Hej.
Det har gået godt i lang tid, men har nu brug for Jeres fantastiske support endnu en gang.
Min søns pc’er har været fuldstændig frosset og kunne ikke starte op. Jeg fik den igang i fejlsikret tilstand og har fulgt vejledningen, og fik fjernet en del snavs. Nu starter den op på normal vis. Men for en sikkerheds skyld vil jeg gerne have kigget logfilerne igennem. Bulguard og Esenet fandt ingenting så her følger filerne fra Antimalware og Antispy.
Malwarebytes Anti-Malware 1.62.0.1300
http://www.malwarebytes.org
Database version: v2012.07.12.10
Windows Vista Service Pack 2 x86 NTFS (Fejlsikret Tilstand Med Netværk)
Internet Explorer 9.0.8112.16421
Tobias :: TOBIAS-PC [administrator]
12-07-2012 22:00:35
mbam-log-2012-07-13 (08-57-06).txt
Skanningstype: Fuldstændig skanning (C:\|D:\|)
Skanningsmuligheder valgt: Hukommelse | Opstart | Registreringsdatabasen | Filsystem | Heuristics/Ekstra | Heuristics/Shuriken | PUP | PUM
Skanningsmuligheder som er deaktiverede: P2P
Objekter skannet: 488363
Tid gået: 1 time(e), 36 minut(ter), 29 sekund(er)
Hukommelses Processorer Inficeret: 0
(Ingen skadelige objekter blev fundet)
Hukommelses Moduler Inficeret: 0
(Ingen skadelige objekter blev fundet)
Registreringsdatabasenøgler Inficeret: 14
HKCR\AppID\{D2083641-E57F-4eab-BB85-0582424F4A29} (Adware.HotBar.CP) -> Ingen handling valgt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1602F07D-8BF3-4C08-BDD6-DDDB1C48AEDC} (Adware.ClickPotato) -> Ingen handling valgt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1602F07D-8BF3-4C08-BDD6-DDDB1C48AEDC} (Adware.ClickPotato) -> Ingen handling valgt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{AC6D819E-AA8F-4418-A3BB-D165C1B18BB5} (Adware.ClickPotato) -> Ingen handling valgt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B58926D6-CFB0-45D2-9C28-4B5A0F0368AE} (Adware.ClickPotato) -> Ingen handling valgt.
HKCR\ClickPotatoLiteAX.info (Adware.ClickPotato) -> Ingen handling valgt.
HKCR\ClickPotatoLiteAX.info.1 (Adware.ClickPotato) -> Ingen handling valgt.
HKCR\ClickPotatoLiteAX.UserProfiles (Adware.ClickPotato) -> Ingen handling valgt.
HKCR\ClickPotatoLiteAX.UserProfiles.1 (Adware.ClickPotato) -> Ingen handling valgt.
HKCR\MenuButtonIE.ButtonIE (Adware.ClickPotato) -> Ingen handling valgt.
HKCR\MenuButtonIE.ButtonIE.1 (Adware.ClickPotato) -> Ingen handling valgt.
HKCR\AppID\MenuButtonIE.DLL (Adware.ClickPotato) -> Ingen handling valgt.
HKCU\Software\clickpotatolitesa (Adware.ClickPotato) -> Ingen handling valgt.
HKLM\SOFTWARE\ClickPotatoLite (Adware.ClickPotato) -> Ingen handling valgt.
Registreringsdatabaseværdier Inficeret: 1
HKLM\SOFTWARE\Mozilla\Firefox\extensions|ClickPotatoLite@ClickPotatoLite.com (Adware.ClickPotato) -> Data: C:\Program Files\ClickPotatoLite\bin\10.0.701.0\firefox\extensions -> Ingen handling valgt.
Registreringsdatabasedata Objekter Inficeret: 0
(Ingen skadelige objekter blev fundet)
Inficerede Mapper: 9
C:\ProgramData\2ACA5CC3-0F83-453D-A079-1076FE1A8B65 (Adware.Seekmo) -> Ingen handling valgt.
C:\ProgramData\ClickPotatoLiteSA (Adware.ClickPotato) -> Ingen handling valgt.
C:\Program Files\ClickPotatoLite (Adware.ClickPotato) -> Ingen handling valgt.
C:\Program Files\ClickPotatoLite\bin (Adware.ClickPotato) -> Ingen handling valgt.
C:\Program Files\ClickPotatoLite\bin\10.0.701.0 (Adware.ClickPotato) -> Ingen handling valgt.
C:\Program Files\ClickPotatoLite\bin\10.0.701.0\firefox (Adware.ClickPotato) -> Ingen handling valgt.
C:\Program Files\ClickPotatoLite\bin\10.0.701.0\firefox\extensions (Adware.ClickPotato) -> Ingen handling valgt.
C:\Program Files\ClickPotatoLite\bin\10.0.701.0\firefox\extensions\plugins (Adware.ClickPotato) -> Ingen handling valgt.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ClickPotato (Adware.ClickPotato) -> Ingen handling valgt.
Inficerede Filer: 11
C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job (Trojan.Downloader) -> Ingen handling valgt.
C:\ProgramData\ClickPotatoLiteSA\ClickPotatoLiteSA.dat (Adware.ClickPotato) -> Ingen handling valgt.
C:\ProgramData\ClickPotatoLiteSA\ClickPotatoLiteSAAbout.mht (Adware.ClickPotato) -> Ingen handling valgt.
C:\ProgramData\ClickPotatoLiteSA\ClickPotatoLiteSAau.dat (Adware.ClickPotato) -> Ingen handling valgt.
C:\ProgramData\ClickPotatoLiteSA\ClickPotatoLiteSAEULA.mht (Adware.ClickPotato) -> Ingen handling valgt.
C:\ProgramData\ClickPotatoLiteSA\ClickPotatoLiteSA_kyf_update.dat (Adware.ClickPotato) -> Ingen handling valgt.
C:\Program Files\ClickPotatoLite\bin\10.0.701.0\copyright.txt (Adware.ClickPotato) -> Ingen handling valgt.
C:\Program Files\ClickPotatoLite\bin\10.0.701.0\firefox\extensions\install.rdf (Adware.ClickPotato) -> Ingen handling valgt.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ClickPotato\About Us.lnk (Adware.ClickPotato) -> Ingen handling valgt.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ClickPotato\ClickPotato Customer Support.lnk (Adware.ClickPotato) -> Ingen handling valgt.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ClickPotato\ClickPotato Uninstall Instructions.lnk (Adware.ClickPotato) -> Ingen handling valgt.
(færdig)
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 07/13/2012 at 10:34 AM
Application Version : 5.5.1012
Core Rules Database Version : 8894
Trace Rules Database Version: 6706
Scan type : Complete Scan
Total Scan Time : 01:33:28
Operating System Information
Windows Vista Home Premium 32-bit, Service Pack 2 (Build 6.00.6002)
UAC Off - Administrator
Memory items scanned : 415
Memory threats detected : 0
Registry items scanned : 35399
Registry threats detected : 0
File items scanned : 78581
File threats detected : 2
Heur.Agent/Gen-WhiteBox
D:\PROGRAMMER\WOLFTEAM_INSTALL_2009_10_26_DNA.EXE
Trojan.Agent/Gen-Multi
C:\PROGRAM FILES\COMMON FILES\FWC\FWCENBJP.DLL
På forhånd tak for hjælpen
Mvh
Dennis
Administrator
Antal indlæg: 7125
Hej Dennis
Download OTL af OldTimer og gem den på dit skrivebord.
Start OTL
Vista og Windows 7 - højreklik på filen - Kør som Administrator.
Øverst sætter du flueben i “Scan All Users ”
I boksen “Custom Scans/Fixes ” kopierer du det fremhævede ind.
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
services.*
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
%systemroot%\*. /rp /s
%systemroot%\*. /mp /s
CREATERESTOREPOINT
Luk alle åbne vinduer og klik på “Quick Scan ” og lad programmet køre.
Det vil give to logfiler på skrivebordet, OTL.txt og Extras.txt.
Så kopier følgende ind i dit næste indlæg (i rækkefølge):
Indholdet af OTL.txt
Indholdet af Extras.txt
Da de er forholdsvis lange, kan du blive nødt til at sende dem i flere indlæg.
Signatur
Undlad venligst at vedhæfte logs, medmindre du bliver bedt om det !
Hej. Er udført som beskrevet. Her kommer først OTL loggen. Den anden følger i næste indlæg.
OTL logfile created on: 13-07-2012 23:02:35 - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Users\Tobias\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000406 | Country: Danmark | Language: DAN | Date Format: dd-MM-yyyy
2,96 Gb Total Physical Memory | 1,50 Gb Available Physical Memory | 50,54% Memory free
6,13 Gb Paging File | 4,49 Gb Available in Paging File | 73,29% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 143,04 Gb Total Space | 22,54 Gb Free Space | 15,76% Space Free | Partition Type: NTFS
Drive D: | 139,50 Gb Total Space | 82,28 Gb Free Space | 58,98% Space Free | Partition Type: NTFS
Computer Name: TOBIAS-PC | User Name: Tobias | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012-07-13 22:59:35 | 000,596,480 |——| M] (OldTimer Tools)—C:\Users\Tobias\Desktop\OTL.exe
PRC - [2012-07-13 11:02:02 | 000,204,800 |——| M] (Realtek Semiconductor Corp.)—C:\Users\Tobias\AppData\Local\Temp\RtkBtMnt.exe
PRC - [2012-07-12 13:59:23 | 001,756,000 |——| M] (BullGuard Ltd.)—C:\Programmer\BullGuard Ltd\BullGuard\BullGuard.exe
PRC - [2012-07-10 01:38:53 | 004,777,856 |——| M] (SUPERAntiSpyware.com)—C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
PRC - [2012-06-20 11:02:45 | 000,304,480 |——| M] (BullGuard Ltd.)—C:\Programmer\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
PRC - [2012-06-14 13:45:16 | 000,178,016 |——| M] (BullGuard Ltd.)—C:\Programmer\BullGuard Ltd\BullGuard\BullGuardScanner.exe
PRC - [2012-06-14 13:45:14 | 000,321,376 |——| M] (BullGuard Ltd.)—C:\Programmer\BullGuard Ltd\BullGuard\BullGuardBhvScanner.exe
PRC - [2012-02-23 12:30:40 | 000,059,240 |——| M] (Apple Inc.)—C:\Programmer\Common Files\Apple\Internet Services\ubd.exe
PRC - [2011-08-12 01:38:07 | 000,116,608 |——| M] (SUPERAntiSpyware.com)—C:\Programmer\SUPERAntiSpyware\SASCore.exe
PRC - [2010-06-10 14:42:44 | 002,621,440 | R—- | M] (Brother Industries, Ltd.)—C:\Programmer\Browny02\Brother\BrStMonW.exe
PRC - [2010-04-16 23:12:38 | 003,872,080 |——| M] (Microsoft Corporation)—C:\Programmer\Windows Live\Messenger\msnmsgr.exe
PRC - [2010-03-03 12:13:20 | 001,824,040 |——| M] (ManyCam LLC)—C:\Programmer\ManyCam 2.4\ManyCam.exe
PRC - [2010-01-25 09:22:56 | 000,245,760 |——| M] (Brother Industries, Ltd.)—C:\Programmer\Browny02\BrYNSvc.exe
PRC - [2009-04-11 08:27:36 | 002,926,592 |——| M] (Microsoft Corporation)—C:\Windows\explorer.exe
PRC - [2009-02-26 15:24:50 | 000,097,680 |——| M] (Microsoft Corporation)—C:\Programmer\Microsoft Office\Office12\ONENOTEM.EXE
PRC - [2008-11-28 11:56:06 | 000,024,576 |——| M] ()—C:\Programmer\Acer\Empowering Technology\Service\ETService.exe
PRC - [2008-11-28 11:08:46 | 000,417,792 |——| M] (Acer Inc.)—C:\Programmer\Acer\Empowering Technology\ePower\ePower_DMC.exe
PRC - [2008-10-17 15:54:38 | 000,167,936 |——| M] (Acer Corp.)—C:\Programmer\Acer Arcade Deluxe\PlayMovie\PMVService.exe
PRC - [2008-10-16 17:26:20 | 000,860,160 |——| M] (Intel(R) Corporation)—C:\Programmer\Intel\WiFi\bin\EvtEng.exe
PRC - [2008-10-16 16:54:34 | 000,466,944 |——| M] (Intel(R) Corporation)—C:\Programmer\Common Files\Intel\WirelessCommon\RegSrvc.exe
PRC - [2008-10-08 22:49:20 | 000,167,936 |——| M] (CyberLink)—C:\Programmer\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
PRC - [2008-10-08 22:49:12 | 000,147,456 |——| M] (CyberLink Corp.)—C:\Programmer\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
PRC - [2008-10-04 05:09:02 | 000,069,632 |——| M] ()—C:\Programmer\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
PRC - [2008-09-18 13:00:10 | 006,294,048 |——| M] (Realtek Semiconductor)—C:\Windows\RtHDVCpl.exe
PRC - [2008-09-11 23:46:38 | 000,544,768 |——| M] (Acer Incorporated)—C:\Programmer\Acer\Empowering Technology\eAudio\eAudio.exe
PRC - [2008-07-29 18:53:00 | 000,500,784 |——| M] (Egis Incorporated)—C:\Programmer\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
PRC - [2008-07-29 18:52:50 | 000,526,896 |——| M] (Egis Incorporated)—C:\Programmer\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
PRC - [2008-07-20 11:45:06 | 000,354,840 |——| M] (Intel Corporation)—C:\Programmer\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008-07-20 11:45:06 | 000,182,808 |——| M] (Intel Corporation)—C:\Programmer\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008-06-04 14:03:36 | 000,817,672 |——| M] (Dritek System Inc.)—C:\Programmer\Launch Manager\QtZgAcer.EXE
PRC - [2008-01-21 04:25:33 | 000,896,512 |——| M] (Microsoft Corporation)—C:\Programmer\Windows Media Player\wmpnetwk.exe
PRC - [2008-01-21 04:25:33 | 000,202,240 |——| M] (Microsoft Corporation)—C:\Programmer\Windows Media Player\wmpnscfg.exe
PRC - [2008-01-21 04:23:32 | 001,008,184 |——| M] (Microsoft Corporation)—C:\Programmer\Windows Defender\MSASCui.exe
PRC - [2008-01-21 04:23:24 | 000,215,552 |——| M] (Microsoft Corporation)—C:\Windows\WindowsMobile\wmdSync.exe
PRC - [2007-12-06 17:15:28 | 000,110,592 |——| M] ()—C:\ACER\Mobility Center\MobilityService.exe
========== Modules (No Company Name) ==========
MOD - [2012-07-13 21:16:47 | 000,065,024 |——| M] ()—C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
MOD - [2012-07-13 21:16:47 | 000,052,736 |——| M] ()—C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll
MOD - [2012-07-13 09:00:46 | 000,117,760 |——| M] ()—C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
MOD - [2012-07-13 09:00:46 | 000,052,224 |——| M] ()—C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
MOD - [2012-06-20 11:05:48 | 000,073,568 |——| M] ()—C:\Programmer\BullGuard Ltd\BullGuard\zlib1.dll
MOD - [2012-06-14 04:01:14 | 000,212,992 |——| M] ()—C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8bbcd31ecc8edc7d1f9cdd83ef2bb2d3\System.ServiceProcess.ni.dll
MOD - [2012-06-14 04:01:09 | 011,820,032 |——| M] ()—C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\508b444db523c5cf20ff12c7f440837b\System.Web.ni.dll
MOD - [2012-06-14 03:58:26 | 012,433,920 |——| M] ()—C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll
MOD - [2012-06-14 03:58:09 | 001,592,320 |——| M] ()—C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll
MOD - [2012-06-10 16:36:19 | 000,025,600 |——| M] ()—C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\1b337cf9a031145849bc48c11b2cfe58\Accessibility.ni.dll
MOD - [2012-06-10 16:36:16 | 000,771,584 |——| M] ()—C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll
MOD - [2012-06-10 16:35:54 | 000,971,264 |——| M] ()—C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bd76aaaa03ddc15d1840207b5a480644\System.Configuration.ni.dll
MOD - [2012-06-10 16:35:50 | 005,450,752 |——| M] ()—C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll
MOD - [2012-06-10 16:34:07 | 007,953,408 |——| M] ()—C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012-06-10 16:33:49 | 011,492,352 |——| M] ()—C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2012-03-14 15:38:02 | 000,029,312 |——| M] ()—C:\Programmer\BullGuard Ltd\BullGuard\res\dk\BpMainRes.dll
MOD - [2012-03-14 15:38:02 | 000,013,952 |——| M] ()—C:\Programmer\BullGuard Ltd\BullGuard\res\dk\BpInspectorRes.dll
MOD - [2012-03-14 15:38:01 | 000,066,688 |——| M] ()—C:\Programmer\BullGuard Ltd\BullGuard\res\dk\BpBackupRes.dll
MOD - [2012-03-14 15:37:44 | 000,450,392 |——| M] ()—C:\Programmer\BullGuard Ltd\BullGuard\LibXml2.dll
MOD - [2012-03-14 15:37:35 | 000,482,648 |——| M] ()—C:\Programmer\BullGuard Ltd\BullGuard\SQLite.dll
MOD - [2011-09-27 08:23:00 | 000,087,912 |——| M] ()—C:\Programmer\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011-09-27 08:22:40 | 001,242,472 |——| M] ()—C:\Programmer\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010-06-15 18:57:15 | 000,034,816 |——| M] ()—C:\Programmer\Google\Google Desktop Search\gzlib.dll
MOD - [2010-02-10 18:47:53 | 001,691,648 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3266.29383__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll
MOD - [2010-02-10 18:47:53 | 000,692,224 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Wizard\2.0.3266.29429__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Wizard.dll
MOD - [2010-02-10 18:47:53 | 000,466,944 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3266.29459__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll
MOD - [2010-02-10 18:47:53 | 000,364,544 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Wizard\2.0.3266.29443__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Wizard.dll
MOD - [2010-02-10 18:47:53 | 000,278,528 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3266.29368__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll
MOD - [2010-02-10 18:47:53 | 000,204,800 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3266.29384__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll
MOD - [2010-02-10 18:47:53 | 000,135,168 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3266.29460__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll
MOD - [2010-02-10 18:47:53 | 000,077,824 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3266.29438__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll
MOD - [2010-02-10 18:47:53 | 000,073,728 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3266.29374__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll
MOD - [2010-02-10 18:47:53 | 000,069,632 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3266.29418__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll
MOD - [2010-02-10 18:47:53 | 000,040,960 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3266.29380__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll
MOD - [2010-02-10 18:47:53 | 000,036,864 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3266.29405__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll
MOD - [2010-02-10 18:47:53 | 000,020,480 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3266.29375__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll
MOD - [2010-02-10 18:47:52 | 000,811,008 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3266.29408__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll
MOD - [2010-02-10 18:47:52 | 000,798,720 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Dashboard\2.0.3266.29439__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Dashboard.dll
MOD - [2010-02-10 18:47:52 | 000,716,800 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.3266.29376__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll
MOD - [2010-02-10 18:47:52 | 000,589,824 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3266.29385__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll
MOD - [2010-02-10 18:47:52 | 000,405,504 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3266.29433__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll
MOD - [2010-02-10 18:47:52 | 000,344,064 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3266.29424__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll
MOD - [2010-02-10 18:47:52 | 000,225,280 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3266.29385__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll
MOD - [2010-02-10 18:47:52 | 000,147,456 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard\2.0.3266.29459__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard.dll
MOD - [2010-02-10 18:47:52 | 000,122,880 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3266.29416__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll
MOD - [2010-02-10 18:47:52 | 000,094,208 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3266.29424__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll
MOD - [2010-02-10 18:47:52 | 000,081,920 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3266.29407__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll
MOD - [2010-02-10 18:47:52 | 000,057,344 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3266.29423__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll
MOD - [2010-02-10 18:47:52 | 000,045,056 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime\2.0.3266.29458__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.dll
MOD - [2010-02-10 18:47:52 | 000,040,960 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3266.29388__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll
MOD - [2010-02-10 18:47:52 | 000,036,864 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3266.29415__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll
MOD - [2010-02-10 18:47:51 | 000,675,840 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Dashboard\2.0.3266.29419__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Dashboard.dll
MOD - [2010-02-10 18:47:51 | 000,450,560 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Dashboard\2.0.3266.29403__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Dashboard.dll
MOD - [2010-02-10 18:47:51 | 000,438,272 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3266.29406__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll
MOD - [2010-02-10 18:47:51 | 000,401,408 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard\2.0.3266.29417__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.dll
MOD - [2010-02-10 18:47:51 | 000,307,200 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Wizard\2.0.3266.29388__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Wizard.dll
MOD - [2010-02-10 18:47:51 | 000,073,728 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Foundation\2.0.3218.28666__90ba9c70f846762e\CLI.Foundation.dll
MOD - [2010-02-10 18:47:51 | 000,061,440 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3218.28678__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll
MOD - [2010-02-10 18:47:51 | 000,061,440 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3266.29406__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll
MOD - [2010-02-10 18:47:51 | 000,049,152 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3218.28694__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll
MOD - [2010-02-10 18:47:51 | 000,045,056 |——| M] ()—C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll
MOD - [2010-02-10 18:47:51 | 000,040,960 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3218.28702__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll
MOD - [2010-02-10 18:47:51 | 000,040,960 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3266.29407__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll
MOD - [2010-02-10 18:47:51 | 000,032,768 |——| M] ()—C:\Windows\assembly\GAC_MSIL\LOG.Foundation\2.0.3218.28664__90ba9c70f846762e\LOG.Foundation.dll
MOD - [2010-02-10 18:47:51 | 000,032,768 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3266.29417__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll
MOD - [2010-02-10 18:47:51 | 000,028,672 |——| M] ()—C:\Windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3218.28665__90ba9c70f846762e\NEWAEM.Foundation.dll
MOD - [2010-02-10 18:47:51 | 000,028,672 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3218.28727__90ba9c70f846762e\CLI.Foundation.XManifest.dll
MOD - [2010-02-10 18:47:51 | 000,028,672 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Shared\2.0.3218.28701__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Shared.dll
MOD - [2010-02-10 18:47:51 | 000,020,480 |——| M] ()—C:\Windows\assembly\GAC_MSIL\DEM.OS.I0602\2.0.3218.28687__90ba9c70f846762e\DEM.OS.I0602.dll
MOD - [2010-02-10 18:47:51 | 000,020,480 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3218.28681__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll
MOD - [2010-02-10 18:47:51 | 000,020,480 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3218.28678__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll
MOD - [2010-02-10 18:47:51 | 000,020,480 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3218.28672__90ba9c70f846762e\CLI.Component.Client.Shared.dll
MOD - [2010-02-10 18:47:51 | 000,020,480 |——| M] ()—C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3218.28677__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll
MOD - [2010-02-10 18:47:51 | 000,020,480 |——| M] ()—C:\Windows\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3218.28672__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll
MOD - [2010-02-10 18:47:51 | 000,016,384 |——| M] ()—C:\Windows\assembly\GAC_MSIL\MOM.Foundation\2.0.3218.28686__90ba9c70f846762e\MOM.Foundation.dll
MOD - [2010-02-10 18:47:51 | 000,016,384 |——| M] ()—C:\Windows\assembly\GAC_MSIL\DEM.OS\2.0.3218.28687__90ba9c70f846762e\DEM.OS.dll
MOD - [2010-02-10 18:47:51 | 000,016,384 |——| M] ()—C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll
MOD - [2010-02-10 18:47:51 | 000,016,384 |——| M] ()—C:\Windows\assembly\GAC_MSIL\DEM.Graphics\2.0.3218.28688__90ba9c70f846762e\DEM.Graphics.dll
MOD - [2010-02-10 18:47:51 | 000,016,384 |——| M] ()—C:\Windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll
MOD - [2010-02-10 18:47:51 | 000,016,384 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3218.28676__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll
MOD - [2010-02-10 18:47:51 | 000,016,384 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3218.28690__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll
MOD - [2010-02-10 18:47:51 | 000,016,384 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3218.28688__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll
MOD - [2010-02-10 18:47:51 | 000,016,384 |——| M] ()—C:\Windows\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3218.28683__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll
MOD - [2010-02-10 18:47:51 | 000,016,384 |——| M] ()—C:\Windows\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3218.28705__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll
MOD - [2010-02-10 18:47:51 | 000,016,384 |——| M] ()—C:\Windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3218.28685__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll
MOD - [2010-02-10 18:47:51 | 000,016,384 |——| M] ()—C:\Windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3218.28705__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll
MOD - [2010-02-10 18:47:51 | 000,006,656 |——| M] ()—C:\Windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll
MOD - [2010-02-10 18:47:50 | 000,065,536 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3218.28694__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll
MOD - [2010-02-10 18:47:50 | 000,053,248 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3218.28693__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll
MOD - [2010-02-10 18:47:50 | 000,053,248 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3218.28692__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll
MOD - [2010-02-10 18:47:50 | 000,049,152 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3218.28692__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll
MOD - [2010-02-10 18:47:50 | 000,045,056 |——| M] ()—C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3266.29468__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll
MOD - [2010-02-10 18:47:50 | 000,040,960 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3218.28694__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll
MOD - [2010-02-10 18:47:50 | 000,032,768 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3218.28685__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll
MOD - [2010-02-10 18:47:50 | 000,028,672 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3218.28690__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll
MOD - [2010-02-10 18:47:50 | 000,028,672 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3218.28688__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll
MOD - [2010-02-10 18:47:50 | 000,028,672 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3218.28686__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll
MOD - [2010-02-10 18:47:50 | 000,024,576 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3218.28693__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll
MOD - [2010-02-10 18:47:50 | 000,024,576 |——| M] ()—C:\Windows\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.dll
MOD - [2010-02-10 18:47:50 | 000,020,480 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3218.28689__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll
MOD - [2010-02-10 18:47:50 | 000,020,480 |——| M] ()—C:\Windows\assembly\GAC_MSIL\APM.Foundation\2.0.3218.28685__90ba9c70f846762e\APM.Foundation.dll
MOD - [2010-02-10 18:47:50 | 000,016,384 |——| M] ()—C:\Windows\assembly\GAC_MSIL\LOCALIZATION.Foundation.Private\2.0.3218.28670__90ba9c70f846762e\LOCALIZATION.Foundation.Private.dll
MOD - [2010-02-10 18:47:50 | 000,016,384 |——| M] ()—C:\Windows\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3218.28678__90ba9c70f846762e\AEM.Server.Shared.dll
MOD - [2010-02-10 18:47:50 | 000,014,848 |——| M] ()—C:\Windows\assembly\GAC_MSIL\AxInterop.WBOCXLib\1.0.0.0__90ba9c70f846762e\AxInterop.WBOCXLib.dll
MOD - [2010-02-10 18:47:50 | 000,013,312 |——| M] ()—C:\Windows\assembly\GAC\Interop.WBOCXLib\1.0.0.0__90ba9c70f846762e\Interop.WBOCXLib.dll
MOD - [2010-02-10 18:47:50 | 000,011,264 |——| M] ()—C:\Windows\assembly\GAC_MSIL\LOCALIZATION.Foundation.Implementation\2.0.3266.29476__90ba9c70f846762e\LOCALIZATION.Foundation.Implementation.dll
MOD - [2010-02-10 18:47:50 | 000,007,168 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3266.29366__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll
MOD - [2010-02-10 18:47:49 | 001,073,152 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3266.29372__90ba9c70f846762e\CLI.Component.Dashboard.dll
MOD - [2010-02-10 18:47:49 | 000,532,480 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Component.Systemtray\2.0.3266.29447__90ba9c70f846762e\CLI.Component.Systemtray.dll
MOD - [2010-02-10 18:47:49 | 000,393,216 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3266.29379__90ba9c70f846762e\CLI.Component.Wizard.dll
MOD - [2010-02-10 18:47:49 | 000,106,496 |——| M] ()—C:\Windows\assembly\GAC_MSIL\MOM.Implementation\2.0.3266.29453__90ba9c70f846762e\MOM.Implementation.dll
MOD - [2010-02-10 18:47:49 | 000,073,728 |——| M] ()—C:\Windows\assembly\GAC_MSIL\ATIDEMOS\2.0.3266.29367__90ba9c70f846762e\ATIDEMOS.dll
MOD - [2010-02-10 18:47:49 | 000,069,632 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3266.29366__90ba9c70f846762e\CLI.Component.Runtime.dll
MOD - [2010-02-10 18:47:49 | 000,061,440 |——| M] ()—C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3266.29451__90ba9c70f846762e\LOG.Foundation.Implementation.dll
MOD - [2010-02-10 18:47:49 | 000,061,440 |——| M] ()—C:\Windows\assembly\GAC_MSIL\APM.Server\2.0.3266.29365__90ba9c70f846762e\APM.Server.dll
MOD - [2010-02-10 18:47:49 | 000,057,344 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3266.29368__90ba9c70f846762e\CLI.Component.SkinFactory.dll
MOD - [2010-02-10 18:47:49 | 000,045,056 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3218.28682__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll
MOD - [2010-02-10 18:47:49 | 000,040,960 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3218.28670__90ba9c70f846762e\CLI.Foundation.Private.dll
MOD - [2010-02-10 18:47:49 | 000,040,960 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3218.28675__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll
MOD - [2010-02-10 18:47:49 | 000,032,768 |——| M] ()—C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3218.28672__90ba9c70f846762e\LOG.Foundation.Private.dll
MOD - [2010-02-10 18:47:49 | 000,032,768 |——| M] ()—C:\Windows\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll
MOD - [2010-02-10 18:47:49 | 000,028,672 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CCC.Implementation\2.0.3266.29452__90ba9c70f846762e\CCC.Implementation.dll
MOD - [2010-02-10 18:47:49 | 000,024,576 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3218.28681__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll
MOD - [2010-02-10 18:47:49 | 000,020,480 |——| M] ()—C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3218.28686__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll
MOD - [2010-02-10 18:47:49 | 000,020,480 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3218.28682__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll
MOD - [2010-02-10 18:47:49 | 000,020,480 |——| M] ()—C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3218.28695__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll
MOD - [2010-02-10 18:47:48 | 000,045,056 |——| M] ()—C:\Windows\assembly\GAC_MSIL\AEM.Server\2.0.3266.29366__90ba9c70f846762e\AEM.Server.dll
MOD - [2009-04-17 08:17:48 | 000,037,376 |——| M] ()—C:\Programmer\ManyCam 2.4\ImageLayer.dll
MOD - [2009-04-17 08:06:40 | 000,094,208 |——| M] ()—C:\Programmer\ManyCam 2.4\VideoSrc.ax
MOD - [2009-04-17 08:06:32 | 000,331,776 |——| M] ()—C:\Programmer\ManyCam 2.4\InputFilter.ax
MOD - [2009-04-17 08:06:24 | 000,092,672 |——| M] ()—C:\Programmer\ManyCam 2.4\CrashRpt.dll
MOD - [2009-03-31 20:05:00 | 000,409,600 |——| M] ()—C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_da_b77a5c561934e089\System.Windows.Forms.resources.dll
MOD - [2009-03-31 20:05:00 | 000,299,008 |——| M] ()—C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_da_b77a5c561934e089\mscorlib.resources.dll
MOD - [2009-03-31 20:05:00 | 000,200,704 |——| M] ()—C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_da_b77a5c561934e089\System.resources.dll
MOD - [2009-02-27 17:38:20 | 000,139,264 | R—- | M] ()—C:\Programmer\Brother\BrUtilities\BrLogAPI.dll
MOD - [2009-01-17 16:29:09 | 000,061,440 |——| M] ()—C:\Windows\assembly\GAC_MSIL\Framework.Library\3.0.3013.0__3036420f80dd6947\Framework.Library.dll
MOD - [2009-01-17 16:29:09 | 000,036,864 |——| M] ()—C:\Windows\assembly\GAC_MSIL\Framework.Utility\3.0.3013.0__4df5dcab8860d239\Framework.Utility.dll
MOD - [2009-01-17 16:29:09 | 000,020,480 |——| M] ()—C:\Windows\assembly\GAC_MSIL\Framework.Model.ControllerInterface\3.0.3013.0__d842b71b4d6ed079\Framework.Model.ControllerInterface.dll
MOD - [2008-12-10 11:05:52 | 000,159,744 |——| M] ()—C:\Windows\System32\atitmmxx.dll
MOD - [2008-11-05 11:06:16 | 000,053,760 |——| M] ()—C:\Programmer\ManyCam 2.4\zlib.dll
MOD - [2008-10-08 22:49:24 | 000,835,584 |——| M] ()—C:\Programmer\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMediaLibrary.dll
MOD - [2008-10-08 22:49:18 | 000,007,680 |——| M] ()—C:\Programmer\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvcPS.dll
MOD - [2008-07-29 18:52:38 | 000,227,888 |——| M] ()—C:\Programmer\Acer\Empowering Technology\eDataSecurity\x86\ShowErrMsg.dll
MOD - [2008-07-28 10:34:06 | 000,057,344 |——| M] ()—C:\Programmer\ManyCam 2.4\cyltracker08.dll
========== Win32 Services (SafeList) ==========
SRV - [2012-07-13 12:48:11 | 000,250,056 |——| M] (Adobe Systems Incorporated) [On_Demand | Stopped]—C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe—(AdobeFlashPlayerUpdateSvc)
SRV - [2012-07-12 13:59:51 | 000,215,904 |——| M] (BullGuard Ltd.) [Auto | Running]—C:\Programmer\BullGuard Ltd\BullGuard\BsMain.dll—(BsMain)
SRV - [2012-06-20 11:05:52 | 000,457,056 |——| M] (BullGuard Ltd.) [Auto | Running]—C:\Programmer\BullGuard Ltd\BullGuard\BsFire.dll—(BsFire)
SRV - [2012-06-20 11:05:48 | 000,391,520 |——| M] (BullGuard Ltd.) [Auto | Running]—C:\Programmer\BullGuard Ltd\BullGuard\BsMailProxy\BsMailProxy.dll—(BsMailProxy)
SRV - [2012-06-20 11:02:45 | 000,304,480 |——| M] (BullGuard Ltd.) [Auto | Running]—C:\Programmer\BullGuard Ltd\BullGuard\BullGuardUpdate.exe—(BsUpdate)
SRV - [2012-06-19 16:12:04 | 000,529,232 |——| M] (Valve Corporation) [On_Demand | Stopped]—C:\Program Files\Common Files\Steam\SteamService.exe—(Steam Client Service)
SRV - [2012-06-14 13:45:17 | 000,227,168 |——| M] (BullGuard Ltd.) [Auto | Running]—C:\Programmer\BullGuard Ltd\BullGuard\BsFileScan.dll—(BsFileScan)
SRV - [2012-06-14 13:45:17 | 000,060,256 |——| M] (BullGuard Ltd.) [Auto | Running]—C:\Programmer\BullGuard Ltd\BullGuard\BsBackup.dll—(BsBackup)
SRV - [2012-06-14 13:45:16 | 000,178,016 |——| M] (BullGuard Ltd.) [Auto | Running]—C:\Programmer\BullGuard Ltd\BullGuard\BullGuardScanner.exe—(BsScanner)
SRV - [2012-06-14 13:45:14 | 000,321,376 |——| M] (BullGuard Ltd.) [Auto | Running]—C:\Programmer\BullGuard Ltd\BullGuard\BullGuardBhvScanner.exe—(BsBhvScan)
SRV - [2011-08-12 01:38:07 | 000,116,608 |——| M] (SUPERAntiSpyware.com) [Auto | Running]—C:\Programmer\SUPERAntiSpyware\SASCore.exe—(!SASCORE)
SRV - [2011-07-20 05:18:24 | 000,440,696 |——| M] (Microsoft Corporation) [On_Demand | Stopped]—C:\Programmer\Common Files\microsoft shared\OFFICE12\ODSERV.EXE—(odserv)
SRV - [2010-01-25 09:22:56 | 000,245,760 |——| M] (Brother Industries, Ltd.) [On_Demand | Running]—C:\Programmer\Browny02\BrYNSvc.exe—(BrYNSvc)
SRV - [2009-11-12 19:08:00 | 003,403,420 |——| M] (INCA Internet Co., Ltd.) [On_Demand | Stopped]—C:\Windows\System32\GameMon.des—(npggsvc)
SRV - [2008-11-28 11:56:06 | 000,024,576 |——| M] () [Auto | Running]—C:\Programmer\Acer\Empowering Technology\Service\ETService.exe—(ETService)
SRV - [2008-10-16 17:26:20 | 000,860,160 |——| M] (Intel(R) Corporation) [Auto | Running]—C:\Programmer\Intel\WiFi\bin\EvtEng.exe—(EvtEng)
SRV - [2008-10-16 16:54:34 | 000,466,944 |——| M] (Intel(R) Corporation) [Auto | Running]—C:\Programmer\Common Files\Intel\WirelessCommon\RegSrvc.exe—(RegSrvc)
SRV - [2008-10-04 05:09:02 | 000,069,632 |——| M] () [Auto | Running]—C:\Programmer\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe—(CLHNService)
SRV - [2008-07-29 18:53:00 | 000,500,784 |——| M] (Egis Incorporated) [Auto | Running]—C:\Programmer\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe—(eDataSecurity Service)
