f-arn TeamSpywarefri !
her er så logs fra OTL
OTL logfile created on: 12-08-2012 10:26:14 - Run 1
OTL by OldTimer - Version 3.2.57.0 Folder = C:\Documents and Settings\Otto\Skrivebord
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000406 | Country: Danmark | Language: DAN | Date Format: dd-MM-yyyy
1023,17 Mb Total Physical Memory | 616,42 Mb Available Physical Memory | 60,25% Memory free
2,40 Gb Paging File | 2,11 Gb Available in Paging File | 87,83% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programmer
Drive C: | 149,04 Gb Total Space | 103,72 Gb Free Space | 69,59% Space Free | Partition Type: NTFS
Drive E: | 298,09 Gb Total Space | 284,23 Gb Free Space | 95,35% Space Free | Partition Type: NTFS
Computer Name: OTTO-C78BE9C4A7 | User Name: Otto | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012-08-12 10:22:08 | 000,596,992 |——| M] (OldTimer Tools)—C:\Documents and Settings\Otto\Skrivebord\OTL.exe
PRC - [2012-08-04 16:32:46 | 000,688,360 |——| M] (Webroot)—C:\Programmer\Webroot\WRSA.exe
PRC - [2012-07-25 10:46:44 | 001,326,176 |——| M] (Secunia)—C:\Programmer\Secunia\PSI\psia.exe
PRC - [2012-07-25 10:46:42 | 000,572,000 |——| M] (Secunia)—C:\Programmer\Secunia\PSI\psi_tray.exe
PRC - [2012-07-05 22:07:00 | 000,161,704 |——| M] (Oracle Corporation)—C:\Programmer\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
PRC - [2012-02-02 17:07:22 | 000,215,688 |——| M] (SPAMfighter ApS)—C:\Programmer\Fighters\SPAMfighter\sfus.exe
PRC - [2012-02-02 17:07:18 | 001,197,704 |——| M] (SPAMfighter ApS)—C:\Programmer\Fighters\SPAMfighter\sfagent.exe
PRC - [2012-02-02 15:08:46 | 001,453,704 |——| M] (SPAMfighter ApS)—C:\Programmer\Fighters\Tray\FightersTray.exe
PRC - [2012-01-23 14:40:12 | 001,324,680 |——| M] (SPAMfighter ApS)—C:\Programmer\Fighters\FighterSuiteService.exe
PRC - [2012-01-17 12:07:54 | 000,252,296 |——| M] (Sun Microsystems, Inc.)—C:\Programmer\Fælles filer\Java\Java Update\jusched.exe
PRC - [2010-03-15 10:58:30 | 000,172,544 |——| M] (Panasonic Corporation)—C:\Programmer\Fælles filer\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
PRC - [2008-10-31 07:24:28 | 001,365,288 |——| M] (Sunbelt Software, Inc.)—C:\Programmer\Sunbelt Software\Personal Firewall\SbPFSvc.exe
PRC - [2008-10-31 07:24:28 | 000,095,528 |——| M] (Sunbelt Software, Inc.)—C:\Programmer\Sunbelt Software\Personal Firewall\SbPFLnch.exe
PRC - [2008-10-31 07:24:26 | 001,705,256 |——| M] (Sunbelt Software, Inc.)—C:\Programmer\Sunbelt Software\Personal Firewall\SbPFCl.exe
PRC - [2008-04-14 18:05:49 | 001,034,752 |——| M] (Microsoft Corporation)—C:\WINDOWS\explorer.exe
PRC - [2007-06-15 12:57:42 | 000,145,504 |——| M] (B.H.A Corporation)—C:\WINDOWS\system32\bgsvcgen.exe
========== Modules (No Company Name) ==========
MOD - [2012-06-14 09:22:15 | 012,433,920 |——| M] ()—C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\01abbadafaf265d9f4ac9bbb247acb98\System.Windows.Forms.ni.dll
MOD - [2012-06-14 09:22:03 | 001,592,320 |——| M] ()—C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d86f2038209a4cf0d0f5b30f6375c9b2\System.Drawing.ni.dll
MOD - [2012-06-14 01:22:04 | 002,933,248 |——| M] ()—C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2012-06-14 01:21:59 | 000,261,632 |——| M] ()—C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
MOD - [2012-05-09 10:28:50 | 000,689,664 |——| M] ()—C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data.SqlServ#\32feb3b093d886259caeeeae957f8f8b\System.Data.SqlServerCe.ni.dll
MOD - [2012-05-09 10:28:13 | 000,627,712 |——| M] ()—C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\29bce0113d611084a9329349e33528ac\System.EnterpriseServices.ni.dll
MOD - [2012-05-09 10:28:12 | 000,627,200 |——| M] ()—C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\41f6f6dd0c8427d4a8e6fd3915505a6b\System.Transactions.ni.dll
MOD - [2012-05-09 10:28:05 | 000,971,264 |——| M] ()—C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d5b7368bde0f65aa15d9f46b498cc89\System.Configuration.ni.dll
MOD - [2012-05-09 09:41:50 | 005,450,752 |——| M] ()—C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\3bba1b8b0b5ef0be238b011cc7a0575e\System.Xml.ni.dll
