include.info og noget toolbar
  FieFyn
Antal indlæg: 16

Hej!
Min søns bærbar har fået noget ondsindet noget, jeg sender lige et par billeder I kan kigge på :

http://imm.io/wee5

http://imm.io/weej

Avast fanger den, men forsøger ikke at fjerne den… ?

Hvad gør jeg?

  FieFyn
Antal indlæg: 16

nå, men jeg kører lige nu en ad aware… de lokker med 30 dages PRO-udgave, det prøver jeg da lige.

Administrator
Avatar
Antal indlæg: 32078

Hej                 wink


Download OTL af Oldtimer, gem den på dit skrivebord: http://oldtimer.geekstogo.com/OTL.exe
• 
Luk alle åbne vinduer. Klik på OTL ikonet (for Vista/win7, skal du højreklikke på ikonet og Kør som Administrator) for at starte programmet.
Når vinduet vises, under Output i toppen skift til Minimal Output.
Marker felterne ud for LOP check og Purity Check.


Klik så på Quick Scan.
• 


Det vil give to (2) logfiler på skrivebordet, en kaldet OTL.txt, den anden vil blive navngivet Extras.txt.
Husk, hvor du har gemt disse 2 filer.

Da de er forholdsvis lange, kan du blive nødt til at sende dem i flere indlæg.

Signatur

Sund Computer fornuft

  FieFyn
Antal indlæg: 16

Jeg kunne ikke helt genkende beskrivelsen af programmet. Men her er to logfiler.



OTS logfile created on: 13-07-2012 00:04:37 - Run 4
OTS by OldTimer - Version 3.1.47.2   Folder = C:\Users\Joakim\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000406 | Country: Danmark | Language: DAN | Date Format: dd-MM-yyyy

4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 71,00% Memory free
8,00 Gb Paging File | 7,00 Gb Available in Paging File | 84,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465,76 Gb Total Space | 377,29 Gb Free Space | 81,01% Space Free | Partition Type: NTFS
Drive D: | 2,17 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive E: | 1,86 Gb Total Space | 1,79 Gb Free Space | 96,22% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JOAKIM-PC
Current User Name: Joakim
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 30 Days
Quick Scan

[Processes - Safe List]
ots.exe -> C:\Users\Joakim\Desktop\OTS.exe -> [2012-07-12 23:48:24 | 000,646,656 |——| M] (OldTimer Tools)
sdtray.exe -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe -> [2012-07-04 12:40:58 | 003,921,432 |——| M] (Safer-Networking Ltd.)
sdupdsvc.exe -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe -> [2012-07-04 12:40:20 | 001,395,736 |——| M] (Safer-Networking Ltd.)
sdfssvc.exe -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe -> [2012-07-04 12:40:18 | 001,188,896 |——| M] (Safer-Networking Ltd.)
avastui.exe -> C:\Programmer\AVAST Software\Avast\AvastUI.exe -> [2012-07-03 18:21:30 | 004,273,976 |——| M] (AVAST Software)
avastsvc.exe -> C:\Programmer\AVAST Software\Avast\AvastSvc.exe -> [2012-07-03 18:21:29 | 000,044,808 |——| M] (AVAST Software)
hamachi-2-ui.exe -> C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe -> [2012-06-27 12:29:26 | 001,996,200 |——| M] (LogMeIn Inc.)
adawareservice.exe -> C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe -> [2012-05-03 18:37:54 | 001,226,096 |——| M] (Lavasoft Limited)
adaware.exe -> C:\PROGRA~2\AD-AWA~1\AdAware.exe -> [2012-05-03 18:37:50 | 020,221,792 |——| M] (Lavasoft Limited)
sdwscsvc.exe -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe -> [2012-03-22 10:55:02 | 000,166,528 |——| M] (Safer-Networking Ltd.)
sbamsvc.exe -> C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe -> [2011-12-19 13:20:06 | 003,289,032 |——| M] (GFI Software)
adawarebp.exe -> C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe -> [2011-10-21 11:09:36 | 000,198,032 |——| M] (Lavasoft)

[Modules - No Company Name]
snlthirdparty150.bpl -> C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl -> [2012-07-04 12:39:50 | 000,051,200 |——| M] ()
jsdialogpack150.bpl -> C:\Program Files (x86)\Spybot - Search & Destroy 2\JSDialogPack150.bpl -> [2012-07-04 12:39:48 | 000,517,632 |——| M] ()
dec150.bpl -> C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl -> [2012-07-04 12:39:48 | 000,410,112 |——| M] ()

[Win32 Services - Safe List]
64bit-(avast! Antivirus)  [Auto | Running] -> C:\Program Files\AVAST Software\Avast\AvastSvc.exe -> [2012-07-03 18:21:29 | 000,044,808 |——| M] (AVAST Software)
64bit-(AMD External Events Utility)  [Auto | Running] -> C:\Windows\SysNative\atiesrxx.exe -> [2009-08-18 03:36:20 | 000,203,264 |——| M] (AMD)
(AdobeFlashPlayerUpdateSvc) Adobe Flash Player Update Service [On_Demand | Stopped] -> C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -> [2012-07-12 13:25:09 | 000,250,056 |——| M] (Adobe Systems Incorporated)
(SDUpdateService) Spybot-S&D 2 Updating Service [Auto | Running] -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe -> [2012-07-04 12:40:20 | 001,395,736 |——| M] (Safer-Networking Ltd.)
(SDScannerService) Spybot-S&D 2 Scanner Service [Auto | Running] -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe -> [2012-07-04 12:40:18 | 001,188,896 |——| M] (Safer-Networking Ltd.)
(Hamachi2Svc) LogMeIn Hamachi Tunneling Engine [Auto | Running] -> C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -> [2012-06-27 12:29:24 | 002,369,960 |——| M] (LogMeIn Inc.)
(Steam Client Service) Steam Client Service [On_Demand | Stopped] -> C:\Program Files (x86)\Common Files\Steam\SteamService.exe -> [2012-06-19 19:27:45 | 000,529,232 |——| M] (Valve Corporation)
(SkypeUpdate) Skype Updater [Auto | Stopped] -> C:\Program Files (x86)\Skype\Updater\Updater.exe -> [2012-06-05 15:17:44 | 000,160,944 | R—- | M] (Skype Technologies)
(Ad-Aware Service) Ad-Aware Service [Auto | Running] -> C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe -> [2012-05-03 18:37:54 | 001,226,096 |——| M] (Lavasoft Limited)
(SDWSCService) Spybot-S&D 2 Security Center Service [Auto | Running] -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe -> [2012-03-22 10:55:02 | 000,166,528 |——| M] (Safer-Networking Ltd.)
(SBAMSvc) Ad-Aware [Auto | Running] -> C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe -> [2011-12-19 13:20:06 | 003,289,032 |——| M] (GFI Software)
(clr_optimization_v4.0.30319_32) Microsoft .NET Framework NGEN v4.0.30319_X86 [Auto | Stopped] -> C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -> [2010-03-18 14:16:28 | 000,130,384 |——| M] (Microsoft Corporation)
(clr_optimization_v2.0.50727_32) Microsoft .NET Framework NGEN v2.0.50727_X86 [Disabled | Stopped] -> C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2009-06-10 23:23:09 | 000,066,384 |——| M] (Microsoft Corporation)

[Driver Services - Safe List]
64bit-(aswSnx) aswSnx [File_System | System | Running] -> C:\Windows\SysNative\drivers\aswSnx.sys -> [2012-07-03 18:21:52 | 000,958,400 |——| M] (AVAST Software)
64bit-(aswSP) aswSP [Kernel | System | Running] -> C:\Windows\SysNative\drivers\aswSP.sys -> [2012-07-03 18:21:52 | 000,355,856 |——| M] (AVAST Software)
64bit-(aswMonFlt) aswMonFlt [File_System | Auto | Running] -> C:\Windows\SysNative\drivers\aswMonFlt.sys -> [2012-07-03 18:21:52 | 000,071,064 |——| M] (AVAST Software)
64bit-(aswTdi) avast! Network Shield Support [Kernel | System | Running] -> C:\Windows\SysNative\drivers\aswTdi.sys -> [2012-07-03 18:21:52 | 000,059,728 |——| M] (AVAST Software)
64bit-(aswRdr) aswRdr [Kernel | System | Running] -> C:\Windows\SysNative\drivers\aswRdr2.sys -> [2012-07-03 18:21:52 | 000,054,072 |——| M] (AVAST Software)
64bit-(aswFsBlk) aswFsBlk [File_System | Auto | Running] -> C:\Windows\SysNative\drivers\aswFsBlk.sys -> [2012-07-03 18:21:51 | 000,025,232 |——| M] (AVAST Software)
64bit-(aswKbd) aswKbd [Kernel | System | Running] -> C:\Windows\SysNative\drivers\aswKbd.sys -> [2012-03-07 01:02:45 | 000,028,504 |——| M] (AVAST Software)
64bit-(SbFw) SbFw [Kernel | System | Running] -> C:\Windows\SysNative\drivers\SbFw.sys -> [2011-12-19 12:44:24 | 000,256,632 |——| M] (GFI Software)
64bit-(sbwtis) sbwtis [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\sbwtis.sys -> [2011-12-19 12:44:24 | 000,084,600 |——| M] (GFI Software)
64bit-(sbhips) sbhips [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\sbhips.sys -> [2011-12-19 12:44:24 | 000,060,536 |——| M] (GFI Software)
64bit-(sbapifs) sbapifs [File_System | Auto | Running] -> C:\Windows\SysNative\drivers\sbapifs.sys -> [2011-11-29 06:59:46 | 000,074,872 |——| M] (GFI Software)
64bit-(SBRE) SBRE [Kernel | System | Running] -> C:\Windows\SysNative\drivers\sbredrv.sys -> [2011-10-26 14:23:36 | 000,057,976 |——| M] (GFI Software)
64bit-(SBFWIMCLMP) GFI Software Firewall NDIS IM Filter Miniport [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\SbFwIm.sys -> [2011-09-29 12:16:18 | 000,119,416 |——| M] (GFI Software)
64bit-(SBFWIMCL) GFI Software Firewall NDIS IM Filter Service [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\SbFwIm.sys -> [2011-09-29 12:16:18 | 000,119,416 |——| M] (GFI Software)
64bit-(amdsata) amdsata [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\amdsata.sys -> [2011-03-11 08:41:12 | 000,107,904 |——| M] (Advanced Micro Devices)
64bit-(amdxata) amdxata [Kernel | Boot | Running] -> C:\Windows\SysNative\drivers\amdxata.sys -> [2011-03-11 08:41:12 | 000,027,008 |——| M] (Advanced Micro Devices)
64bit-(HpSAMD) HpSAMD [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\HpSAMD.sys -> [2010-11-20 15:33:35 | 000,078,720 |——| M] (Hewlett-Packard Company)
64bit-(TsUsbFlt) TsUsbFlt [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\TsUsbFlt.sys -> [2010-11-20 13:07:05 | 000,059,392 |——| M] (Microsoft Corporation)
64bit-(sdbus) sdbus [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\sdbus.sys -> [2010-11-20 11:37:42 | 000,109,056 |——| M] (Microsoft Corporation)
64bit-(atikmdag) atikmdag [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\atikmdag.sys -> [2009-08-18 04:48:48 | 006,037,504 |——| M] (ATI Technologies Inc.)
64bit-(amdsbs) amdsbs [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\amdsbs.sys -> [2009-07-14 03:52:20 | 000,194,128 |——| M] (AMD Technologies Inc.)
64bit-(LSI_SAS2) LSI_SAS2 [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\lsi_sas2.sys -> [2009-07-14 03:48:04 | 000,065,600 |——| M] (LSI Corporation)
64bit-(stexstor) stexstor [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\stexstor.sys -> [2009-07-14 03:45:55 | 000,024,656 |——| M] (Promise Technology)
64bit-(BCM43XX) Broadcom 802.11 Network Adapter Driver [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\BCMWL664.SYS -> [2009-07-08 00:45:50 | 002,769,400 |——| M] (Broadcom Corporation)
64bit-(rimsptsk) rimsptsk [Kernel | Auto | Running] -> C:\Windows\SysNative\drivers\rimspx64.sys -> [2009-06-25 08:13:44 | 000,055,296 |——| M] (REDC)
64bit-(k57nd60a) Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0 [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\k57nd60a.sys -> [2009-06-10 22:34:36 | 000,270,848 |——| M] (Broadcom Corporation)
64bit-(ebdrv) Broadcom NetXtreme II 10 GigE VBD [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\evbda.sys -> [2009-06-10 22:34:33 | 003,286,016 |——| M] (Broadcom Corporation)
64bit-(b06bdrv) Broadcom NetXtreme II VBD [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\bxvbda.sys -> [2009-06-10 22:34:28 | 000,468,480 |——| M] (Broadcom Corporation)
64bit-(b57nd60a) Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0 [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\b57nd60a.sys -> [2009-06-10 22:34:23 | 000,270,848 |——| M] (Broadcom Corporation)
64bit-(hcw85cir) Hauppauge Consumer Infrared Receiver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\hcw85cir.sys -> [2009-06-10 22:31:59 | 000,031,232 |——| M] (Hauppauge Computer Works, Inc.)
64bit-(hamachi) Hamachi Network Interface [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\hamachi.sys -> [2009-03-18 16:35:42 | 000,033,856 | -H—| M] (LogMeIn, Inc.)
64bit-(rismxdp) Ricoh xD-Picture Card Driver [Kernel | Auto | Running] -> C:\Windows\SysNative\drivers\rixdpx64.sys -> [2006-11-18 14:07:48 | 000,055,296 |——| M] (REDC)
64bit-(rimmptsk) rimmptsk [Kernel | Auto | Running] -> C:\Windows\SysNative\drivers\rimmpx64.sys -> [2006-11-17 18:49:52 | 000,052,224 |——| M] (REDC)
(SBRE) SBRE [Kernel | System | Running] -> C:\Windows\SysWOW64\drivers\SBREDrv.sys -> [2011-10-26 14:23:40 | 000,101,112 |——| M] (GFI Software)
(WIMMount) WIMMount [File_System | On_Demand | Stopped] -> C:\Windows\SysWOW64\drivers\wimmount.sys -> [2009-07-14 03:19:10 | 000,019,008 |——| M] (Microsoft Corporation)

