Hej Emeritius,
jeg kan ikke se mit eget svar til dig, saa jeg ved ikke, om det kom igennem, derfor proever jeg igen….
Du var til stor hjaelp i sommers, men nu har jeg desvaerre igen faaet samme problem, hvor nogen - denne gang paa dansk - har haft held til at laase min computer og kun mod betaling vil laase den op igen. Det er naturligvis fup og svindel. Jeg haaber du kan hjaelpe. Jeg kender jo steps’ene fra i sommers, saa her er resultatet af FRST scanningen:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-01-2013
Ran by SYSTEM at 20-01-2013 14:35:10
Running from G:\
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [IntelTBRunOnce] wscript.exe //b //nologo “C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs” [4526 2010-11-29] ()
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2531624 2010-12-16] (Synaptics Incorporated)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11860072 2011-06-08] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE4 [2226280 2011-06-02] (Realtek Semiconductor)
HKLM\...\Run: [Power Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1831528 2011-05-10] (Acer Incorporated)
HKLM\...\Run: [BCSSync] “C:\Program Files\Microsoft Office\Office14\BCSSync.exe” /DelayServices [112512 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [MSC] “c:\Program Files\Microsoft Security Client\msseces.exe” -hide -runkey [1289704 2012-09-12] (Microsoft Corporation)
HKLM-x32\...\Run: [SuiteTray] “C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe” [340848 2011-04-02] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisTecPMMUpdate] “C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe” [408432 2011-03-28] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] “C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe” -d [202608 2011-03-28] (Egis Technology Inc.)
HKLM-x32\...\Run: [BackupManagerTray] “C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe” -h -k [297280 2011-04-23] (NTI Corporation)
HKLM-x32\...\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe [1103440 2011-06-30] (Dritek System Inc.)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] “C:\Dolby PCEE4\pcee4.exe” -autostart [506712 2011-02-03] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [ArcadeMovieService] “C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe” [177448 2011-05-09] (CyberLink Corp.)
HKLM-x32\...\Run: [Google Desktop Search] “C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe” /startup [30192 2011-10-04] (Google)
HKLM-x32\...\Run: [SunJavaUpdateSched] “C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe” [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\SSMMgr.exe /autorun [618496 2010-06-07] ()
HKLM-x32\...\Run: [CLX3180_Scan2Pc] C:\Windows\Twain_32\Samsung\CLX3180\Scan2pc.exe [1990144 2011-04-28] ()
HKLM-x32\...\Run: [3180 Scan2PC] “C:\Windows\twain_32\Samsung\CLX3180\Scan2Pc.exe” [1990144 2011-04-28] ()
HKLM-x32\...\Run: [APSDaemon] “C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe” [59240 2011-09-26] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] “C:\Program Files (x86)\iTunes\iTunesHelper.exe” [421736 2011-11-12] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe” [946352 2012-12-02] (Adobe Systems Incorporated)
HKU\AGR\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-07-29] ()
HKU\ASP.NET v4.0\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-07-29] ()
HKU\Classic .NET AppPool\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-07-29] ()
HKU\Default\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-07-29] ()
HKU\Default User\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-07-29] ()
HKU\DefaultAppPool\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-07-29] ()
HKU\Kim\...\Run: [gStart] C:\Program Files (x86)\Garmin\Training Center\gStart.exe [1891416 2008-08-13] (GARMIN Corp.)
HKU\Kim\...\Run: [Google Update] “C:\Users\Kim\AppData\Local\Google\Update\GoogleUpdate.exe” /c [116648 2012-04-20] (Google Inc.)