SRV - [2008-07-20 11:45:06 | 000,354,840 |——| M] (Intel Corporation) [Auto | Running]—C:\Programmer\Intel\Intel Matrix Storage Manager\IAANTmon.exe—(IAANTMON) Intel(R)
SRV - [2008-01-21 04:25:33 | 000,896,512 |——| M] (Microsoft Corporation) [Auto | Running]—C:\Programmer\Windows Media Player\wmpnetwk.exe—(WMPNetworkSvc)
SRV - [2008-01-21 04:23:32 | 000,272,952 |——| M] (Microsoft Corporation) [Auto | Running]—C:\Programmer\Windows Defender\MpSvc.dll—(WinDefend)
SRV - [2008-01-21 04:23:24 | 000,365,568 |——| M] (Microsoft Corporation) [Auto | Running]—C:\Windows\WindowsMobile\wcescomm.dll—(WcesComm)
SRV - [2008-01-21 04:23:24 | 000,167,936 |——| M] (Microsoft Corporation) [Auto | Running]—C:\Windows\WindowsMobile\rapimgr.dll—(RapiMgr)
SRV - [2007-12-06 17:15:28 | 000,110,592 |——| M] () [Auto | Running]—C:\ACER\Mobility Center\MobilityService.exe—(MobilityService)
SRV - [2006-10-26 14:03:08 | 000,145,184 |——| M] (Microsoft Corporation) [On_Demand | Stopped]—C:\Programmer\Common Files\microsoft shared\Source Engine\OSE.EXE—(ose)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped]—system32\DRIVERS\nwlnkfwd.sys—(NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped]—system32\DRIVERS\nwlnkflt.sys—(NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped]—system32\DRIVERS\ipinip.sys—(IpInIp)
DRV - [2012-06-20 11:05:51 | 000,033,920 | R—- | M] (Agnitum Ltd.) [Kernel | System | Running]—C:\Windows\System32\drivers\Afw.sys—(afw)
DRV - [2012-06-20 11:05:48 | 000,339,584 | R—- | M] (Agnitum Ltd.) [Kernel | On_Demand | Running]—C:\Windows\System32\drivers\AfwCore.sys—(afwcore)
DRV - [2012-03-14 15:38:02 | 000,020,040 |——| M] (NovaShield, Inc.) [Kernel | System | Running]—C:\Windows\System32\drivers\NSNetmon.sys—(NovaShieldTDIDriver)
DRV - [2012-03-14 15:37:52 | 000,216,136 |——| M] (NovaShield, Inc.) [File_System | System | Running]—C:\Windows\System32\drivers\NSKernel.sys—(NovaShieldFilterDriver)
DRV - [2012-03-14 15:37:49 | 000,308,296 |——| M] (BitDefender S.R.L.) [File_System | On_Demand | Running]—C:\Windows\System32\drivers\Trufos.sys—(Trufos)
DRV - [2011-07-22 18:27:02 | 000,012,880 |——| M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running]—C:\Programmer\SUPERAntiSpyware\sasdifsv.sys—(SASDIFSV)
DRV - [2011-07-12 23:55:22 | 000,067,664 |——| M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running]—C:\Programmer\SUPERAntiSpyware\SASKUTIL.SYS—(SASKUTIL)
DRV - [2011-04-11 13:35:30 | 000,061,152 |——| M] (BullGuard Ltd.) [File_System | System | Running]—C:\Windows\System32\drivers\BdSpy.sys—(BdSpy)
DRV - [2010-04-19 21:29:20 | 000,018,432 |——| M] (Apple Inc.) [Kernel | On_Demand | Stopped]—C:\Windows\System32\drivers\netaapl.sys—(Netaapl)
DRV - [2009-12-04 11:59:52 | 000,014,720 |——| M] (BitDefender S.R.L.) [Kernel | On_Demand | Stopped]—C:\Programmer\BullGuard Ltd\BullGuard\Antirootkit\profos.sys—(Profos)
DRV - [2009-09-14 20:05:10 | 000,102,784 |——| M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped]—C:\Windows\System32\drivers\ewusbmdm.sys—(hwdatacard)
DRV - [2009-08-05 06:18:22 | 000,048,640 |——| M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running]—C:\Windows\System32\drivers\L1E60x86.sys—(L1E)
DRV - [2009-03-18 17:35:40 | 000,026,176 | -H—| M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped]—C:\Windows\System32\drivers\hamachi.sys—(hamachi)
DRV - [2008-12-10 12:30:58 | 004,172,288 |——| M] (ATI Technologies Inc.) [Kernel | On_Demand | Running]—C:\Windows\System32\drivers\atikmdag.sys—(atikmdag)
DRV - [2008-11-17 07:40:22 | 003,668,480 |——| M] (Intel Corporation) [Kernel | On_Demand | Running]—C:\Windows\System32\drivers\NETw5v32.sys—(NETw5v32) Intel(R)
DRV - [2008-10-01 11:04:16 | 000,012,832 |——| M] (Acer, Inc.) [Kernel | Auto | Running]—C:\Windows\System32\drivers\int15.sys—(int15)
DRV - [2008-07-24 08:17:00 | 000,437,760 |——| M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped]—C:\Windows\System32\drivers\arusb_lh.sys—(arusb_lh)
DRV - [2008-01-14 12:06:32 | 000,021,632 |——| M] (ManyCam LLC.) [Kernel | On_Demand | Running]—C:\Windows\System32\drivers\ManyCam.sys—(ManyCam)
DRV - [2007-10-19 00:36:54 | 000,008,704 |——| M] (Conexant Systems, Inc.) [Kernel | Auto | Running]—C:\Windows\System32\drivers\XAudio.sys—(XAudio)
DRV - [2007-03-28 08:51:40 | 000,043,008 |——| M] (Winbond Electronics Corporation) [Kernel | On_Demand | Running]—C:\Windows\System32\drivers\winbondcir.sys—(winbondcir)
DRV - [2006-07-03 15:34:52 | 000,110,272 |——| M] (BEHRINGER) [Kernel | On_Demand | Stopped]—C:\Windows\System32\drivers\BUSB2902.sys—(BEHRINGER_2902)
DRV - [2004-02-04 10:27:56 | 000,049,536 |——| M] (Texas Instruments Incorporated) [Kernel | On_Demand | Stopped]—C:\Windows\System32\drivers\tiehdusb.sys—(TIEHDUSB)
DRV - [2000-02-22 16:46:40 | 000,009,152 |——| M] () [Kernel | Auto | Stopped]—C:\Windows\System32\drivers\Ticalc.sys—(TICalc)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: “URL” = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: “URL” = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz=1I7ACAW
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: “URL” = http://search.sweetim.com/search.asp?src=6&q={searchTerms}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0
IE - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0406&s=2&o=vp32&d=0210&m=aspire_6930g
IE - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://global.acer.com [binary data]
IE - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = https://mail.google.com/mail/?shva=1#inbox [binary data]
IE - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
IE - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000\..\SearchScopes,DefaultScope = {3B4DD6A7-2803-44AD-A85A-F0F69D5E2BCE}
IE - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: “URL” = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000\..\SearchScopes\{3B4DD6A7-2803-44AD-A85A-F0F69D5E2BCE}: “URL” = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&sourceid=ie7&rlz=1I7ACAW_daDK366DK366
IE - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: “URL” = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz=1I7ACAW
IE - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: “URL” = http://www.google.com/search?q={searchTerms}&rlz=1I7ACAW_daDK366DK366&ie;={inputEncoding}&oe;={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000\..\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}: “URL” = http://127.0.0.1:4664/search&s=AQ0UNa4jF-jKmFTGxsJvNN9AALQ?q={searchTerms}
IE - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: “URL” = http://search.sweetim.com/search.asp?src=6&q={searchTerms}
IE - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0
IE - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyOverride” = *.local
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Tobias\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\antiphishing@bullguard: c:\program files\bullguard ltd\bullguard\Antiphishing\FF\antiphishing@bullguard\ [2012-04-13 03:26:04 | 000,000,000 |—-D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\{380AE6CB-09B9-4373-B360-D01C2462A6E7}: C:\Program Files\BullGuard Ltd\BullGuard\backup\thunderbirdbkplugin [2012-03-27 03:31:00 | 000,000,000 |—-D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\{0E810812-F4BB-4309-942A-755587587A5E}: C:\Program Files\BullGuard Ltd\BullGuard\Spamfilter\TbSpamfilter [2012-06-10 14:37:46 | 000,000,000 |—-D | M]
========== Chrome ==========
CHR - homepage: http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q={searchTerms}
CHR - homepage: http://www.google.com
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\20.0.1132.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\20.0.1132.57\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\20.0.1132.57\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Tobias\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - Extension: YouTube = C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google-s\u00F8gning = C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Gmail = C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2010-02-11 18:56:45 | 000,000,027 |——| M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (ShowBarObj Class) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Programmer\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll (Egis)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programmer\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Programmer\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Programmer\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcadeDeluxeAgent] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [BullGuard] C:\Program Files\BullGuard Ltd\BullGuard\BullGuard.exe (BullGuard Ltd.)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [eAudio] C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe (Acer Incorporated)
O4 - HKLM..\Run: [eDataSecurity Loader] C:\Programmer\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe (Egis Incorporated)
O4 - HKLM..\Run: [ePower_DMC] C:\Programmer\Acer\Empowering Technology\ePower\ePower_DMC.exe (Acer Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Programmer\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [LManager] C:\Programmer\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [PlayMovie] C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe (Acer Corp.)
O4 - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000..\Run: [Facebook Update] C:\Users\Tobias\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000..\Run: [ManyCam] C:\Program Files\ManyCam 2.4\ManyCam.exe (ManyCam LLC)
O4 - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000..\Run: [MobileDocuments] C:\Programmer\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O4 - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000..\Run: [Pando Media Booster] C:\Programmer\Pando Networks\Media Booster\PMB.exe ()
O4 - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000..\Run: [ProductReg] C:\Program Files\Acer\WR_PopUp\ProductReg.exe (Acer)
O4 - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000..\Run: [Steam] C:\Program Files\Steam\steam.exe (Valve Corporation)
O4 - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000..\Run: [WMPNSCFG] C:\Programmer\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Tobias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
O4 - Startup: C:\Users\Tobias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Screen Clipper and Launcher til OneNote 2007.lnk = C:\Programmer\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O8 - Extra context menu item: E&ksporter; til Microsoft Excel - C:\Programmer\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube Download - C:\Users\Tobias\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Tobias\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Tobias\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Google Sidewiki ... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmer\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra ‘Tools’ menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programmer\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programmer\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra ‘Tools’ menuitem : S&end; til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programmer\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Report to BullGuard - {27FD17FB-CF63-486b-B2BE-8D8781CBEA01} - c:\Programmer\BullGuard Ltd\BullGuard\Antiphishing\IE\BgAntiphishingIE.dll (BullGuard Ltd.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmer\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra ‘Tools’ menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmer\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programmer\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programmer\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\System32\BGLsp.dll (BullGuard Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Windows\System32\BGLsp.dll (BullGuard Ltd.)
O15 - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4C2EE2BE-E790-49A8-988F-48C327C200B4}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C0A86001-C93F-4A0F-9BC5-9A0ABB598E57}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programmer\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programmer\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programmer\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programmer\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programmer\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programmer\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Programmer\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - AppInit_DLLs: (BgGamingMonitor.dll) - C:\Windows\System32\BgGamingMonitor.dll (BullGuard Ltd.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Programmer\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Users\Tobias\Pictures\LOVE.jpg
O24 - Desktop BackupWallPaper: C:\Users\Tobias\Pictures\LOVE.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Programmer\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006-09-18 23:43:36 | 000,000,024 |——| M] () - C:\autoexec.bat—[ NTFS ]
O33 - MountPoints2\{1175556f-2fd0-11e0-b039-00238bb8d9d3}\Shell\AutoRun\command - “” = F:\avira.exe
O33 - MountPoints2\{caffc7e7-f18a-11e0-bd22-00238bb8d9d3}\Shell - “” = AutoRun
O33 - MountPoints2\{caffc7e7-f18a-11e0-bd22-00238bb8d9d3}\Shell\AutoRun\command - “” = F:\AutoRun.exe
O33 - MountPoints2\{caffc7f9-f18a-11e0-bd22-00238bb8d9d3}\Shell - “” = AutoRun
O33 - MountPoints2\{caffc7f9-f18a-11e0-bd22-00238bb8d9d3}\Shell\AutoRun\command - “” = F:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open]—“%1” %*
O35 - HKLM\..exefile [open]—“%1” %*
O37 - HKLM\...com [@ = comfile]—“%1” %*
O37 - HKLM\...exe [@ = exefile]—“%1” %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012-07-13 22:59:35 | 000,596,480 |——| C] (OldTimer Tools)—C:\Users\Tobias\Desktop\OTL.exe
[2012-07-13 21:25:48 | 000,000,000 |—-D | C]—C:\Program Files\Common Files\Java
[2012-07-13 20:49:22 | 000,000,000 | -HSD | C]—C:\found.000
[2012-07-13 20:18:18 | 000,000,000 |—-D | C]—C:\Program Files\Common Files\Adobe
[2012-07-13 15:32:49 | 000,000,000 |—-D | C]—C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012-07-13 15:28:45 | 000,000,000 |—-D | C]—C:\Program Files\iPod
[2012-07-13 15:28:29 | 000,000,000 |—-D | C]—C:\Program Files\iTunes
[2012-07-13 15:14:02 | 000,000,000 |—-D | C]—C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012-07-13 15:13:03 | 000,000,000 |—-D | C]—C:\Program Files\QuickTime
[2012-07-13 09:00:26 | 000,000,000 |—-D | C]—C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012-07-13 09:00:00 | 000,000,000 |—-D | C]—C:\Users\Tobias\AppData\Roaming\SUPERAntiSpyware.com
[2012-07-13 08:59:58 | 000,000,000 |—-D | C]—C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2012-07-13 08:59:53 | 000,000,000 |—-D | C]—C:\ProgramData\SUPERAntiSpyware.com
[2012-07-13 08:59:53 | 000,000,000 |—-D | C]—C:\Program Files\SUPERAntiSpyware
[2012-07-13 08:57:22 | 000,000,000 |—-D | C]—C:\Users\Tobias\Desktop\swf
[2012-07-12 21:58:33 | 000,000,000 |—-D | C]—C:\Users\Tobias\AppData\Roaming\Malwarebytes
[2012-07-12 21:58:17 | 000,000,000 |—-D | C]—C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes’ Anti-Malware
[2012-07-12 21:58:14 | 000,022,344 |——| C] (Malwarebytes Corporation)—C:\Windows\System32\drivers\mbam.sys
[2012-07-12 21:58:14 | 000,000,000 |—-D | C]—C:\ProgramData\Malwarebytes
[2012-07-12 21:58:13 | 000,000,000 |—-D | C]—C:\Program Files\Malwarebytes’ Anti-Malware
[2012-07-12 18:44:29 | 000,000,000 |—-D | C]—C:\Program Files\ESET
[2012-06-21 22:24:00 | 000,000,000 |—-D | C]—C:\Users\Tobias\Desktop\enigma
[2012-06-21 11:51:56 | 000,000,000 |—-D | C]—C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audio Related Programs
[2012-06-18 10:48:21 | 000,000,000 |—-D | C]—C:\ProgramData\NCH Software
[2012-06-18 10:48:06 | 000,000,000 |—-D | C]—C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video Related Programs
[2012-06-18 10:48:06 | 000,000,000 |—-D | C]—C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
[2012-06-18 10:48:03 | 000,000,000 |—-D | C]—C:\Program Files\NCH Software
[2012-06-18 10:47:54 | 000,000,000 |—-D | C]—C:\Users\Tobias\AppData\Roaming\NCH Software
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Tobias\Documents\*.tmp files -> C:\Users\Tobias\Documents\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012-07-13 23:12:01 | 000,000,920 |——| M] ()—C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-07-13 23:08:02 | 000,000,966 |——| M] ()—C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3335635223-1391227600-2490444171-1000UA.job
[2012-07-13 22:59:35 | 000,596,480 |——| M] (OldTimer Tools)—C:\Users\Tobias\Desktop\OTL.exe
[2012-07-13 22:58:56 | 000,003,216 | -H—| M] () -
Og her extras loggen:
OTL Extras logfile created on: 13-07-2012 23:02:35 - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Users\Tobias\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000406 | Country: Danmark | Language: DAN | Date Format: dd-MM-yyyy
2,96 Gb Total Physical Memory | 1,50 Gb Available Physical Memory | 50,54% Memory free
6,13 Gb Paging File | 4,49 Gb Available in Paging File | 73,29% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 143,04 Gb Total Space | 22,54 Gb Free Space | 15,76% Space Free | Partition Type: NTFS
Drive D: | 139,50 Gb Total Space | 82,28 Gb Free Space | 58,98% Space Free | Partition Type: NTFS
Computer Name: TOBIAS-PC | User Name: Tobias | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile]—C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile]—C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = Opera.HTML]—C:\Program Files\Opera\Opera.exe (Opera Software)
[HKEY_USERS\S-1-5-21-3335635223-1391227600-2490444171-1000\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML]—Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open]—“%1” %*
cmdfile [open]—“%1” %*
comfile [open]—“%1” %*
cplfile [cplopen]—%SystemRoot%\System32\control.exe “%1”,%* (Microsoft Corporation)
exefile [open]—“%1” %*
helpfile [open]—Reg Error: Key error.