[Registry - Safe List]
< 64bit-Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\“Local Page” -> %SystemRoot%\system32\blank.htm ->
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\“Local Page” -> C:\Windows\SysWOW64\blank.htm ->
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> ->
HKEY_CURRENT_USER\: Main\\“Start Page” -> http://safesearchr.lavasoft.com/?source=3336ca5f&tbp=homepage&toolbarid=adawaretb&v=2_1&u=899E7FE26168F51CAF59164FFF1FA3B1 ->
HKEY_CURRENT_USER\: Main\\“Start Page Redirect Cache” -> http://dk.msn.com/?ocid=iehp ->
HKEY_CURRENT_USER\: Main\\“Start Page Redirect Cache AcceptLangs” -> da-DK ->
HKEY_CURRENT_USER\: Main\\“Start Page Redirect Cache_TIMESTAMP” -> B2 90 B1 FD 2E F2 CC 01 [binary data] ->
HKEY_CURRENT_USER\: “ProxyEnable” -> 0 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
< FireFox Extensions [User Folders] > ->
< HOSTS File > ([2006-09-18 23:37:24 | 000,000,761 |——| M] - 20 lines) -> C:\Windows\SysNative\Drivers\etc\hosts ->
Reset Hosts
127.0.0.1     localhost
::1         localhost
< 64bit-BHO’s [HKEY_LOCAL_MACHINE] > -> 64bit-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} [HKLM] -> C:\Programmer\AVAST Software\Avast\aswWebRepIE64.dll [avast! WebRep] -> [2012-07-03 18:21:16 | 001,387,952 |——| M] (AVAST Software)
{9030D464-4C02-4ABF-8ECC-5164760863C6} [HKLM] -> C:\Programmer\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [Windows Live ID Sign-in Helper] -> [2011-03-28 21:14:36 | 000,529,280 |——| M] (Microsoft Corp.)
{D27FC31C-6E3D-4305-8D53-ACDAEFA5F862} [HKLM] ->  [Complitly] -> File not found
< BHO’s [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll [Spybot-S&D IE Protection] -> [2012-06-26 10:49:48 | 003,229,752 |——| M] (Safer-Networking Ltd.)
{6c97a91e-4524-4019-86af-2aa2d567bf5c} [HKLM] -> C:\Program Files (x86)\adawaretb\adawareDx.dll [Ad-Aware Security Toolbar] -> [2012-04-11 22:08:22 | 000,087,440 |——| M] ()
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> C:\Program Files (x86)\Java\jre6\bin\ssv.dll [Java(tm) Plug-In SSV Helper] -> [2012-02-24 01:10:48 | 000,325,408 |——| M] (Sun Microsystems, Inc.)
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} [HKLM] -> C:\Programmer\AVAST Software\Avast\aswWebRepIE.dll [avast! WebRep] -> [2012-07-03 18:21:25 | 001,160,792 |——| M] (AVAST Software)
{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} [HKLM] -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [Skype Browser Helper] -> [2012-03-02 11:51:20 | 004,296,864 |——| M] (Skype Technologies S.A.)
{D27FC31C-6E3D-4305-8D53-ACDAEFA5F862} [HKLM] ->  [Complitly] -> File not found
< 64bit-Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
“{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}” [HKLM] -> C:\Programmer\AVAST Software\Avast\aswWebRepIE64.dll [avast! WebRep] -> [2012-07-03 18:21:16 | 001,387,952 |——| M] (AVAST Software)
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
“{6c97a91e-4524-4019-86af-2aa2d567bf5c}” [HKLM] -> C:\Program Files (x86)\adawaretb\adawareDx.dll [Ad-Aware Security Toolbar] -> [2012-04-11 22:08:22 | 000,087,440 |——| M] ()
“{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}” [HKLM] -> C:\Programmer\AVAST Software\Avast\aswWebRepIE.dll [avast! WebRep] -> [2012-07-03 18:21:25 | 001,160,792 |——| M] (AVAST Software)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
“Ad-Aware Antivirus” -> C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher.exe [“C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher”—windows-run] -> [2012-05-03 18:37:52 | 001,771,888 |——| M] (Lavasoft Limited)
“Ad-Aware Browsing Protection” -> C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [“C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe”] -> [2011-10-21 11:09:36 | 000,198,032 |——| M] (Lavasoft)
“avast” -> C:\Program Files\AVAST Software\Avast\avastUI.exe [“C:\Program Files\AVAST Software\Avast\avastUI.exe” /nogui] -> [2012-07-03 18:21:30 | 004,273,976 |——| M] (AVAST Software)
“LogMeIn Hamachi Ui” -> C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [“C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe”—auto-start] -> [2012-06-27 12:29:26 | 001,996,200 |——| M] (LogMeIn Inc.)
“SDTray” -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [“C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe”] -> [2012-07-04 12:40:58 | 003,921,432 |——| M] (Safer-Networking Ltd.)
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
“EA Core” ->  [“C:\Program Files (x86)\Electronic Arts\EADM\Core.exe” -silent] -> File not found
“RESTART_STICKY_NOTES” ->  [C:\Windows\System32\StikyNot.exe] -> File not found
“Spybot-S&D Cleaning” -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [“C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe” /autoclean] -> [2012-07-04 12:40:24 | 003,527,176 |——| M] (Safer-Networking Ltd.)
“Steam” -> C:\Program Files (x86)\Steam\steam.exe [“C:\Program Files (x86)\Steam\steam.exe” -silent] -> [2012-02-25 16:30:55 | 001,242,448 |——| M] (Valve Corporation)
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\“NoActiveDesktop” ->  [1] -> File not found
\\“NoActiveDesktopChanges” ->  [1] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\“ConsentPromptBehaviorAdmin” ->  [5] -> File not found
\\“ConsentPromptBehaviorUser” ->  [3] -> File not found
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{898EA8C8-E7FF-479B-8935-AEC46303B9E5}:{898EA8C8-E7FF-479B-8935-AEC46303B9E5} [HKLM] -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [Button: Skype Click to Call] -> [2012-03-02 11:51:20 | 004,296,864 |——| M] (Skype Technologies S.A.)
{898EA8C8-E7FF-479B-8935-AEC46303B9E5}:{898EA8C8-E7FF-479B-8935-AEC46303B9E5} [HKLM] -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [Menu: Skype Click to Call] -> [2012-03-02 11:51:20 | 004,296,864 |——| M] (Skype Technologies S.A.)
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}:{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll [Menu: Spybot - Search && Destroy Configuration] -> [2012-06-26 10:49:48 | 003,229,752 |——| M] (Safer-Networking Ltd.)
< 64bit-Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime;=%s ->
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
< 64bit-Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
“” -> http://
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
“” -> http://
< 64bit-Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< 64bit-Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< 64bit-Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab [Shockwave Flash Object] ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} [HKLM] -> http://quickscan.bitdefender.com/qsax/qsax.cab [Bitdefender QuickScan Control] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab [Java Plug-in 1.6.0_31] ->
{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab [Java Plug-in 1.6.0_31] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab [Java Plug-in 1.6.0_31] ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ ->
DhcpNameServer -> 212.10.10.5 212.10.10.4 ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{11EE1909-8C82-428E-B762-BE53A7562343}\\DhcpNameServer -> 212.10.10.5 212.10.10.4   (Dell Wireless 1510 Wireless-N WLAN Mini-Card) ->
< 64bit-Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
64bit-*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
explorer.exe -> C:\Windows\explorer.exe -> [2011-02-25 08:19:30 | 002,871,808 |——| M] (Microsoft Corporation)
*MultiFile Done* -> ->
64bit-*UserInit* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit ->
C:\Windows\system32\userinit.exe -> C:\Windows\SysNative\userinit.exe -> [2010-11-20 15:25:24 | 000,030,720 |——| M] (Microsoft Corporation)
*MultiFile Done* -> ->
64bit-*VMApplet* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet ->
SystemPropertiesPerformance.exe -> C:\Windows\SysNative\SystemPropertiesPerformance.exe -> [2009-07-14 03:39:47 | 000,082,432 |——| M] (Microsoft Corporation)
/pagefile ->  -> File not found
*MultiFile Done* -> ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
explorer.exe -> C:\Windows\SysWow64\explorer.exe -> [2011-02-25 07:30:54 | 002,616,320 |——| M] (Microsoft Corporation)
*MultiFile Done* -> ->
*UserInit* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit ->
userinit.exe -> C:\Windows\SysWow64\userinit.exe -> [2010-11-20 14:17:48 | 000,026,624 |——| M] (Microsoft Corporation)
*MultiFile Done* -> ->
*VMApplet* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet ->
/pagefile ->  -> File not found
*MultiFile Done* -> ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
SDWinLogon ->  -> File not found
< 64bit-SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad ->
“{E6FB5E20-DE35-11CF-9C87-00AA005127ED}” [HKLM] -> Reg Error: Key error. [WebCheck] -> File not found
< SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad ->
“{E6FB5E20-DE35-11CF-9C87-00AA005127ED}” [HKLM] -> Reg Error: Key error. [WebCheck] -> File not found
< Vista Public Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\AuthorizedApplications ->
< Vista Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications ->
64bit-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
\List\\“C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe” -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon] -> [2012-07-04 12:40:58 | 003,921,432 |——| M] (Safer-Networking Ltd.)
\List\\“C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe” -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service] -> [2012-07-04 12:40:18 | 001,188,896 |——| M] (Safer-Networking Ltd.)
\List\\“C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe” -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater] -> [2012-07-04 12:41:04 | 003,880,456 |——| M] (Safer-Networking Ltd.)
\List\\“C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe” -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service] -> [2012-07-04 12:40:20 | 001,395,736 |——| M] (Safer-Networking Ltd.)
< Vista Active Firewall Rules > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules ->
{11FFB607-1080-4868-BE5E-0244330C3978} -> rport=137 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-28523 | app=system |
{1B79DE66-4DF6-4B83-B50C-CB4A31360BE4} -> lport=2177 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31261 | app=%systemroot%\system32\svchost.exe | svc=qwave |
{2274B23A-512F-4BE9-9189-81FEBEAEF5AD} -> lport=138 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-28527 | app=system |
{233DDCDF-52BE-4A6A-BF41-992DDD29F70F} -> rport=1900 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31273 | app=%systemroot%\system32\svchost.exe | svc=ssdpsrv |
{25CA6817-00EA-4DE5-A7E9-F73CE2275EE9} -> lport=2869 | protocol=6 | dir=in | action=allow | name=windows live communications platform (upnp) |
{263A66EA-DD62-4737-A72B-C2D7258F38A5} -> lport=5355 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-28548 | app=%systemroot%\system32\svchost.exe | svc=dnscache |
{37A48231-69D6-4A19-99E0-641AC80F72BB} -> lport=139 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28503 | app=system |
{3813CF1A-FFEC-47A4-8DFE-A8956C1F272D} -> rport=5355 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-28550 | app=%systemroot%\system32\svchost.exe | svc=dnscache |
{4215CBB2-FE79-40E3-A746-9AAA81A092A5} -> rport=139 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-28507 | app=system |
{44915AAB-DD21-409B-965C-33A7DAFC716E} -> lport=2869 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31277 | app=system |
{473D7F39-5551-4598-999E-102EC5779DA0} -> lport=137 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-28519 | app=system |
{4A2BA108-DA6D-4034-8853-1E662B902EA6} -> lport=1900 | protocol=17 | dir=in | action=allow | name=windows live communications platform (ssdp) |
{59D8B470-7163-4850-B2F3-217CD5B16737} -> rport=2177 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31257 | app=%systemroot%\system32\svchost.exe | svc=qwave |
{6702B17D-37D2-478C-8899-A451D055433C} -> lport=10243 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31285 | app=system |
{6AC02131-B7CA-41E7-AFBA-44505C7ED085} -> rport=138 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-28531 | app=system |
{6D9A6665-8708-48E8-B302-3142F774FA05} -> lport=2177 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31253 | app=%systemroot%\system32\svchost.exe | svc=qwave |
{766C61A5-17FB-4C7D-BC95-BAA1F1F41D43} -> rport=2177 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31265 | app=%systemroot%\system32\svchost.exe | svc=qwave |
{862531A4-B67A-4D6A-A840-80B41126C372} -> lport=rpc | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28535 | app=%systemroot%\system32\spoolsv.exe | svc=spooler |
{9A156D8D-B73B-42FE-8A71-97B2574887EE} -> rport=10243 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31289 | app=system |
{BCB64E43-AE5F-41CF-B8A4-27ACCF5EBB7F} -> lport=1900 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31269 | app=%systemroot%\system32\svchost.exe | svc=ssdpsrv |
{C0AA24EB-FE86-4025-B41D-60B8CF4C7E62} -> lport=rpc-epmap | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28539 | svc=rpcss |
{D28F592C-9BB8-448F-AB98-282DB4979BBD} -> rport=445 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-28515 | app=system |
{EA75B2D4-FAF5-4E6C-8E01-B1A26690D62A} -> lport=445 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28511 | app=system |
< Vista Active Application Exception Rules > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules ->
{0455890F-FE47-4BCB-94B5-2D61FC25D590} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31321 | app=%systemroot%\system32\svchost.exe | svc=upnphost |
{0587224D-0D40-47BE-A087-DBF05A2D1AF4} -> profile=public | protocol=6 | dir=in | action=block | name=ea download manager | app=c:\program files (x86)\electronic arts\eadm\core.exe |
{108CBA3E-9132-4625-922C-D50BA2618E99} -> dir=in | action=allow | name=windows live communications platform | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
{11087AEA-1855-440A-940C-919B70F6D346} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31003 | app=%programfiles%\windows media player\wmplayer.exe |
{1C4DAE37-FD91-4DC2-BFB3-F79198B56B8A} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31305 | app=%programfiles%\windows media player\wmpnetwk.exe |
{1E64116C-85BE-4024-9C44-735DD4B78517} -> profile=private | protocol=58 | dir=out | action=allow | name=@firewallapi.dll,-28546 |
{224F5533-7E50-42EA-80A0-7B7338BE5D62} -> profile=private | protocol=1 | dir=in | action=allow | name=@firewallapi.dll,-28543 |
{22CC6EEB-EF04-48B5-B67F-663445DB89BC} -> protocol=58 | dir=out | action=allow | name=@iphlpsvc.dll,-503 |
{2643EABF-ECC3-46A1-A2B7-B423CE1DE650} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31317 | app=%programfiles%\windows media player\wmpnetwk.exe |
{2AF883A8-08A8-44F0-83F3-4C5F43568D98} -> profile=domain | protocol=6 | dir=in | action=allow | name=pando media booster | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
{3069608C-0912-4F80-8B05-C4C0DDFB183F} -> profile=private | protocol=6 | dir=in | action=allow | name=call of duty: modern warfare 2 - multiplayer | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
{31FFE58C-672F-41BE-9995-DA361C04A6AE} -> profile=private | protocol=58 | dir=in | action=allow | name=@firewallapi.dll,-28545 |
{351988E7-CEDE-4717-8047-5AE2B31D5533} -> profile=public | protocol=17 | dir=in | action=block | name=java(tm) platform se binary | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
{36FD6228-0965-4C3F-997A-E5FE0E4D7A1C} -> profile=public | protocol=6 | dir=in | action=allow | name=call of duty: modern warfare 3 | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe |
{38DA306C-4E69-4D5E-8F3F-90930B9532CB} -> dir=in | action=allow | name=skype | app=c:\program files (x86)\skype\phone\skype.exe |
{3B157CEE-8D8A-4D53-9894-E440D4C149AC} -> profile=private | protocol=6 | dir=in | action=allow | name=steam | app=c:\program files (x86)\steam\steam.exe |
{424A33AF-5969-4B04-860E-0A8CF120F98C} -> profile=public | protocol=17 | dir=in | action=allow | name=stronghold legends | app=c:\program files (x86)\firefly studios\stronghold legends\strongholdlegends.exe |
{447257D0-ADE0-45FA-AB96-876525ED2C84} -> dir=in | action=allow | name=pando media booster | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
{478ED7A4-9DBC-4994-B091-71CC7963008F} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31293 | app=%programfiles%\windows media player\wmplayer.exe |
{56EC8BDC-50DE-44EC-B78B-25122633BAD6} -> profile=private | protocol=6 | dir=in | action=allow | name=pando media booster | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
{574D0079-E8B5-40FF-AE1D-0A8C687855F7} -> profile=public | protocol=17 | dir=in | action=allow | name=call of duty: modern warfare 3 - multiplayer | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe |
{59D205A9-8553-4570-BD27-DE77F39195D0} -> profile=public | protocol=6 | dir=in | action=allow | name=stronghold legends | app=c:\program files (x86)\firefly studios\stronghold legends\strongholdlegends.exe |
{5EA83B2A-0649-46FB-B8A0-9C794B8FD7FC} -> profile=public | protocol=17 | dir=in | action=block | name=ea download manager | app=c:\program files (x86)\electronic arts\eadm\core.exe |
{64C83EF5-1005-46F1-9F31-79F8DF954BAC} -> profile=domain | protocol=17 | dir=in | action=allow | name=pando media booster | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
{6F58BAFF-8B36-4FCA-B401-2F2D0750DF8B} -> profile=public | protocol=17 | dir=in | action=allow | name=call of duty: modern warfare 3 | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe |
{6F62790E-D43B-4AFA-9E46-3D5B8A097360} -> profile=private | protocol=17 | dir=in | action=allow | name=call of duty: modern warfare 2 - multiplayer | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
{6F957FA1-A715-480C-8253-929CFEA0C431} -> profile=private | protocol=17 | dir=in | action=allow | name=steam | app=c:\program files (x86)\steam\steam.exe |
{71FE9FE0-426F-41FD-92E9-8F6BBE5F9B03} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31023 | app=%programfiles(x86)%\windows media player\wmplayer.exe |
{79F0AA81-82CB-4580-8868-AEE1D748E140} -> profile=public | protocol=6 | dir=in | action=allow | name=ad-aware security toolbar dtx broker | app=c:\program files (x86)\adawaretb\dtuser.exe |
{7A2C30D2-59FE-46AE-A501-CAD739F4B944} -> profile=private | protocol=17 | dir=in | action=allow | name=call of duty: modern warfare 2 | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
{8AC16086-0133-4911-A725-7B5AFBE6AE87} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31297 | app=%programfiles%\windows media player\wmplayer.exe |
{8BFB585D-B572-447E-9A48-3AEC18CDEE83} -> profile=public | protocol=6 | dir=in | action=allow | name=call of duty: modern warfare 2 - multiplayer | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
{8D54DD10-F8E8-4632-919C-C42527360C65} -> profile=public | protocol=17 | dir=in | action=allow | name=call of duty: modern warfare 2 - multiplayer | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
{8F92E57B-CB5C-459D-9DEF-80ABC08CA39B} -> profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31313 | app=%programfiles%\windows media player\wmpnetwk.exe |
{94D5FE9B-46E6-4660-AD9E-9038CCEF2166} -> profile=private | protocol=17 | dir=in | action=allow | name=dungeon defenders | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dungeondefenders.exe |
{9EB596E6-8DCB-45EA-9234-B651E08BB580} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31025 | app=%programfiles(x86)%\windows media player\wmplayer.exe |
{AEB529A3-C472-49C5-A29B-21E3444752CF} -> profile=private | protocol=6 | dir=in | action=allow | name=dungeon defenders | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dungeondefenders.exe |
{AFF1CDFC-3C89-44AF-A2FA-9FFF2572A3D8} -> profile=public | protocol=17 | dir=in | action=allow | name=ad-aware security toolbar dtx broker | app=c:\program files (x86)\adawaretb\dtuser.exe |
{B131E4EE-806D-41CC-BDC8-940699E8AF55} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31011 | app=%programfiles%\windows media player\wmplayer.exe |
{B24895CF-BEE9-41E8-A57B-AD6C8311BFA3} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31281 | app=system |
{BAE97DED-8C5B-486A-9CCF-7278CEE37BD4} -> profile=private | protocol=6 | dir=in | action=allow | name=call of duty: modern warfare 2 | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
{C66016E2-5266-4F35-8890-8D181CC12B0D} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31007 | app=%programfiles%\windows media player\wmplayer.exe |
{D1634433-03E0-4CD8-8039-1B65B3072F58} -> profile=private | protocol=1 | dir=out | action=allow | name=@firewallapi.dll,-28544 |
{E2C60463-83E5-4F1F-8743-8504C4297CFA} -> profile=public | protocol=6 | dir=in | action=allow | name=call of duty: modern warfare 3 - multiplayer | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 3\iw5mp.exe |
{E3B9718E-17E6-48A0-B84D-722E05DD834C} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31309 | app=%programfiles%\windows media player\wmpnetwk.exe |
{E7FF96D3-F86E-461D-8F56-A845CF014F8B} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31024 | app=%programfiles(x86)%\windows media player\wmplayer.exe |
{EA31DE36-347E-4DF6-B275-99E7BD307410} -> protocol=58 | dir=in | action=allow | name=@iphlpsvc.dll,-502 | app=system |
{F2D902CE-686C-4B9B-9697-D03146DD9B96} -> profile=private | protocol=17 | dir=in | action=allow | name=pando media booster | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
{F8868861-3C2B-42B1-B4B6-1CD952706EA6} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31301 | app=%programfiles%\windows media player\wmplayer.exe |
{FE4475C6-A2A8-45CF-B97D-E7322A1AEDE1} -> profile=public | protocol=6 | dir=in | action=block | name=java(tm) platform se binary | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
TCP Query User{588163E3-140F-4541-A431-968AB4073802}C:\program files (x86)\steam\steam.exe -> profile=public | protocol=6 | dir=in | action=allow | name=steam | app=c:\program files (x86)\steam\steam.exe |
TCP Query User{64F11F05-E179-4287-8927-971DD3D1F11A}C:\program files (x86)\electronic arts\eadm\core.exe -> profile=private | protocol=6 | dir=in | action=allow | name=ea download manager | app=c:\program files (x86)\electronic arts\eadm\core.exe |
TCP Query User{6F497727-611C-496F-90F9-A7D5E98FCDB3}C:\program files (x86)\steam\steamapps\kingman1231\team fortress 2\hl2.exe -> profile=public | protocol=6 | dir=in | action=allow | name=hl2 | app=c:\program files (x86)\steam\steamapps\kingman1231\team fortress 2\hl2.exe |
TCP Query User{748D1EA7-6FC5-4A16-84CD-1ABBD3254AD0}C:\program files (x86)\java\jre6\bin\javaw.exe -> profile=private | protocol=6 | dir=in | action=allow | name=java(tm) platform se binary | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
TCP Query User{FBC20424-7D1A-473D-BB86-CC1886DA581A}C:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe -> profile=public | protocol=6 | dir=in | action=block | name=iw4sp | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
UDP Query User{069E77D9-6CB4-481B-A57C-FC0026218EF8}C:\program files (x86)\steam\steamapps\kingman1231\team fortress 2\hl2.exe -> profile=public | protocol=17 | dir=in | action=allow | name=hl2 | app=c:\program files (x86)\steam\steamapps\kingman1231\team fortress 2\hl2.exe |
UDP Query User{5B0A8658-6C4D-470D-8983-81BCBA6F53B3}C:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe -> profile=public | protocol=17 | dir=in | action=block | name=iw4sp | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
UDP Query User{B7642B7A-8B8C-41C3-821C-B6D8725885EB}C:\program files (x86)\steam\steam.exe -> profile=public | protocol=17 | dir=in | action=allow | name=steam | app=c:\program files (x86)\steam\steam.exe |
UDP Query User{F8CD41C3-1CA3-48CE-879B-13FFDDF850AA}C:\program files (x86)\electronic arts\eadm\core.exe -> profile=private | protocol=17 | dir=in | action=allow | name=ea download manager | app=c:\program files (x86)\electronic arts\eadm\core.exe |
UDP Query User{F8EA8853-2161-4ADD-974D-AF5DF09EF96E}C:\program files (x86)\java\jre6\bin\javaw.exe -> profile=private | protocol=17 | dir=in | action=allow | name=java(tm) platform se binary | app=c:\program files (x86)\java\jre6\bin\javaw.exe |
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
“C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe” -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service] -> [2012-07-04 12:40:18 | 001,188,896 |——| M] (Safer-Networking Ltd.)
“C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe” -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon] -> [2012-07-04 12:40:58 | 003,921,432 |——| M] (Safer-Networking Ltd.)
“C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe” -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater] -> [2012-07-04 12:41:04 | 003,880,456 |——| M] (Safer-Networking Ltd.)
“C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe” -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service] -> [2012-07-04 12:40:20 | 001,395,736 |——| M] (Safer-Networking Ltd.)
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
“AutoRun” -> 1 ->
“DisplayName” -> Cd-rom-driver ->
“ImagePath” ->  [\SystemRoot\system32\drivers\cdrom.sys] -> File not found
< Drives with AutoRun files > ->  ->
D:\Autorun.exe [MZ | ] -> D:\Autorun.exe [ UDF ] -> [2009-05-06 21:51:39 | 000,212,240 | R—- | M] (Electronic Arts Inc.)
D:\Autorun.inf [[autorun] | open=autorun.exe | icon=SporeEP1.ico | label=“SPORE_EP1” | ] -> D:\Autorun.inf [ UDF ] -> [2009-05-06 21:37:26 | 000,000,067 | R—- | M] ()
D:\autorun [] -> D:\autorun [ UDF ] -> [2009-05-06 21:48:00 | 000,000,000 | R—D | M]
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
\{9c57675c-5e03-11e1-8527-806e6f6e6963}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9c57675c-5e03-11e1-8527-806e6f6e6963}\shell
\{9c57675c-5e03-11e1-8527-806e6f6e6963}\shell\\”” ->  [AutoRun] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9c57675c-5e03-11e1-8527-806e6f6e6963}\shell\AutoRun\command
\{9c57675c-5e03-11e1-8527-806e6f6e6963}\shell\AutoRun\command\\”” -> D:\Autorun.exe [D:\autorun.exe] -> [2009-05-06 21:51:39 | 000,212,240 | R—- | M] (Electronic Arts Inc.)
< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command ->
64bit-comfile [open] -> “%1” %*
64bit-exefile [open] -> “%1” %*
comfile [open] -> “%1” %* ->
exefile [open] -> “%1” %* ->
< 64bit-File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>\ ->
.com [@ = comfile] -> “%1” %* ->
.exe [@ = exefile] -> “%1” %* ->
< File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>\ ->
.com [@ = comfile] -> “%1” %* ->
.exe [@ = exefile] -> “%1” %* ->