MOD - [2012-05-09 01:21:19 | 006,616,576 |——| M] ()—C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\12c6fe8d4dd78f9bddf847d3b2821c03\System.Data.ni.dll
MOD - [2012-05-09 01:20:18 | 007,953,408 |——| M] ()—C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll
MOD - [2012-05-09 01:20:07 | 011,492,352 |——| M] ()—C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll
MOD - [2012-03-28 21:27:53 | 002,020,416 |——| M] ()—C:\Programmer\Fighters\SPAMfighter\sfse.dll
MOD - [2012-02-02 17:07:44 | 000,549,512 |——| M] ()—C:\Programmer\Fighters\SPAMfighter\sfsg.dll
MOD - [2009-03-25 13:23:56 | 000,299,008 |——| M] ()—C:\WINDOWS\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_da_b77a5c561934e089\mscorlib.resources.dll
MOD - [2007-01-22 11:22:28 | 000,470,016 |——| M] ()—C:\Programmer\Sunbelt Software\Personal Firewall\PocoXML.dll
MOD - [2007-01-22 11:22:14 | 000,859,648 |——| M] ()—C:\Programmer\Sunbelt Software\Personal Firewall\PocoFoundation.dll
MOD - [2007-01-22 11:22:12 | 000,018,432 |——| M] ()—C:\Programmer\Sunbelt Software\Personal Firewall\PocoExt.dll
MOD - [2006-02-14 15:36:10 | 000,155,648 |——| M] ()—C:\Programmer\Sunbelt Software\Personal Firewall\ssleay32.dll
MOD - [2006-02-14 15:35:54 | 000,827,392 |——| M] ()—C:\Programmer\Sunbelt Software\Personal Firewall\libeay32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped]—%SystemRoot%\System32\appmgmts.dll—(AppMgmt)
SRV - [2012-08-05 12:37:37 | 000,113,120 |——| M] (Mozilla Foundation) [On_Demand | Stopped]—C:\Programmer\Mozilla Maintenance Service\maintenanceservice.exe—(MozillaMaintenance)
SRV - [2012-08-04 16:32:46 | 000,688,360 |——| M] (Webroot) [Auto | Running]—C:\Programmer\Webroot\WRSA.exe—(WRSVC)
SRV - [2012-07-25 10:46:44 | 001,326,176 |——| M] (Secunia) [Auto | Running]—C:\Programmer\Secunia\PSI\psia.exe—(Secunia PSI Agent)
SRV - [2012-07-05 22:07:00 | 000,161,704 |——| M] (Oracle Corporation) [Auto | Running]—C:\Programmer\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe—(JavaQuickStarterService)
SRV - [2012-02-02 17:07:22 | 000,215,688 |——| M] (SPAMfighter ApS) [Auto | Running]—C:\Programmer\Fighters\SPAMfighter\sfus.exe—(SPAMfighter Update Service)
SRV - [2012-01-23 14:40:12 | 001,324,680 |——| M] (SPAMfighter ApS) [Auto | Running]—C:\Programmer\Fighters\FighterSuiteService.exe—(Suite Service)
SRV - [2008-10-31 07:24:28 | 001,365,288 |——| M] (Sunbelt Software, Inc.) [Auto | Running]—C:\Programmer\Sunbelt Software\Personal Firewall\SbPFSvc.exe—(SPF4)
SRV - [2008-10-31 07:24:28 | 000,095,528 |——| M] (Sunbelt Software, Inc.) [Auto | Running]—C:\Programmer\Sunbelt Software\Personal Firewall\SbPFLnch.exe—(SbPF.Launcher)
SRV - [2007-06-15 12:57:42 | 000,145,504 |——| M] (B.H.A Corporation) [Auto | Running]—C:\WINDOWS\system32\bgsvcgen.exe—(bgsvcgen)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped]——(WDICA)
DRV - File not found [Kernel | On_Demand | Stopped]——(PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped]——(PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped]——(PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped]——(PDCOMP)
DRV - File not found [Kernel | System | Stopped]——(PCIDump)
DRV - File not found [Kernel | System | Stopped]——(lbrtfdc)
DRV - File not found [Kernel | System | Stopped]——(i2omgmt)
DRV - File not found [Kernel | System | Stopped]——(Changer)
DRV - [2012-08-04 16:32:47 | 000,111,632 |——| M] (Webroot) [Kernel | Boot | Running]—C:\WINDOWS\system32\drivers\WRkrn.sys—(WRkrn)
DRV - [2010-09-01 10:30:58 | 000,015,544 |——| M] (Secunia) [File_System | On_Demand | Stopped]—C:\WINDOWS\system32\drivers\psi_mf.sys—(PSI)
DRV - [2009-06-30 11:37:16 | 000,028,552 |——| M] (Panda Security, S.L.) [File_System | Boot | Running]—C:\WINDOWS\system32\drivers\pavboot.sys—(pavboot)
DRV - [2008-10-31 07:09:06 | 000,270,888 | R—- | M] (Sunbelt Software, Inc.) [Kernel | System | Running]—C:\WINDOWS\system32\drivers\SbFw.sys—(SbFw)
DRV - [2008-06-21 04:54:54 | 000,066,600 | R—- | M] (Sunbelt Software, Inc.) [Kernel | System | Running]—C:\WINDOWS\system32\drivers\sbhips.sys—(sbhips)