hlpfile [open]—%SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
http [open]—“C:\Program Files\Opera\Opera.exe” “%1” (Opera Software)
https [open]—“C:\Program Files\Opera\Opera.exe” “%1” (Opera Software)
inffile [install]—%SystemRoot%\System32\InfDefaultInstall.exe “%1” (Microsoft Corporation)
piffile [open]—“%1” %*
regfile [merge]—Reg Error: Key error.
scrfile [config]—“%1”
scrfile [install]—rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open]—“%1” /S
txtfile [edit]—Reg Error: Key error.
Unknown [openas]—%SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd]—cmd.exe /s /k pushd “%V” (Microsoft Corporation)
Directory [find]—%SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open]—C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE “%L” (Microsoft Corporation)
Folder [open]—%SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore]—%SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find]—%SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
“cval” = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
“AntiVirusOverride” = 0
“AntiSpywareOverride” = 0
“FirewallOverride” = 0
“VistaSp1” = Reg Error: Unknown registry data type—File not found
“VistaSp2” = Reg Error: Unknown registry data type—File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
“EnableFirewall” = 1
“DisableNotifications” = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
“EnableFirewall” = 1
“DisableNotifications” = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
“EnableFirewall” = 0
“DisableNotifications” = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
“{01B2BC05-3BD9-4FC5-95E8-90E9B06D5758}” = lport=2869 | protocol=6 | dir=in | app=system |
“{038603E2-42BD-44AC-BC46-B70F4669619D}” = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 |
“{042048CF-87EC-4BB3-BFDC-306FE6ACF3AD}” = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
“{168DAF51-C682-484C-9BE5-3C32B9CA791B}” = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
“{23167665-01EE-4E3B-ABA1-E4D26EBA53C6}” = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
“{3030F2E3-3A49-47A7-9492-C51E959DF79D}” = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
“{36A23CA3-5D95-47E7-95C1-7DAE2C711E30}” = lport=2869 | protocol=6 | dir=in | app=system |
“{36CE1CB2-8F14-4BDB-B194-6FBF45D9ABBB}” = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
“{371118FD-0610-478C-A608-558E872F9EB4}” = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
“{37B49103-AF65-463B-B12C-CBE9EE723411}” = rport=445 | protocol=6 | dir=out | app=system |
“{381DE57B-9532-4F50-A2B1-FF6706CC8E84}” = lport=10243 | protocol=6 | dir=in | app=system |
“{441A63CA-F3CE-4EDB-BFA7-5C62726A6033}” = lport=139 | protocol=6 | dir=in | app=system |
“{4D91BD27-BCD5-4A9E-B930-0E7965EE0729}” = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
“{55070957-E83F-48BA-B60E-742E2D91F31C}” = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
“{55C9F0B7-F941-4236-B839-A7091214387F}” = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
“{63131FA7-718A-438F-B700-F0497B170BB0}” = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
“{643F216A-0BC9-4D81-8D09-197853468CAF}” = lport=445 | protocol=6 | dir=in | app=system |
“{7B25498B-C1CA-4EAA-8A98-33A199BC5FCB}” = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
“{7EC964A7-F732-4E49-8BB6-E60CB19A3A58}” = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
“{82E66F64-746A-4A6D-B6F4-E19F28450F8A}” = rport=2869 | protocol=6 | dir=out | app=system |
“{85151710-8BE3-42CC-8683-E9EE79FA94DA}” = rport=10243 | protocol=6 | dir=out | app=system |
“{85ED14E9-0622-4847-BE70-DF76F60F6A88}” = rport=137 | protocol=17 | dir=out | app=system |
“{89849F9C-6475-4264-AA68-CDD47169141C}” = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
“{9010A5BB-2D89-4F0D-8EC5-A91DBA3FDF36}” = lport=137 | protocol=17 | dir=in | app=system |
“{928979EA-B928-4768-BD2A-B96D62699DD6}” = rport=139 | protocol=6 | dir=out | app=system |
“{9856F898-54CA-4B2C-8020-C2DF8F63A3A5}” = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
“{9B89AD4D-11D5-4AF5-ADC5-B8775B139C43}” = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
“{9C141DDF-5171-4EB0-A3E7-1457F331E29E}” = lport=138 | protocol=17 | dir=in | app=system |
“{AC954731-2798-4393-BB18-B4C97033E924}” = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
“{AF0FBA50-E259-45E6-BEAA-D6AD9FE6DACC}” = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
“{BE2B6C1A-999C-4807-BCAD-F7BCDDF51738}” = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
“{C91E1AA3-8833-494E-A8BC-3D0FBC43AC94}” = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
“{C9A5AF99-8430-42C8-8587-842FC8BF169C}” = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
“{CAC9AA06-EB53-4F00-9BFE-93000189D41B}” = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
“{D0F7BA19-FF9E-4FE6-B3A6-7A16B01640DF}” = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
“{D1446970-119D-4121-88FB-0BCBC4FAAE0D}” = lport=8398 | protocol=6 | dir=in | name=league of legends launcher |
“{D5FD95FF-A3F6-4B6E-AAB6-8FD44A4B80C0}” = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
“{E21CA391-BFA2-4BEB-A98E-F4FB7DFAB71D}” = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
“{E474C405-290C-4F1B-8400-45FBA3127511}” = lport=8398 | protocol=17 | dir=in | name=league of legends launcher |
“{E82BCB7F-B935-4D7E-A38D-56E98F0F1E17}” = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
“{E9FB0C77-6F2B-4A37-ACD3-5B3146343275}” = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
“{EA6D3053-E6DC-4360-93DB-1A09637B4225}” = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
“{F179B86B-6732-416D-A658-ABBD8038EEEF}” = rport=138 | protocol=17 | dir=out | app=system |
“{F32C3972-08F2-476F-A6FF-88F821E441D9}” = lport=2869 | protocol=6 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
“{007984A2-BA07-44DD-9CD0-7DCDEB1583C3}” = protocol=6 | dir=in | app=c:\program files\opera\pluginwrapper\opera_plugin_wrapper.exe |
“{01D3B82C-57AE-43A7-B9A1-37F98CD0AE82}” = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
“{08F5B85B-9021-4483-80AF-9D628C0FA4C9}” = protocol=6 | dir=in | app=c:\program files\steam\steamapps\cryfder\counter-strike source\hl2.exe |
“{0AEC3E8F-5B38-4CEB-8DB8-2425928A514B}” = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
“{0C891EF5-BBEA-44F4-B14C-C59EF7EDCABC}” = protocol=17 | dir=in | app=d:\programmer\world of warcraft\launcher.exe |
“{0F0E15C8-8F30-4E32-A297-B52663FEEA09}” = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\mount and blade demo\runme.exe |
“{0AA21AE6-9DFF-4E47-9079-F7DB4A359389}” = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\mountblade warband\mb_warband.exe |
“{103AA396-32AE-4F42-BE1E-17912AEB781E}” = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
“{16D9E028-9F81-4ED0-B53F-908BD461A3C7}” = protocol=6 | dir=in | app=d:\programmer\world of warcraft\launcher.exe |
“{1828F383-2D6F-4004-B4D7-6E56E86BEC0D}” = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
“{18A26CB7-4E83-43FA-AEE1-796B00F772D1}” = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
“{1C7A32FC-59EB-47AC-A490-E1794BC35A57}” = dir=in | app=c:\users\tobias\appdata\local\facebook\video\skype\facebookvideocalling.exe |
“{1CDFCC68-A4A9-4928-AEB9-83EA60443C78}” = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
“{1D878B89-6566-4493-AC6D-F321A643587E}” = protocol=17 | dir=in | app=c:\program files\steam\steamapps\cryfder\counter-strike source\hl2.exe |
“{2195755F-C0AD-4DF9-B09C-ED1A6B4EFDB3}” = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
“{22B1E047-1823-4D1D-A79B-A504DCC4890F}” = dir=in | app=c:\program files\acer arcade deluxe\homemedia\homemedia.exe |
“{2490955D-23FD-4D17-92FF-3F3FC2879EE3}” = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
“{25B5B5FF-6D95-423A-B48D-024BAC816EE1}” = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
“{2608381D-3047-4254-AFE1-A5D192A67E8E}” = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\mount and blade demo\runme.exe |
“{26EA203E-F3CC-43E6-9FDF-0FC42C39D470}” = protocol=17 | dir=in | app=c:\program files\opera\opera.exe |
“{27CAAA0D-4F95-4B07-99FF-B2B5162672C1}” = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\mountblade warband\mb_warband.exe |
“{2DE0BC3B-7BE9-4E9C-9C90-899572C47ED2}” = protocol=17 | dir=in | app=d:\programmer\world of warcraft\launcher.patch.exe |
“{309CF33F-D809-4AC2-997C-D6F329FE0B09}” = dir=in | app=c:\program files\acer arcade deluxe\playmovie\pmvservice.exe |
“{3ACEE67C-3117-4DAE-844A-A40A114B8AB9}” = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\mount and blade demo\runme.exe |
“{3B52B552-FC3B-4F7D-8767-70C03F823231}” = dir=in | app=c:\program files\acer arcade deluxe\acer arcade deluxe\acer arcade deluxe.exe |
“{3B9814A9-E779-4E7D-A598-9D2A3FDF45E3}” = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\hunting unlimited 2010\hu2010.exe |
“{3D36ACEB-2ACC-4802-B0A5-0F74FBC89683}” = protocol=6 | dir=in | app=d:\programmer\world of warcraft\launcher.exe |
“{40C81EEF-B9CD-46FD-A962-170CABC60920}” = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\mountblade warband\mb_warband.exe |
“{4100836B-5351-43F3-A3EE-C6F540F510EE}” = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
“{42C5C6F9-83C8-4F62-9F15-9D4CECEBAD81}” = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
“{45D0DB2E-77E7-414E-9E3E-AE1FA2043515}” = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
“{45F3F25E-3A0F-4B74-A4D6-5D7D6806FF10}” = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
“{466DD6AB-1AD7-420F-92A7-4C268A226E33}” = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\hunting unlimited 2010\hu2010.exe |
“{46A9395B-E394-430E-B30C-4182F7E87C68}” = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
“{477A91A3-2C29-44DC-8EF2-9DCF1EFEBA34}” = protocol=17 | dir=in | app=d:\programmer\game\thehunter.exe |
“{47B29332-F2E7-4CC7-8616-3FB30195332A}” = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
“{4BAECC93-45ED-4C6C-BB94-1CA761F50E0A}” = protocol=17 | dir=in | app=d:\programmer\world of warcraft\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe |
“{4D73CF6B-8516-4465-8885-02F85C0972AC}” = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
“{51600733-51C6-4E19-956A-93738E0A6161}” = protocol=6 | dir=in | app=d:\programmer\game\thehunter.exe |
“{5300AEF3-D7B4-4EFC-8C75-36220E271EBB}” = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe |
“{5368FCE9-E0E6-42E9-A551-41D8B0B34AD2}” = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\mountblade warband\mb_warband.exe |
“{56235B59-2F25-4661-A1F3-99C4E3CD0C98}” = dir=in | app=c:\program files\acer arcade deluxe\playmovie\playmovie.exe |
“{5ABFB401-8831-4EF2-AD90-FE5DFD18089C}” = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
“{5D0B650B-8F95-4726-86FA-C27147275237}” = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |
“{5D952730-6EDC-408B-B077-CD8C213E576F}” = protocol=6 | dir=in | app=d:\programmer\game\league of legends.exe |
“{5E483738-B4D9-4ED7-8C4B-C2DF886577FB}” = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\supermnc\binaries\win32\supermncgameclient.exe |
“{6015A878-1D9E-43D6-9315-FD4EA65A0C7E}” = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
“{6135640B-5743-42D5-A0AC-A7A57C528831}” = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
“{68CD4D5F-46A8-4FE1-A201-6F22461149E5}” = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\supermnc\binaries\win32\supermncgameclient.exe |
“{6A5659B7-A447-4408-B5D6-40BE7FB7D1E1}” = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
“{6A5AD37A-13F0-4965-81E6-6B2D1C3D51E4}” = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
“{6C4D3638-0ADD-46D8-8334-20DF1CDB9134}” = protocol=17 | dir=in | app=c:\users\tobias\appdata\local\microsoft\windows\temporary internet files\content.ie5\qpdptulm\sweetimsetup[1].exe |
“{6CC052BC-5026-48C8-93CD-0AB3995F85E6}” = protocol=17 | dir=in | app=c:\program files\opera\pluginwrapper\opera_plugin_wrapper.exe |
“{723B71EC-C45A-4DCF-BA4F-E7142FC1E3B8}” = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
“{72E0FC0B-87F7-478A-95B6-C15D07FBDAD9}” = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
“{7D1A5406-B3A2-4094-9797-1983EFB9B06A}” = protocol=17 | dir=in | app=d:\programmer\launcher\launcher.exe |
“{7DC5B208-5C6E-49A8-898E-C6494AB1AAE0}” = protocol=6 | dir=in | app=d:\programmer\world of warcraft\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe |
“{8716B01A-E187-4479-BCA2-8482D44148AB}” = protocol=17 | dir=in | app=d:\programmer\air\lolclient.exe |
“{87790F43-5B3C-41B8-B519-1F7CE5B16707}” = protocol=17 | dir=in | app=d:\programmer\game\league of legends.exe |
“{88C24C05-8B08-4401-A9EA-A8A55037C501}” = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
“{8B17BDA0-CB90-4A1C-B027-80E7C9B21443}” = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe |
“{901F9E1D-BE2A-4D62-B9CC-953BEE694EF8}” = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
“{939565BD-9557-41AD-920F-29E4059A8540}” = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe |
“{98E106D4-597A-4E4F-9EC6-5BD5FE602161}” = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
“{9A7B7979-5DCB-4FF8-BA49-C1C630D783DE}” = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\mount and blade demo\runme.exe |
“{9D04B405-9E0B-4857-998F-87F038375456}” = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
“{A109D391-2094-4179-9A75-B9572DBC5650}” = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
“{A1288E3F-7522-4EC2-85BE-77ECF17AEE12}” = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
“{A2E26977-BD91-4219-8AEA-001B8748AD25}” = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
“{A5A9F02B-4191-45D1-9BE5-D90CBFBF6410}” = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
“{AB1C22E7-3E0D-483D-9A71-208440E2ECCD}” = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
“{AB3F6D9B-357E-4C97-AC69-94B62023AC7F}” = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
“{ABE8BEA7-F228-4AEF-8A3F-FAA92B880BC9}” = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
“{ADDA31D3-D5DE-4CF5-BF39-99237693B59F}” = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
“{B00CB27A-AC7F-48E1-885C-6272FB88B51C}” = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
“{B2CDD528-6A2E-4757-931E-DB1FF0C57A55}” = protocol=6 | dir=in | app=d:\programmer\world of warcraft\launcher.patch.exe |
“{BA44AA89-C859-45ED-89CB-94EAC680B502}” = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
“{BCD90CBD-186A-4209-A9A0-67CA2826416B}” = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
“{C001C50E-4EF1-4593-9036-6FACB9067625}” = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
“{C0122066-FFCC-4359-910F-0EBA2F01399C}” = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe |
“{C2C88714-1C7A-4AE0-A503-BC32A3831555}” = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