[Files/Folders - Created Within 30 Days]
OTS.exe -> C:\Users\Joakim\Desktop\OTS.exe -> [2012-07-12 23:49:02 | 000,646,656 |——| C] (OldTimer Tools)
Spybot - Search & Destroy -> C:\ProgramData\Spybot - Search & Destroy -> [2012-07-12 23:03:01 | 000,000,000 |—-D | C]
Spybot - Search & Destroy 2 -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2 -> [2012-07-12 23:02:56 | 000,000,000 |—-D | C]
sdnclean64.exe -> C:\Windows\SysNative\sdnclean64.exe -> [2012-07-12 23:02:50 | 000,017,272 |——| C] (Safer Networking Limited)
Spybot - Search & Destroy 2 -> C:\Program Files (x86)\Spybot - Search & Destroy 2 -> [2012-07-12 23:02:43 | 000,000,000 |—-D | C]
adaware -> C:\Users\Joakim\AppData\Local\adaware -> [2012-07-12 21:05:05 | 000,000,000 |—-D | C]
Ad-Aware Antivirus -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-Aware Antivirus -> [2012-07-12 21:04:56 | 000,000,000 |—-D | C]
sbhips.sys -> C:\Windows\SysNative\drivers\sbhips.sys -> [2012-07-12 21:04:51 | 000,060,536 |——| C] (GFI Software)
SbFwIm.sys -> C:\Windows\SysNative\drivers\SbFwIm.sys -> [2012-07-12 21:04:40 | 000,119,416 |——| C] (GFI Software)
SbFw.sys -> C:\Windows\SysNative\drivers\SbFw.sys -> [2012-07-12 21:04:38 | 000,256,632 |——| C] (GFI Software)
sbredrv.sys -> C:\Windows\SysNative\drivers\sbredrv.sys -> [2012-07-12 21:04:35 | 000,057,976 |——| C] (GFI Software)
sbbd.exe -> C:\Windows\SysNative\sbbd.exe -> [2012-07-12 21:04:35 | 000,045,936 |——| C] (GFI Software)
Lavasoft -> C:\ProgramData\Lavasoft -> [2012-07-12 21:04:32 | 000,000,000 |—-D | C]
Ad-Aware Antivirus -> C:\Program Files (x86)\Ad-Aware Antivirus -> [2012-07-12 21:04:31 | 000,000,000 |—-D | C]
adawarebp -> C:\Users\Joakim\AppData\Local\adawarebp -> [2012-07-12 21:04:11 | 000,000,000 |—-D | C]
Ad-Aware Browsing Protection -> C:\ProgramData\Ad-Aware Browsing Protection -> [2012-07-12 21:04:11 | 000,000,000 |—-D | C]
Toolbar Cleaner -> C:\Program Files (x86)\Toolbar Cleaner -> [2012-07-12 21:04:09 | 000,000,000 |—-D | C]
adawaretb -> C:\Program Files (x86)\adawaretb -> [2012-07-12 21:04:04 | 000,000,000 |—-D | C]
Ad-Aware Antivirus -> C:\Users\Joakim\AppData\Roaming\Ad-Aware Antivirus -> [2012-07-12 21:03:32 | 000,000,000 |—-D | C]
AxInstSV -> C:\Windows\AxInstSV -> [2012-07-12 20:36:25 | 000,000,000 | -H-D | C]
Google Chrome -> C:\Users\Joakim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome -> [2012-07-12 13:17:45 | 000,000,000 |—-D | C]
.minecraft -> C:\Users\Joakim\AppData\Roaming\.minecraft -> [2012-07-12 13:11:48 | 000,000,000 |—-D | C]
hamachi.sys -> C:\Windows\SysNative\hamachi.sys -> [2012-07-10 12:24:31 | 000,033,856 | -H—| C] (LogMeIn, Inc.)
LogMeIn Hamachi -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi -> [2012-07-10 12:24:29 | 000,000,000 |—-D | C]
LogMeIn Hamachi -> C:\Program Files (x86)\LogMeIn Hamachi -> [2012-07-10 12:24:29 | 000,000,000 |—-D | C]
paulscode -> C:\Users\Joakim\AppData\Roaming\paulscode -> [2012-06-19 19:36:14 | 000,000,000 |—-D | C]
net -> C:\Users\Joakim\AppData\Roaming\net -> [2012-06-19 19:36:14 | 000,000,000 |—-D | C]
ibxm -> C:\Users\Joakim\AppData\Roaming\ibxm -> [2012-06-19 19:36:14 | 000,000,000 |—-D | C]
forge -> C:\Users\Joakim\AppData\Roaming\forge -> [2012-06-19 19:36:14 | 000,000,000 |—-D | C]
cpw -> C:\Users\Joakim\AppData\Roaming\cpw -> [2012-06-19 19:36:14 | 000,000,000 |—-D | C]
xml-pull -> C:\Users\Joakim\AppData\Roaming\xml-pull -> [2012-06-19 19:35:22 | 000,000,000 |—-D | C]
org -> C:\Users\Joakim\AppData\Roaming\org -> [2012-06-19 19:35:21 | 000,000,000 |—-D | C]
javax -> C:\Users\Joakim\AppData\Roaming\javax -> [2012-06-19 19:35:21 | 000,000,000 |—-D | C]
de -> C:\Users\Joakim\AppData\Roaming\de -> [2012-06-19 19:35:20 | 000,000,000 |—-D | C]
skyz -> C:\Users\Joakim\AppData\Roaming\skyz -> [2012-06-17 11:21:07 | 000,000,000 |—-D | C]
bukkit -> C:\Users\Joakim\Desktop\bukkit -> [2012-06-15 15:11:05 | 000,000,000 |—-D | C]

[Files/Folders - Modified Within 30 Days]
PerfStringBackup.INI -> C:\Windows\SysNative\PerfStringBackup.INI -> [2012-07-13 00:00:37 | 001,264,910 |——| M] ()
perfh009.dat -> C:\Windows\SysNative\perfh009.dat -> [2012-07-13 00:00:37 | 000,616,008 |——| M] ()
perfh006.dat -> C:\Windows\SysNative\perfh006.dat -> [2012-07-13 00:00:37 | 000,470,324 |——| M] ()
perfc009.dat -> C:\Windows\SysNative\perfc009.dat -> [2012-07-13 00:00:37 | 000,106,388 |——| M] ()
perfc006.dat -> C:\Windows\SysNative\perfc006.dat -> [2012-07-13 00:00:37 | 000,079,926 |——| M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 -> [2012-07-12 23:50:04 | 000,010,048 | -H—| M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 -> [2012-07-12 23:50:04 | 000,010,048 | -H—| M] ()
OTS.exe -> C:\Users\Joakim\Desktop\OTS.exe -> [2012-07-12 23:48:24 | 000,646,656 |——| M] (OldTimer Tools)
Ad-Aware Antivirus.lnk -> C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk -> [2012-07-12 23:43:15 | 000,001,868 |——| M] ()
bootstat.dat -> C:\Windows\bootstat.dat -> [2012-07-12 23:41:37 | 000,067,584 |—S- | M] ()
hiberfil.sys -> C:\hiberfil.sys -> [2012-07-12 23:41:34 | 3193,655,296 | -HS- | M] ()
Adobe Flash Player Updater.job -> C:\Windows\tasks\Adobe Flash Player Updater.job -> [2012-07-12 23:25:00 | 000,000,830 |——| M] ()
GoogleUpdateTaskUserS-1-5-21-2361015560-1428424842-530145086-1000UA.job -> C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2361015560-1428424842-530145086-1000UA.job -> [2012-07-12 23:21:00 | 000,000,912 |——| M] ()
Spybot-S&D Start Center.lnk -> C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk -> [2012-07-12 23:02:56 | 000,002,173 |——| M] ()
ServiceConfig.xml -> C:\Windows\SysWow64\ServiceConfig.xml -> [2012-07-12 22:40:18 | 000,001,188 |——| M] ()
spywarefri.PNG -> C:\Users\Joakim\Desktop\spywarefri.PNG -> [2012-07-12 20:32:38 | 000,317,857 |——| M] ()
includeitinfo.PNG -> C:\Users\Joakim\Desktop\includeitinfo.PNG -> [2012-07-12 20:32:14 | 000,024,259 |——| M] ()
GoogleUpdateTaskUserS-1-5-21-2361015560-1428424842-530145086-1000Core.job -> C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2361015560-1428424842-530145086-1000Core.job -> [2012-07-12 13:21:01 | 000,000,860 |——| M] ()
FNTCACHE.DAT -> C:\Windows\SysNative\FNTCACHE.DAT -> [2012-07-11 14:58:52 | 000,273,656 |——| M] ()
config.nt -> C:\Windows\SysWow64\config.nt -> [2012-07-10 20:18:43 | 000,000,000 |——| M] ()
Udklip.PNG -> C:\Users\Joakim\Desktop\Udklip.PNG -> [2012-07-10 20:06:58 | 000,201,372 |——| M] ()
LogMeIn Hamachi.lnk -> C:\Users\Public\Desktop\LogMeIn Hamachi.lnk -> [2012-07-10 12:24:30 | 000,000,926 |——| M] ()
IMG_0452.JPG -> C:\Users\Joakim\Desktop\IMG_0452.JPG -> [2012-07-10 10:22:46 | 000,074,572 |——| M] ()
aswSnx.sys -> C:\Windows\SysNative\drivers\aswSnx.sys -> [2012-07-03 18:21:52 | 000,958,400 |——| M] (AVAST Software)
aswSP.sys -> C:\Windows\SysNative\drivers\aswSP.sys -> [2012-07-03 18:21:52 | 000,355,856 |——| M] (AVAST Software)
aswMonFlt.sys -> C:\Windows\SysNative\drivers\aswMonFlt.sys -> [2012-07-03 18:21:52 | 000,071,064 |——| M] (AVAST Software)
aswTdi.sys -> C:\Windows\SysNative\drivers\aswTdi.sys -> [2012-07-03 18:21:52 | 000,059,728 |——| M] (AVAST Software)
aswRdr2.sys -> C:\Windows\SysNative\drivers\aswRdr2.sys -> [2012-07-03 18:21:52 | 000,054,072 |——| M] (AVAST Software)
aswFsBlk.sys -> C:\Windows\SysNative\drivers\aswFsBlk.sys -> [2012-07-03 18:21:51 | 000,025,232 |——| M] (AVAST Software)
avastSS.scr -> C:\Windows\avastSS.scr -> [2012-07-03 18:21:32 | 000,041,224 |——| M] (AVAST Software)
aswBoot.exe -> C:\Windows\SysWow64\aswBoot.exe -> [2012-07-03 18:21:28 | 000,227,648 |——| M] (AVAST Software)
aswBoot.exe -> C:\Windows\SysNative\aswBoot.exe -> [2012-07-03 18:21:18 | 000,285,328 |——| M] (AVAST Software)
2012-06-26_21.51.19 - Genvej.lnk -> C:\Users\Joakim\Desktop\2012-06-26_21.51.19 - Genvej.lnk -> [2012-06-26 21:52:08 | 000,001,159 |——| M] ()
2012-06-26_21.51.19.png -> C:\Users\Joakim\Desktop\2012-06-26_21.51.19.png -> [2012-06-26 21:51:19 | 000,011,864 |——| M] ()
GuiAPI-0.14.2-1.2.5.zip -> C:\Users\Joakim\Desktop\GuiAPI-0.14.2-1.2.5.zip -> [2012-06-25 18:58:19 | 001,063,661 |——| M] ()
Video call snapshot 5.png -> C:\Users\Joakim\Desktop\Video call snapshot 5.png -> [2012-06-25 16:19:43 | 000,322,277 |——| M] ()
Video call snapshot 1.png -> C:\Users\Joakim\Desktop\Video call snapshot 1.png -> [2012-06-25 16:19:40 | 000,240,527 |——| M] ()
Team Fortress 2.url -> C:\Users\Joakim\Desktop\Team Fortress 2.url -> [2012-06-21 15:30:34 | 000,000,219 |——| M] ()
Sunken Island Adventure (1.2.5).zip -> C:\Users\Joakim\Desktop\Sunken Island Adventure (1.2.5).zip -> [2012-06-19 15:49:12 | 002,631,617 |——| M] ()
CustomMobSpawner 1.4.3.zip -> C:\Users\Joakim\Desktop\CustomMobSpawner 1.4.3.zip -> [2012-06-17 11:38:29 | 000,019,895 |——| M] ()
MinecraftForge-3.3.7.135-Client.zip -> C:\Users\Joakim\Desktop\MinecraftForge-3.3.7.135-Client.zip -> [2012-06-17 11:37:12 | 000,807,734 |——| M] ()
ModLoader.zip -> C:\Users\Joakim\Desktop\ModLoader.zip -> [2012-06-17 11:36:21 | 000,103,347 |——| M] ()
DrZharks MoCreatures Mod v3.6.2.zip -> C:\Users\Joakim\Desktop\DrZharks MoCreatures Mod v3.6.2.zip -> [2012-06-17 11:35:06 | 005,070,386 |——| M] ()
SinglePlayerCommands-MC1.2.5_V3.2.2.jar -> C:\Users\Joakim\Desktop\SinglePlayerCommands-MC1.2.5_V3.2.2.jar -> [2012-06-17 08:40:13 | 000,999,771 |——| M] ()
fun face.png -> C:\Users\Joakim\Desktop\fun face.png -> [2012-06-15 22:06:00 | 000,452,440 |——| M] ()
Tornadoes Mod Installer.exe -> C:\Users\Joakim\Desktop\Tornadoes Mod Installer.exe -> [2012-06-14 15:16:55 | 001,150,464 |——| M] ()
ModLoader.class -> C:\Users\Joakim\AppData\Roaming\ModLoader.class -> [2012-06-13 23:11:14 | 000,015,378 |——| M] ()
xt.class -> C:\Users\Joakim\AppData\Roaming\xt.class -> [2012-06-13 23:11:14 | 000,008,789 |——| M] ()
BaseMod.class -> C:\Users\Joakim\AppData\Roaming\BaseMod.class -> [2012-06-13 23:11:14 | 000,007,778 |——| M] ()
alj.class -> C:\Users\Joakim\AppData\Roaming\alj.class -> [2012-06-13 23:11:14 | 000,006,779 |——| M] ()
ClientRegistry.class -> C:\Users\Joakim\AppData\Roaming\ClientRegistry.class -> [2012-06-13 23:11:14 | 000,006,359 |——| M] ()
aao.class -> C:\Users\Joakim\AppData\Roaming\aao.class -> [2012-06-13 23:11:14 | 000,005,953 |——| M] ()
uu.class -> C:\Users\Joakim\AppData\Roaming\uu.class -> [2012-06-13 23:11:14 | 000,005,101 |——| M] ()
adn.class -> C:\Users\Joakim\AppData\Roaming\adn.class -> [2012-06-13 23:11:14 | 000,004,464 |——| M] ()
ModTextureStatic.class -> C:\Users\Joakim\AppData\Roaming\ModTextureStatic.class -> [2012-06-13 23:11:14 | 000,004,435 |——| M] ()
gi.class -> C:\Users\Joakim\AppData\Roaming\gi.class -> [2012-06-13 23:11:14 | 000,004,183 |——| M] ()
ach.class -> C:\Users\Joakim\AppData\Roaming\ach.class -> [2012-06-13 23:11:14 | 000,004,161 |——| M] ()
vx.class -> C:\Users\Joakim\AppData\Roaming\vx.class -> [2012-06-13 23:11:14 | 000,004,086 |——| M] ()
ht.class -> C:\Users\Joakim\AppData\Roaming\ht.class -> [2012-06-13 23:11:14 | 000,004,056 |——| M] ()
tu.class -> C:\Users\Joakim\AppData\Roaming\tu.class -> [2012-06-13 23:11:14 | 000,003,854 |——| M] ()
ModTextureAnimation.class -> C:\Users\Joakim\AppData\Roaming\ModTextureAnimation.class -> [2012-06-13 23:11:14 | 000,003,341 |——| M] ()
FMLRenderAccessLibrary.class -> C:\Users\Joakim\AppData\Roaming\FMLRenderAccessLibrary.class -> [2012-06-13 23:11:14 | 000,002,602 |——| M] ()
gf.class -> C:\Users\Joakim\AppData\Roaming\gf.class -> [2012-06-13 23:11:14 | 000,002,395 |——| M] ()
zp.class -> C:\Users\Joakim\AppData\Roaming\zp.class -> [2012-06-13 23:11:14 | 000,002,282 |——| M] ()
bv.class -> C:\Users\Joakim\AppData\Roaming\bv.class -> [2012-06-13 23:11:14 | 000,002,193 |——| M] ()
nh.class -> C:\Users\Joakim\AppData\Roaming\nh.class -> [2012-06-13 23:11:14 | 000,002,178 |——| M] ()
ael.class -> C:\Users\Joakim\AppData\Roaming\ael.class -> [2012-06-13 23:11:14 | 000,002,153 |——| M] ()
qa.class -> C:\Users\Joakim\AppData\Roaming\qa.class -> [2012-06-13 23:11:14 | 000,002,078 |——| M] ()
ajv.class -> C:\Users\Joakim\AppData\Roaming\ajv.class -> [2012-06-13 23:11:14 | 000,001,618 |——| M] ()
ahy.class -> C:\Users\Joakim\AppData\Roaming\ahy.class -> [2012-06-13 23:11:14 | 000,001,134 |——| M] ()
MLProp.class -> C:\Users\Joakim\AppData\Roaming\MLProp.class -> [2012-06-13 23:11:14 | 000,000,536 |——| M] ()
SidedProxy.class -> C:\Users\Joakim\AppData\Roaming\SidedProxy.class -> [2012-06-13 23:11:14 | 000,000,516 |——| M] ()
vl.class -> C:\Users\Joakim\AppData\Roaming\vl.class -> [2012-06-13 23:11:04 | 000,088,615 |——| M] ()
xd.class -> C:\Users\Joakim\AppData\Roaming\xd.class -> [2012-06-13 23:11:04 | 000,061,001 |——| M] ()
l.class -> C:\Users\Joakim\AppData\Roaming\l.class -> [2012-06-13 23:11:04 | 000,038,381 |——| M] ()
pb.class -> C:\Users\Joakim\AppData\Roaming\pb.class -> [2012-06-13 23:11:04 | 000,034,563 |——| M] ()
acq.class -> C:\Users\Joakim\AppData\Roaming\acq.class -> [2012-06-13 23:11:04 | 000,030,583 |——| M] ()
adl.class -> C:\Users\Joakim\AppData\Roaming\adl.class -> [2012-06-13 23:11:04 | 000,028,779 |——| M] ()
lr.class -> C:\Users\Joakim\AppData\Roaming\lr.class -> [2012-06-13 23:11:04 | 000,028,626 |——| M] ()
yw.class -> C:\Users\Joakim\AppData\Roaming\yw.class -> [2012-06-13 23:11:04 | 000,028,243 |——| M] ()
nn.class -> C:\Users\Joakim\AppData\Roaming\nn.class -> [2012-06-13 23:11:04 | 000,026,541 |——| M] ()
ama.class -> C:\Users\Joakim\AppData\Roaming\ama.class -> [2012-06-13 23:11:04 | 000,023,125 |——| M] ()
yr.class -> C:\Users\Joakim\AppData\Roaming\yr.class -> [2012-06-13 23:11:04 | 000,021,616 |——| M] ()
ack.class -> C:\Users\Joakim\AppData\Roaming\ack.class -> [2012-06-13 23:11:04 | 000,020,614 |——| M] ()
aiy.class -> C:\Users\Joakim\AppData\Roaming\aiy.class -> [2012-06-13 23:11:04 | 000,017,075 |——| M] ()
aaw.class -> C:\Users\Joakim\AppData\Roaming\aaw.class -> [2012-06-13 23:11:04 | 000,013,815 |——| M] ()
mn.class -> C:\Users\Joakim\AppData\Roaming\mn.class -> [2012-06-13 23:11:04 | 000,013,742 |——| M] ()
we.class -> C:\Users\Joakim\AppData\Roaming\we.class -> [2012-06-13 23:11:04 | 000,011,446 |——| M] ()
fr.class -> C:\Users\Joakim\AppData\Roaming\fr.class -> [2012-06-13 23:11:04 | 000,010,608 |——| M] ()
ro.class -> C:\Users\Joakim\AppData\Roaming\ro.class -> [2012-06-13 23:11:04 | 000,010,527 |——| M] ()
aiv.class -> C:\Users\Joakim\AppData\Roaming\aiv.class -> [2012-06-13 23:11:04 | 000,009,504 |——| M] ()
tw.class -> C:\Users\Joakim\AppData\Roaming\tw.class -> [2012-06-13 23:11:04 | 000,008,695 |——| M] ()
sn.class -> C:\Users\Joakim\AppData\Roaming\sn.class -> [2012-06-13 23:11:04 | 000,008,622 |——| M] ()
ahi.class -> C:\Users\Joakim\AppData\Roaming\ahi.class -> [2012-06-13 23:11:04 | 000,008,154 |——| M] ()
abc.class -> C:\Users\Joakim\AppData\Roaming\abc.class -> [2012-06-13 23:11:04 | 000,008,109 |——| M] ()
ame.class -> C:\Users\Joakim\AppData\Roaming\ame.class -> [2012-06-13 23:11:04 | 000,008,055 |——| M] ()
adz.class -> C:\Users\Joakim\AppData\Roaming\adz.class -> [2012-06-13 23:11:04 | 000,007,907 |——| M] ()
vf.class -> C:\Users\Joakim\AppData\Roaming\vf.class -> [2012-06-13 23:11:04 | 000,007,548 |——| M] ()
cw.class -> C:\Users\Joakim\AppData\Roaming\cw.class -> [2012-06-13 23:11:04 | 000,007,479 |——| M] ()
rk.class -> C:\Users\Joakim\AppData\Roaming\rk.class -> [2012-06-13 23:11:04 | 000,007,238 |——| M] ()
lg.class -> C:\Users\Joakim\AppData\Roaming\lg.class -> [2012-06-13 23:11:04 | 000,007,066 |——| M] ()
ahu.class -> C:\Users\Joakim\AppData\Roaming\ahu.class -> [2012-06-13 23:11:04 | 000,006,991 |——| M] ()
sd.class -> C:\Users\Joakim\AppData\Roaming\sd.class -> [2012-06-13 23:11:04 | 000,006,723 |——| M] ()
aem.class -> C:\Users\Joakim\AppData\Roaming\aem.class -> [2012-06-13 23:11:04 | 000,006,697 |——| M] ()
uf.class -> C:\Users\Joakim\AppData\Roaming\uf.class -> [2012-06-13 23:11:04 | 000,006,451 |——| M] ()
ais.class -> C:\Users\Joakim\AppData\Roaming\ais.class -> [2012-06-13 23:11:04 | 000,006,378 |——| M] ()
pv.class -> C:\Users\Joakim\AppData\Roaming\pv.class -> [2012-06-13 23:11:04 | 000,006,337 |——| M] ()
uo.class -> C:\Users\Joakim\AppData\Roaming\uo.class -> [2012-06-13 23:11:04 | 000,006,271 |——| M] ()
cu.class -> C:\Users\Joakim\AppData\Roaming\cu.class -> [2012-06-13 23:11:04 | 000,006,040 |——| M] ()
aez.class -> C:\Users\Joakim\AppData\Roaming\aez.class -> [2012-06-13 23:11:04 | 000,005,875 |——| M] ()
qx.class -> C:\Users\Joakim\AppData\Roaming\qx.class -> [2012-06-13 23:11:04 | 000,005,809 |——| M] ()
acb.class -> C:\Users\Joakim\AppData\Roaming\acb.class -> [2012-06-13 23:11:04 | 000,005,722 |——| M] ()
ko.class -> C:\Users\Joakim\AppData\Roaming\ko.class -> [2012-06-13 23:11:04 | 000,005,702 |——| M] ()
ct.class -> C:\Users\Joakim\AppData\Roaming\ct.class -> [2012-06-13 23:11:04 | 000,005,647 |——| M] ()
ahg.class -> C:\Users\Joakim\AppData\Roaming\ahg.class -> [2012-06-13 23:11:04 | 000,005,448 |——| M] ()
km.class -> C:\Users\Joakim\AppData\Roaming\km.class -> [2012-06-13 23:11:04 | 000,005,424 |——| M] ()
agh.class -> C:\Users\Joakim\AppData\Roaming\agh.class -> [2012-06-13 23:11:04 | 000,005,413 |——| M] ()
os.class -> C:\Users\Joakim\AppData\Roaming\os.class -> [2012-06-13 23:11:04 | 000,005,408 |——| M] ()
amc.class -> C:\Users\Joakim\AppData\Roaming\amc.class -> [2012-06-13 23:11:04 | 000,005,241 |——| M] ()
kw.class -> C:\Users\Joakim\AppData\Roaming\kw.class -> [2012-06-13 23:11:04 | 000,004,823 |——| M] ()
alk.class -> C:\Users\Joakim\AppData\Roaming\alk.class -> [2012-06-13 23:11:04 | 000,004,709 |——| M] ()
fq.class -> C:\Users\Jo