HKU\Kim\...\Winlogon: [Shell] explorer.exe,C:\Users\Kim\AppData\Roaming\skype.dat [65536 2011-11-16] ()
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
AppInit_DLLs: C:\Windows\System32\nvinitx.dll
Startup: C:\Users\Kim\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
==================== Services (Whitelisted) ===================
3 GoogleDesktopManager-051210-111108; “C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe” [30192 2011-10-04] (Google)
2 HWDeviceService64.exe; “C:\ProgramData\DatacardService\HWDeviceService64.exe” -/service [346976 2011-03-14] ()
2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [15872 2010-11-20] (Microsoft Corporation)
2 MsDtsServer100; “C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe” [210784 2011-06-17] (Microsoft Corporation)
2 MsMpSvc; “C:\Program Files\Microsoft Security Client\MsMpEng.exe” [22072 2012-09-12] (Microsoft Corporation)
2 MSSQLSERVER; “C:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe” -sMSSQLSERVER [62111072 2011-06-17] (Microsoft Corporation)
3 NisSrv; “C:\Program Files\Microsoft Security Client\NisSrv.exe” [368896 2012-09-12] (Microsoft Corporation)
2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256832 2011-04-23] (NTI Corporation)
3 SQLSERVERAGENT; “C:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE” -i MSSQLSERVER [431456 2011-06-17] (Microsoft Corporation)
2 TrueMove hi-speed connection. RunOuc; C:\Program Files (x86)\TrueMove hi-speed connection\UpdateDog\ouc.exe [655712 2011-08-23] ()
2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation)
2 W3SVC; C:\Windows\SysWow64\inetsrv\iisw3adm.dll [397824 2010-11-20] (Microsoft Corporation)
3 wifimansvc; C:\Program Files (x86)\TrueMove hi-speed connection\eap\wifimansvc.exe [598528 2011-09-26] ()
3 MSSQLFDLauncher; “C:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe” -s MSSQL10_50.MSSQLSERVER [x]
==================== Drivers (Whitelisted) =====================
2 DgiVecp; C:\Windows\System32\Drivers\DgiVecp.sys [53816 2009-07-13] (Samsung Electronics Co., Ltd.)
0 MpFilter; C:\Windows\System32\Drivers\MpFilter.sys [228768 2012-08-30] (Microsoft Corporation)
2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [128456 2012-08-30] (Microsoft Corporation)
3 NPF; C:\Windows\System32\Drivers\NPF.sys [35344 2011-09-21] (CACE Technologies, Inc.)
3 NPF; C:\Windows\SysWow64\Drivers\NPF.sys [35344 2011-09-21] (CACE Technologies, Inc.)
3 catchme; \??\C:\ComboFix\catchme.sys [x]
==================== NetSvcs (Whitelisted) ====================
==================== One Month Created Files and Folders ========
2013-01-17 08:16 - 2013-01-17 08:16 - 00509185 ____A C:\Users\Kim\Desktop\AGR screenshots.pptx
2013-01-17 08:12 - 2013-01-17 08:13 - 00236544 ____A C:\Users\Kim\Desktop\AGR screenshot.ppt
2013-01-16 12:46 - 2013-01-16 12:46 - 00013768 ____A C:\Users\Kim\Desktop\Book1.xlsx
2013-01-16 10:37 - 2013-01-16 10:57 - 00013444 ____A C:\Users\Kim\Desktop\Rest fakturering 2012 Nilec - KP.xlsx
2013-01-11 07:13 - 2013-01-14 08:24 - 00000000 ____D C:\Users\Kim\Desktop\New folder (2)
2013-01-09 13:39 - 2013-01-09 13:39 - 00012487 ____A C:\Users\Kim\Desktop\Costs december 2012 - Palmi.xlsx
2013-01-09 09:19 - 2013-01-17 02:10 - 00013177 ____A C:\Users\Kim\Desktop\Otsuka calendar JAN2013.xlsx
2013-01-09 06:22 - 2012-12-07 05:20 - 00441856 ____A (Microsoft Corporation) C:\Windows\System32\Wpc.dll
2013-01-09 06:22 - 2012-12-07 05:15 - 02746368 ____A (Microsoft Corporation) C:\Windows\System32\gameux.dll
2013-01-09 06:22 - 2012-12-07 04:26 - 00308736 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2013-01-09 06:22 - 2012-12-07 04:20 - 02576384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
2013-01-09 06:22 - 2012-12-07 03:20 - 00045568 ____A (Microsoft) C:\Windows\System32\oflc-nz.rs
2013-01-09 06:22 - 2012-12-07 03:20 - 00044544 ____A (Microsoft) C:\Windows\System32\pegibbfc.rs
2013-01-09 06:22 - 2012-12-07 03:20 - 00043520 ____A (Microsoft) C:\Windows\System32\csrr.rs
2013-01-09 06:22 - 2012-12-07 03:20 - 00030720 ____A (Microsoft) C:\Windows\System32\usk.rs