“{C5D2D353-901D-4A75-82BC-3E7A9456EBC9}” = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
“{C8B2C784-B512-49FF-9C72-65213A8265F3}” = dir=in | app=c:\program files\skype\phone\skype.exe |
“{D138B8FC-EF44-4F23-A6DA-F916C6F4647C}” = protocol=6 | dir=in | app=c:\program files\steam\steamapps\cryfder\counter-strike source\hl2.exe |
“{D13B397C-2381-4CAD-8516-A7AF53C9A53D}” = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
“{D5CC7F6D-A574-463A-8B2B-B7F9ED92BA68}” = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
“{DA81DFB8-C6E1-4701-BC22-135622ACF0A5}” = protocol=6 | dir=in | app=c:\users\tobias\appdata\local\microsoft\windows\temporary internet files\content.ie5\qpdptulm\sweetimsetup[1].exe |
“{E0EA4187-D1DA-4711-A03B-AFD4B39A236C}” = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
“{E385459E-0CB4-4618-ACB1-159D45B0ECDE}” = protocol=17 | dir=in | app=d:\programmer\world of warcraft\launcher.exe |
“{E3BB2AFD-5AD0-4FC7-B2C2-78A1D7969ECF}” = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
“{E5D4A0B6-4E9D-4E9B-8DDE-2CE021E5E72D}” = protocol=6 | dir=out | app=system |
“{F2319AFB-7630-4E28-B155-8D3EDB9F9C75}” = protocol=6 | dir=in | app=d:\programmer\air\lolclient.exe |
“{F9C68820-6197-4CE3-8431-6812BCDD2019}” = protocol=6 | dir=in | app=c:\program files\opera\opera.exe |
“{FFBCD2BC-B38F-4649-BC7D-5E645C18D8FC}” = protocol=6 | dir=in | app=d:\programmer\launcher\launcher.exe |
“{FFFBA5EA-7608-4A31-AFE6-529E8A3B4372}” = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
“{FAA11EF9-04A6-4A4B-913F-93D7B925564F}” = protocol=17 | dir=in | app=c:\program files\steam\steamapps\cryfder\counter-strike source\hl2.exe |
“TCP Query User{1FDDE895-E1E7-438B-ABE6-03B70432A8C9}D:\programmer\warcraft iii\war3.exe” = protocol=6 | dir=in | app=d:\programmer\warcraft iii\war3.exe |
“TCP Query User{23DD6317-3E6A-43C7-9206-C2BDF1FB68F5}D:\programmer\world of warcraft\launcher.patch.exe” = protocol=6 | dir=in | app=d:\programmer\world of warcraft\launcher.patch.exe |
“TCP Query User{2D5C23A2-B56A-43C0-9897-85EECBEE4E4F}D:\programmer\world of warcraft\temp\wow-4.0.1.2210-enus-tools-downloader.exe” = protocol=6 | dir=in | app=d:\programmer\world of warcraft\temp\wow-4.0.1.2210-enus-tools-downloader.exe |
“TCP Query User{386788A6-70D2-4474-8BAD-15AFAF4E6A1E}C:\aeriagames\wolfteam\wolfteam.bin” = protocol=6 | dir=in | app=c:\aeriagames\wolfteam\wolfteam.bin |
“TCP Query User{3C8BD010-E9B9-4089-8733-B9040310D7FB}C:\windows\system32\java.exe” = protocol=6 | dir=in | app=c:\windows\system32\java.exe |
“TCP Query User{40F7AE5E-9AD0-41C6-8EF9-FA143292BA26}D:\programmer\lol.launcher.exe” = protocol=6 | dir=in | app=d:\programmer\lol.launcher.exe |
“TCP Query User{4A93E907-F659-4124-A1A4-56186F1B21FE}C:\program files\java\jre6\bin\javaw.exe” = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
“TCP Query User{52ADE924-4CC0-44C6-B1D1-4127CAA1DA76}C:\users\tobias\desktop\vuze\azureus.exe” = protocol=6 | dir=in | app=c:\users\tobias\desktop\vuze\azureus.exe |
“TCP Query User{5DE87122-EE49-440B-A3D7-5334B00EE968}C:\users\tobias\desktop\warcraft 3 crack\warcraft 1,2\war3.exe” = protocol=6 | dir=in | app=c:\users\tobias\desktop\warcraft 3 crack\warcraft 1,2\war3.exe |
“TCP Query User{60FB260D-CAD6-4F51-8A9E-6643D58F5AED}D:\programmer\world of warcraft\temp\wow-4.0.1.2120-enus-tools-downloader.exe” = protocol=6 | dir=in | app=d:\programmer\world of warcraft\temp\wow-4.0.1.2120-enus-tools-downloader.exe |
“TCP Query User{64BD5EBF-9106-4973-9C1C-F8CDE501E773}D:\programmer\world of warcraft\temp\wow-4.2.0.2552-enus-tools-downloader.exe” = protocol=6 | dir=in | app=d:\programmer\world of warcraft\temp\wow-4.2.0.2552-enus-tools-downloader.exe |
“TCP Query User{697E5FEB-C9E3-4FC5-A8B9-ECA6B97D844C}C:\aeriagames\wolfteam\wolfteam.bin” = protocol=6 | dir=in | app=c:\aeriagames\wolfteam\wolfteam.bin |
“TCP Query User{6C365355-7FF2-42E6-80AE-801C3D4CDCD6}C:\program files\opera\opera.exe” = protocol=6 | dir=in | app=c:\program files\opera\opera.exe |
“TCP Query User{754BC630-2EA8-430F-99FB-EB6574DF77FD}C:\users\tobias\program files\dna\btdna.exe” = protocol=6 | dir=in | app=c:\users\tobias\program files\dna\btdna.exe |
“TCP Query User{85F3DFFD-0D37-4195-B0DA-34252AA2D637}C:\program files\internet explorer\iexplore.exe” = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
“TCP Query User{95199F16-5CAF-4FC7-8AB3-56651E43A9C9}C:\program files\tmnationsforever\tmforever.exe” = protocol=6 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
“TCP Query User{A294248F-3E35-4CED-9DB9-1E566ED0BC7A}C:\program files\steam\steamapps\cryfder\team fortress 2\hl2.exe” = protocol=6 | dir=in | app=c:\program files\steam\steamapps\cryfder\team fortress 2\hl2.exe |
“TCP Query User{ADB93FA2-2D28-479A-B625-5086219591E1}D:\programmer\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe” = protocol=6 | dir=in | app=d:\programmer\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe |
“TCP Query User{B14E31A1-8B49-4AC9-A853-28701200F326}F:\warcraft 3 crack\warcraft 1,2\war3.exe” = protocol=6 | dir=in | app=f:\warcraft 3 crack\warcraft 1,2\war3.exe |
“TCP Query User{BA2507F5-B128-4297-9BE1-87BE83AA8454}C:\users\tobias\desktop\random unused genveje\vuze\azureus.exe” = protocol=6 | dir=in | app=c:\users\tobias\desktop\random unused genveje\vuze\azureus.exe |
“TCP Query User{D376FCA1-FF6D-4548-A2F1-F0FDF445B872}D:\programmer\warcraft iii\war3.exe” = protocol=6 | dir=in | app=d:\programmer\warcraft iii\war3.exe |
“TCP Query User{E8F94B3F-616E-48E1-88BA-481F976C4EE5}C:\program files\tmnationsforever\tmforever.exe” = protocol=6 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
“TCP Query User{F318ADD6-EA4D-420F-87E1-5EDEC0722DFE}D:\programmer\world of warcraft\backgrounddownloader.exe” = protocol=6 | dir=in | app=d:\programmer\world of warcraft\backgrounddownloader.exe |
“TCP Query User{F90BC08A-A861-4167-B6F9-B242B9159105}C:\users\tobias\desktop\ting\warcraft 3 crack\warcraft 1,2\war3.exe” = protocol=6 | dir=in | app=c:\users\tobias\desktop\ting\warcraft 3 crack\warcraft 1,2\war3.exe |
“TCP Query User{FA5F135C-EFC7-4888-87E5-4FF258531543}C:\users\tobias\program files\dna\btdna.exe” = protocol=6 | dir=in | app=c:\users\tobias\program files\dna\btdna.exe |
“UDP Query User{01D38E8E-05C1-413E-9C37-C5F2DAFAC390}D:\programmer\warcraft iii\war3.exe” = protocol=17 | dir=in | app=d:\programmer\warcraft iii\war3.exe |
“UDP Query User{23F51FA8-63AB-4DD8-A81A-E76F484EA8A1}D:\programmer\warcraft iii\war3.exe” = protocol=17 | dir=in | app=d:\programmer\warcraft iii\war3.exe |
“UDP Query User{2F08FAF0-56C4-4731-A3D9-D2D97EA112A6}C:\aeriagames\wolfteam\wolfteam.bin” = protocol=17 | dir=in | app=c:\aeriagames\wolfteam\wolfteam.bin |
“UDP Query User{31512FF3-240F-4858-8171-68FC921E82D8}C:\program files\tmnationsforever\tmforever.exe” = protocol=17 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
“UDP Query User{31B9C355-A9B0-4566-9AF7-730B4236F267}C:\program files\internet explorer\iexplore.exe” = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
“UDP Query User{40A97A43-4B40-4054-8AD6-66EC68F8663F}C:\users\tobias\program files\dna\btdna.exe” = protocol=17 | dir=in | app=c:\users\tobias\program files\dna\btdna.exe |
“UDP Query User{4ABE9100-BBB0-437F-B0E2-57F4482D5B9E}D:\programmer\world of warcraft\temp\wow-4.0.1.2120-enus-tools-downloader.exe” = protocol=17 | dir=in | app=d:\programmer\world of warcraft\temp\wow-4.0.1.2120-enus-tools-downloader.exe |
“UDP Query User{4F374372-8E6D-4EC8-85BC-13C136E8989F}D:\programmer\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe” = protocol=17 | dir=in | app=d:\programmer\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe |
“UDP Query User{51D7251B-1049-4DA1-8DAF-66126B561E0B}D:\programmer\lol.launcher.exe” = protocol=17 | dir=in | app=d:\programmer\lol.launcher.exe |
“UDP Query User{5746DBB8-0336-45F7-B460-845884D4F7B2}C:\program files\java\jre6\bin\javaw.exe” = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
“UDP Query User{688A0BF9-76CE-4A6A-94DA-E9417306871E}C:\users\tobias\desktop\random unused genveje\vuze\azureus.exe” = protocol=17 | dir=in | app=c:\users\tobias\desktop\random unused genveje\vuze\azureus.exe |
“UDP Query User{79BD6E67-FE46-4154-A642-606374073463}C:\program files\opera\opera.exe” = protocol=17 | dir=in | app=c:\program files\opera\opera.exe |
“UDP Query User{90E1626D-3ADF-4FE0-B5B0-3B1C59C817EA}D:\programmer\world of warcraft\temp\wow-4.0.1.2210-enus-tools-downloader.exe” = protocol=17 | dir=in | app=d:\programmer\world of warcraft\temp\wow-4.0.1.2210-enus-tools-downloader.exe |
“UDP Query User{9C3F36AA-9D39-4FAC-AF49-3C3866622B46}C:\users\tobias\desktop\warcraft 3 crack\warcraft 1,2\war3.exe” = protocol=17 | dir=in | app=c:\users\tobias\desktop\warcraft 3 crack\warcraft 1,2\war3.exe |
“UDP Query User{AD26702F-9C9E-4E7E-B4F8-506BB772959F}F:\warcraft 3 crack\warcraft 1,2\war3.exe” = protocol=17 | dir=in | app=f:\warcraft 3 crack\warcraft 1,2\war3.exe |
“UDP Query User{AD311D76-E91B-47DF-AC19-F7A7B46DAEEF}C:\aeriagames\wolfteam\wolfteam.bin” = protocol=17 | dir=in | app=c:\aeriagames\wolfteam\wolfteam.bin |
“UDP Query User{BABD4B26-2D07-49D8-9BE1-AF8EB5BE9CB0}D:\programmer\world of warcraft\launcher.patch.exe” = protocol=17 | dir=in | app=d:\programmer\world of warcraft\launcher.patch.exe |
“UDP Query User{CFCAEF21-3395-40FE-B17F-6B1A8FD22D43}C:\users\tobias\desktop\ting\warcraft 3 crack\warcraft 1,2\war3.exe” = protocol=17 | dir=in | app=c:\users\tobias\desktop\ting\warcraft 3 crack\warcraft 1,2\war3.exe |
“UDP Query User{D5364494-8CBE-4EF7-B72D-E8BA505AC6F8}C:\program files\tmnationsforever\tmforever.exe” = protocol=17 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
“UDP Query User{D5885F5A-18C9-4D91-9131-452C13EAF025}C:\windows\system32\java.exe” = protocol=17 | dir=in | app=c:\windows\system32\java.exe |
“UDP Query User{D58D76DE-530B-4453-8F3A-0682C66A4EE5}C:\users\tobias\desktop\vuze\azureus.exe” = protocol=17 | dir=in | app=c:\users\tobias\desktop\vuze\azureus.exe |
“UDP Query User{E0ED39F1-BE22-423F-B6B5-B43F07B3441E}D:\programmer\world of warcraft\temp\wow-4.2.0.2552-enus-tools-downloader.exe” = protocol=17 | dir=in | app=d:\programmer\world of warcraft\temp\wow-4.2.0.2552-enus-tools-downloader.exe |
“UDP Query User{E4C4366C-5866-4025-AB6F-648EBD30DD1B}D:\programmer\world of warcraft\backgrounddownloader.exe” = protocol=17 | dir=in | app=d:\programmer\world of warcraft\backgrounddownloader.exe |
“UDP Query User{EAF9EBA9-11DA-4CF2-99B6-5E3B46D5EA6D}C:\program files\steam\steamapps\cryfder\team fortress 2\hl2.exe” = protocol=17 | dir=in | app=c:\program files\steam\steamapps\cryfder\team fortress 2\hl2.exe |
“UDP Query User{FDCC759E-C65E-49AB-900F-22DB9DD625CF}C:\users\tobias\program files\dna\btdna.exe” = protocol=17 | dir=in | app=c:\users\tobias\program files\dna\btdna.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
“{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}” = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
“{048298C9-A4D3-490B-9FF9-AB023A9238F3}” = Steam
“{060AAE5B-9455-4D30-E03C-41442C580A47}” = Catalyst Control Center Localization Polish
“{0E44E447-6ED1-B31B-E0C6-E0A8533762C9}” = CCC Help German
“{0E592AF6-6381-0BD5-1990-44366C40282A}” = CCC Help Danish
“{0E64B098-8018-4256-BA23-C316A43AD9B0}” = QuickTime
“{10F498FF-5392-4DF3-8F73-FE172A9F3800}” = Winbond CIR Device Drivers
“{11316260-6666-467B-AC34-183FCB5D4335}” = Acer Mobility Center Plug-In
“{122ADF8C-DDA1-480C-9936-C88F2825B265}” = Apple Application Support
“{12EFA1A4-AC3B-443C-8143-237EDE760403}” = NTI Backup Now Standard
“{13D85C14-2B85-419F-AC41-C7F21E68B25D}” = Acer eSettings Management
“{15D967B5-A4BE-42AE-9E84-64CD062B25AA}” = eSobi v2
“{178832DE-9DE0-4C87-9F82-9315A9B03985}” = Windows Live Writer
“{179C56A4-F57F-4561-8BBF-F911D26EB435}” = WebReg
“{18455581-E099-4BA8-BC6B-F34B2F06600C}” = Google Toolbar for Internet Explorer
“{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}” = YouTube Downloader 2.6.3
“{205C6BDD-7B73-42DE-8505-9A093F35A238}” = Overførselsværktøj til Windows Live
“{222E0321-4496-CD3B-71BE-BBFCB4A09A3A}” = Catalyst Control Center Localization Chinese Standard
“{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}” = MSVCRT
“{2318C2B1-4965-11d4-9B18-009027A5CD4F}” = Google Toolbar for Internet Explorer
“{2413930C-8309-47A6-BC61-5EF27A4222BC}” = NTI Media Maker 8
“{2637C347-9DAD-11D6-9EA2-00055D0CA761}” = Acer Arcade Deluxe
“{26A24AE4-039D-4CA4-87B4-2F83216033FF}” = Java(TM) 6 Update 33
“{29D1E00F-2447-6D6A-C552-1E7F5A6449EA}” = Catalyst Control Center Graphics Full New
“{2A66D903-1ED8-D5CF-6A13-4ADF3D7ECD05}” = Catalyst Control Center Localization Norwegian
“{3108C217-BE83-42E4-AE9E-A56A2A92E549}” = Atheros Communications Inc.(R) AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
“{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}” = Windows Live Communications Platform
“{31C09120-6DDC-787F-7255-967B81777C7E}” = CCC Help Polish
“{32FC88B4-52B5-86FA-3E61-5E3AD43855D2}” = CCC Help Chinese Traditional
“{3329E4B5-8A30-1A98-5E87-1811857AD34A}” = Catalyst Control Center Localization Chinese Traditional
“{35C0A1E4-D02A-412C-841F-266DBB116ABB}” = Intel(R) PROSet/Wireless WiFi software
“{3BDC4390-55D4-CC3E-7D4F-399F7D3D64F3}” = CCC Help Chinese Standard
“{3C3901C5-3455-3E0A-A214-0B093A5070A6}” = Microsoft .NET Framework 4 Client Profile
“{425640DF-10DB-F749-5ACE-41F5E00D3155}” = CCC Help Portuguese
“{45338B07-A236-4270-9A77-EBB4115517B5}” = Windows Live Sign-in Assistant
“{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}” = Windows Live Essentials
“{4A03706F-666A-4037-7777-5F2748764D10}” = Java Auto Updater
“{4E646581-8E6D-B265-8894-E4E569572655}” = CCC Help Czech
“{51B4EC5E-25AD-077B-CEAE-B882F23FB605}” = Catalyst Control Center Graphics Previews Vista
“{56EEFA3A-9E17-9922-68C8-FD1BD151AE65}” = ccc-utility
“{57265292-228A-41FA-9AEC-4620CBCC2739}” = Acer eAudio Management
“{58E5844B-7CE2-413D-83D1-99294BF6C74F}” = Acer ePower Management
“{59C80C5E-8C92-40FF-B910-2BB5C7281F61}” = Europa Universalis III
“{5B63A470-9334-44D1-AF61-6CE2DB565AE9}” = Orion
“{5D37080C-C718-87B4-2BCE-E04D23402BF0}” = CCC Help Norwegian
“{5DE17717-8B56-25F2-FB34-9AF121FA8167}” = Catalyst Control Center Core Implementation
“{6009F2FC-EC56-4e28-B91C-0BA5104D6419}” = SF_CDA_Software
“{60DF23EB-65DC-6933-C0DE-87D7F305A933}” = CCC Help Russian
“{61BF161D-B3CF-B966-DFE2-D36A74FE2FD3}” = CCC Help Thai
“{6412CECE-8172-4BE5-935B-6CECACD2CA87}” = Windows Live Mail
“{6A85F81E-9285-0964-BC23-714FC45263D0}” = CCC Help Greek
“{6AD9F5F3-5BD0-4000-BD9C-B536CF86D988}” = iTunes
“{6B58131B-E1C3-9FC8-160C-C1E01B200C94}” = ATI Catalyst Install Manager
“{6BD84F7F-660E-02B0-D324-A15456320EDA}” = Catalyst Control Center InstallProxy