  FieFyn
Antal indlæg: 16

[Files/Folders - Created Within 30 Days]
OTS.exe -> C:\Users\Joakim\Desktop\OTS.exe -> [2012-07-12 23:49:02 | 000,646,656 |——| C] (OldTimer Tools)
Spybot - Search & Destroy -> C:\ProgramData\Spybot - Search & Destroy -> [2012-07-12 23:03:01 | 000,000,000 |—-D | C]
Spybot - Search & Destroy 2 -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2 -> [2012-07-12 23:02:56 | 000,000,000 |—-D | C]
sdnclean64.exe -> C:\Windows\SysNative\sdnclean64.exe -> [2012-07-12 23:02:50 | 000,017,272 |——| C] (Safer Networking Limited)
Spybot - Search & Destroy 2 -> C:\Program Files (x86)\Spybot - Search & Destroy 2 -> [2012-07-12 23:02:43 | 000,000,000 |—-D | C]
adaware -> C:\Users\Joakim\AppData\Local\adaware -> [2012-07-12 21:05:05 | 000,000,000 |—-D | C]
Ad-Aware Antivirus -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-Aware Antivirus -> [2012-07-12 21:04:56 | 000,000,000 |—-D | C]
sbhips.sys -> C:\Windows\SysNative\drivers\sbhips.sys -> [2012-07-12 21:04:51 | 000,060,536 |——| C] (GFI Software)
SbFwIm.sys -> C:\Windows\SysNative\drivers\SbFwIm.sys -> [2012-07-12 21:04:40 | 000,119,416 |——| C] (GFI Software)
SbFw.sys -> C:\Windows\SysNative\drivers\SbFw.sys -> [2012-07-12 21:04:38 | 000,256,632 |——| C] (GFI Software)
sbredrv.sys -> C:\Windows\SysNative\drivers\sbredrv.sys -> [2012-07-12 21:04:35 | 000,057,976 |——| C] (GFI Software)
sbbd.exe -> C:\Windows\SysNative\sbbd.exe -> [2012-07-12 21:04:35 | 000,045,936 |——| C] (GFI Software)
Lavasoft -> C:\ProgramData\Lavasoft -> [2012-07-12 21:04:32 | 000,000,000 |—-D | C]
Ad-Aware Antivirus -> C:\Program Files (x86)\Ad-Aware Antivirus -> [2012-07-12 21:04:31 | 000,000,000 |—-D | C]
adawarebp -> C:\Users\Joakim\AppData\Local\adawarebp -> [2012-07-12 21:04:11 | 000,000,000 |—-D | C]
Ad-Aware Browsing Protection -> C:\ProgramData\Ad-Aware Browsing Protection -> [2012-07-12 21:04:11 | 000,000,000 |—-D | C]
Toolbar Cleaner -> C:\Program Files (x86)\Toolbar Cleaner -> [2012-07-12 21:04:09 | 000,000,000 |—-D | C]
adawaretb -> C:\Program Files (x86)\adawaretb -> [2012-07-12 21:04:04 | 000,000,000 |—-D | C]
Ad-Aware Antivirus -> C:\Users\Joakim\AppData\Roaming\Ad-Aware Antivirus -> [2012-07-12 21:03:32 | 000,000,000 |—-D | C]
AxInstSV -> C:\Windows\AxInstSV -> [2012-07-12 20:36:25 | 000,000,000 | -H-D | C]
Google Chrome -> C:\Users\Joakim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome -> [2012-07-12 13:17:45 | 000,000,000 |—-D | C]
.minecraft -> C:\Users\Joakim\AppData\Roaming\.minecraft -> [2012-07-12 13:11:48 | 000,000,000 |—-D | C]
mshtmled.dll -> C:\Windows\SysNative\mshtmled.dll -> [2012-07-11 14:23:11 | 000,096,768 |——| C] (Microsoft Corporation)
url.dll -> C:\Windows\SysNative\url.dll -> [2012-07-11 14:23:10 | 000,237,056 |——| C] (Microsoft Corporation)
url.dll -> C:\Windows\SysWow64\url.dll -> [2012-07-11 14:23:10 | 000,231,936 |——| C] (Microsoft Corporation)
mshtmled.dll -> C:\Windows\SysWow64\mshtmled.dll -> [2012-07-11 14:23:10 | 000,073,216 |——| C] (Microsoft Corporation)
ieui.dll -> C:\Windows\SysNative\ieui.dll -> [2012-07-11 14:23:08 | 000,248,320 |——| C] (Microsoft Corporation)
ieui.dll -> C:\Windows\SysWow64\ieui.dll -> [2012-07-11 14:23:08 | 000,176,640 |——| C] (Microsoft Corporation)
ieUnatt.exe -> C:\Windows\SysNative\ieUnatt.exe -> [2012-07-11 14:23:08 | 000,173,056 |——| C] (Microsoft Corporation)
ieUnatt.exe -> C:\Windows\SysWow64\ieUnatt.exe -> [2012-07-11 14:23:07 | 000,142,848 |——| C] (Microsoft Corporation)
inetcpl.cpl -> C:\Windows\SysWow64\inetcpl.cpl -> [2012-07-11 14:23:06 | 001,427,968 |——| C] (Microsoft Corporation)
jscript9.dll -> C:\Windows\SysNative\jscript9.dll -> [2012-07-11 14:23:05 | 002,311,680 |——| C] (Microsoft Corporation)
inetcpl.cpl -> C:\Windows\SysNative\inetcpl.cpl -> [2012-07-11 14:23:05 | 001,494,528 |——| C] (Microsoft Corporation)
jscript.dll -> C:\Windows\SysWow64\jscript.dll -> [2012-07-11 14:23:05 | 000,716,800 |——| C] (Microsoft Corporation)
jscript.dll -> C:\Windows\SysNative\jscript.dll -> [2012-07-11 14:23:04 | 000,818,688 |——| C] (Microsoft Corporation)
msxml3r.dll -> C:\Windows\SysWow64\msxml3r.dll -> [2012-07-11 12:44:22 | 000,002,048 |——| C] (Microsoft Corporation)
msxml3r.dll -> C:\Windows\SysNative\msxml3r.dll -> [2012-07-11 12:44:21 | 000,002,048 |——| C] (Microsoft Corporation)
ncrypt.dll -> C:\Windows\SysNative\ncrypt.dll -> [2012-07-11 12:44:04 | 000,307,200 |——| C] (Microsoft Corporation)
cdosys.dll -> C:\Windows\SysWow64\cdosys.dll -> [2012-07-11 12:43:52 | 000,805,376 |——| C] (Microsoft Corporation)
cdosys.dll -> C:\Windows\SysNative\cdosys.dll -> [2012-07-11 12:43:48 | 001,133,568 |——| C] (Microsoft Corporation)
hamachi.sys -> C:\Windows\SysNative\hamachi.sys -> [2012-07-10 12:24:31 | 000,033,856 | -H—| C] (LogMeIn, Inc.)
LogMeIn Hamachi -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi -> [2012-07-10 12:24:29 | 000,000,000 |—-D | C]
LogMeIn Hamachi -> C:\Program Files (x86)\LogMeIn Hamachi -> [2012-07-10 12:24:29 | 000,000,000 |—-D | C]
wucltux.dll -> C:\Windows\SysNative\wucltux.dll -> [2012-06-23 11:45:54 | 002,622,464 |——| C] (Microsoft Corporation)
wuauclt.exe -> C:\Windows\SysNative\wuauclt.exe -> [2012-06-23 11:45:54 | 000,057,880 |——| C] (Microsoft Corporation)
wups2.dll -> C:\Windows\SysNative\wups2.dll -> [2012-06-23 11:45:54 | 000,044,056 |——| C] (Microsoft Corporation)
wuapi.dll -> C:\Windows\SysNative\wuapi.dll -> [2012-06-23 11:45:35 | 000,701,976 |——| C] (Microsoft Corporation)
wudriver.dll -> C:\Windows\SysNative\wudriver.dll -> [2012-06-23 11:45:35 | 000,099,840 |——| C] (Microsoft Corporation)
wups.dll -> C:\Windows\SysNative\wups.dll -> [2012-06-23 11:45:35 | 000,038,424 |——| C] (Microsoft Corporation)
wuwebv.dll -> C:\Windows\SysNative\wuwebv.dll -> [2012-06-23 11:45:20 | 000,186,752 |——| C] (Microsoft Corporation)
wuapp.exe -> C:\Windows\SysNative\wuapp.exe -> [2012-06-23 11:45:19 | 000,036,864 |——| C] (Microsoft Corporation)
paulscode -> C:\Users\Joakim\AppData\Roaming\paulscode -> [2012-06-19 19:36:14 | 000,000,000 |—-D | C]
net -> C:\Users\Joakim\AppData\Roaming\net -> [2012-06-19 19:36:14 | 000,000,000 |—-D | C]
ibxm -> C:\Users\Joakim\AppData\Roaming\ibxm -> [2012-06-19 19:36:14 | 000,000,000 |—-D | C]
forge -> C:\Users\Joakim\AppData\Roaming\forge -> [2012-06-19 19:36:14 | 000,000,000 |—-D | C]
cpw -> C:\Users\Joakim\AppData\Roaming\cpw -> [2012-06-19 19:36:14 | 000,000,000 |—-D | C]
xml-pull -> C:\Users\Joakim\AppData\Roaming\xml-pull -> [2012-06-19 19:35:22 | 000,000,000 |—-D | C]
org -> C:\Users\Joakim\AppData\Roaming\org -> [2012-06-19 19:35:21 | 000,000,000 |—-D | C]
javax -> C:\Users\Joakim\AppData\Roaming\javax -> [2012-06-19 19:35:21 | 000,000,000 |—-D | C]
de -> C:\Users\Joakim\AppData\Roaming\de -> [2012-06-19 19:35:20 | 000,000,000 |—-D | C]
skyz -> C:\Users\Joakim\AppData\Roaming\skyz -> [2012-06-17 11:21:07 | 000,000,000 |—-D | C]
bukkit -> C:\Users\Joakim\Desktop\bukkit -> [2012-06-15 15:11:05 | 000,000,000 |—-D | C]
rdpcorekmts.dll -> C:\Windows\SysNative\rdpcorekmts.dll -> [2012-06-14 14:44:01 | 000,149,504 |——| C] (Microsoft Corporation)
rdpwsx.dll -> C:\Windows\SysNative\rdpwsx.dll -> [2012-06-14 14:44:01 | 000,077,312 |——| C] (Microsoft Corporation)
rdrmemptylst.exe -> C:\Windows\SysNative\rdrmemptylst.exe -> [2012-06-14 14:44:01 | 000,009,216 |——| C] (Microsoft Corporation)
ntoskrnl.exe -> C:\Windows\SysNative\ntoskrnl.exe -> [2012-06-14 14:43:43 | 005,559,664 |——| C] (Microsoft Corporation)
ntkrnlpa.exe -> C:\Windows\SysWow64\ntkrnlpa.exe -> [2012-06-14 14:43:39 | 003,968,368 |——| C] (Microsoft Corporation)
ntoskrnl.exe -> C:\Windows\SysWow64\ntoskrnl.exe -> [2012-06-14 14:43:39 | 003,913,072 |——| C] (Microsoft Corporation)
msi.dll -> C:\Windows\SysNative\msi.dll -> [2012-06-14 14:43:36 | 003,216,384 |——| C] (Microsoft Corporation)
crypt32.dll -> C:\Windows\SysNative\crypt32.dll -> [2012-06-14 14:43:21 | 001,462,272 |——| C] (Microsoft Corporation)
cryptnet.dll -> C:\Windows\SysNative\cryptnet.dll -> [2012-06-14 14:43:17 | 000,140,288 |——| C] (Microsoft Corporation)