2013-01-09 06:22 - 2012-12-07 03:20 - 00023552 ____A (Microsoft) C:\Windows\System32\oflc.rs
2013-01-09 06:22 - 2012-12-07 03:20 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi-pt.rs
2013-01-09 06:22 - 2012-12-07 03:20 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi-fi.rs
2013-01-09 06:22 - 2012-12-07 03:19 - 00055296 ____A (Microsoft) C:\Windows\System32\cero.rs
2013-01-09 06:22 - 2012-12-07 03:19 - 00051712 ____A (Microsoft) C:\Windows\System32\esrb.rs
2013-01-09 06:22 - 2012-12-07 03:19 - 00046592 ____A (Microsoft) C:\Windows\System32\fpb.rs
2013-01-09 06:22 - 2012-12-07 03:19 - 00040960 ____A (Microsoft) C:\Windows\System32\cob-au.rs
2013-01-09 06:22 - 2012-12-07 03:19 - 00021504 ____A (Microsoft) C:\Windows\System32\grb.rs
2013-01-09 06:22 - 2012-12-07 03:19 - 00020480 ____A (Microsoft) C:\Windows\System32\pegi.rs
2013-01-09 06:22 - 2012-12-07 03:19 - 00015360 ____A (Microsoft) C:\Windows\System32\djctq.rs
2013-01-09 06:22 - 2012-12-07 02:46 - 00055296 ____A (Microsoft) C:\Windows\SysWOW64\cero.rs
2013-01-09 06:22 - 2012-12-07 02:46 - 00051712 ____A (Microsoft) C:\Windows\SysWOW64\esrb.rs
2013-01-09 06:22 - 2012-12-07 02:46 - 00046592 ____A (Microsoft) C:\Windows\SysWOW64\fpb.rs
2013-01-09 06:22 - 2012-12-07 02:46 - 00045568 ____A (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs
2013-01-09 06:22 - 2012-12-07 02:46 - 00044544 ____A (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs
2013-01-09 06:22 - 2012-12-07 02:46 - 00043520 ____A (Microsoft) C:\Windows\SysWOW64\csrr.rs
2013-01-09 06:22 - 2012-12-07 02:46 - 00040960 ____A (Microsoft) C:\Windows\SysWOW64\cob-au.rs
2013-01-09 06:22 - 2012-12-07 02:46 - 00030720 ____A (Microsoft) C:\Windows\SysWOW64\usk.rs
2013-01-09 06:22 - 2012-12-07 02:46 - 00023552 ____A (Microsoft) C:\Windows\SysWOW64\oflc.rs
2013-01-09 06:22 - 2012-12-07 02:46 - 00021504 ____A (Microsoft) C:\Windows\SysWOW64\grb.rs
2013-01-09 06:22 - 2012-12-07 02:46 - 00020480 ____A (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs
2013-01-09 06:22 - 2012-12-07 02:46 - 00020480 ____A (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs
2013-01-09 06:22 - 2012-12-07 02:46 - 00020480 ____A (Microsoft) C:\Windows\SysWOW64\pegi.rs
2013-01-09 06:22 - 2012-12-07 02:46 - 00015360 ____A (Microsoft) C:\Windows\SysWOW64\djctq.rs
2013-01-09 06:22 - 2012-11-21 21:44 - 00800768 ____A (Microsoft Corporation) C:\Windows\System32\usp10.dll
2013-01-09 06:22 - 2012-11-21 20:45 - 00626688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2013-01-09 06:22 - 2012-11-19 21:48 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2013-01-09 06:22 - 2012-11-19 20:51 - 00220160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-01-09 06:22 - 2012-11-08 21:45 - 00750592 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-01-09 06:22 - 2012-11-08 20:43 - 00492032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-01-09 06:22 - 2012-10-31 21:43 - 02002432 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2013-01-09 06:22 - 2012-10-31 21:43 - 01882624 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2013-01-09 06:22 - 2012-10-31 20:47 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2013-01-09 06:22 - 2012-10-31 20:47 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2013-01-09 06:21 - 2012-11-29 21:45 - 00362496 ____A (Microsoft Corporation) C:\Windows\System32\wow64win.dll
2013-01-09 06:21 - 2012-11-29 21:45 - 00243200 ____A (Microsoft Corporation) C:\Windows\System32\wow64.dll
2013-01-09 06:21 - 2012-11-29 21:45 - 00215040 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2013-01-09 06:21 - 2012-11-29 21:45 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll
2013-01-09 06:21 - 2012-11-29 21:43 - 00016384 ____A (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll
2013-01-09 06:21 - 2012-11-29 21:41 - 01161216 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2013-01-09 06:21 - 2012-11-29 21:41 - 00424448 ____A (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00006144 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00005120 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 21:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:54 - 00005120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-01-09 06:21 - 2012-11-29 20:53 - 01114112 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-01-09 06:21 - 2012-11-29 20:53 - 00274944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00005120 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 20:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 19:23 - 00338432 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
2013-01-09 06:21 - 2012-11-29 18:44 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-01-09 06:21 - 2012-11-29 18:44 - 00014336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-01-09 06:21 - 2012-11-29 18:44 - 00007680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-01-09 06:21 - 2012-11-29 18:44 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-01-09 06:21 - 2012-11-29 18:38 - 00006144 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 18:38 - 00004608 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 18:38 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 18:38 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-01-09 06:21 - 2012-11-29 15:17 - 00420064 ____A C:\Windows\SysWOW64\locale.nls
2013-01-09 06:21 - 2012-11-29 15:15 - 00420064 ____A C:\Windows\System32\locale.nls
2013-01-09 06:21 - 2012-11-22 19:26 - 03149824 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-01-09 06:21 - 2012-11-22 19:13 - 00068608 ____A (Microsoft Corporation) C:\Windows\System32\taskhost.exe
2013-01-07 00:06 - 2013-01-07 12:44 - 00000000 ____D C:\Users\Kim\Desktop\CPA
2012-12-21 05:32 - 2012-12-16 09:11 - 00046080 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll
2012-12-21 05:32 - 2012-12-16 06:45 - 00367616 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
2012-12-21 05:32 - 2012-12-16 06:13 - 00295424 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2012-12-21 05:32 - 2012-12-16 06:13 - 00034304 ____A (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2012-12-21 02:10 - 2012-12-21 02:39 - 00013441 ____A C:\Users\Kim\Desktop\Rest fakturering 2012 Nilec.xlsx
==================== One Month Modified Files and Folders =======
2013-01-20 05:23 - 2013-01-20 05:04 - 00000004 ____A C:\Users\Kim\AppData\Roaming\skype.ini
2013-01-20 05:23 - 2011-09-19 11:52 - 01838960 ____A C:\Windows\WindowsUpdate.log
2013-01-20 05:23 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\inetsrv
2013-01-20 05:19 - 2009-07-13 20:45 - 00016976 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-01-20 05:19 - 2009-07-13 20:45 - 00016976 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-01-20 05:15 - 2012-06-11 01:48 - 00000926 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-01-20 05:13 - 2011-10-04 06:44 - 00000000 ____D C:\Users\Kim\AppData\Roaming\Dropbox
2013-01-20 05:11 - 2011-10-04 10:44 - 00000000 ____D C:\Users\All Users\clear.fi
2013-01-20 05:09 - 2011-10-04 06:47 - 00000000 ___RD C:\Users\Kim\Dropbox
2013-01-20 05:08 - 2012-06-11 01:48 - 00000922 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-01-20 05:07 - 2012-07-13 14:56 - 00056561 ____A C:\Windows\setupact.log
2013-01-20 05:07 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-01-20 05:00 - 2012-04-20 04:27 - 00000934 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2868354298-1189698340-2338035166-1001UA.job
2013-01-20 04:34 - 2011-10-04 10:48 - 00000000 ____D C:\Users\Kim\AppData\Roaming\Skype
2013-01-20 04:27 - 2012-08-12 22:16 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-01-20 03:05 - 2009-07-13 21:13 - 00970790 ____A C:\Windows\System32\PerfStringBackup.INI
2013-01-18 14:00 - 2012-04-20 04:27 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2868354298-1189698340-2338035166-1001Core.job
2013-01-18 03:35 - 2011-10-05 22:16 - 00613731 ____A C:\Users\Kim\danid.log
2013-01-18 00:13 - 2011-11-03 02:59 - 00000000 ____D C:\Users\Kim\AppData\Local\CutePDF Writer
2013-01-17 08:27 - 2012-11-05 23:08 - 00000000 ____D C:\Users\Kim\Desktop\Kronans
2013-01-17 08:16 - 2013-01-17 08:16 - 00509185 ____A C:\Users\Kim\Desktop\AGR screenshots.pptx