“{6C309974-85FF-6875-0DA8-FD3C2B399DC4}” = Catalyst Control Center Localization Spanish
“{6E3970FD-8A5E-A3A1-4E7E-71F8C49DFF63}” = Catalyst Control Center Localization Portuguese
“{6F9DF109-4D98-46e1-BCE8-8EB6AA1DBF35}” = Microsoft Works
“{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}” = Microsoft Visual C++ 2005 Redistributable
“{71C2828F-2678-4675-BDEC-895424861262}_is1” = C:\Program Files\Acer GameZone\GameConsole
“{72291519-2DCA-BA30-798F-48C4E64E2313}” = Catalyst Control Center Localization Czech
“{7299052b-02a4-4627-81f2-1818da5d550d}” = Microsoft Visual C++ 2005 Redistributable
“{72BFF3AC-28AC-27EA-6FBD-5B2D14FEFCC7}” = Catalyst Control Center Localization French
“{734DCD79-13DA-855A-0EFB-83CE364C3452}” = CCC Help Dutch
“{751AB006-C405-3CB4-7827-86882BF1BA51}” = Catalyst Control Center Localization Korean
“{75CFDE75-80CA-E0AF-7A29-98E57C0C81EF}” = Skins
“{770657D0-A123-3C07-8E44-1C83EC895118}” = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
“{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}” = Apple Software Update
“{79155F2B-9895-49D7-8612-D92580E0DE5B}” = Bonjour
“{79BFBCBB-2085-5908-FF53-7BB34CE952B7}” = CCC Help Swedish
“{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}” = Acer ScreenSaver
“{7B260281-BD06-400C-F51A-3FEB65108CB8}” = CCC Help Hungarian
“{7B268071-3D05-DBBF-3B44-59B7857D408F}” = Catalyst Control Center Localization Turkish
“{7CAC6A44-C3DE-4153-ACA6-7524602C789E}” = Facebook Video Calling 1.2.0.159
“{7CEA1D61-541E-4BE3-8537-587085049358}” = ICIDU NI-707522 Wireless N Client Utility Installation Program
“{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110082360}” = Alien Shooter
“{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110209593}” = Chicken Invaders 2
“{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110422467}” = Tiks Texas Hold em
“{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}” = Cake Mania
“{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}” = Galapago
“{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111796363}” = Mystery Solitaire - Secret Island
“{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111940693}” = Bookworm Adventures
“{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112028410}” = Putt Mania
“{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112548397}” = The Rise of Atlantis
“{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}” = Alice Greenfingers
“{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113786380}” = Heroes of Hellas
“{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}” = Dream Day First Home
“{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113848220}” = Agatha Christie Peril at End House
“{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113919217}” = Mythic Mahjong
“{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-114072167}” = Go-Go Gourmet
“{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11408540}” = Magic Match Adventures
“{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-114086870}” = Womens Murder Club
“{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-114717227}” = Magic Farm
“{83D87171-666D-3D0C-8346-6D7AE6EACDF8}” = Catalyst Control Center Localization Hungarian
“{85EB55AA-7CB2-5BF1-14E3-07CA055D2020}” = CCC Help Italian
“{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}” = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
“{8875D8E2-F967-AD9C-5738-7BBC8EF482D7}” = Catalyst Control Center Localization Thai
“{89E26372-ED92-510E-7911-161F8F55E677}” = CCC Help English
“{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}” = Microsoft Silverlight
“{8E5233E1-7495-44FB-8DEB-4BE906D59619}” = Junk Mail filter update
“{8F1ADE4D-EFAC-4F5A-B346-23C2687FAF50}” = Apple Mobile Device Support
“{8F1B6239-FEA0-450A-A950-B05276CE177C}” = Acer Empowering Technology
“{8F3B6BD9-781B-4226-BB8F-9C1707B91C0A}” = Politikens Tysk-Dansk Dansk-Tysk Ordbog
“{90120000-0016-0406-0000-0000000FF1CE}” = Microsoft Office Excel MUI (Danish) 2007
“{90120000-0016-0406-0000-0000000FF1CE}_HOMESTUDENTR_{8D25149C-FFF5-42E1-BF6D-1CED49BDB182}” = Microsoft Office 2007 Service Pack 3 (SP3)
“{90120000-0018-0406-0000-0000000FF1CE}” = Microsoft Office PowerPoint MUI (Danish) 2007
“{90120000-0018-0406-0000-0000000FF1CE}_HOMESTUDENTR_{8D25149C-FFF5-42E1-BF6D-1CED49BDB182}” = Microsoft Office 2007 Service Pack 3 (SP3)
“{90120000-001B-0406-0000-0000000FF1CE}” = Microsoft Office Word MUI (Danish) 2007
“{90120000-001B-0406-0000-0000000FF1CE}_HOMESTUDENTR_{8D25149C-FFF5-42E1-BF6D-1CED49BDB182}” = Microsoft Office 2007 Service Pack 3 (SP3)
“{90120000-001F-0406-0000-0000000FF1CE}” = Microsoft Office Proof (Danish) 2007
“{90120000-001F-0406-0000-0000000FF1CE}_HOMESTUDENTR_{8F771259-9037-4097-AA88-8613F3BE5627}” = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
“{90120000-001F-0407-0000-0000000FF1CE}” = Microsoft Office Proof (German) 2007
“{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{928D7B99-2BEA-49F9-83B8-20FA57860643}” = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
“{90120000-001F-0409-0000-0000000FF1CE}” = Microsoft Office Proof (English) 2007
“{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}” = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
“{90120000-002C-0406-0000-0000000FF1CE}” = Microsoft Office Proofing (Danish) 2007
“{90120000-006E-0406-0000-0000000FF1CE}” = Microsoft Office Shared MUI (Danish) 2007
“{90120000-006E-0406-0000-0000000FF1CE}_HOMESTUDENTR_{11584158-91C7-4B1B-BFD1-F47D680F13CF}” = Microsoft Office 2007 Service Pack 3 (SP3)
“{90120000-00A1-0406-0000-0000000FF1CE}” = Microsoft Office OneNote MUI (Danish) 2007
“{90120000-00A1-0406-0000-0000000FF1CE}_HOMESTUDENTR_{8D25149C-FFF5-42E1-BF6D-1CED49BDB182}” = Microsoft Office 2007 Service Pack 3 (SP3)
“{90140000-2005-0000-0000-0000000FF1CE}” = Microsoft Office File Validation Add-In
“{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}” = Intel® Matrix Storage Manager
“{91120000-002F-0000-0000-0000000FF1CE}” = Microsoft Office Home and Student 2007
“{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}” = Microsoft Office 2007 Service Pack 3 (SP3)
“{918A9082-6287-4D25-9002-5E5D5E4971CB}” = League of Legends
“{92606477-9366-4D3B-8AE3-6BE4B29727AB}” = League of Legends
“{926BD0E8-24A3-41D2-AF9B-340F1A37ED12}” = MobileMe Control Panel
“{94EED5A2-2464-3468-1674-DE5948D933B4}” = Catalyst Control Center Localization Danish
“{95120000-00B9-0409-0000-0000000FF1CE}” = Microsoft Application Error Reporting
“{95156C6A-B0D1-4AA7-0513-D733BEEBBC18}” = CCC Help Japanese
“{9718521B-A345-4ad9-A52B-74D1435FB708}” = SF_CDA_ProductContext
“{980A182F-E0A2-4A40-94C1-AE0C1235902E}” = Pando Media Booster
“{981DE354-9301-440f-AAFC-025AA2354A93}” = HP Deskjet & Photosmart Printer Driver Software 8.0.A
“{9A25302D-30C0-39D9-BD6F-21E6EC160475}” = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
“{9BE518E6-ECC6-35A9-88E4-87755C07200F}” = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
“{9DF0196F-B6B8-4C3A-8790-DE42AA530101}” = SPORE™
“{A511966D-B370-4AD8-597A-9CF792F943C9}” = CCC Help Finnish
“{A5633652-3795-4829-BB0B-644F0279E279}” = Acer eDataSecurity Management
“{A77255C4-AFCB-44A3-BF0F-2091A71FFD9E}” = Acer Crystal Eye Webcam 2.0.8
“{A8B94669-8654-4126-BD28-D0D2412CDED6}” = TI Connect 1.6
“{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}” = Google Update Helper
“{AC76BA86-7AD7-1033-7B44-A94000000001}” = Adobe Reader 9.4.0
“{AE9EF716-D8C6-3854-9221-546B03005611}” = ccc-core-static
“{B00A7D65-6C5C-7A14-A22F-D52DD7798AB3}” = Catalyst Control Center Localization Japanese
“{B10914FD-8812-47A4-85A1-50FCDE7F1F33}” = Windows Live Sync
“{B1541910-5E93-0610-A8E5-FC9170D1A4F8}” = CCC Help Spanish
“{B1CE6512-B757-0283-6C06-5A58B295A0E7}” = CCC Help Turkish
“{B24C006F-470C-91A5-1AFA-F16EEFE0CD7A}” = Catalyst Control Center Localization Italian
“{B2544A03-10D0-4E5E-BA69-0362FFC20D18}” = OGA Notifier 2.0.0048.0
“{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}” = Windows Live Messenger
“{B69349AE-2D41-3708-8BA4-4DC22645CA04}” = Microsoft .NET Framework 3.5 Language Pack SP1 - dan
“{B6CF2967-C81E-40C0-9815-C05774FEF120}” = Skype Toolbars
“{BC1280C0-7FA5-2434-5820-26352484E790}” = Catalyst Control Center Graphics Light
“{BE77A81F-B315-4666-9BF3-AE70C0ADB057}” = BufferChm
“{C05EEF5D-DBA7-46E3-546F-4DEB8C26B261}” = CCC Help Korean
“{C716522C-3731-4667-8579-40B098294500}” = Toolbox
“{C779648B-410E-4BBA-B75B-5815BCEFE71D}” = Safari
“{C7D35D4A-18A4-1853-2E43-6AC00FCDEE3A}” = Catalyst Control Center Localization Russian
“{CB099890-1D5F-11D5-9EA9-0050BAE317E1}” = CyberLink PowerDirector
“{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}” = SUPERAntiSpyware
“{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}” = Microsoft .NET Framework 3.5 SP1
“{D36DD326-7280-11D8-97C8-000129760CBE}” = PhotoNow!
“{D6F879CC-59D6-4D4B-AE9B-D761E48D25ED}” = Skype™ 5.3
“{D704735D-9558-C09C-07BC-DD6259D3ED83}” = Catalyst Control Center Localization Dutch
“{DA20E1A8-07CB-4EE7-9B72-A7E28C953F0E}” = Acer Product Registration
“{DA7DF8E2-4B8F-4286-97FE-DE3FFFE9B728}” = iCloud
“{DC24971E-1946-445D-8A82-CE685433FA7D}” = Realtek USB 2.0 Card Reader
“{DCA87C0C-DC10-C275-384E-B7C85A0145AC}” = CCC Help French
“{DE12C2CE-11A1-789A-9BF6-8A7212FBA668}” = Catalyst Control Center Localization Greek
“{E06F04B9-45E6-4AC0-8083-85F7515F40F7}” = UnloadSupport
“{E08F6426-8A5F-115D-744F-E38B9426E3EE}” = Catalyst Control Center Localization Swedish
“{E2019D64-E819-3B4F-9C85-95BE2688ABF9}” = Microsoft .NET Framework 4 Client Profile DAN Language Pack
“{E2A97415-BD97-4867-B906-05E39E9EE51F}” = HL-2270DW
“{E4C774A3-D902-4A42-D5A8-09B07D5568C1}” = Catalyst Control Center Graphics Full Existing
“{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}” = Microsoft Office Suite Activation Assistant
“{E6158D07-2637-4ECF-B576-37C489669174}” = Windows Live Call
“{EE39FFBD-544E-49E4-A999-6819828EAE91}” = Windows Live Photo Gallery
“{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}” = Microsoft SQL Server 2005 Compact Edition [ENU]
“{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}” = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
“{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}” = Microsoft Choice Guard
“{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}” = Realtek High Definition Audio Driver
“{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}” = 32 Bit HP CIO Components Installer
“{F65931E9-22ED-98E3-D540-C78FBC36144F}” = Catalyst Control Center Localization Finnish
“{FA95AFFE-6299-40F7-A763-7208461F4DC0}” = Politikens Engelskordbog
“{FD2F10F2-BC65-0CAB-A26A-51AFFED6012A}” = Catalyst Control Center Localization German
“{FE23D063-934D-4829-A0D8-00634CE79B4A}” = Adobe AIR
“{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}” = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
“Adobe AIR” = Adobe AIR
“Adobe Flash Player ActiveX” = Adobe Flash Player 11 ActiveX
“Adobe Flash Player Plugin” = Adobe Flash Player 11 Plugin
“Adobe Shockwave Player” = Adobe Shockwave Player 11.5
“BullGuard” = BullGuard 9.0
“CCleaner” = CCleaner
“CNXT_MODEM_HDA_HSF” = HDAUDIO Soft Data Fax Modem with SmartCP
“Debut” = Debut Video Capture Software
“Diablo II” = Diablo II
“ESET Online Scanner” = ESET Online Scanner v3
“Fraps” = Fraps
“Free Audio CD Burner_is1” = Free Audio CD Burner version 1.4
“Free DVD Video Converter_is1” = Free DVD Video Converter version 1.5.12
“Free Studio_is1” = Free Studio version 5.2.1
“Free YouTube to iPod Converter_is1” = Free YouTube to iPod Converter version 3.9.27
“Free YouTube to MP3 Converter_is1” = Free YouTube to MP3 Converter version 3.9
“Google Chrome” = Google Chrome
“Google Desktop” = Google Desktop
“GridVista” = Acer GridVista
“HijackThis” = HijackThis 2.0.2
“HOMESTUDENTR” = Microsoft Office Home and Student 2007
“hon” = Heroes of Newerth
“Huawei Modems” = Huawei modem
“InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}” = NTI Backup Now 5
“InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}” = eSobi v2
“InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}” = NTI Media Maker 8
“InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}” = Acer Arcade Deluxe
“InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}” = CyberLink PowerDirector
“LEGO Racers” = LEGO Racers
“LManager” = Launch Manager
“Malwarebytes’ Anti-Malware_is1” = Malwarebytes Anti-Malware version 1.62.0.1300
“ManyCam” = ManyCam 2.4 (remove only)
“Microsoft .NET Framework 4 Client Profile” = Microsoft .NET Framework 4 Client Profile
“Microsoft .NET Framework 4 Client Profile DAN Language Pack” = Microsoft .NET Framework 4 Client Profile DAN sprogpakke
“Native Instruments Guitar Combos Behringer Edition” = Native Instruments Guitar Combos Behringer Edition
“Opera 12.00.1467” = Opera 12.00
“ProInst” = Intel PROSet Wireless
“ST5UNST #1” = ENIGMA
“Stamp” = Stamp ID3 Tag Editor
“Steam App 10180” = Call of Duty: Modern Warfare 2
“Steam App 10190” = Call of Duty: Modern Warfare 2 - Multiplayer
“Steam App 113420” = Fallen Earth
“Steam App 12690” = Hunting Unlimited 2010
“Steam App 22110” = Mount & Blade Demo
“Steam App 240” = Counter-Strike: Source
“Steam App 440” = Team Fortress 2
“Steam App 48700” = Mount & Blade: Warband
“Steam App 630” = Alien Swarm
“Steam App 9880” = Champions Online: Free For All
“SynTPDeinstKey” = Synaptics Pointing Device Driver
“theHunter” = theHunter (remove only)
“TI-Black Link” = TI-Black Link
“TI-Graph Link 89” = TI-Graph Link 89
“TmNationsForever_is1” = TmNationsForever
“Uninstall_is1” = Uninstall 1.0.0.1
“USB_AUDIO_DEusb-audio.deBehringer2902” = BEHRINGER USB AUDIO DRIVER
“Warcraft III” = Warcraft III
“WinLiveSuite_Wave3” = Windows Live Essentials
“WolfTeam” = WolfTeam
“World of Warcraft” = World of Warcraft
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-3335635223-1391227600-2490444171-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
“Diablo II” = Diablo II
“GeoGebra 4” = GeoGebra 4
“GeoGebraPrim” = GeoGebraPrim
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 12-07-2012 07:44:34 | Computer Name = Tobias-PC | Source = WinMgmt | ID = 10
Description =
Error - 12-07-2012 07:44:49 | Computer Name = Tobias-PC | Source = System Restore | ID = 8203
Description =
Error - 12-07-2012 07:44:58 | Computer Name = Tobias-PC | Source = EventSystem | ID = 4609
Description =
Error - 13-07-2012 04:58:24 | Computer Name = Tobias-PC | Source = WinMgmt | ID = 10
Description =
Error - 13-07-2012 05:02:23 | Computer Name = Tobias-PC | Source = Application Error | ID = 1000
Description = Program med fejl PLFSetI.exe, version 1.0.1.0, tidsstempel 0x471d62d0,
modul med fejl PLFSetI.exe, version 1.0.1.0, tidsstempel 0x471d62d0, undtagelseskode
0xc0000005, forskydning med fejl 0x00001afe, proces-id 0x518, programmets starttidspunkt
0x01cd60d5fc2600f0.