[Files/Folders - Modified Within 30 Days]
PerfStringBackup.INI -> C:\Windows\SysNative\PerfStringBackup.INI -> [2012-07-13 00:00:37 | 001,264,910 |——| M] ()
perfh009.dat -> C:\Windows\SysNative\perfh009.dat -> [2012-07-13 00:00:37 | 000,616,008 |——| M] ()
perfh006.dat -> C:\Windows\SysNative\perfh006.dat -> [2012-07-13 00:00:37 | 000,470,324 |——| M] ()
perfc009.dat -> C:\Windows\SysNative\perfc009.dat -> [2012-07-13 00:00:37 | 000,106,388 |——| M] ()
perfc006.dat -> C:\Windows\SysNative\perfc006.dat -> [2012-07-13 00:00:37 | 000,079,926 |——| M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 -> [2012-07-12 23:50:04 | 000,010,048 | -H—| M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 -> [2012-07-12 23:50:04 | 000,010,048 | -H—| M] ()
OTS.exe -> C:\Users\Joakim\Desktop\OTS.exe -> [2012-07-12 23:48:24 | 000,646,656 |——| M] (OldTimer Tools)
Ad-Aware Antivirus.lnk -> C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk -> [2012-07-12 23:43:15 | 000,001,868 |——| M] ()
bootstat.dat -> C:\Windows\bootstat.dat -> [2012-07-12 23:41:37 | 000,067,584 |—S- | M] ()
hiberfil.sys -> C:\hiberfil.sys -> [2012-07-12 23:41:34 | 3193,655,296 | -HS- | M] ()
Adobe Flash Player Updater.job -> C:\Windows\tasks\Adobe Flash Player Updater.job -> [2012-07-12 23:25:00 | 000,000,830 |——| M] ()
GoogleUpdateTaskUserS-1-5-21-2361015560-1428424842-530145086-1000UA.job -> C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2361015560-1428424842-530145086-1000UA.job -> [2012-07-12 23:21:00 | 000,000,912 |——| M] ()
Spybot-S&D Start Center.lnk -> C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk -> [2012-07-12 23:02:56 | 000,002,173 |——| M] ()
ServiceConfig.xml -> C:\Windows\SysWow64\ServiceConfig.xml -> [2012-07-12 22:40:18 | 000,001,188 |——| M] ()
spywarefri.PNG -> C:\Users\Joakim\Desktop\spywarefri.PNG -> [2012-07-12 20:32:38 | 000,317,857 |——| M] ()
includeitinfo.PNG -> C:\Users\Joakim\Desktop\includeitinfo.PNG -> [2012-07-12 20:32:14 | 000,024,259 |——| M] ()
FlashPlayerApp.exe -> C:\Windows\SysWow64\FlashPlayerApp.exe -> [2012-07-12 13:25:09 | 000,426,184 |——| M] (Adobe Systems Incorporated)
FlashPlayerCPLApp.cpl -> C:\Windows\SysWow64\FlashPlayerCPLApp.cpl -> [2012-07-12 13:25:09 | 000,070,344 |——| M] (Adobe Systems Incorporated)
GoogleUpdateTaskUserS-1-5-21-2361015560-1428424842-530145086-1000Core.job -> C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2361015560-1428424842-530145086-1000Core.job -> [2012-07-12 13:21:01 | 000,000,860 |——| M] ()
FNTCACHE.DAT -> C:\Windows\SysNative\FNTCACHE.DAT -> [2012-07-11 14:58:52 | 000,273,656 |——| M] ()
config.nt -> C:\Windows\SysWow64\config.nt -> [2012-07-10 20:18:43 | 000,000,000 |——| M] ()
Udklip.PNG -> C:\Users\Joakim\Desktop\Udklip.PNG -> [2012-07-10 20:06:58 | 000,201,372 |——| M] ()
LogMeIn Hamachi.lnk -> C:\Users\Public\Desktop\LogMeIn Hamachi.lnk -> [2012-07-10 12:24:30 | 000,000,926 |——| M] ()
IMG_0452.JPG -> C:\Users\Joakim\Desktop\IMG_0452.JPG -> [2012-07-10 10:22:46 | 000,074,572 |——| M] ()
aswSnx.sys -> C:\Windows\SysNative\drivers\aswSnx.sys -> [2012-07-03 18:21:52 | 000,958,400 |——| M] (AVAST Software)
aswSP.sys -> C:\Windows\SysNative\drivers\aswSP.sys -> [2012-07-03 18:21:52 | 000,355,856 |——| M] (AVAST Software)
aswMonFlt.sys -> C:\Windows\SysNative\drivers\aswMonFlt.sys -> [2012-07-03 18:21:52 | 000,071,064 |——| M] (AVAST Software)
aswTdi.sys -> C:\Windows\SysNative\drivers\aswTdi.sys -> [2012-07-03 18:21:52 | 000,059,728 |——| M] (AVAST Software)
aswRdr2.sys -> C:\Windows\SysNative\drivers\aswRdr2.sys -> [2012-07-03 18:21:52 | 000,054,072 |——| M] (AVAST Software)
aswFsBlk.sys -> C:\Windows\SysNative\drivers\aswFsBlk.sys -> [2012-07-03 18:21:51 | 000,025,232 |——| M] (AVAST Software)
avastSS.scr -> C:\Windows\avastSS.scr -> [2012-07-03 18:21:32 | 000,041,224 |——| M] (AVAST Software)
aswBoot.exe -> C:\Windows\SysWow64\aswBoot.exe -> [2012-07-03 18:21:28 | 000,227,648 |——| M] (AVAST Software)
aswBoot.exe -> C:\Windows\SysNative\aswBoot.exe -> [2012-07-03 18:21:18 | 000,285,328 |——| M] (AVAST Software)
2012-06-26_21.51.19 - Genvej.lnk -> C:\Users\Joakim\Desktop\2012-06-26_21.51.19 - Genvej.lnk -> [2012-06-26 21:52:08 | 000,001,159 |——| M] ()
2012-06-26_21.51.19.png -> C:\Users\Joakim\Desktop\2012-06-26_21.51.19.png -> [2012-06-26 21:51:19 | 000,011,864 |——| M] ()
GuiAPI-0.14.2-1.2.5.zip -> C:\Users\Joakim\Desktop\GuiAPI-0.14.2-1.2.5.zip -> [2012-06-25 18:58:19 | 001,063,661 |——| M] ()
Video call snapshot 5.png -> C:\Users\Joakim\Desktop\Video call snapshot 5.png -> [2012-06-25 16:19:43 | 000,322,277 |——| M] ()
Video call snapshot 1.png -> C:\Users\Joakim\Desktop\Video call snapshot 1.png -> [2012-06-25 16:19:40 | 000,240,527 |——| M] ()
Team Fortress 2.url -> C:\Users\Joakim\Desktop\Team Fortress 2.url -> [2012-06-21 15:30:34 | 000,000,219 |——| M] ()
Sunken Island Adventure (1.2.5).zip -> C:\Users\Joakim\Desktop\Sunken Island Adventure (1.2.5).zip -> [2012-06-19 15:49:12 | 002,631,617 |——| M] ()
CustomMobSpawner 1.4.3.zip -> C:\Users\Joakim\Desktop\CustomMobSpawner 1.4.3.zip -> [2012-06-17 11:38:29 | 000,019,895 |——| M] ()
MinecraftForge-3.3.7.135-Client.zip -> C:\Users\Joakim\Desktop\MinecraftForge-3.3.7.135-Client.zip -> [2012-06-17 11:37:12 | 000,807,734 |——| M] ()
ModLoader.zip -> C:\Users\Joakim\Desktop\ModLoader.zip -> [2012-06-17 11:36:21 | 000,103,347 |——| M] ()
DrZharks MoCreatures Mod v3.6.2.zip -> C:\Users\Joakim\Desktop\DrZharks MoCreatures Mod v3.6.2.zip -> [2012-06-17 11:35:06 | 005,070,386 |——| M] ()
SinglePlayerCommands-MC1.2.5_V3.2.2.jar -> C:\Users\Joakim\Desktop\SinglePlayerCommands-MC1.2.5_V3.2.2.jar -> [2012-06-17 08:40:13 | 000,999,771 |——| M] ()
fun face.png -> C:\Users\Joakim\Desktop\fun face.png -> [2012-06-15 22:06:00 | 000,452,440 |——| M] ()
Tornadoes Mod Installer.exe -> C:\Users\Joakim\Desktop\Tornadoes Mod Installer.exe -> [2012-06-14 15:16:55 | 001,150,464 |——| M] ()
ModLoader.class -> C:\Users\Joakim\AppData\Roaming\ModLoader.class -> [2012-06-13 23:11:14 | 000,015,378 |——| M] ()
xt.class -> C:\Users\Joakim\AppData\Roaming\xt.class -> [2012-06-13 23:11:14 | 000,008,789 |——| M] ()
BaseMod.class -> C:\Users\Joakim\AppData\Roaming\BaseMod.class -> [2012-06-13 23:11:14 | 000,007,778 |——| M] ()
alj.class -> C:\Users\Joakim\AppData\Roaming\alj.class -> [2012-06-13 23:11:14 | 000,006,779 |——| M] ()
ClientRegistry.class -> C:\Users\Joakim\AppData\Roaming\ClientRegistry.class -> [2012-06-13 23:11:14 | 000,006,359 |——| M] ()
aao.class -> C:\Users\Joakim\AppData\Roaming\aao.class -> [2012-06-13 23:11:14 | 000,005,953 |——| M] ()
uu.class -> C:\Users\Joakim\AppData\Roaming\uu.class -> [2012-06-13 23:11:14 | 000,005,101 |——| M] ()
adn.class -> C:\Users\Joakim\AppData\Roaming\adn.class -> [2012-06-13 23:11:14 | 000,004,464 |——| M] ()
ModTextureStatic.class -> C:\Users\Joakim\AppData\Roaming\ModTextureStatic.class -> [2012-06-13 23:11:14 | 000,004,435 |——| M] ()
gi.class -> C:\Users\Joakim\AppData\Roaming\gi.class -> [2012-06-13 23:11:14 | 000,004,183 |——| M] ()
ach.class -> C:\Users\Joakim\AppData\Roaming\ach.class -> [2012-06-13 23:11:14 | 000,004,161 |——| M] ()
vx.class -> C:\Users\Joakim\AppData\Roaming\vx.class -> [2012-06-13 23:11:14 | 000,004,086 |——| M] ()
ht.class -> C:\Users\Joakim\AppData\Roaming\ht.class -> [2012-06-13 23:11:14 | 000,004,056 |——| M] ()
tu.class -> C:\Users\Joakim\AppData\Roaming\tu.class -> [2012-06-13 23:11:14 | 000,003,854 |——| M] ()
ModTextureAnimation.class -> C:\Users\Joakim\AppData\Roaming\ModTextureAnimation.class -> [2012-06-13 23:11:14 | 000,003,341 |——| M] ()
FMLRenderAccessLibrary.class -> C:\Users\Joakim\AppData\Roaming\FMLRenderAccessLibrary.class -> [2012-06-13 23:11:14 | 000,002,602 |——| M] ()
gf.class -> C:\Users\Joakim\AppData\Roaming\gf.class -> [2012-06-13 23:11:14 | 000,002,395 |——| M] ()
zp.class -> C:\Users\Joakim\AppData\Roaming\zp.class -> [2012-06-13 23:11:14 | 000,002,282 |——| M] ()
bv.class -> C:\Users\Joakim\AppData\Roaming\bv.class -> [2012-06-13 23:11:14 | 000,002,193 |——| M] ()
nh.class -> C:\Users\Joakim\AppData\Roaming\nh.class -> [2012-06-13 23:11:14 | 000,002,178 |——| M] ()
ael.class -> C:\Users\Joakim\AppData\Roaming\ael.class -> [2012-06-13 23:11:14 | 000,002,153 |——| M] ()
qa.class -> C:\Users\Joakim\AppData\Roaming\qa.class -> [2012-06-13 23:11:14 | 000,002,078 |——| M] ()
ajv.class -> C:\Users\Joakim\AppData\Roaming\ajv.class -> [2012-06-13 23:11:14 | 000,001,618 |——| M] ()
ahy.class -> C:\Users\Joakim\AppData\Roaming\ahy.class -> [2012-06-13 23:11:14 | 000,001,134 |——| M] ()
MLProp.class -> C:\Users\Joakim\AppData\Roaming\MLProp.class -> [2012-06-13 23:11:14 | 000,000,536 |——| M] ()
SidedProxy.class -> C:\Users\Joakim\AppData\Roaming\SidedProxy.class -> [2012-06-13 23:11:14 | 000,000,516 |——| M] ()
vl.class -> C:\Users\Joakim\AppData\Roaming\vl.class -> [2012-06-13 23:11:04 | 000,088,615 |——| M] ()
xd.class -> C:\Users\Joakim\AppData\Roaming\xd.class -> [2012-06-13 23:11:04 | 000,061,001 |——| M] ()
l.class -> C:\Users\Joakim\AppData\Roaming\l.class -> [2012-06-13 23:11:04 | 000,038,381 |——| M] ()
pb.class -> C:\Users\Joakim\AppData\Roaming\pb.class -> [2012-06-13 23:11:04 | 000,034,563 |——| M] ()
acq.class -> C:\Users\Joakim\AppData\Roaming\acq.class -> [2012-06-13 23:11:04 | 000,030,583 |——| M] ()
adl.class -> C:\Users\Joakim\AppData\Roaming\adl.class -> [2012-06-13 23:11:04 | 000,028,779 |——| M] ()
lr.class -> C:\Users\Joakim\AppData\Roaming\lr.class -> [2012-06-13 23:11:04 | 000,028,626 |——| M] ()
yw.class -> C:\Users\Joakim\AppData\Roaming\yw.class -> [2012-06-13 23:11:04 | 000,028,243 |——| M] ()
nn.class -> C:\Users\Joakim\AppData\Roaming\nn.class -> [2012-06-13 23:11:04 | 000,026,541 |——| M] ()
ama.class -> C:\Users\Joakim\AppData\Roaming\ama.class -> [2012-06-13 23:11:04 | 000,023,125 |——| M] ()
yr.class -> C:\Users\Joakim\AppData\Roaming\yr.class -> [2012-06-13 23:11:04 | 000,021,616 |——| M] ()
ack.class -> C:\Users\Joakim\AppData\Roaming\ack.class -> [2012-06-13 23:11:04 | 000,020,614 |——| M] ()
aiy.class -> C:\Users\Joakim\AppData\Roaming\aiy.class -> [2012-06-13 23:11:04 | 000,017,075 |——| M] ()
aaw.class -> C:\Users\Joakim\AppData\Roaming\aaw.class -> [2012-06-13 23:11:04 | 000,013,815 |——| M] ()
mn.class -> C:\Users\Joakim\AppData\Roaming\mn.class -> [2012-06-13 23:11:04 | 000,013,742 |——| M] ()
we.class -> C:\Users\Joakim\AppData\Roaming\we.class -> [2012-06-13 23:11:04 | 000,011,446 |——| M] ()
fr.class -> C:\Users\Joakim\AppData\Roaming\fr.class -> [2012-06-13 23:11:04 | 000,010,608 |——| M] ()
ro.class -> C:\Users\Joakim\AppData\Roaming\ro.class -> [2012-06-13 23:11:04 | 000,010,527 |——| M] ()
aiv.class -> C:\Users\Joakim\AppData\Roaming\aiv.class -> [2012-06-13 23:11:04 | 000,009,504 |——| M] ()
tw.class -> C:\Users\Joakim\AppData\Roaming\tw.class -> [2012-06-13 23:11:04 | 000,008,695 |——| M] ()
sn.class -> C:\Users\Joakim\AppData\Roaming\sn.class -> [2012-06-13 23:11:04 | 000,008,622 |——| M] ()
ahi.class -> C:\Users\Joakim\AppData\Roaming\ahi.class -> [2012-06-13 23:11:04 | 000,008,154 |——| M] ()
abc.class -> C:\Users\Joakim\AppData\Roaming\abc.class -> [2012-06-13 23:11:04 | 000,008,109 |——| M] ()
ame.class -> C:\Users\Joakim\AppData\Roaming\ame.class -> [2012-06-13 23:11:04 | 000,008,055 |——| M] ()
adz.class -> C:\Users\Joakim\AppData\Roaming\adz.class -> [2012-06-13 23:11:04 | 000,007,907 |——| M] ()
vf.class -> C:\Users\Joakim\AppData\Roaming\vf.class -> [2012-06-13 23:11:04 | 000,007,548 |——| M] ()
cw.class -> C:\Users\Joakim\AppData\Roaming\cw.class -> [2012-06-13 23:11:04 | 000,007,479 |——| M] ()
rk.class -> C:\Users\Joakim\AppData\Roaming\rk.class -> [2012-06-13 23:11:04 | 000,007,238 |——| M] ()
lg.class -> C:\Users\Joakim\AppData\Roaming\lg.class -> [2012-06-13 23:11:04 | 000,007,066 |——| M] ()
ahu.class -> C:\Users\Joakim\AppData\Roaming\ahu.class -> [2012-06-13 23:11:04 | 000,006,991 |——| M] ()
sd.class -> C:\Users\Joakim\AppData\Roaming\sd.class -> [2012-06-13 23:11:04 | 000,006,723 |——| M] ()
aem.class -> C:\Users\Joakim\AppData\Roaming\aem.class -> [2012-06-13 23:11:04 | 000,006,697 |——| M] ()
uf.class -> C:\Users\Joakim\AppData\Roaming\uf.class -> [2012-06-13 23:11:04 | 000,006,451 |——| M] ()
ais.class -> C:\Users\Joakim\AppData\Roaming\ais.class -> [2012-06-13 23:11:04 | 000,006,378 |——| M] ()
pv.class -> C:\Users\Joakim\AppData\Roaming\pv.class -> [2012-06-13 23:11:04 | 000,006,337 |——| M] ()
uo.class -> C:\Users\Joakim\AppData\Roaming\uo.class -> [2012-06-13 23:11:04 | 000,006,271 |——| M] ()
cu.class -> C:\Users\Joakim\AppData\Roaming\cu.class -> [2012-06-13 23:11:04 | 000,006,040 |——| M] ()
aez.class -> C:\Users\Joakim\AppData\Roaming\aez.class -> [2012-06-13 23:11:04 | 000,005,875 |——| M] ()
qx.class -> C:\Users\Joakim\AppData\Roaming\qx.class -> [2012-06-13 23:11:04 | 000,005,809 |——| M] ()
acb.class -> C:\Users\Joakim\AppData\Roaming\acb.class -> [2012-06-13 23:11:04 | 000,005,722 |——| M] ()
ko.class -> C:\Users\Joakim\AppData\Roaming\ko.class -> [2012-06-13 23:11:04 | 000,005,702 |——| M] ()
ct.class -> C:\Users\Joakim\AppData\Roaming\ct.class -> [2012-06-13 23:11:04 | 000,005,647 |——| M] ()
ahg.class -> C:\Users\Joakim\AppData\Roaming\ahg.class -> [2012-06-13 23:11:04 | 000,005,448 |——| M] ()
km.class -> C:\Users\Joakim\AppData\Roaming\km.class -> [2012-06-13 23:11:04 | 000,005,424 |——| M] ()
agh.class -> C:\Users\Joakim\AppData\Roaming\agh.class -> [2012-06-13 23:11:04 | 000,005,413 |——| M] ()
os.class -> C:\Users\Joakim\AppData\Roaming\os.class -> [2012-06-13 23:11:04 | 000,005,408 |——| M] ()
amc.class -> C:\Users\Joakim\AppData\Roaming\amc.class -> [2012-06-13 23:11:04 | 000,005,241 |——| M] ()
kw.class -> C:\Users\Joakim\AppData\Roaming\kw.class -> [2012-06-13 23:11:04 | 000,004,823 |——| M] ()
alk.class -> C:\Users\Joakim\AppData\Roaming\alk.class -> [2012-06-13 23:11:04 | 000,004,709 |——| M] ()
fq.class -> C:\Users\Joakim\AppData\Roaming\fq.class -> [2012-06-13 23:11:04 | 000,004,519 |——| M] ()
ul.class -> C:\Users\Joakim\AppData\Roaming\ul.class -> [2012-06-13 23:11:04 | 000,004,466 |——| M] ()
aes.class -> C:\Users\Joakim\AppData\Roaming\aes.class -> [2012-06-13 23:11:04 | 000,004,347 |——| M] ()
kt.class -> C:\Users\Joakim\AppData\Roaming\kt.class -> [2012-06-13 23:11:04 | 000,004,346 |——| M] ()
pt.class -> C:\Users\Joakim\AppData\Roaming\pt.class -> [2012-06-13 23:11:04 | 000,004,240 |——| M] ()
hm.class -> C:\Users\Joakim\AppData\Roaming\hm.class -> [2012-06-13 23:11:04 | 000,003,956 |——| M] ()
ajd.class -> C:\Users\Joakim\AppData\Roaming\ajd.class -> [2012-06-13 23:11:04 | 000,003,907 |——| M] ()
dq.class -> C:\Users\Joakim\AppData\Roaming\dq.class -> [2012-06-13 23:11:04 | 000,003,894 |——| M] ()
alb.class -> C:\Users\Joakim\AppData\Roaming\alb.class -> [2012-06-13 23:11:04 | 000,003,743 |——| M] ()
ki.class -> C:\Users\Joakim\AppData\Roaming\ki.class -> [2012-06-13 23:11:04 | 000,003,705 |——| M] ()
sb.class -> C:\Users\Joakim\AppData\Roaming\sb.class -> [2012-06-13 23:11:04 | 000,003,638 |——| M] ()
jx.class -> C:\Users\Joakim\AppData\Roaming\jx.class -> [2012-06-13 23:11:04 | 000,003,553 |——| M] ()
jt.class -> C:\Users\Joakim\AppData\Roaming\jt.class -> [2012-06-13 23:11:04 | 000,003,492 |——| M] ()
bh.class -> C:\Users\Joakim\AppData\Roaming\bh.class -> [2012-06-13 23:11:04 | 000,003,398 |——| M] ()
aff.class -> C:\Users\Joakim\AppData\Roaming\aff.class -> [2012-06-13 23:11:04 | 000,003,260 |——| M] ()
bf.class -> C:\Users\Joakim\AppData\Roaming\bf.class -> [2012-06-13 23:11:04 | 000,003,232 |——| M] ()
qm.class -> C:\Users\Joakim\AppData\Roaming\qm.class -> [2012-06-13 23:11:04 | 000,002,954 |——| M] ()
ha.class -> C:\Users\Joakim\AppData\Roaming\ha.class -> [2012-06-13 23:11:04 | 000,002,938 |——| M] ()
my.class -> C:\Users\Joakim\AppData\Roaming\my.class -> [2012-06-13 23:11:04 | 000,002,889 |——| M] ()
bb.class -> C:\Users\Joakim\AppData\Roaming\bb.class -> [2012-06-13 23:11:04 | 000,002,824 |——| M] ()
amn.class -> C:\Users\Joakim\AppData\Roaming\amn.class -> [2012-06-13 23:11:04 | 000,002,802 |——| M] ()
tg.class -> C:\Users\Joakim\AppData\Roaming\tg.class -> [2012-06-13 23:11:04 | 000,002,720 |——| M] ()
zo.class -> C:\Users\Joakim\AppData\Roaming\zo.class -> [2012-06-13 23:11:04 | 000,002,694 |——| M] ()
rr.class -> C:\Users\Joakim\AppData\Roaming\rr.class -> [2012-06-13 23:11:04 | 000,002,647 |——| M] ()
dy.class -> C:\Users\Joakim\AppData\Roaming\dy.class -> [2012-06-13 23:11:04 | 000,002,619 |——| M] ()
ug.class -> C:\Users\Joakim\AppData\Roaming\ug.class -> [2012-06-13 23:11:04 | 000,002,559 |——| M] ()
lo.class -> C:\Users\Joakim\AppData\Roaming\lo.class -> [2012-06-13 23:11:04 | 000,002,554 |——| M] ()
mm.class -> C:\Users\Joakim\AppData\Roaming\mm.class -> [2012-06-13 23:11:04 | 000,002,531 |——| M] ()
rb.class -> C:\Users\Joakim\AppData\Roaming\rb.class -> [2012-06-13 23:11:04 | 000,002,520 |——| M] ()
cx.class -> C:\Users\Joakim\AppData\Roaming\cx.class -> [2012-06-13 23:11:04 | 000,002,492 |——| M] ()
of.class -> C:\Users\Joakim\AppData\Roaming\of.class -> [2012-06-13 23:11:04 | 000,002,442 |——| M] ()
ii.class -> C:\Users\Joakim\AppData\Roaming\ii.class -> [2012-06-13 23:11:04 | 000,002,369 |——| M] ()
fv.class -> C:\Users\Joakim\AppData\Roaming\fv.class -> [2012-06-13 23:11:04 | 000,002,283 |——| M] ()
i.class -> C:\Users\Joakim\AppData\Roaming\i.class -> [2012-06-13 23:11:04 | 000,002,267 |——| M] ()
eh.class -> C:\Users\Joakim\AppData\Roaming\eh.class -> [2012-06-13 23:11:04 | 000,002,262 |——| M] ()
oz.class -> C:\Users\Joakim\AppData\Roaming\oz.class -> [2012-06-13 23:11:04 | 000,002,142 |——| M] ()
afm.class -> C:\Users\Joakim\AppData\Roaming\afm.class -> [2012-06-13 23:11:04 | 000,002,135 |——| M] ()
pp.class -> C:\Users\Joakim\AppData\Roaming\pp.class -> [2012-06-13 23:11:04 | 000,001,938 |——| M] ()
akf.class -> C:\Users\Joakim\AppData\Roaming\akf.class -> [2012-06-13 23:11:04 | 000,001,881 |——| M] ()
da.class -> C:\Users\Joakim\AppData\Roaming\da.class -> [2012-06-13 23:11:04 | 000,001,794 |——| M] ()
agm.class -> C:\Users\Joakim\AppData\Roaming\agm.class -> [2012-06-13 23:11:04 | 000,001,542 |——| M] ()
ic.class -> C:\Users\Joakim\AppData\Roaming\ic.class -> [2012-06-13 23:11:04 | 000,001,510 |——| M] ()
agy.class -> C:\Users\Joakim\AppData\Roaming\agy.class -> [2012-06-13 23:11:04 | 000,001,391 |——| M] ()
to.class -> C:\Users\Joakim\AppData\Roaming\to.class -> [2012-06-13 23:11:04 | 000,001,150 |——| M] ()
mod_MinecraftForge.class -> C:\Users\Joakim\AppData\Roaming\mod_MinecraftForge.class -> [2012-06-13 23:11:04 | 000,001,109 |——| M] ()
abw.class -> C:\Users\Joakim\AppData\Roaming\abw.class -> [2012-06-13 23:11:04 | 000,001,093 |——| M] ()
aia.class -> C:\Users\Joakim\AppData\Roaming\aia.class -> [2012-06-13 23:11:04 | 000,001,070 |——| M] ()
pl.class -> C:\Users\Joakim\AppData\Roaming\pl.class -> [2012-06-13 23:11:04 | 000,000,996 |——| M] ()
ms.class -> C:\Users\Joakim\AppData\Roaming\ms.class -> [2012-06-13 23:11:04 | 000,000,499 |——| M] ()
fmlversion.properties -> C:\Users\Joakim\AppData\Roaming\fmlversion.properties -> [2012-06-13 23:09:06 | 000,000,187 |——| M] ()
forge_logo.png -> C:\Users\Joakim\AppData\Roaming\forge_logo.png -> [2012-06-13 23:08:50 | 000,024,332 |——| M] ()
mod_MinecraftForge.info -> C:\Users\Joakim\AppData\Roaming\mod_MinecraftForge.info -> [2012-06-13 23:08:50 | 000,000,645 |——| M] ()
More+Nature+Mod+Installer.exe -> C:\Users\Joakim\Desktop\More+Nature+Mod+Installer.exe -> [2012-06-13 20:22:29 | 001,139,200 |——| M] ()