DRV - [2008-06-21 04:54:54 | 000,065,576 |——| M] (Sunbelt Software, Inc.) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\SbFwIm.sys—(SBFWIMCL)
DRV - [2008-05-08 22:23:22 | 000,238,080 | R—- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\viahduaa.sys—(VIAHdAudAddService)
DRV - [2008-04-17 18:16:00 | 000,030,720 | R—- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\l251x86.sys—(AtcL002)
DRV - [2008-02-14 15:12:00 | 001,389,056 | R—- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running]—C:\WINDOWS\system32\drivers\monfilt.sys—(monfilt)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: “URL” = http://search.live.com/results.aspx?q={searchTerms}&src;={referrer:source?}
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: “URL” = http://search.live.com/results.aspx?q={searchTerms}&src;={referrer:source?}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: “URL” = http://search.live.com/results.aspx?q={searchTerms}&src;={referrer:source?}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0
IE - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ni.dk
IE - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-527237240-484763869-725345543-1004\..\SearchScopes,DefaultScope = {FEB9EAB5-E8EA-4BEA-9913-290B63508852}
IE - HKU\S-1-5-21-527237240-484763869-725345543-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: “URL” = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKU\S-1-5-21-527237240-484763869-725345543-1004\..\SearchScopes\{45255D36-A24A-4F1D-BD3B-E805462CD9E0}: “URL” = http://search.lycos.com/setup.php?src=ie&query;={searchTerms}
IE - HKU\S-1-5-21-527237240-484763869-725345543-1004\..\SearchScopes\{555912F4-C4E2-4803-AB37-08D595AA3E21}: “URL” = http://search.aol.com/aolcom/search?query={searchTerms}&invocationType=msie70a
IE - HKU\S-1-5-21-527237240-484763869-725345543-1004\..\SearchScopes\{A5F9145C-BA7E-472F-AEE1-6E74B7C24EA3}: “URL” = http://www.ask.com/web?q={searchTerms}&qsrc=0&o=0&l=dir
IE - HKU\S-1-5-21-527237240-484763869-725345543-1004\..\SearchScopes\{FEB9EAB5-E8EA-4BEA-9913-290B63508852}: “URL” = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie;={inputEncoding}&oe;={outputEncoding}&startIndex;={startIndex?}&startPage;={startPage}
IE - HKU\S-1-5-21-527237240-484763869-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: “Ask.com”
FF - prefs.js..browser.search.defaultenginename: “AVG Secure Search”
FF - prefs.js..browser.search.order.1: “Ask.com”
FF - prefs.js..browser.search.selectedEngine: “AVG Secure Search”
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: “http://www.ni.dk/”
FF - prefs.js..extensions.enabledItems: .:1.0
FF - prefs.js..extensions.enabledItems: {736048c1-a1ec-4a70-b12b-1e399e79024e}:2.1.7
FF - prefs.js..extensions.enabledItems: .:0.6.723
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.9.77
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..network.proxy.type: 4
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: File not found
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Programmer\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Programmer\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Programmer\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandasecurity.com/activescan: C:\Programmer\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security, S.L.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Programmer\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\smartwebprinting@hp.com: C:\Programmer\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-02-09 20:32:48 | 000,000,000 |—-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Programmer\Mozilla Firefox\components [2012-08-05 12:37:38 | 000,000,000 |—-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Programmer\Mozilla Firefox\plugins [2012-08-04 14:43:45 | 000,000,000 |—-D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Programmer\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-02-09 20:32:48 | 000,000,000 |—-D | M]
[2011-03-22 21:56:07 | 000,000,000 |—-D | M] (No name found)—C:\Documents and Settings\Otto\Application Data\Mozilla\Extensions