Error - 13-07-2012 08:44:44 | Computer Name = Tobias-PC | Source = EventSystem | ID = 4621
Description =
Error - 13-07-2012 08:54:12 | Computer Name = Tobias-PC | Source = WinMgmt | ID = 10
Description =
Error - 13-07-2012 09:00:04 | Computer Name = Tobias-PC | Source = Application Error | ID = 1000
Description = Program med fejl PLFSetI.exe, version 1.0.1.0, tidsstempel 0x471d62d0,
modul med fejl PLFSetI.exe, version 1.0.1.0, tidsstempel 0x471d62d0, undtagelseskode
0xc0000005, forskydning med fejl 0x00001afe, proces-id 0x1094, programmets starttidspunkt
0x01cd60f75ea2a4b4.
Error - 13-07-2012 15:00:07 | Computer Name = Tobias-PC | Source = WinMgmt | ID = 10
Description =
Error - 13-07-2012 15:14:57 | Computer Name = Tobias-PC | Source = Application Error | ID = 1000
Description = Program med fejl PLFSetI.exe, version 1.0.1.0, tidsstempel 0x471d62d0,
modul med fejl PLFSetI.exe, version 1.0.1.0, tidsstempel 0x471d62d0, undtagelseskode
0xc0000005, forskydning med fejl 0x00001afe, proces-id 0x11b0, programmets starttidspunkt
0x01cd612bc0f28bad.
[ OSession Events ]
Error - 06-09-2011 10:30:25 | Computer Name = Tobias-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2170
seconds with 480 seconds of active time. This session ended with a crash.
Error - 14-10-2011 05:09:25 | Computer Name = Tobias-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session
lasted 755 seconds with 300 seconds of active time. This session ended with a crash.
Error - 08-11-2011 06:03:31 | Computer Name = Tobias-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 59158
seconds with 6420 seconds of active time. This session ended with a crash.
Error - 08-11-2011 11:31:50 | Computer Name = Tobias-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 3475
seconds with 1500 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 13-07-2012 14:13:02 | Computer Name = Tobias-PC | Source = Ntfs | ID = 262199
Description = Filstrukturen på disken er beskadiget og ubrugelig. Kør tilbehørsprogrammet
chkdsk på diskenheden C:.
Error - 13-07-2012 14:13:08 | Computer Name = Tobias-PC | Source = Ntfs | ID = 262199
Description = Filstrukturen på disken er beskadiget og ubrugelig. Kør tilbehørsprogrammet
chkdsk på diskenheden ACER.
Error - 13-07-2012 14:13:28 | Computer Name = Tobias-PC | Source = Ntfs | ID = 262199
Description = Filstrukturen på disken er beskadiget og ubrugelig. Kør tilbehørsprogrammet
chkdsk på diskenheden ACER.
Error - 13-07-2012 14:13:38 | Computer Name = Tobias-PC | Source = Ntfs | ID = 262199
Description = Filstrukturen på disken er beskadiget og ubrugelig. Kør tilbehørsprogrammet
chkdsk på diskenheden ACER.
Error - 13-07-2012 14:17:46 | Computer Name = Tobias-PC | Source = DCOM | ID = 10005
Description =
Error - 13-07-2012 14:17:46 | Computer Name = Tobias-PC | Source = Service Control Manager | ID = 7009
Description =
Error - 13-07-2012 14:17:46 | Computer Name = Tobias-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 13-07-2012 14:39:52 | Computer Name = Tobias-PC | Source = DCOM | ID = 10010
Description =
Error - 13-07-2012 15:00:08 | Computer Name = Tobias-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 13-07-2012 15:21:51 | Computer Name = Tobias-PC | Source = DCOM | ID = 10010
Description =
< End of report >
Administrator
Antal indlæg: 7125
Vil du godt åbne OTL.txt, finde linien med
========== Files - Modified Within 30 Days ==========
og kopiere resten herind
Signatur
Undlad venligst at vedhæfte logs, medmindre du bliver bedt om det !
Beklager. Var ellers overbevist om alt var kommet med. Men her kommer resten:
========== Files - Modified Within 30 Days ==========
[2012-07-13 23:12:01 | 000,000,920 |——| M] ()—C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-07-13 23:08:02 | 000,000,966 |——| M] ()—C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3335635223-1391227600-2490444171-1000UA.job
[2012-07-13 22:59:35 | 000,596,480 |——| M] (OldTimer Tools)—C:\Users\Tobias\Desktop\OTL.exe
[2012-07-13 22:58:56 | 000,003,216 | -H—| M] ()—C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012-07-13 22:58:56 | 000,003,216 | -H—| M] ()—C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012-07-13 22:48:00 | 000,000,830 |——| M] ()—C:\Windows\tasks\Adobe Flash Player Updater.job
[2012-07-13 21:14:38 | 000,000,916 |——| M] ()—C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012-07-13 20:58:49 | 000,317,840 |——| M] ()—C:\Windows\System32\FNTCACHE.DAT
[2012-07-13 20:58:35 | 000,067,584 |—S- | M] ()—C:\Windows\bootstat.dat
[2012-07-13 20:18:59 | 000,001,891 |——| M] ()—C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2012-07-13 15:32:49 | 000,001,668 |——| M] ()—C:\Users\Public\Desktop\iTunes.lnk
[2012-07-13 15:14:03 | 000,001,730 |——| M] ()—C:\Users\Public\Desktop\QuickTime Player.lnk
[2012-07-13 11:08:00 | 000,000,944 |——| M] ()—C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3335635223-1391227600-2490444171-1000Core.job
[2012-07-13 10:56:48 | 000,000,000 |——| M] ()—C:\Windows\System32\atiicdxx.dat
[2012-07-13 10:56:38 | 000,000,000 |——| M] ()—C:\Windows\ativpsrm.bin
[2012-07-13 09:00:34 | 000,000,512 |——| M] ()—C:\Windows\tasks\SUPERAntiSpyware Scheduled Task e2398776-fb14-4772-acef-d318d49f5609.job
[2012-07-13 09:00:34 | 000,000,512 |——| M] ()—C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 40667333-1db2-40b3-a827-710391c2dff6.job
[2012-07-13 09:00:26 | 000,001,975 |——| M] ()—C:\Users\Public\Desktop\Google Chrome.lnk
[2012-07-13 09:00:26 | 000,001,959 |——| M] ()—C:\Users\Tobias\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012-07-13 08:59:58 | 000,001,804 |——| M] ()—C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012-07-12 21:59:20 | 000,000,910 |——| M] ()—C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012-07-03 13:46:44 | 000,022,344 |——| M] (Malwarebytes Corporation)—C:\Windows\System32\drivers\mbam.sys
[2012-06-22 18:54:07 | 000,112,128 |——| M] ()—C:\Users\Tobias\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012-06-22 14:28:10 | 000,000,216 |——| M] ()—C:\Users\Tobias\Desktop\Fallen Earth.url
[2012-06-22 14:24:33 | 000,000,214 |——| M] ()—C:\Users\Tobias\Desktop\Champions Online Free For All.url
[2012-06-22 14:17:21 | 000,000,213 |——| M] ()—C:\Users\Tobias\Desktop\Alien Swarm.url
[2012-06-22 09:44:14 | 000,142,835 |——| M] ()—C:\Users\Tobias\Desktop\kongregate.jpg
[2012-06-22 00:08:55 | 000,000,055 |——| M] ()—C:\Users\Tobias\Documents\Untitled.eni
[2012-06-21 22:26:13 | 000,000,613 |——| M] ()—C:\Users\Tobias\Desktop\ENIGMA.LNK
[2012-06-21 11:56:52 | 000,595,996 |——| M] ()—C:\Windows\System32\perfh009.dat
[2012-06-21 11:56:52 | 000,472,392 |——| M] ()—C:\Windows\System32\perfh006.dat
[2012-06-21 11:56:52 | 000,104,070 |——| M] ()—C:\Windows\System32\perfc009.dat
[2012-06-21 11:56:52 | 000,080,386 |——| M] ()—C:\Windows\System32\perfc006.dat
[2012-06-21 11:52:32 | 000,001,857 |——| M] ()—C:\Users\Public\Desktop\Stamp ID3 Tag Editor.lnk
[2012-06-21 11:52:16 | 000,035,239 |——| M] ()—C:\Users\Tobias\AppData\Roaming\Stamp.dmp
[2012-06-20 11:05:51 | 000,033,920 | R—- | M] (Agnitum Ltd.)—C:\Windows\System32\drivers\Afw.sys
[2012-06-20 11:05:48 | 000,339,584 | R—- | M] (Agnitum Ltd.)—C:\Windows\System32\drivers\AfwCore.sys
[2012-06-18 10:48:04 | 000,000,919 |——| M] ()—C:\Users\Public\Desktop\Debut Video Capture Software.lnk
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Tobias\Documents\*.tmp files -> C:\Users\Tobias\Documents\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012-07-13 20:57:19 | 000,317,840 |——| C] ()—C:\Windows\System32\FNTCACHE.DAT
[2012-07-13 20:18:59 | 000,001,891 |——| C] ()—C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2012-07-13 20:18:58 | 000,001,804 |——| C] ()—C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2012-07-13 15:32:49 | 000,001,668 |——| C] ()—C:\Users\Public\Desktop\iTunes.lnk
[2012-07-13 15:14:03 | 000,001,730 |——| C] ()—C:\Users\Public\Desktop\QuickTime Player.lnk
[2012-07-13 10:56:48 | 000,000,000 |——| C] ()—C:\Windows\System32\atiicdxx.dat
[2012-07-13 10:56:38 | 000,000,000 |——| C] ()—C:\Windows\ativpsrm.bin
[2012-07-13 09:00:34 | 000,000,512 |——| C] ()—C:\Windows\tasks\SUPERAntiSpyware Scheduled Task e2398776-fb14-4772-acef-d318d49f5609.job
[2012-07-13 09:00:34 | 000,000,512 |——| C] ()—C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 40667333-1db2-40b3-a827-710391c2dff6.job
[2012-07-13 09:00:26 | 000,001,975 |——| C] ()—C:\Users\Public\Desktop\Google Chrome.lnk
[2012-07-13 09:00:26 | 000,001,959 |——| C] ()—C:\Users\Tobias\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012-07-13 08:59:58 | 000,001,804 |——| C] ()—C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012-07-12 21:59:20 | 000,000,910 |——| C] ()—C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012-06-22 14:24:33 | 000,000,214 |——| C] ()—C:\Users\Tobias\Desktop\Champions Online Free For All.url
[2012-06-22 14:19:33 | 000,000,216 |——| C] ()—C:\Users\Tobias\Desktop\Fallen Earth.url
[2012-06-22 14:17:21 | 000,000,213 |——| C] ()—C:\Users\Tobias\Desktop\Alien Swarm.url
[2012-06-22 09:44:14 | 000,142,835 |——| C] ()—C:\Users\Tobias\Desktop\kongregate.jpg
[2012-06-22 00:08:55 | 000,000,055 |——| C] ()—C:\Users\Tobias\Documents\Untitled.eni
[2012-06-21 22:26:13 | 000,000,613 |——| C] ()—C:\Users\Tobias\Desktop\ENIGMA.LNK
[2012-06-21 11:52:15 | 000,035,239 |——| C] ()—C:\Users\Tobias\AppData\Roaming\Stamp.dmp
[2012-06-21 11:51:56 | 000,001,857 |——| C] ()—C:\Users\Public\Desktop\Stamp ID3 Tag Editor.lnk
[2012-06-21 11:51:56 | 000,001,795 |——| C] ()—C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stamp ID3 Tag Editor.lnk
[2012-06-18 10:48:04 | 000,000,931 |——| C] ()—C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Debut Video Capture Software.lnk
[2012-06-18 10:48:04 | 000,000,919 |——| C] ()—C:\Users\Public\Desktop\Debut Video Capture Software.lnk
[2012-01-29 16:00:54 | 000,000,001 |——| C] ()—C:\Windows\System32\SI.bin
[2011-12-14 15:26:00 | 000,045,056 |——| C] ()—C:\Windows\System32\BRTCPCON.DLL
[2011-12-14 15:25:57 | 000,000,114 |——| C] ()—C:\Windows\System32\BRLMW03A.INI
[2011-12-14 15:25:56 | 000,000,050 |——| C] ()—C:\Windows\System32\BRADM10A.DAT
[2011-12-11 16:09:10 | 000,000,008 |——| C] ()—C:\Users\Tobias\AppData\Roaming\DofusAppId0_1
[2011-12-10 23:23:11 | 000,000,173 |——| C] ()—C:\Users\Tobias\AppData\Roaming\D2Info0
[2011-12-10 23:23:10 | 000,000,008 |——| C] ()—C:\Users\Tobias\AppData\Roaming\DofusAppId0_2
[2011-11-05 19:57:32 | 000,000,040 |——| C] ()—C:\Users\Tobias\jagex_cl_runescape_LIVE.dat
[2011-10-20 20:47:08 | 000,146,958 |——| C] ()—C:\Windows\hppins20.dat
[2011-10-20 20:46:30 | 000,016,655 |——| C] ()—C:\Windows\hppmdl20.dat
[2011-10-11 14:50:14 | 000,071,253 |——| C] ()—C:\Windows\Huawei ModemsUninstall.exe
[2011-09-06 16:14:17 | 000,009,152 |——| C] ()—C:\Windows\System32\drivers\Ticalc.sys
[2011-09-06 16:14:17 | 000,000,288 |——| C] ()—C:\Windows\Wlink89.ini
[2011-05-23 10:13:47 | 000,010,240 |——| C] ()—C:\Windows\System32\vidx16.dll
[2011-04-24 10:28:51 | 000,000,129 |——| C] ()—C:\Users\Tobias\jagex_runescape_preferences2.dat
[2011-04-24 10:28:39 | 000,000,034 |——| C] ()—C:\Users\Tobias\jagex_runescape_preferences.dat
[2011-04-14 18:00:44 | 000,000,000 |——| C] ()—C:\Windows\System32\atmfd.dll
[2011-03-19 15:21:50 | 000,000,056 | -H—| C] ()—C:\ProgramData\ezsidmv.dat
[2011-01-06 17:09:05 | 000,101,836 | -H—| C] ()—C:\Windows\System32\mlfcache.dat
[2010-09-26 03:55:33 | 000,027,724 |——| C] ()—C:\Windows\War3Unin.dat
[2010-09-04 14:22:34 | 000,021,840 |——| C] ()—C:\Windows\System32\SIntfNT.dll
[2010-09-04 14:22:34 | 000,017,212 |——| C] ()—C:\Windows\System32\SIntf32.dll
[2010-09-04 14:22:34 | 000,012,067 |——| C] ()—C:\Windows\System32\SIntf16.dll
[2010-09-04 14:19:34 | 000,017,909 |——| C] ()—C:\Windows\DIIUnin.dat
[2010-05-02 19:59:12 | 000,112,128 |——| C] ()—C:\Users\Tobias\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-02-21 23:57:14 | 000,006,836 |——| C] ()—C:\Users\Tobias\AppData\Local\d3d9caps.dat
[2010-02-21 16:28:22 | 000,000,000 |——| C] ()—C:\Users\Tobias\AppData\Roaming\wklnhst.dat
========== LOP Check ==========
[2009-01-17 16:47:32 | 000,000,000 |—-D | M]—C:\Users\asfqwefwe\AppData\Roaming\Acer GameZone Console
[2011-09-26 00:24:00 | 000,000,000 |—-D | M]—C:\Users\asfqwefwe\AppData\Roaming\BullGuard
[2011-09-26 00:18:25 | 000,000,000 |—-D | M]—C:\Users\asfqwefwe\AppData\Roaming\PowerCinema
[2011-09-26 00:24:00 | 000,000,000 |—-D | M]—C:\Users\asfqwefwe\AppData\Roaming\Software Inspection Library
[2009-01-17 16:47:32 | 000,000,000 |—-D | M]—C:\Users\Default\AppData\Roaming\Acer GameZone Console
[2009-01-17 16:47:32 | 000,000,000 |—-D | M]—C:\Users\Default User\AppData\Roaming\Acer GameZone Console
[2012-06-21 16:10:01 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\.minecraft
[2009-01-17 16:47:32 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\Acer GameZone Console
[2011-12-10 23:23:13 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\app
[2011-12-06 19:55:08 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\Azureus
[2011-10-11 14:52:30 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\Birdstep Technology
[2012-03-27 09:02:25 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\BullGuard
[2011-12-14 10:56:25 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\Dofus 2
[2011-12-10 23:23:10 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\Dofus-2.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2011-12-11 16:09:10 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2012-03-31 19:04:22 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\DVDVideoSoft
[2011-01-31 10:15:37 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\DVDVideoSoftIEHelpers
[2011-11-05 19:55:21 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\EpicBot
[2010-04-11 16:12:29 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\eSobi
[2011-05-16 20:13:06 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\GetRightToGo
[2012-01-29 15:38:21 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\Lionhead Studios
[2010-10-06 22:10:15 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\LolClient
[2012-05-24 08:55:39 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\LolClient2
[2010-03-20 21:15:01 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\ManyCam
[2011-05-24 21:43:48 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\Mount&Blade;
[2011-05-31 19:43:26 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\Mount&Blade; Warband
[2012-06-10 15:48:51 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\Opera
[2011-03-24 20:17:45 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\PowerCinema
[2011-09-12 11:02:17 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\pymclevel
[2011-12-10 23:23:13 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2010-02-27 16:34:12 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\SoftDMA
[2011-01-27 17:34:06 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\Software Inspection Library
[2011-10-05 18:56:36 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\SPORE
[2010-12-05 21:08:00 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\Template
[2010-02-11 19:26:02 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\Ubisoft
[2012-05-02 13:15:57 | 000,000,000 |—-D | M]—C:\Users\Tobias\AppData\Roaming\Windows Live Writer
[2012-07-13 11:08:00 | 000,000,944 |——| M] ()—C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3335635223-1391227600-2490444171-1000Core.job
[2012-07-13 23:08:02 | 000,000,966 |——| M] ()—C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3335635223-1391227600-2490444171-1000UA.job
[2012-07-13 20:41:34 | 000,032,616 |——| M] ()—C:\Windows\Tasks\SCHEDLGU.TXT
[2012-07-13 09:00:34 | 000,000,512 |——| M] ()—C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 40667333-1db2-40b3-a827-710391c2dff6.job