[Files - No Company Name]
Spybot-S&D Start Center.lnk -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk -> [2012-07-12 23:02:56 | 000,002,185 |——| C] ()
Spybot-S&D Start Center.lnk -> C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk -> [2012-07-12 23:02:56 | 000,002,173 |——| C] ()
ServiceConfig.xml -> C:\Windows\SysWow64\ServiceConfig.xml -> [2012-07-12 22:40:18 | 000,001,188 |——| C] ()
Ad-Aware Antivirus.lnk -> C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk -> [2012-07-12 21:04:56 | 000,001,868 |——| C] ()
spywarefri.PNG -> C:\Users\Joakim\Desktop\spywarefri.PNG -> [2012-07-12 20:32:38 | 000,317,857 |——| C] ()
includeitinfo.PNG -> C:\Users\Joakim\Desktop\includeitinfo.PNG -> [2012-07-12 20:32:14 | 000,024,259 |——| C] ()
GoogleUpdateTaskUserS-1-5-21-2361015560-1428424842-530145086-1000UA.job -> C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2361015560-1428424842-530145086-1000UA.job -> [2012-07-12 13:16:54 | 000,000,912 |——| C] ()
GoogleUpdateTaskUserS-1-5-21-2361015560-1428424842-530145086-1000Core.job -> C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2361015560-1428424842-530145086-1000Core.job -> [2012-07-12 13:16:52 | 000,000,860 |——| C] ()
LogMeIn Hamachi.lnk -> C:\Users\Public\Desktop\LogMeIn Hamachi.lnk -> [2012-07-10 12:24:30 | 000,000,926 |——| C] ()
IMG_0452.JPG -> C:\Users\Joakim\Desktop\IMG_0452.JPG -> [2012-07-10 10:21:55 | 000,074,572 |——| C] ()
2012-06-26_21.51.19 - Genvej.lnk -> C:\Users\Joakim\Desktop\2012-06-26_21.51.19 - Genvej.lnk -> [2012-06-26 21:52:08 | 000,001,159 |——| C] ()
2012-06-26_21.51.19.png -> C:\Users\Joakim\Desktop\2012-06-26_21.51.19.png -> [2012-06-26 21:51:19 | 000,011,864 |——| C] ()
Video call snapshot 5.png -> C:\Users\Joakim\Desktop\Video call snapshot 5.png -> [2012-06-25 16:19:37 | 000,322,277 |——| C] ()
Video call snapshot 1.png -> C:\Users\Joakim\Desktop\Video call snapshot 1.png -> [2012-06-25 16:19:34 | 000,240,527 |——| C] ()
Team Fortress 2.url -> C:\Users\Joakim\Desktop\Team Fortress 2.url -> [2012-06-21 15:30:34 | 000,000,219 |——| C] ()
adl (2).class -> C:\Users\Joakim\AppData\Roaming\adl (2).class -> [2012-06-19 19:36:36 | 000,022,590 |——| C] ()
ahu (2).class -> C:\Users\Joakim\AppData\Roaming\ahu (2).class -> [2012-06-19 19:36:36 | 000,006,409 |——| C] ()
ahg (2).class -> C:\Users\Joakim\AppData\Roaming\ahg (2).class -> [2012-06-19 19:36:36 | 000,004,745 |——| C] ()
EntityRendererProxy.class -> C:\Users\Joakim\AppData\Roaming\EntityRendererProxy.class -> [2012-06-19 19:36:36 | 000,000,589 |——| C] ()
CustomSpawner.java -> C:\Users\Joakim\AppData\Roaming\CustomSpawner.java -> [2012-06-19 19:36:31 | 000,055,467 |——| C] ()
CustomSpawner.class -> C:\Users\Joakim\AppData\Roaming\CustomSpawner.class -> [2012-06-19 19:36:31 | 000,017,530 |——| C] ()
mod_example.java -> C:\Users\Joakim\AppData\Roaming\mod_example.java -> [2012-06-19 19:36:31 | 000,005,436 |——| C] ()
vl.class -> C:\Users\Joakim\AppData\Roaming\vl.class -> [2012-06-19 19:36:14 | 000,088,615 |——| C] ()
xd.class -> C:\Users\Joakim\AppData\Roaming\xd.class -> [2012-06-19 19:36:14 | 000,061,001 |——| C] ()
l.class -> C:\Users\Joakim\AppData\Roaming\l.class -> [2012-06-19 19:36:14 | 000,038,381 |——| C] ()
pb.class -> C:\Users\Joakim\AppData\Roaming\pb.class -> [2012-06-19 19:36:14 | 000,034,563 |——| C] ()
lr.class -> C:\Users\Joakim\AppData\Roaming\lr.class -> [2012-06-19 19:36:14 | 000,028,626 |——| C] ()
yw.class -> C:\Users\Joakim\AppData\Roaming\yw.class -> [2012-06-19 19:36:14 | 000,028,243 |——| C] ()
nn.class -> C:\Users\Joakim\AppData\Roaming\nn.class -> [2012-06-19 19:36:14 | 000,026,541 |——| C] ()
forge_logo.png -> C:\Users\Joakim\AppData\Roaming\forge_logo.png -> [2012-06-19 19:36:14 | 000,024,332 |——| C] ()
ama.class -> C:\Users\Joakim\AppData\Roaming\ama.class -> [2012-06-19 19:36:14 | 000,023,125 |——| C] ()
yr.class -> C:\Users\Joakim\AppData\Roaming\yr.class -> [2012-06-19 19:36:14 | 000,021,616 |——| C] ()
aiy.class -> C:\Users\Joakim\AppData\Roaming\aiy.class -> [2012-06-19 19:36:14 | 000,017,075 |——| C] ()
ModLoader.class -> C:\Users\Joakim\AppData\Roaming\ModLoader.class -> [2012-06-19 19:36:14 | 000,015,378 |——| C] ()
mn.class -> C:\Users\Joakim\AppData\Roaming\mn.class -> [2012-06-19 19:36:14 | 000,013,742 |——| C] ()
we.class -> C:\Users\Joakim\AppData\Roaming\we.class -> [2012-06-19 19:36:14 | 000,011,446 |——| C] ()
fr.class -> C:\Users\Joakim\AppData\Roaming\fr.class -> [2012-06-19 19:36:14 | 000,010,608 |——| C] ()
ro.class -> C:\Users\Joakim\AppData\Roaming\ro.class -> [2012-06-19 19:36:14 | 000,010,527 |——| C] ()
aiv.class -> C:\Users\Joakim\AppData\Roaming\aiv.class -> [2012-06-19 19:36:14 | 000,009,504 |——| C] ()
xt.class -> C:\Users\Joakim\AppData\Roaming\xt.class -> [2012-06-19 19:36:14 | 000,008,789 |——| C] ()
tw.class -> C:\Users\Joakim\AppData\Roaming\tw.class -> [2012-06-19 19:36:14 | 000,008,695 |——| C] ()
sn.class -> C:\Users\Joakim\AppData\Roaming\sn.class -> [2012-06-19 19:36:14 | 000,008,622 |——| C] ()
ame.class -> C:\Users\Joakim\AppData\Roaming\ame.class -> [2012-06-19 19:36:14 | 000,008,055 |——| C] ()
BaseMod.class -> C:\Users\Joakim\AppData\Roaming\BaseMod.class -> [2012-06-19 19:36:14 | 000,007,778 |——| C] ()
vf.class -> C:\Users\Joakim\AppData\Roaming\vf.class -> [2012-06-19 19:36:14 | 000,007,548 |——| C] ()
cw.class -> C:\Users\Joakim\AppData\Roaming\cw.class -> [2012-06-19 19:36:14 | 000,007,479 |——| C] ()
rk.class -> C:\Users\Joakim\AppData\Roaming\rk.class -> [2012-06-19 19:36:14 | 000,007,238 |——| C] ()
lg.class -> C:\Users\Joakim\AppData\Roaming\lg.class -> [2012-06-19 19:36:14 | 000,007,066 |——| C] ()
alj.class -> C:\Users\Joakim\AppData\Roaming\alj.class -> [2012-06-19 19:36:14 | 000,006,779 |——| C] ()
sd.class -> C:\Users\Joakim\AppData\Roaming\sd.class -> [2012-06-19 19:36:14 | 000,006,723 |——| C] ()
uf.class -> C:\Users\Joakim\AppData\Roaming\uf.class -> [2012-06-19 19:36:14 | 000,006,451 |——| C] ()
ais.class -> C:\Users\Joakim\AppData\Roaming\ais.class -> [2012-06-19 19:36:14 | 000,006,378 |——| C] ()
ClientRegistry.class -> C:\Users\Joakim\AppData\Roaming\ClientRegistry.class -> [2012-06-19 19:36:14 | 000,006,359 |——| C] ()
pv.class -> C:\Users\Joakim\AppData\Roaming\pv.class -> [2012-06-19 19:36:14 | 000,006,337 |——| C] ()
uo.class -> C:\Users\Joakim\AppData\Roaming\uo.class -> [2012-06-19 19:36:14 | 000,006,271 |——| C] ()
cu.class -> C:\Users\Joakim\AppData\Roaming\cu.class -> [2012-06-19 19:36:14 | 000,006,040 |——| C] ()
qx.class -> C:\Users\Joakim\AppData\Roaming\qx.class -> [2012-06-19 19:36:14 | 000,005,809 |——| C] ()
ko.class -> C:\Users\Joakim\AppData\Roaming\ko.class -> [2012-06-19 19:36:14 | 000,005,702 |——| C] ()
ct.class -> C:\Users\Joakim\AppData\Roaming\ct.class -> [2012-06-19 19:36:14 | 000,005,647 |——| C] ()
km.class -> C:\Users\Joakim\AppData\Roaming\km.class -> [2012-06-19 19:36:14 | 000,005,424 |——| C] ()
os.class -> C:\Users\Joakim\AppData\Roaming\os.class -> [2012-06-19 19:36:14 | 000,005,408 |——| C] ()
amc.class -> C:\Users\Joakim\AppData\Roaming\amc.class -> [2012-06-19 19:36:14 | 000,005,241 |——| C] ()
uu.class -> C:\Users\Joakim\AppData\Roaming\uu.class -> [2012-06-19 19:36:14 | 000,005,101 |——| C] ()
kw.class -> C:\Users\Joakim\AppData\Roaming\kw.class -> [2012-06-19 19:36:14 | 000,004,823 |——| C] ()
alk.class -> C:\Users\Joakim\AppData\Roaming\alk.class -> [2012-06-19 19:36:14 | 000,004,709 |——| C] ()
fq.class -> C:\Users\Joakim\AppData\Roaming\fq.class -> [2012-06-19 19:36:14 | 000,004,519 |——| C] ()
ul.class -> C:\Users\Joakim\AppData\Roaming\ul.class -> [2012-06-19 19:36:14 | 000,004,466 |——| C] ()
ModTextureStatic.class -> C:\Users\Joakim\AppData\Roaming\ModTextureStatic.class -> [2012-06-19 19:36:14 | 000,004,435 |——| C] ()
kt.class -> C:\Users\Joakim\AppData\Roaming\kt.class -> [2012-06-19 19:36:14 | 000,004,346 |——| C] ()
pt.class -> C:\Users\Joakim\AppData\Roaming\pt.class -> [2012-06-19 19:36:14 | 000,004,240 |——| C] ()
gi.class -> C:\Users\Joakim\AppData\Roaming\gi.class -> [2012-06-19 19:36:14 | 000,004,183 |——| C] ()
vx.class -> C:\Users\Joakim\AppData\Roaming\vx.class -> [2012-06-19 19:36:14 | 000,004,086 |——| C] ()
ht.class -> C:\Users\Joakim\AppData\Roaming\ht.class -> [2012-06-19 19:36:14 | 000,004,056 |——| C] ()
hm.class -> C:\Users\Joakim\AppData\Roaming\hm.class -> [2012-06-19 19:36:14 | 000,003,956 |——| C] ()
ajd.class -> C:\Users\Joakim\AppData\Roaming\ajd.class -> [2012-06-19 19:36:14 | 000,003,907 |——| C] ()
dq.class -> C:\Users\Joakim\AppData\Roaming\dq.class -> [2012-06-19 19:36:14 | 000,003,894 |——| C] ()
tu.class -> C:\Users\Joakim\AppData\Roaming\tu.class -> [2012-06-19 19:36:14 | 000,003,854 |——| C] ()
alb.class -> C:\Users\Joakim\AppData\Roaming\alb.class -> [2012-06-19 19:36:14 | 000,003,743 |——| C] ()
ki.class -> C:\Users\Joakim\AppData\Roaming\ki.class -> [2012-06-19 19:36:14 | 000,003,705 |——| C] ()
sb.class -> C:\Users\Joakim\AppData\Roaming\sb.class -> [2012-06-19 19:36:14 | 000,003,638 |——| C] ()
jx.class -> C:\Users\Joakim\AppData\Roaming\jx.class -> [2012-06-19 19:36:14 | 000,003,553 |——| C] ()
jt.class -> C:\Users\Joakim\AppData\Roaming\jt.class -> [2012-06-19 19:36:14 | 000,003,492 |——| C] ()
bh.class -> C:\Users\Joakim\AppData\Roaming\bh.class -> [2012-06-19 19:36:14 | 000,003,398 |——| C] ()
ModTextureAnimation.class -> C:\Users\Joakim\AppData\Roaming\ModTextureAnimation.class -> [2012-06-19 19:36:14 | 000,003,341 |——| C] ()
bf.class -> C:\Users\Joakim\AppData\Roaming\bf.class -> [2012-06-19 19:36:14 | 000,003,232 |——| C] ()
qm.class -> C:\Users\Joakim\AppData\Roaming\qm.class -> [2012-06-19 19:36:14 | 000,002,954 |——| C] ()
ha.class -> C:\Users\Joakim\AppData\Roaming\ha.class -> [2012-06-19 19:36:14 | 000,002,938 |——| C] ()
my.class -> C:\Users\Joakim\AppData\Roaming\my.class -> [2012-06-19 19:36:14 | 000,002,889 |——| C] ()
bb.class -> C:\Users\Joakim\AppData\Roaming\bb.class -> [2012-06-19 19:36:14 | 000,002,824 |——| C] ()
amn.class -> C:\Users\Joakim\AppData\Roaming\amn.class -> [2012-06-19 19:36:14 | 000,002,802 |——| C] ()
tg.class -> C:\Users\Joakim\AppData\Roaming\tg.class -> [2012-06-19 19:36:14 | 000,002,720 |——| C] ()
zo.class -> C:\Users\Joakim\AppData\Roaming\zo.class -> [2012-06-19 19:36:14 | 000,002,694 |——| C] ()
rr.class -> C:\Users\Joakim\AppData\Roaming\rr.class -> [2012-06-19 19:36:14 | 000,002,647 |——| C] ()
dy.class -> C:\Users\Joakim\AppData\Roaming\dy.class -> [2012-06-19 19:36:14 | 000,002,619 |——| C] ()
FMLRenderAccessLibrary.class -> C:\Users\Joakim\AppData\Roaming\FMLRenderAccessLibrary.class -> [2012-06-19 19:36:14 | 000,002,602 |——| C] ()
ug.class -> C:\Users\Joakim\AppData\Roaming\ug.class -> [2012-06-19 19:36:14 | 000,002,559 |——| C] ()
lo.class -> C:\Users\Joakim\AppData\Roaming\lo.class -> [2012-06-19 19:36:14 | 000,002,554 |——| C] ()
mm.class -> C:\Users\Joakim\AppData\Roaming\mm.class -> [2012-06-19 19:36:14 | 000,002,531 |——| C] ()
rb.class -> C:\Users\Joakim\AppData\Roaming\rb.class -> [2012-06-19 19:36:14 | 000,002,520 |——| C] ()
cx.class -> C:\Users\Joakim\AppData\Roaming\cx.class -> [2012-06-19 19:36:14 | 000,002,492 |——| C] ()
of.class -> C:\Users\Joakim\AppData\Roaming\of.class -> [2012-06-19 19:36:14 | 000,002,442 |——| C] ()
gf.class -> C:\Users\Joakim\AppData\Roaming\gf.class -> [2012-06-19 19:36:14 | 000,002,395 |——| C] ()
ii.class -> C:\Users\Joakim\AppData\Roaming\ii.class -> [2012-06-19 19:36:14 | 000,002,369 |——| C] ()
fv.class -> C:\Users\Joakim\AppData\Roaming\fv.class -> [2012-06-19 19:36:14 | 000,002,283 |——| C] ()
zp.class -> C:\Users\Joakim\AppData\Roaming\zp.class -> [2012-06-19 19:36:14 | 000,002,282 |——| C] ()
i.class -> C:\Users\Joakim\AppData\Roaming\i.class -> [2012-06-19 19:36:14 | 000,002,267 |——| C] ()
eh.class -> C:\Users\Joakim\AppData\Roaming\eh.class -> [2012-06-19 19:36:14 | 000,002,262 |——| C] ()
bv.class -> C:\Users\Joakim\AppData\Roaming\bv.class -> [2012-06-19 19:36:14 | 000,002,193 |——| C] ()
nh.class -> C:\Users\Joakim\AppData\Roaming\nh.class -> [2012-06-19 19:36:14 | 000,002,178 |——| C] ()
oz.class -> C:\Users\Joakim\AppData\Roaming\oz.class -> [2012-06-19 19:36:14 | 000,002,142 |——| C] ()
qa.class -> C:\Users\Joakim\AppData\Roaming\qa.class -> [2012-06-19 19:36:14 | 000,002,078 |——| C] ()
pp.class -> C:\Users\Joakim\AppData\Roaming\pp.class -> [2012-06-19 19:36:14 | 000,001,938 |——| C] ()
akf.class -> C:\Users\Joakim\AppData\Roaming\akf.class -> [2012-06-19 19:36:14 | 000,001,881 |——| C] ()
da.class -> C:\Users\Joakim\AppData\Roaming\da.class -> [2012-06-19 19:36:14 | 000,001,794 |——| C] ()
ajv.class -> C:\Users\Joakim\AppData\Roaming\ajv.class -> [2012-06-19 19:36:14 | 000,001,618 |——| C] ()
ic.class -> C:\Users\Joakim\AppData\Roaming\ic.class -> [2012-06-19 19:36:14 | 000,001,510 |——| C] ()
to.class -> C:\Users\Joakim\AppData\Roaming\to.class -> [2012-06-19 19:36:14 | 000,001,150 |——| C] ()
mod_MinecraftForge.class -> C:\Users\Joakim\AppData\Roaming\mod_MinecraftForge.class -> [2012-06-19 19:36:14 | 000,001,109 |——| C] ()
aia.class -> C:\Users\Joakim\AppData\Roaming\aia.class -> [2012-06-19 19:36:14 | 000,001,070 |——| C] ()
pl.class -> C:\Users\Joakim\AppData\Roaming\pl.class -> [2012-06-19 19:36:14 | 000,000,996 |——| C] ()
mod_MinecraftForge.info -> C:\Users\Joakim\AppData\Roaming\mod_MinecraftForge.info -> [2012-06-19 19:36:14 | 000,000,645 |——| C] ()
MLProp.class -> C:\Users\Joakim\AppData\Roaming\MLProp.class -> [2012-06-19 19:36:14 | 000,000,536 |——| C] ()
SidedProxy.class -> C:\Users\Joakim\AppData\Roaming\SidedProxy.class -> [2012-06-19 19:36:14 | 000,000,516 |——| C] ()
ms.class -> C:\Users\Joakim\AppData\Roaming\ms.class -> [2012-06-19 19:36:14 | 000,000,499 |——| C] ()
fmlversion.properties -> C:\Users\Joakim\AppData\Roaming\fmlversion.properties -> [2012-06-19 19:36:14 | 000,000,187 |——| C] ()
acq.class -> C:\Users\Joakim\AppData\Roaming\acq.class -> [2012-06-19 19:36:13 | 000,030,583 |——| C] ()
adl.class -> C:\Users\Joakim\AppData\Roaming\adl.class -> [2012-06-19 19:36:13 | 000,028,779 |——| C] ()
ack.class -> C:\Users\Joakim\AppData\Roaming\ack.class -> [2012-06-19 19:36:13 | 000,020,614 |——| C] ()
aaw.class -> C:\Users\Joakim\AppData\Roaming\aaw.class -> [2012-06-19 19:36:13 | 000,013,815 |——| C] ()
ahi.class -> C:\Users\Joakim\AppData\Roaming\ahi.class -> [2012-06-19 19:36:13 | 000,008,154 |——| C] ()
abc.class -> C:\Users\Joakim\AppData\Roaming\abc.class -> [2012-06-19 19:36:13 | 000,008,109 |——| C] ()
adz.class -> C:\Users\Joakim\AppData\Roaming\adz.class -> [2012-06-19 19:36:13 | 000,007,907 |——| C] ()
ahu.class -> C:\Users\Joakim\AppData\Roaming\ahu.class -> [2012-06-19 19:36:13 | 000,006,991 |——| C] ()
aem.class -> C:\Users\Joakim\AppData\Roaming\aem.class -> [2012-06-19 19:36:13 | 000,006,697 |——| C] ()
aao.class -> C:\Users\Joakim\AppData\Roaming\aao.class -> [2012-06-19 19:36:13 | 000,005,953 |——| C] ()
aez.class -> C:\Users\Joakim\AppData\Roaming\aez.class -> [2012-06-19 19:36:13 | 000,005,875 |——| C] ()
acb.class -> C:\Users\Joakim\AppData\Roaming\acb.class -> [2012-06-19 19:36:13 | 000,005,722 |——| C] ()
ahg.class -> C:\Users\Joakim\AppData\Roaming\ahg.class -> [2012-06-19 19:36:13 | 000,005,448 |——| C] ()
agh.class -> C:\Users\Joakim\AppData\Roaming\agh.class -> [2012-06-19 19:36:13 | 000,005,413 |——| C] ()
adn.class -> C:\Users\Joakim\AppData\Roaming\adn.class -> [2012-06-19 19:36:13 | 000,004,464 |——| C] ()
aes.class -> C:\Users\Joakim\AppData\Roaming\aes.class -> [2012-06-19 19:36:13 | 000,004,347 |——| C] ()
ach.class -> C:\Users\Joakim\AppData\Roaming\ach.class -> [2012-06-19 19:36:13 | 000,004,161 |——| C] ()
aff.class -> C:\Users\Joakim\AppData\Roaming\aff.class -> [2012-06-19 19:36:13 | 000,003,260 |——| C] ()
ael.class -> C:\Users\Joakim\AppData\Roaming\ael.class -> [2012-06-19 19:36:13 | 000,002,153 |——| C] ()
afm.class -> C:\Users\Joakim\AppData\Roaming\afm.class -> [2012-06-19 19:36:13 | 000,002,135 |——| C] ()
agm.class -> C:\Users\Joakim\AppData\Roaming\agm.class -> [2012-06-19 19:36:13 | 000,001,542 |——| C] ()
agy.class -> C:\Users\Joakim\AppData\Roaming\agy.class -> [2012-06-19 19:36:13 | 000,001,391 |——| C] ()
ahy.class -> C:\Users\Joakim\AppData\Roaming\ahy.class -> [2012-06-19 19:36:13 | 000,001,134 |——| C] ()
abw.class -> C:\Users\Joakim\AppData\Roaming\abw.class -> [2012-06-19 19:36:13 | 000,001,093 |——| C] ()
twlGuiTheme.xml -> C:\Users\Joakim\AppData\Roaming\twlGuiTheme.xml -> [2012-06-19 19:35:22 | 000,013,480 |——| C] ()
SettingList.class -> C:\Users\Joakim\AppData\Roaming\SettingList.class -> [2012-06-19 19:35:22 | 000,005,565 |——| C] ()
WidgetItem2DRender.class -> C:\Users\Joakim\AppData\Roaming\WidgetItem2DRender.class -> [2012-06-19 19:35:22 | 000,004,275 |——| C] ()
WidgetList.class -> C:\Users\Joakim\AppData\Roaming\WidgetList.class -> [2012-06-19 19:35:22 | 000,003,880 |——| C] ()
WidgetClassicTwocolumn.class -> C:\Users\Joakim\AppData\Roaming\WidgetClassicTwocolumn.class -> [2012-06-19 19:35:22 | 000,003,760 |——| C] ()
SettingMulti.class -> C:\Users\Joakim\AppData\Roaming\SettingMulti.class -> [2012-06-19 19:35:22 | 000,003,434 |——| C] ()
WidgetSimplewindow.class -> C:\Users\Joakim\AppData\Roaming\WidgetSimplewindow.class -> [2012-06-19 19:35:22 | 000,003,413 |——| C] ()
WidgetText.class -> C:\Users\Joakim\AppData\Roaming\WidgetText.class -> [2012-06-19 19:35:22 | 000,003,352 |——| C] ()
SettingDictionary.class -> C:\Users\Joakim\AppData\Roaming\SettingDictionary.class -> [2012-06-19 19:35:22 | 000,003,121 |——| C] ()
WidgetFloat.class -> C:\Users\Joakim\AppData\Roaming\WidgetFloat.class -> [2012-06-19 19:35:22 | 000,003,024 |——| C] ()
SettingInt.class -> C:\Users\Joakim\AppData\Roaming\SettingInt.class -> [2012-06-19 19:35:22 | 000,003,010 |——| C] ()
WidgetTick.class -> C:\Users\Joakim\AppData\Roaming\WidgetTick.class -> [2012-06-19 19:35:22 | 000,002,959 |——| C] ()
WidgetKeybinding.class -> C:\Users\Joakim\AppData\Roaming\WidgetKeybinding.class -> [2012-06-19 19:35:22 | 000,002,944 |——| C] ()
WidgetSingleRow.class -> C:\Users\Joakim\AppData\Roaming\WidgetSingleRow.class -> [2012-06-19 19:35:22 | 000,002,933 |——| C] ()
WidgetInt.class -> C:\Users\Joakim\AppData\Roaming\WidgetInt.class -> [2012-06-19 19:35:22 | 000,002,916 |——| C] ()
SettingFloat.class -> C:\Users\Joakim\AppData\Roaming\SettingFloat.class -> [2012-06-19 19:35:22 | 000,002,912 |——| C] ()
WidgetBoolean.class -> C:\Users\Joakim\AppData\Roaming\WidgetBoolean.class -> [2012-06-19 19:35:22 | 000,002,906 |——| C] ()
SettingKey.class -> C:\Users\Joakim\AppData\Roaming\SettingKey.class -> [2012-06-19 19:35:22 | 000,002,743 |——| C] ()
WidgetMulti.class -> C:\Users\Joakim\AppData\Roaming\WidgetMulti.class -> [2012-06-19 19:35:22 | 000,002,342 |——| C] ()
WidgetSinglecolumn.class -> C:\Users\Joakim\AppData\Roaming\WidgetSinglecolumn.class -> [2012-06-19 19:35:22 | 000,002,334 |——| C] ()
SettingBoolean.class -> C:\Users\Joakim\AppData\Roaming\SettingBoolean.class -> [2012-06-19 19:35:22 | 000,002,186 |——| C] ()
WidgetSetting.class -> C:\Users\Joakim\AppData\Roaming\WidgetSetting.class -> [2012-06-19 19:35:22 | 000,001,891 |——| C] ()
SettingText.class -> C:\Users\Joakim\AppData\Roaming\SettingText.class -> [2012-06-19 19:35:22 | 000,001,738 |——| C] ()
WidgetTick$SingleTick.class -> C:\Users\Joakim\AppData\Roaming\WidgetTick$SingleTick.class -> [2012-06-19 19:35:22 | 000,001,632 |——| C] ()
Setting.class -> C:\Users\Joakim\AppData\Roaming\Setting.class -> [2012-06-19 19:35:22 | 000,001,557 |——| C] ()
WidgetTick$FrameTick.class -> C:\Users\Joakim\AppData\Roaming\WidgetTick$FrameTick.class -> [2012-06-19 19:35:22 | 000,001,373 |——| C] ()
WidgetTick$DelayTick.class -> C:\Users\Joakim\AppData\Roaming\WidgetTick$DelayTick.class -> [2012-06-19 19:35:22 | 000,001,335 |——| C] ()
twlGuiThemeIndentedbuttons.png -> C:\Users\Joakim\AppData\Roaming\twlGuiThemeIndentedbuttons.png -> [2012-06-19 19:35:22 | 000,001,222 |——| C] ()
scrollwindow.png -> C:\Users\Joakim\AppData\Roaming\scrollwindow.png -> [2012-06-19 19:35:22 | 000,000,708 |——| C] ()
WidgetSlider.class -> C:\Users\Joakim\AppData\Roaming\WidgetSlider.class -> [2012-06-19 19:35:22 | 000,000,498 |——| C] ()
WidgetTick$iTick.class -> C:\Users\Joakim\AppData\Roaming\WidgetTick$iTick.class -> [2012-06-19 19:35:22 | 000,000,225 |——| C] ()
ModSettings.class -> C:\Users\Joakim\AppData\Roaming\ModSettings.class -> [2012-06-19 19:35:21 | 000,019,611 |——| C] ()
font.fnt -> C:\Users\Joakim\AppData\Roaming\font.fnt -> [2012-06-19 19:35:21 | 000,011,144 |——| C] ()
GuiApiHelper.class -> C:\Users\Joakim\AppData\Roaming\GuiApiHelper.class -> [2012-06-19 19:35:21 | 000,007,659 |——| C] ()
ModAction.class -> C:\Users\Joakim\AppData\Roaming\ModAction.class -> [2012-06-19 19:35:21 | 000,007,626 |——| C] ()
font_00.png -> C:\Users\Joakim\AppData\Roaming\font_00.png -> [2012-06-19 19:35:21 | 000,006,904 |——| C] ()
GuiApiFontHelper.class -> C:\Users\Joakim\AppData\Roaming\GuiApiFontHelper.class -> [2012-06-19 19:35:21 | 000,005,724 |——| C] ()
GuiWidgetScreen.class -> C:\Users\Joakim\AppData\Roaming\GuiWidgetScreen.class -> [2012-06-19 19:35:21 | 000,004,191 |——| C] ()
GuiModScreen.class -> C:\Users\Joakim\AppData\Roaming\GuiModScreen.class -> [2012-06-19 19:35:21 | 000,002,587 |——| C] ()
ModSettingScreen.class -> C:\Users\Joakim\AppData\Roaming\ModSettingScreen.class -> [2012-06-19 19:35:21 | 000,002,488 |——| C] ()
GuiModSelect.class -> C:\Users\Joakim\AppData\Roaming\GuiModSelect.class -> [2012-06-19 19:35:21 | 000,001,949 |——| C] ()
GuiApiFontHelper$FontStates.class -> C:\Users\Joakim\AppData\Roaming\GuiApiFontHelper$FontStates.class -> [2012-06-19 19:35:21 | 000,001,197 |——| C] ()
cd.class -> C:\Users\Joakim\AppData\Roaming\cd.class -> [2012-06-19 19:35:20 | 000,003,641 |——| C] ()
Sunken Island Adventure (1.2.5).zip -> C:\Users\Joakim\Desktop\Sunken Island Adventure (1.2.5).zip -> [2012-06-19 15:49:20 | 002,631,617 |——| C] ()
ModLoader.zip -> C:\Users\Joakim\Desktop\ModLoader.zip -> [2012-06-17 11:39:36 | 000,103,347 |——| C] ()
CustomMobSpawner 1.4.3.zip -> C:\Users\Joakim\Desktop\CustomMobSpawner 1.4.3.zip -> [2012-06-17 11:38:56 | 000,019,895 |——| C] ()
GuiAPI-0.14.2-1.2.5.zip -> C:\Users\Joakim\Desktop\GuiAPI-0.14.2-1.2.5.zip -> [2012-06-17 11:37:56 | 001,063,661 |——| C] ()
MinecraftForge-3.3.7.135-Client.zip -> C:\Users\Joakim\Desktop\MinecraftForge-3.3.7.135-Client.zip -> [2012-06-17 11:37:14 | 000,807,734 |——| C] ()
DrZharks MoCreatures Mod v3.6.2.zip -> C:\Users\Joakim\Desktop\DrZharks MoCreatures Mod v3.6.2.zip -> [2012-06-17 11:34:54 | 005,070,386 |——| C] ()
SinglePlayerCommands-MC1.2.5_V3.2.2.jar -> C:\Users\Joakim\Desktop\SinglePlayerCommands-MC1.2.5_V3.2.2.jar -> [2012-06-17 08:40:10 | 000,999,771 |——| C] ()
fun face.png -> C:\Users\Joakim\Desktop\fun face.png -> [2012-06-15 22:06:00 | 000,452,440 |——| C] ()
Tornadoes Mod Installer.exe -> C:\Users\Joakim\Desktop\Tornadoes Mod Installer.exe -> [2012-06-14 15:16:55 | 001,150,464 |——| C] ()
More+Nature+Mod+Installer.exe -> C:\Users\Joakim\Desktop\More+Nature+Mod+Installer.exe -> [2012-06-13 20:22:36 | 001,139,200 |——| C] ()
WININIT.INI -> C:\Windows\WININIT.INI -> [2012-06-10 14:58:46 | 000,000,048 |——| C] ()
ativpsrm.bin -> C:\Windows\ativpsrm.bin -> [2012-02-23 12:39:36 | 000,000,000 |——| C] ()
bdmjpeg.dll -> C:\Windows\SysWow64\bdmjpeg.dll -> [2011-09-19 09:07:46 | 000,015,360 |——| C] ()
bdmpegv.dll -> C:\Windows\SysWow64\bdmpegv.dll -> [2011-09-19 09:07:32 | 000,058,368 |——| C] ()