[2012-08-04 16:20:53 | 000,000,000 |—-D | M] (No name found)—C:\Documents and Settings\Otto\Application Data\Mozilla\Firefox\Profiles\gykbvx47.default\extensions
[2010-04-27 20:22:44 | 000,000,000 |—-D | M] (Microsoft .NET Framework Assistant)—C:\Documents and Settings\Otto\Application Data\Mozilla\Firefox\Profiles\gykbvx47.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010-02-02 14:36:45 | 000,000,000 |—-D | M] (“Trustpilot Guard”)—C:\Documents and Settings\Otto\Application Data\Mozilla\Firefox\Profiles\gykbvx47.default\extensions\{736048c1-a1ec-4a70-b12b-1e399e79024e}
[2012-03-24 12:23:56 | 000,000,000 |—-D | M] (IE Tab)—C:\Documents and Settings\Otto\Application Data\Mozilla\Firefox\Profiles\gykbvx47.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2012-08-04 16:20:54 | 000,000,000 |—-D | M] (Bitdefender QuickScan)—C:\Documents and Settings\Otto\Application Data\Mozilla\Firefox\Profiles\gykbvx47.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2010-03-23 11:30:05 | 000,000,000 |—-D | M] (“BitDefender QuickScanner”)—C:\Documents and Settings\Otto\Application Data\Mozilla\Firefox\Profiles\gykbvx47.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}(2)
[2012-02-16 17:51:22 | 000,000,000 |—-D | M] (Bitdefender QuickScan)—C:\Documents and Settings\Otto\Application Data\Mozilla\Firefox\Profiles\gykbvx47.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}(3)
[2010-07-28 17:40:57 | 000,000,000 |—-D | M] (FireFound)—C:\Documents and Settings\Otto\Application Data\Mozilla\Firefox\Profiles\gykbvx47.default\extensions\firefound@efinke(2).com
[2012-02-16 18:00:44 | 000,000,000 |—-D | M] (No name found)—C:\Programmer\Mozilla Firefox\extensions
[2011-07-16 10:51:08 | 000,067,428 |——| M] () (No name found)—C:\DOCUMENTS AND SETTINGS\OTTO\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\GYKBVX47.DEFAULT\EXTENSIONS\TRACKMENOT@MRL.NYU.EDU.XPI
[2012-08-05 12:37:37 | 000,136,672 |——| M] (Mozilla Foundation)—C:\Programmer\mozilla firefox\components\browsercomps.dll
[2010-06-25 15:35:50 | 000,075,208 |——| M] (Foxit Software Company)—C:\Programmer\mozilla firefox\plugins\npFoxitReaderPlugin.dll
[2012-08-05 12:37:34 | 000,001,525 |——| M] ()—C:\Programmer\mozilla firefox\searchplugins\amazon-co-uk.xml
[2012-07-29 13:42:38 | 000,003,752 |——| M] ()—C:\Programmer\mozilla firefox\searchplugins\avg-secure-search.xml
[2012-08-05 12:37:34 | 000,002,252 |——| M] ()—C:\Programmer\mozilla firefox\searchplugins\bing.xml
[2012-08-05 12:37:34 | 000,001,178 |——| M] ()—C:\Programmer\mozilla firefox\searchplugins\wikipedia-da.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie;={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl;={language}&q={searchTerms}
CHR - homepage: http://www.google.com
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Programmer\Google\Chrome\Application\17.0.963.46\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Programmer\Google\Chrome\Application\17.0.963.46\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Programmer\Google\Chrome\Application\17.0.963.46\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Programmer\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Programmer\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
CHR - plugin: Windows Genuine Advantage (Enabled) = C:\Programmer\Mozilla Firefox\plugins\npLegitCheckPlugin.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Programmer\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Programmer\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Programmer\Windows Media Player\npdsplay.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Programmer\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Programmer\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Programmer\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 7 U2 (Enabled) = C:\Programmer\Java\jre7\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Programmer\Microsoft Silverlight\5.0.61118.0\npctrl.dll
CHR - plugin: Panda ActiveScan 2.0 (Enabled) = C:\Programmer\Panda Security\ActiveScan 2.0\npwrapper.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\Otto\Lokale indstillinger\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