2013-01-17 08:13 - 2013-01-17 08:12 - 00236544 ____A C:\Users\Kim\Desktop\AGR screenshot.ppt
2013-01-17 02:10 - 2013-01-09 09:19 - 00013177 ____A C:\Users\Kim\Desktop\Otsuka calendar JAN2013.xlsx
2013-01-16 12:46 - 2013-01-16 12:46 - 00013768 ____A C:\Users\Kim\Desktop\Book1.xlsx
2013-01-16 10:57 - 2013-01-16 10:37 - 00013444 ____A C:\Users\Kim\Desktop\Rest fakturering 2012 Nilec - KP.xlsx
2013-01-14 08:24 - 2013-01-11 07:13 - 00000000 ____D C:\Users\Kim\Desktop\New folder (2)
2013-01-11 13:35 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2013-01-10 07:27 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2013-01-10 04:35 - 2012-09-12 08:16 - 00000000 ____D C:\Users\Kim\AppData\Local\join.me
2013-01-09 23:32 - 2009-07-13 20:45 - 04986544 ____A C:\Windows\System32\FNTCACHE.DAT
2013-01-09 23:15 - 2011-10-04 06:29 - 00000000 ____D C:\Users\All Users\Microsoft Help
2013-01-09 23:14 - 2011-10-04 11:00 - 00956702 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2013-01-09 23:08 - 2011-10-04 05:20 - 67599240 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-01-09 13:39 - 2013-01-09 13:39 - 00012487 ____A C:\Users\Kim\Desktop\Costs december 2012 - Palmi.xlsx
2013-01-09 09:54 - 2012-08-14 01:37 - 00010286 ____A C:\Windows\PFRO.log
2013-01-09 06:28 - 2012-08-12 22:16 - 00697864 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-01-09 06:28 - 2011-08-15 23:27 - 00074248 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-01-07 22:31 - 2012-12-20 09:21 - 00015795 ____A C:\Users\Kim\Desktop\JCH bonusmodel.xlsx
2013-01-07 12:44 - 2013-01-07 00:06 - 00000000 ____D C:\Users\Kim\Desktop\CPA
2013-01-06 23:22 - 2012-11-18 09:45 - 00000000 ____D C:\Users\Kim\Desktop\Anja kontrakt
2013-01-02 19:58 - 2011-10-04 06:47 - 00001013 ____A C:\Users\Kim\Desktop\Dropbox.lnk
2012-12-21 02:39 - 2012-12-21 02:10 - 00013441 ____A C:\Users\Kim\Desktop\Rest fakturering 2012 Nilec.xlsx
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: “%1” %* => OK
==================== Restore Points =========================
Restore point made on: 2012-12-21 05:32:42
Restore point made on: 2012-12-24 07:56:51
Restore point made on: 2012-12-28 02:52:00
Restore point made on: 2013-01-02 17:48:20
Restore point made on: 2013-01-06 08:17:39
Restore point made on: 2013-01-09 23:00:09
Restore point made on: 2013-01-13 22:32:13
Restore point made on: 2013-01-17 23:28:20
==================== Memory info ===========================
Percentage of memory in use: 18%
Total physical RAM: 3946.73 MB
Available physical RAM: 3198.79 MB
Total Pagefile: 3944.93 MB
Available Pagefile: 3193.53 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
==================== Partitions =============================
1 Drive c: (Acer) (Fixed) (Total:450.66 GB) (Free:255.72 GB) NTFS
2 Drive e: (PQSERVICE) (Fixed) (Total:15 GB) (Free:0.73 GB) NTFS
4 Drive g: () (Removable) (Total:1.87 GB) (Free:1.41 GB) FAT
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
——————————- ———- ———- —- —-
Disk 0 Online 465 GB 0 B
Disk 1 Online 1911 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
——————- ———————————- ———-
Partition 1 Recovery 15 GB 1024 KB
Partition 2 Primary 100 MB 15 GB
Partition 3 Primary 450 GB 15 GB
==================================================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
——————- —————- ——- ————————- ————- ————
* Volume 3 E PQSERVICE NTFS Partition 15 GB Healthy Hidden
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
——————- —————- ——- ————————- ————- ————
* Volume 1 Y SYSTEM RESE NTFS Partition 100 MB Healthy
=========================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
——————- —————- ——- ————————- ————- ————
* Volume 2 C Acer NTFS Partition 450 GB Healthy
=========================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
——————- ———————————- ———-
Partition 1 Primary 1910 MB 16 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
——————- —————- ——- ————————- ————- ————
* Volume 4 G FAT Removable 1910 MB Healthy
=========================================================
Last Boot: 2013-01-16 11:37
==================== End Of Log =============================