[2012-07-13 09:00:34 | 000,000,512 |——| M] ()—C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task e2398776-fb14-4772-acef-d318d49f5609.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: EXPLORER.EXE >
[2008-10-29 08:20:29 | 002,923,520 |——| M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE—C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008-10-29 08:29:41 | 002,927,104 |——| M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D—C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008-10-30 05:59:17 | 002,927,616 |——| M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E—C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009-04-11 08:27:36 | 002,926,592 |——| M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253—C:\Windows\explorer.exe
[2009-04-11 08:27:36 | 002,926,592 |——| M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253—C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008-10-28 04:15:02 | 002,923,520 |——| M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB—C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008-01-21 04:24:24 | 002,927,104 |——| M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F—C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
< MD5 for: SERVICES >
[2006-09-18 23:41:30 | 000,017,244 |——| M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7—C:\ACER\Preload\Acer\Recovery\HPartition\Windows\System32\drivers\etc\services
[2006-09-18 23:41:30 | 000,017,244 |——| M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7—C:\ACER\Preload\Acer\Recovery\HPartition\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.0.6000.16386_none_024e4071fa6fea95\services
[2006-09-18 23:41:30 | 000,017,244 |——| M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7—C:\Windows\System32\drivers\etc\services
[2006-09-18 23:41:30 | 000,017,244 |——| M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7—C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.0.6000.16386_none_024e4071fa6fea95\services
< MD5 for: SERVICES.EXE >
[2008-01-21 04:24:48 | 000,279,040 |——| M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C—C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2006-11-02 11:45:40 | 000,279,552 |——| M] (Microsoft Corporation) MD5=329CF3C97CE4C19375C8ABCABAE258B0—C:\ACER\Preload\Acer\Recovery\HPartition\Windows\System32\services.exe
[2006-11-02 11:45:40 | 000,279,552 |——| M] (Microsoft Corporation) MD5=329CF3C97CE4C19375C8ABCABAE258B0—C:\ACER\Preload\Acer\Recovery\HPartition\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.exe
[2009-04-11 08:27:59 | 000,279,552 |——| M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B—C:\Windows\System32\services.exe
[2009-04-11 08:27:59 | 000,279,552 |——| M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B—C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2006-11-02 11:58:52 | 000,017,920 |——| M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C—C:\ACER\Preload\Acer\Recovery\HPartition\Windows\System32\en-US\services.exe.mui
[2006-11-02 11:58:52 | 000,017,920 |——| M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C—C:\ACER\Preload\Acer\Recovery\HPartition\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.0.6000.16386_en-us_67c6851b290a1ced\services.exe.mui
[2008-01-21 07:44:54 | 000,018,432 |——| M] (Microsoft Corporation) MD5=E04635D69B822C425A65DBC965B9017D—C:\Windows\System32\da-DK\services.exe.mui
[2008-01-21 07:44:54 | 000,018,432 |——| M] (Microsoft Corporation) MD5=E04635D69B822C425A65DBC965B9017D—C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.0.6000.16386_da-dk_c1aa19e63855bc8e\services.exe.mui
< MD5 for: SERVICES.LNK >
[2008-01-21 04:42:58 | 000,001,688 |——| M] () MD5=C50AE46E57C3F3FB61A3B3A1E5D9C412—C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2008-01-21 04:42:58 | 000,001,688 |——| M] () MD5=C50AE46E57C3F3FB61A3B3A1E5D9C412—C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >
[2006-09-18 23:46:11 | 000,002,866 |——| M] () MD5=26A11C895A7F0B6D32105EBE127D8500—C:\ACER\Preload\Acer\Recovery\HPartition\Windows\System32\wbem\services.mof
[2006-09-18 23:46:11 | 000,002,866 |——| M] () MD5=26A11C895A7F0B6D32105EBE127D8500—C:\ACER\Preload\Acer\Recovery\HPartition\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.mof
[2006-09-18 23:46:11 | 000,002,866 |——| M] () MD5=26A11C895A7F0B6D32105EBE127D8500—C:\Windows\System32\wbem\services.mof
[2006-09-18 23:46:11 | 000,002,866 |——| M] () MD5=26A11C895A7F0B6D32105EBE127D8500—C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.mof
[2006-09-18 23:46:11 | 000,002,866 |——| M] () MD5=26A11C895A7F0B6D32105EBE127D8500—C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.mof
< MD5 for: SERVICES.MSC >
[2008-01-21 07:44:37 | 000,092,751 |——| M] () MD5=45061F4B05648B0549C709E431A9D33F—C:\Windows\System32\da-DK\services.msc
[2008-01-21 07:44:37 | 000,092,751 |——| M] () MD5=45061F4B05648B0549C709E431A9D33F—C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.0.6000.16386_da-dk_fbebe9d20ebf5681\services.msc
[2006-09-18 23:29:40 | 000,092,745 |——| M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2—C:\Windows\System32\services.msc
[2006-09-18 23:29:40 | 000,092,745 |——| M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2—C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.0.6001.18000_none_cf63e2a445bae4e3\services.msc
< MD5 for: SVCHOST.EXE >
[2006-11-02 11:45:47 | 000,022,016 |——| M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09—C:\ACER\Preload\Acer\Recovery\HPartition\Windows\System32\svchost.exe
[2006-11-02 11:45:47 | 000,022,016 |——| M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09—C:\ACER\Preload\Acer\Recovery\HPartition\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6000.16386_none_b38497a50862ad11\svchost.exe
[2008-01-21 04:23:43 | 000,021,504 |——| M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF—C:\Windows\System32\svchost.exe
[2008-01-21 04:23:43 | 000,021,504 |——| M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF—C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe
[2012-07-03 13:46:42 | 000,217,672 |——| M] () MD5=8A7F34F0BBD076EC3815680A7309114F—C:\Program Files\Malwarebytes’ Anti-Malware\Chameleon\svchost.exe
< MD5 for: USERINIT.EXE >
[2008-01-21 04:24:49 | 000,025,088 |——| M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9—C:\Windows\System32\userinit.exe
[2008-01-21 04:24:49 | 000,025,088 |——| M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9—C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006-11-02 11:45:50 | 000,024,576 |——| M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11—C:\ACER\Preload\Acer\Recovery\HPartition\Windows\System32\userinit.exe
[2006-11-02 11:45:50 | 000,024,576 |——| M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11—C:\ACER\Preload\Acer\Recovery\HPartition\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
< MD5 for: WINLOGON.EXE >
[2009-04-11 08:28:13 | 000,314,368 |——| M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452—C:\Windows\System32\winlogon.exe
[2009-04-11 08:28:13 | 000,314,368 |——| M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452—C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2012-07-03 13:46:42 | 000,217,672 |——| M] () MD5=8A7F34F0BBD076EC3815680A7309114F—C:\Program Files\Malwarebytes’ Anti-Malware\Chameleon\winlogon.exe
[2006-11-02 11:45:57 | 000,308,224 |——| M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD—C:\ACER\Preload\Acer\Recovery\HPartition\Windows\System32\winlogon.exe
[2006-11-02 11:45:57 | 000,308,224 |——| M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD—C:\ACER\Preload\Acer\Recovery\HPartition\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008-01-21 04:24:49 | 000,314,880 |——| M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24—C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
< %systemroot%\*. /rp /s >
< %systemroot%\*. /mp /s >
========== Alternate Data Streams ==========
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:798A3728
< End of report >
Administrator
Antal indlæg: 7125
Hent og installer ERUNT: http://www.derfisch.de/lars/erunt-setup.exe
Start den og lad den lave en Backup af Registreringsdatabasen.
Du skal ikke la’ den starte Automatisk
———
Deaktiver dine Sikkerheds programmer, mens “Fixet” kører.
Start OTL
Vista og Windows 7 - højreklik på filen - Kør som Administrator.
Kopier nedenstånde med fed skrift ind i feltet “Custom Scans/Fixes ”
:OTL
DRV - [2009-03-18 17:35:40 | 000,026,176 | -H—| M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped]—C:\Windows\System32\drivers\hamachi.sys—(hamachi)
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: “URL” = http://search.sweetim.com/search.asp?src=6&q={searchTerms}
IE - HKU\S-1-5-21-3335635223-1391227600-2490444171-1000\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: “URL” = http://search.sweetim.com/search.asp?src=6&q={searchTerms}
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O4 - Startup: C:\Users\Tobias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Tobias\Documents\*.tmp files -> C:\Users\Tobias\Documents\*.tmp -> ]
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:798A3728
:files
C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
ipconfig /flushdns /c
:Commands
[CREATERESTOREPOINT]
[emptytemp]
[Reboot]
Luk alle andre åbne vinduer og klik på “Run Fix ”
Efter genstart åbnes en logfil, kopier den tekst herind i denne tråd.
Ellers ligger den her: C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log
PS Hvordan kører PCen
Signatur
Undlad venligst at vedhæfte logs, medmindre du bliver bedt om det !
Hej
Så har jeg gjort som beskrevet, og loggen følger nedenfor.
PC’en kører rigtig fint nu
Når man starter den op skriver den dog : DefaultsettingEXE MFC Application mangler (eller kan ikke findes) og programmet lukkes. Det ved jeg ikke om har noget at sige.
Log:
All processes killed
========== OTL ==========
Error: No service named LogMeIn, Inc.) [Kernel | On_Demand | Stopped]—C:\Windows\System32\drivers\hamachi.sys—(hamachi was found to stop!
Service\Driver key LogMeIn, Inc.) [Kernel | On_Demand | Stopped]—C:\Windows\System32\drivers\hamachi.sys—(hamachi not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847}\ not found.
Registry key HKEY_USERS\S-1-5-21-3335635223-1391227600-2490444171-1000\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
C:\Users\Tobias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip moved successfully.
C:\Windows\msdownld.tmp folder deleted successfully.
C:\Users\Tobias\Documents\~WRL3503.tmp deleted successfully.
ADS C:\ProgramData\Temp:798A3728 deleted successfully.
========== FILES ==========
File\Folder C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job not found.
< ipconfig /flushdns /c >
Windows IP-konfiguration
DNS Resolver Cache blev t›mt.
C:\Users\Tobias\Desktop\cmd.bat deleted successfully.
C:\Users\Tobias\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
Restore point Set: OTL Restore Point
[EMPTYTEMP]
User: All Users
User: asfqwefwe
->Temp folder emptied: 434795 bytes
->Temporary Internet Files folder emptied: 7419209 bytes
->Flash cache emptied: 637 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56475 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Prøven
->Flash cache emptied: 0 bytes
User: Public
User: Tobias
->Temp folder emptied: 11317519 bytes
->Temporary Internet Files folder emptied: 86830222 bytes
->Java cache emptied: 39939377 bytes
->Google Chrome cache emptied: 52590596 bytes
->Apple Safari cache emptied: 0 bytes
->Opera cache emptied: 13976171 bytes
->Flash cache emptied: 3192109 bytes
User: tubbe
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 49149 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 206,00 mb
OTL by OldTimer - Version 3.2.54.0 log created on 07142012_161500
Files\Folders moved on Reboot…
PendingFileRenameOperations files…
Registry entries deleted on Reboot…
Administrator
Antal indlæg: 7125
Signatur
Undlad venligst at vedhæfte logs, medmindre du bliver bedt om det !
Har nu kørt scannow.
Den siger stadig ved opstart at den her application er holdt op med at fungere og programmet lukkes.
Scannow sagde der var en log ved navn cbs.txt, men den log er monsterlang. Og selv hvis jeg kun tager det fra idag efter 22:00, altså hvor jeg kørte scannow, er den også enormt lang. Skal du bruge den log?
Administrator
Antal indlæg: 7125
Prøv at læse det link jeg lagde, og gør så som der står mht findstr /C:...
Signatur
Undlad venligst at vedhæfte logs, medmindre du bliver bedt om det !
OK.Log kommer her.
2012-07-14 22:11:50, Info CSI 000000c8 [SR] Cannot repair member file [l:18{9}]“fmifs.dll” of Microsoft-Windows-Fmifs, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing
2012-07-14 22:12:27, Info CSI 000000d0 [SR] Cannot repair member file [l:18{9}]“atmfd.dll” of Microsoft-Windows-GDI, Version = 6.0.6002.18405, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2012-07-14 22:19:47, Info CSI 00000182 [SR] Cannot repair member file [l:24{12}]“settings.ini” of Microsoft-Windows-Sidebar, Version = 6.0.6002.18005, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2012-07-14 22:19:51, Info CSI 00000184 [SR] Cannot repair member file [l:24{12}]“settings.ini” of Microsoft-Windows-Sidebar, Version = 6.0.6002.18005, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2012-07-14 22:26:15, Info CSI 000001df [SR] Cannot repair member file [l:18{9}]“fmifs.dll” of Microsoft-Windows-Fmifs, Version = 6.0.6001.18000, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, file is missing
2012-07-14 22:26:15, Info CSI 000001e1 [SR] Cannot repair member file [l:18{9}]“atmfd.dll” of Microsoft-Windows-GDI, Version = 6.0.6002.18405, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2012-07-14 22:26:16, Info CSI 000001e3 [SR] Cannot repair member file [l:24{12}]“settings.ini” of Microsoft-Windows-Sidebar, Version = 6.0.6002.18005, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
2012-07-14 22:26:16, Info CSI 000001e8 [SR] Cannot repair member file [l:24{12}]“settings.ini” of Microsoft-Windows-Sidebar, Version = 6.0.6002.18005, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
Administrator
Antal indlæg: 7125
Start CCleaner -> Værktøjer - > opstart.
Find HKLM..\Run: [PLFSetI]
Daktiver den. (Den skal ikke slettes)
Genstart.
Forsvandt DefaultsettingEXE MFC fejlen
Signatur
Undlad venligst at vedhæfte logs, medmindre du bliver bedt om det !
Hej. Jo, nu forsvandt fejlen. Så er der vist ikke mere at komme efter
Administrator
Antal indlæg: 7125
Start OTL og klik på CleanUp
Det vil fjerne OTL, og andre værktøjer vi har brugt.
Hvis der efterlades noget, må du slette det manuelt.
———
Du bruger forældet software, så vil du godt læse dette , skrevet af Perhaps Emeritus.
Hent Security Check af screen317
Start den og følg instruktionerne.
Kopier loggen herind.
Signatur
Undlad venligst at vedhæfte logs, medmindre du bliver bedt om det !
OTL er fjernet.
Forældede programmer; dokument læst. Alt skulle være opdateret nu. Bullguard har også en funktion som kan scanne efter sårbarheder og den er også kørt.
Securitycheck er kørt. Der var ingen instruktioner at følge da den bare kørte igennem af sig selv. Log følger her:
Results of screen317’s Security Check version 0.99.42
Windows Vista Service Pack 2 x86 (UAC is enabled)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
BullGuard Antivirus
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Out of date HijackThis installed!
SUPERAntiSpyware
Malwarebytes Anti-Malware version 1.62.0.1300
HijackThis 2.0.2
CCleaner
JavaFX 2.1.1
Java(TM) 6 Update 33
Java(TM) 7 Update 5
Adobe Flash Player 11.3.300.265
Adobe Reader X (10.1.0)
Google Chrome 20.0.1132.57
````````Process Check: objlist.exe by Laurent````````
Windows Defender MSASCui.exe
Windows Defender MSASCui.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````