CHR - Extension: Google-s\u00F8gning = C:\Documents and Settings\Otto\Lokale indstillinger\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: Gmail = C:\Documents and Settings\Otto\Lokale indstillinger\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\
O1 HOSTS File: ([2012-02-09 09:33:44 | 000,000,027 |——| M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmer\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [Adobe ARM] C:\Programmer\Fælles filer\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Programmer\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Programmer\Fælles filer\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [CommonToolkitTray] C:\Programmer\Fighters\Tray\FightersTray.exe (SPAMfighter ApS)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Programmer\NVIDIA Corporation\nview\nwiz.exe ()
O4 - HKLM..\Run: [sfagent] C:\Programmer\Fighters\SPAMfighter\sfagent.exe (SPAMfighter ApS)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programmer\Fælles filer\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [WRSVC] C:\Programmer\Webroot\WRSA.exe (Webroot)
O4 - Startup: C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\PHOTOfunSTUDIO 5.1 HD Edition.lnk = C:\Programmer\Fælles filer\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe (Panasonic Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Secunia PSI Tray.lnk = C:\Programmer\Secunia\PSI\psi_tray.exe (Secunia)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewOnDrive = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableLocalMachineRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableLocalMachineRunOnce = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableCurrentUserRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableCurrentUserRunOnce = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoShellSearchButton = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFile = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideClock = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayContextMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayItemsDisplay = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetFolders = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDevMgrUpdate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskbar = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDFSTab = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogoff = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoEncryptOnMove = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRunasInstallPrompt = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoHardwareTab = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuSubFolders = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewOnDrive = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableLocalMachineRun = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableLocalMachineRunOnce = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableCurrentUserRun = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableCurrentUserRunOnce = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoShellSearchButton = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFile = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideClock = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayContextMenu = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayItemsDisplay = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetFolders = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDevMgrUpdate = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskbar = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDFSTab = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogoff = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoEncryptOnMove = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRunasInstallPrompt = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoHardwareTab = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuSubFolders = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewOnDrive = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableLocalMachineRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableLocalMachineRunOnce = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableCurrentUserRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableCurrentUserRunOnce = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoShellSearchButton = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFile = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideClock = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayContextMenu = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayItemsDisplay = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetFolders = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDevMgrUpdate = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskbar = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDFSTab = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogoff = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoEncryptOnMove = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRunasInstallPrompt = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoHardwareTab = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuSubFolders = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewOnDrive = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableLocalMachineRun = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableLocalMachineRunOnce = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableCurrentUserRun = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableCurrentUserRunOnce = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoShellSearchButton = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFile = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideClock = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayContextMenu = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayItemsDisplay = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetFolders = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDevMgrUpdate = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskbar = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDFSTab = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogoff = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoEncryptOnMove = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRunasInstallPrompt = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoHardwareTab = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuSubFolders = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewOnDrive = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableLocalMachineRun = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableLocalMachineRunOnce = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableCurrentUserRun = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableCurrentUserRunOnce = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoShellSearchButton = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFile = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideClock = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayContextMenu = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayItemsDisplay = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetFolders = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDevMgrUpdate = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskbar = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDFSTab = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogoff = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoEncryptOnMove = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRunasInstallPrompt = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoHardwareTab = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuSubFolders = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewOnDrive = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableLocalMachineRun = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableLocalMachineRunOnce = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableCurrentUserRun = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableCurrentUserRunOnce = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoShellSearchButton = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFile = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideClock = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayContextMenu = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayItemsDisplay = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetFolders = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDevMgrUpdate = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskbar = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDFSTab = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogoff = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoEncryptOnMove = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRunasInstallPrompt = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoHardwareTab = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuSubFolders = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O7 - HKU\S-1-5-21-527237240-484763869-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1344691940546 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 94.126.0.21 94.126.0.20
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2369DA87-4D92-4B59-8E99-E37CDE9320D3}: DhcpNameServer = 94.126.0.21 94.126.0.20
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programmer\Fælles filer\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Min aktuelle startside) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Landskab.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Landskab.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-12-22 16:56:14 | 000,000,000 |——| M] () - C:\AUTOEXEC.BAT—[ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open]—“%1” %*
O35 - HKLM\..exefile [open]—“%1” %*
O35 - HKU\S-1-5-19..exefile [open]—“%1” %*
O35 - HKU\S-1-5-20..exefile [open]—“%1” %*
O35 - HKU\S-1-5-21-527237240-484763869-725345543-1004..exefile [open]—“%1” %*
O37 - HKLM\...com [@ = comfile]—“%1” %*
O37 - HKLM\...exe [@ = exefile]—“%1” %*
O37 - HKU\.DEFAULT\...exe [@ = exefile]—“%1” %*
O37 - HKU\S-1-5-18\...exe [@ = exefile]—“%1” %*
O37 - HKU\S-1-5-19\...exe [@ = exefile]—“%1” %*
O37 - HKU\S-1-5-20\...exe [@ = exefile]—“%1” %*
O37 - HKU\S-1-5-21-527237240-484763869-725345543-1004\...exe [@ = exefile]—“%1” %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012-08-12 10:22:08 | 000,596,992 |——| C] (OldTimer Tools)—C:\Documents and Settings\Otto\Skrivebord\OTL.exe
[2012-08-11 16:01:17 | 000,000,000 | -H-D | C]—C:\Documents and Settings\Otto\Printere
[2012-08-11 15:38:42 | 000,000,000 |—-D | C]—C:\Documents and Settings\Otto\Lokale indstillinger\Application Data\Secunia PSI
[2012-08-11 11:57:27 | 000,000,000 | RH-D | C]—C:\Documents and Settings\Otto\Recent
[2012-08-11 11:56:01 | 000,000,000 |—-D | C]—C:\Documents and Settings\Otto\Skrivebord\SWF
[2012-08-11 10:34:28 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\036DFF9800095B9E632D786C7B07D329
[2012-08-10 12:27:55 | 000,000,000 |—-D | C]—C:\Documents and Settings\Otto\Dokumenter\20120810
[2012-08-04 16:34:29 | 000,000,000 |—-D | C]—C:\Programmer\Oracle
[2012-07-29 13:52:45 | 000,000,000 |—-D | C]—C:\Documents and Settings\Otto\Lokale indstillinger\Application Data\AVG Secure Search
[2012-07-29 13:50:37 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\AVG Secure Search
[2012-07-29 13:49:16 | 000,000,000 |—-D | C]—C:\Documents and Settings\Otto\Application Data\AVG Secure Search
[2012-07-29 13:45:10 | 000,000,000 |—-D | C]—C:\Programmer\Fælles filer\AVG Secure Search
[2012-07-29 13:44:59 | 000,000,000 |—-D | C]—C:\Programmer\AVG Secure Search
[2012-07-29 13:41:28 | 000,000,000 |—-D | C]—C:\Documents and Settings\All Users\Application Data\Common Files
[2012-07-28 13:05:26 | 000,000,000 |—-D | C]—C:\Programmer\Oracle(3)
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012-08-12 10:32:00 | 000,000,414 | -H—| M] ()—C:\WINDOWS\tasks\User_Feed_Synchronization-{546A936A-57DD-4930-88B4-54613D6DE3ED}.job