[File - Lop Check]
.minecraft -> C:\Users\Joakim\AppData\Roaming\.minecraft -> [2012-07-12 13:11:48 | 000,000,000 |—-D | M]
.Nitrous -> C:\Users\Joakim\AppData\Roaming\.Nitrous -> [2012-06-12 14:12:07 | 000,000,000 |—-D | M]
Ad-Aware Antivirus -> C:\Users\Joakim\AppData\Roaming\Ad-Aware Antivirus -> [2012-07-12 21:06:43 | 000,000,000 |—-D | M]
BANDISOFT -> C:\Users\Joakim\AppData\Roaming\BANDISOFT -> [2012-06-11 22:13:09 | 000,000,000 |—-D | M]
cpw -> C:\Users\Joakim\AppData\Roaming\cpw -> [2012-06-19 19:36:14 | 000,000,000 |—-D | M]
de -> C:\Users\Joakim\AppData\Roaming\de -> [2012-03-28 01:20:27 | 000,000,000 |—-D | M]
forge -> C:\Users\Joakim\AppData\Roaming\forge -> [2012-06-19 19:36:14 | 000,000,000 |—-D | M]
ibxm -> C:\Users\Joakim\AppData\Roaming\ibxm -> [2012-06-19 19:36:14 | 000,000,000 |—-D | M]
javax -> C:\Users\Joakim\AppData\Roaming\javax -> [2011-11-25 07:40:51 | 000,000,000 |—-D | M]
LolClient -> C:\Users\Joakim\AppData\Roaming\LolClient -> [2012-05-05 13:12:15 | 000,000,000 |—-D | M]
LolClient2 -> C:\Users\Joakim\AppData\Roaming\LolClient2 -> [2012-06-19 19:35:44 | 000,000,000 |—-D | M]
net -> C:\Users\Joakim\AppData\Roaming\net -> [2012-06-19 19:36:14 | 000,000,000 |—-D | M]
org -> C:\Users\Joakim\AppData\Roaming\org -> [2011-11-25 07:40:51 | 000,000,000 |—-D | M]
paulscode -> C:\Users\Joakim\AppData\Roaming\paulscode -> [2012-06-19 19:36:14 | 000,000,000 |—-D | M]
skyz -> C:\Users\Joakim\AppData\Roaming\skyz -> [2012-06-17 11:21:07 | 000,000,000 |—-D | M]
SPORE -> C:\Users\Joakim\AppData\Roaming\SPORE -> [2012-04-26 16:18:47 | 000,000,000 |—-D | M]
xml-pull -> C:\Users\Joakim\AppData\Roaming\xml-pull -> [2011-11-25 07:40:52 | 000,000,000 |—-D | M]
SCHEDLGU.TXT -> C:\Windows\Tasks\SCHEDLGU.TXT -> [2012-05-08 15:57:36 | 000,032,596 |——| M] ()

