-16 20:18:06 | 000,080,368 |——| C] ()—C:\WINDOWS\System32\pbadrvdll.dll
[2010-10-16 20:18:02 | 000,143,360 |——| C] ()—C:\WINDOWS\System32\bioapi_mds300.dll.bak
[2010-10-16 20:18:02 | 000,143,360 |——| C] ()—C:\WINDOWS\System32\bioapi_mds300.dll
[2010-10-16 20:18:02 | 000,106,496 |——| C] ()—C:\WINDOWS\System32\bioapi100.dll.bak
[2010-10-16 20:18:02 | 000,106,496 |——| C] ()—C:\WINDOWS\System32\bioapi100.dll
[2010-10-16 11:46:32 | 000,000,000 |——| C] ()—C:\WINDOWS\tosOBEX.INI
[2010-10-16 11:19:53 | 000,016,480 |——| C] ()—C:\WINDOWS\System32\rixdicon.dll
[2010-10-16 10:01:31 | 000,106,113 |——| C] ()—C:\WINDOWS\System32\nvModes.dat
[2010-10-16 00:53:59 | 000,004,161 |——| C] ()—C:\WINDOWS\ODBCINST.INI
[2010-10-16 00:52:51 | 003,646,344 |——| C] ()—C:\WINDOWS\System32\FNTCACHE.DAT
[2010-10-15 23:35:26 | 000,002,048 |—S- | C] ()—C:\WINDOWS\bootstat.dat
[2010-10-15 23:29:18 | 000,021,644 |——| C] ()—C:\WINDOWS\System32\emptyregdb.dat
[2010-09-17 11:00:30 | 000,106,208 |——| C] ()—C:\WINDOWS\System32\CprIf.dll
[2004-08-27 12:00:00 | 000,002,048 | -HS- | C] ()—C:\WINDOWS\Installer\{bcda107f-ad12-95a3-75a1-058bac59bc77}\@
[2004-08-27 12:00:00 | 000,002,048 | -HS- | C] ()—C:\Documents and Settings\kdp.DOMAIN\Lokale indstillinger\Application Data\{bcda107f-ad12-95a3-75a1-058bac59bc77}\@
========== LOP Check ==========
[2012-01-18 16:29:38 | 000,000,000 |—-D | M]—C:\Documents and Settings\Administrator\Application Data\Garmin
[2010-10-24 15:00:04 | 000,000,000 |—-D | M]—C:\Documents and Settings\Administrator\Application Data\Wave Systems Corp
[2010-10-24 14:46:01 | 000,000,000 |—-D | M]—C:\Documents and Settings\Administrator\Application Data\Windows Desktop Search
[2012-01-18 17:15:29 | 000,000,000 |—-D | M]—C:\Documents and Settings\administrator.DOMAIN\Application Data\Garmin
[2012-01-18 17:20:15 | 000,000,000 |—-D | M]—C:\Documents and Settings\administrator.DOMAIN\Application Data\Wave Systems Corp
[2012-01-18 17:15:34 | 000,000,000 |—-D | M]—C:\Documents and Settings\administrator.DOMAIN\Application Data\Windows Desktop Search
[2012-01-20 11:52:25 | 000,000,000 |—-D | M]—C:\Documents and Settings\administrator.DOMAIN\Application Data\Windows Search
[2012-05-09 15:09:14 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\Autodesk
[2011-03-01 10:43:55 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2011-02-09 14:22:32 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\Ecrion
[2012-06-08 14:24:53 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\F-Secure
[2011-12-09 21:22:51 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\Freemake
[2012-06-08 14:18:26 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\fssg
[2012-06-11 08:11:43 | 000,000,000 |—-D | M]—C:\Documents and Settings\All