[File - Purity Scan]

< End of report >

  FieFyn
Antal indlæg: 16

Arrghh er det ok jeg lægger et link til et google dokument? Jeg magter åbenbart ikke at dele den logfil korrekt.

https://docs.google.com/document/d/1rlQZVoTujE3Hz7BxL4srQ8mwR66TckEJVyQOXg2VBrQ/edit

Administrator
Avatar
Antal indlæg: 32078

Du har to aktive antivirus programmer kørende, det er ikke nogen god idé da de vil konflikte.


Afinstaller enten:

Ad-Aware Antivirus

eller

Avast.

Genstart.


Hent Combofix, og gem den på dit skrivebord:
Her

NB -> Deaktiver dit antivirus/antispyware program. Da det/de kan ”forstyrre” og konflikte med combofix, eller fjerne vigtige combofix filer, hvilket kan få computeren til fryse.


Kør så combofix.exe, og følg anvisningerne.


Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.

Når combofix er færdig, og efter det (muligvis) har genstartet, skulle der gerne åbnes en logfil: combofix.txt
Indholdet af denne fil må du gerne lægge herind.

Den kan også findes her - > C: combofix txt

Signatur

Sund Computer fornuft

  FieFyn
Antal indlæg: 16

ComboFix 12-07-13.01 - Joakim 13-07-2012 15:04:35.1.2 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.45.1030.18.4061.2689 [GMT 2:00]
Kører fra: c:\users\Joakim\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Spybot - Search and Destroy *Disabled/Updated* {1EAF1D03-5480-F3B2-EB14-11F0F5EE2699}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\prefs.js
c:\users\Joakim\AppData\Roaming\Microsoft\Windows\Recent\Call of Duty Modern Warfare 3.url
c:\users\Joakim\Desktop\Setup.exe
c:\windows\security\Database\tmp.edb
.
.
(((((((((((((((((((((((((((((  Filer skabt fra 2012-06-13 til 2012-07-13 )))))))))))))))))))))))))))))))))))
.
.
2012-07-13 13:09 . 2012-07-13 13:09   ————  d——-w-  c:\users\Default\AppData\Local\temp
2012-07-13 12:55 . 2012-07-13 12:55   ————  d——-w-  c:\programdata\GFI Software
2012-07-12 21:03 . 2012-07-12 21:36   ————  d——-w-  c:\programdata\Spybot - Search & Destroy
2012-07-12 21:02 . 2009-01-25 11:14   17272   ——a-w-  c:\windows\system32\sdnclean64.exe
2012-07-12 21:02 . 2012-07-12 21:03   ————  d——-w-  c:\program files (x86)\Spybot - Search & Destroy 2
2012-07-12 19:05 . 2012-07-12 19:05   ————  d——-w-  c:\users\Joakim\AppData\Local\adaware
2012-07-12 19:04 . 2012-07-12 19:04   ————  d——-w-  c:\programdata\Lavasoft
2012-07-12 19:04 . 2012-07-13 12:56   ————  d——-w-  c:\program files (x86)\Ad-Aware Antivirus
2012-07-12 19:04 . 2012-07-13 12:18   ————  d——-w-  c:\programdata\Ad-Aware Browsing Protection
2012-07-12 19:03 . 2012-07-13 12:54   ————  d——-w-  c:\users\Joakim\AppData\Roaming\Ad-Aware Antivirus
2012-07-12 18:36 . 2012-07-12 18:36   ————  d—h—w-  c:\windows\AxInstSV
2012-07-12 11:11 . 2012-07-12 11:11   ————  d——-w-  c:\users\Joakim\AppData\Roaming\.minecraft
2012-07-11 12:25 . 2012-06-12 03:08   3148800   ——a-w-  c:\windows\system32\win32k.sys
2012-07-11 10:43 . 2012-06-06 06:05   1499136   ——a-w-  c:\program files\Common Files\System\ado\msado15.dll
2012-07-11 10:43 . 2012-06-06 05:05   1019904   ——a-w-  c:\program files (x86)\Common Files\System\ado\msado15.dll
2012-07-11 10:43 . 2012-06-06 06:05   466944   ——a-w-  c:\program files\Common Files\System\ado\msadomd.dll
2012-07-11 10:43 . 2012-06-06 06:05   495616   ——a-w-  c:\program files\Common Files\System\ado\msadox.dll
2012-07-11 10:43 . 2012-06-06 06:05   258048   ——a-w-  c:\program files\Common Files\System\msadc\msadco.dll
2012-07-11 10:43 . 2012-06-06 05:03   805376   ——a-w-  c:\windows\SysWow64\cdosys.dll
2012-07-11 10:43 . 2012-06-06 05:05   352256   ——a-w-  c:\program files (x86)\Common Files\System\ado\msadomd.dll
2012-07-11 10:43 . 2012-06-06 06:05   61440   ——a-w-  c:\program files\Common Files\System\ado\msador15.dll
2012-07-11 10:43 . 2012-06-06 05:05   57344   ——a-w-  c:\program files (x86)\Common Files\System\ado\msador15.dll
2012-07-11 10:43 . 2012-06-06 05:05   212992   ——a-w-  c:\program files (x86)\Common Files\System\msadc\msadco.dll
2012-07-11 10:43 . 2012-06-06 05:05   143360   ——a-w-  c:\program files (x86)\Common Files\System\ado\msjro.dll
2012-07-11 10:43 . 2012-06-06 05:05   372736   ——a-w-  c:\program files (x86)\Common Files\System\ado\msadox.dll
2012-07-11 10:43 . 2012-06-06 06:02   1133568   ——a-w-  c:\windows\system32\cdosys.dll
2012-07-10 12:34 . 2012-05-31 04:04   9013136   ——a-w-  c:\programdata\Microsoft\Windows Defender\Definition Updates\{32CED3F9-657B-47B0-96A1-8A7FEB41AAAA}\mpengine.dll
2012-07-10 10:24 . 2009-03-18 15:35   33856   —-ha-w-  c:\windows\system32\hamachi.sys
2012-07-10 10:24 . 2012-07-10 10:24   ————  d——-w-  c:\program files (x86)\LogMeIn Hamachi
2012-06-23 09:45 . 2012-06-02 22:19   2428952   ——a-w-  c:\windows\system32\wuaueng.dll
2012-06-23 09:45 . 2012-06-02 22:19   57880   ——a-w-  c:\windows\system32\wuauclt.exe
2012-06-23 09:45 . 2012-06-02 22:19   44056   ——a-w-  c:\windows\system32\wups2.dll
2012-06-23 09:45 . 2012-06-02 22:15   2622464   ——a-w-  c:\windows\system32\wucltux.dll
2012-06-23 09:45 . 2012-06-02 22:19   38424   ——a-w-  c:\windows\system32\wups.dll
2012-06-23 09:45 . 2012-06-02 22:19   701976   ——a-w-  c:\windows\system32\wuapi.dll
2012-06-23 09:45 . 2012-06-02 22:15   99840   ——a-w-  c:\windows\system32\wudriver.dll
2012-06-23 09:45 . 2012-06-02 13:19   186752   ——a-w-  c:\windows\system32\wuwebv.dll
2012-06-23 09:45 . 2012-06-02 13:15   36864   ——a-w-  c:\windows\system32\wuapp.exe
2012-06-19 17:36 . 2012-06-19 17:36   ————  d——-w-  c:\users\Joakim\AppData\Roaming\paulscode
2012-06-19 17:36 . 2012-06-19 17:36   ————  d——-w-  c:\users\Joakim\AppData\Roaming\net
2012-06-19 17:36 . 2012-06-19 17:36   ————  d——-w-  c:\users\Joakim\AppData\Roaming\ibxm
2012-06-19 17:36 . 2012-06-19 17:36   ————  d——-w-  c:\users\Joakim\AppData\Roaming\forge
2012-06-19 17:36 . 2012-06-19 17:36   ————  d——-w-  c:\users\Joakim\AppData\Roaming\cpw
2012-06-19 17:35 . 2011-11-25 05:40   ————  d——-w-  c:\users\Joakim\AppData\Roaming\xml-pull
2012-06-19 17:35 . 2011-11-25 05:40   ————  d——-w-  c:\users\Joakim\AppData\Roaming\org
2012-06-19 17:35 . 2011-11-25 05:40   ————  d——-w-  c:\users\Joakim\AppData\Roaming\javax
2012-06-19 17:35 . 2012-03-27 23:20   ————  d——-w-  c:\users\Joakim\AppData\Roaming\de
2012-06-17 09:21 . 2012-06-17 09:21   ————  d——-w-  c:\users\Joakim\AppData\Roaming\skyz
2012-06-14 12:44 . 2012-04-26 05:41   77312   ——a-w-  c:\windows\system32\rdpwsx.dll
2012-06-14 12:44 . 2012-04-26 05:41   149504   ——a-w-  c:\windows\system32\rdpcorekmts.dll
2012-06-14 12:44 . 2012-04-26 05:34   9216   ——a-w-  c:\windows\system32\rdrmemptylst.exe
.
.
.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-12 11:25 . 2012-04-16 15:31   426184   ——a-w-  c:\windows\SysWow64\FlashPlayerApp.exe
2012-07-12 11:25 . 2012-02-23 12:22   70344   ——a-w-  c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-03 16:21 . 2012-04-21 09:18   54072   ——a-w-  c:\windows\system32\drivers\aswRdr2.sys
2012-07-03 16:21 . 2012-02-23 16:24   355856   ——a-w-  c:\windows\system32\drivers\aswSP.sys
2012-07-03 16:21 . 2012-02-23 16:24   958400   ——a-w-  c:\windows\system32\drivers\aswSnx.sys
2012-07-03 16:21 . 2012-02-23 16:24   59728   ——a-w-  c:\windows\system32\drivers\aswTdi.sys
2012-07-03 16:21 . 2012-02-23 16:24   71064   ——a-w-  c:\windows\system32\drivers\aswMonFlt.sys
2012-07-03 16:21 . 2012-02-23 16:24   25232   ——a-w-  c:\windows\system32\drivers\aswFsBlk.sys
2012-07-03 16:21 . 2012-02-23 16:23   41224   ——a-w-  c:\windows\avastSS.scr
2012-07-03 16:21 . 2012-02-23 16:23   227648   ——a-w-  c:\windows\SysWow64\aswBoot.exe
2012-07-03 16:21 . 2012-02-23 12:51   285328   ——a-w-  c:\windows\system32\aswBoot.exe
2012-06-11 20:09 . 2011-03-28 16:36   19736   ——a-w-  c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-05-31 10:25 . 2012-02-23 11:07   279656   ———w-  c:\windows\system32\MpSigStub.exe
2012-05-20 08:03 . 2012-05-20 08:03   71680   ——a-w-  c:\windows\system32\frapsv64.dll
2012-05-20 08:03 . 2012-05-20 08:03   65536   ——a-w-  c:\windows\SysWow64\frapsvid.dll
2012-04-23 12:32 . 2012-04-23 12:32   1246   ——a-w-  c:\windows\SysWow64\ealregsnapshot1.reg
.
.
(((((((((((((((((((((((((((((((((((  Start steder i reg.basen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Sidebar”=“c:\program files\Windows Sidebar\sidebar.exe” [2010-11-20 1475584]
“Steam”=“c:\program files (x86)\Steam\steam.exe” [2012-02-25 1242448]
“Skype”=“c:\program files (x86)\Skype\Phone\Skype.exe” [2012-06-05 17344176]
“Spybot-S&D Cleaning”=“c:\program files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe” [2012-07-04 3527176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
“avast”=“c:\program files\AVAST Software\Avast\avastUI.exe” [2012-07-03 4273976]
“SunJavaUpdateSched”=“c:\program files (x86)\Common Files\Java\Java Update\jusched.exe” [2012-01-18 254696]
“QuickTime Task”=“c:\program files (x86)\QuickTime\QTTask.exe” [2009-05-26 413696]
“LogMeIn Hamachi Ui”=“c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe” [2012-06-27 1996200]
“Ad-Aware Browsing Protection”=“c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe” [2011-10-21 198032]
“SDTray”=“c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe” [2012-07-04 3921432]
.
c:\users\Joakim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Free Stuff.url [2012-2-21 109]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“ConsentPromptBehaviorAdmin”= 5 (0x5)
“ConsentPromptBehaviorUser”= 3 (0x3)
“EnableUIADesktopToggle”= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
“aux1”=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute   REG_MULTI_SZ     autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages   REG_MULTI_SZ     kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-05 160944]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-12 250056]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 WatAdminSvc;Tjenesten Windows Aktivering;c:\windows\system32\Wat\WatAdminSvc.exe [2012-02-23 1255736]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 203264]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-07-03 71064]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-06-27 2369960]
S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2012-07-04 1188896]
S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2012-07-04 1395736]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2012-03-22 166528]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [2009-06-10 270848]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
.
.
—- Andre Services/Drivers i Hukommelsen—-
.
*NewlyCreated* - WS2IFSL
.
Indhold af mappen ‘Planlagte Opgaver’
.
2012-07-13 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-16 11:25]
.
2012-07-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2361015560-1428424842-530145086-1000Core.job
- c:\users\Joakim\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-12 11:16]
.
2012-07-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2361015560-1428424842-530145086-1000UA.job
- c:\users\Joakim\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-12 11:16]
.
.
————- X64 Entries—————-
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@=”{472083B0-C522-11CF-8763-00608CC02F24}”
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-07-03 16:21   133400   ——a-w-  c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
“LoadAppInit_DLLs”=0x0
.
———- Yderligere scanning———-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://safesearchr.lavasoft.com/?source=3336ca5f&tbp=homepage&toolbarid=adawaretb&v=2_1&u=899E7FE26168F51CAF59164FFF1FA3B1
mLocal Page = c:\windows\SysWOW64\blank.htm
.
- - - - TOMME GENVEJE FJERNET - - - -
.
Wow6432Node-HKCU-Run-EA Core - c:\program files (x86)\Electronic Arts\EADM\Core.exe
Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe
Notify-SDWinLogon - SDWinLogon.dll
BHO-{D27FC31C-6E3D-4305-8D53-ACDAEFA5F862} - c:\users\Joakim\AppData\Roaming\Complitly\64\Complitly64.dll
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-Complitly_is1 - c:\program files (x86)\Complitly\unins000.exe
.
.
.
——————————- LÅSTE REGISTRERINGS NØGLER——————————-
.
[HKEY_USERS\S-1-5-21-2361015560-1428424842-530145086-1000\Software\SecuROM\License information*]
“datasecu”=hex:ec,b7,a1,b5,f9,db,27,d8,21,b0,46,2c,0e,e0,d1,1e,31,fb,6f,4e,c7,
  f2,11,91,19,da,11,0b,e7,83,0c,f8,8a,dc,51,af,da,a1,39,59,79,65,1e,22,44,69,\
“rkeysecu”=hex:64,b6,bd,e1,3e,80,9e,c4,40,b4,90,83,87,8e,33,49
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@=“FlashBroker”
“LocalizedString”=”@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe,-101”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
“Enabled”=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@=”{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@=“Shockwave Flash Object”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx”
“ThreadingModel”=“Apartment”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@=“0”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@=“ShockwaveFlash.ShockwaveFlash.11”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@=”{D27CDB6B-AE6D-11cf-96B8-444553540000}”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@=“1.0”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@=“ShockwaveFlash.ShockwaveFlash”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@=“Macromedia Flash Factory Object”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx”
“ThreadingModel”=“Apartment”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@=“FlashFactory.FlashFactory.1”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@=“c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@=”{D27CDB6B-AE6D-11cf-96B8-444553540000}”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@=“1.0”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@=“FlashFactory.FlashFactory”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@=“IFlashBroker4”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@=”{00020424-0000-0000-C000-000000000046}”
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@=”{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”
“Version”=“1.0”
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
————————————Andre kørende processer————————————
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
.
**************************************************************************
.
Gennemført tid: 2012-07-13 15:14:57 - maskinen blev genstartet
ComboFix-quarantined-files.txt 2012-07-13 13:14
.
Pre-Kørsel: 404.752.596.992 byte ledig
Post-Kørsel: 404.561.825.792 byte ledig
.
- - End Of File - - 4EC835FCDE74272071DF79442E51AF3E

  FieFyn
Antal indlæg: 16

Tak for den anvisning, og her var den logfil, der kom ud af det.

Administrator
Avatar
Antal indlæg: 32078

Fint           wink

Hvordan opfører computeren sig nu ?

Signatur

Sund Computer fornuft

  FieFyn
Antal indlæg: 16

Jeg er DYBT imponeret!
Den kører bare godt, og den dumme toolbar er væk!

TUSIND tak!

/sofie

Administrator
Avatar
Antal indlæg: 32078

Herligt, og velbekomme     thumbsup


Åbn OTL.

Klik på CleanUp! knappen.

Du vil blive spurgt, om du vil begynde at rensningen? Vælg Ja.

Dette trin fjerner de filer, mapper og genveje skabt af de værktøjer,  du har downloadet og kørt.

Når du er færdig, vil du blive bedt om at genstarte computeren.

Genstart venligst din computer.

Signatur

Sund Computer fornuft