[2012-08-12 10:24:00 | 000,000,830 |——| M] ()—C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012-08-12 10:22:08 | 000,596,992 |——| M] (OldTimer Tools)—C:\Documents and Settings\Otto\Skrivebord\OTL.exe
[2012-08-12 10:12:00 | 000,000,910 |——| M] ()—C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012-08-12 08:58:00 | 000,000,906 |——| M] ()—C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012-08-12 08:57:16 | 000,450,256 |——| M] ()—C:\WINDOWS\System32\perfh006.dat
[2012-08-12 08:57:16 | 000,435,266 |——| M] ()—C:\WINDOWS\System32\perfh009.dat
[2012-08-12 08:57:16 | 000,080,024 |——| M] ()—C:\WINDOWS\System32\perfc006.dat
[2012-08-12 08:57:16 | 000,069,256 |——| M] ()—C:\WINDOWS\System32\perfc009.dat
[2012-08-12 08:53:06 | 000,002,048 |—S- | M] ()—C:\WINDOWS\bootstat.dat
[2012-08-11 15:40:05 | 000,000,732 |——| M] ()—C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Secunia PSI Tray.lnk
[2012-08-11 15:34:16 | 000,013,692 |——| M] ()—C:\WINDOWS\System32\wpa.dbl
[2012-08-11 11:58:47 | 000,002,902 |——| M] ()—C:\Documents and Settings\Otto\Dokumenter\cc_20120811_115843.reg
[2012-08-11 11:58:31 | 000,024,192 |——| M] ()—C:\Documents and Settings\Otto\Dokumenter\cc_20120811_115826.reg
[2012-08-05 19:13:00 | 000,000,376 |——| M] ()—C:\WINDOWS\tasks\UPCC-AutoCheckUpdate7Days.job
[2012-08-04 20:33:36 | 000,239,944 |——| M] ()—C:\WINDOWS\System32\FNTCACHE.DAT
[2012-08-04 16:32:47 | 000,148,664 |——| M] (Webroot)—C:\WINDOWS\System32\WRusr.dll
[2012-08-04 16:32:47 | 000,111,632 |——| M] (Webroot)—C:\WINDOWS\System32\drivers\WRkrn.sys
[2012-08-03 11:19:41 | 001,074,636 |——| M] ()—C:\WINDOWS\System32\nvdrsdb0.bin
[2012-08-03 11:19:41 | 000,000,001 |——| M] ()—C:\WINDOWS\System32\nvdrssel.bin
[2012-08-03 11:19:36 | 001,074,636 |——| M] ()—C:\WINDOWS\System32\nvdrsdb1.bin
[2012-07-21 16:56:56 | 000,002,331 |——| M] ()—C:\Documents and Settings\Otto\Skrivebord\License.xbin
[2012-07-21 16:55:11 | 000,026,668 |——| M] ()—C:\Documents and Settings\Otto\Dokumenter\cc_20120721_165507.reg
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012-08-11 15:38:28 | 000,000,732 |——| C] ()—C:\Documents and Settings\All Users\Menuen Start\Programmer\Start\Secunia PSI Tray.lnk
[2012-08-11 15:38:28 | 000,000,695 |——| C] ()—C:\Documents and Settings\All Users\Menuen Start\Programmer\Secunia PSI.lnk
[2012-08-11 11:58:45 | 000,002,902 |——| C] ()—C:\Documents and Settings\Otto\Dokumenter\cc_20120811_115843.reg
[2012-08-11 11:58:29 | 000,024,192 |——| C] ()—C:\Documents and Settings\Otto\Dokumenter\cc_20120811_115826.reg
[2012-08-03 11:18:53 | 000,010,264 |——| C] ()—C:\WINDOWS\System32\nvinfo.pb
[2012-07-21 16:55:09 | 000,026,668 |——| C] ()—C:\Documents and Settings\Otto\Dokumenter\cc_20120721_165507.reg
[2012-05-30 15:19:11 | 000,195,542 |——| C] ()—C:\Documents and Settings\Otto\Lokale indstillinger\Application Data\census.cache
[2012-05-30 15:19:04 | 000,174,809 |——| C] ()—C:\Documents and Settings\Otto\Lokale indstillinger\Application Data\ars.cache
[2012-02-16 21:57:33 | 000,003,072 |——| C] ()—C:\WINDOWS\System32\iacenc.dll
[2011-09-02 16:52:33 | 000,000,251 |——| C] ()—C:\Documents and Settings\Otto\Application Data\burnaware.ini
[2011-07-31 20:13:18 | 000,184,512 |——| C] ()—C:\WINDOWS\hpoins21.dat.temp
[2011-07-31 20:13:18 | 000,007,262 |——| C] ()—C:\WINDOWS\hpomdl21.dat.temp
[2011-07-31 18:10:40 | 000,003,100 |——| C] ()—C:\WINDOWS\System32\ASOROSet.bin
[2011-06-01 18:06:09 | 002,784,050 |——| C] ()—C:\WINDOWS\System32\nvdata.data
[2011-02-23 15:49:20 | 000,000,022 | -HS- | C] ()—C:\Documents and Settings\Otto\Application Data\Sys2662.Config.Repository.bin
[2011-01-18 18:34:45 | 000,000,036 |——| C] ()—C:\Documents and Settings\Otto\Lokale indstillinger\Application Data\housecall.guid.cache
[2010-11-12 16:01:41 | 001,074,636 |——| C] ()—C:\WINDOWS\System32\nvdrsdb0.bin
[2010-11-12 16:01:35 | 001,074,636 |——| C] ()—C:\WINDOWS\System32\nvdrsdb1.bin
[2009-06-18 11:02:14 | 000,000,000 |——| C] ()—C:\Documents and Settings\Otto\temp.dat
[2008-12-22 19:18:19 | 000,000,133 |——| C] ()—C:\Documents and Settings\Otto\Lokale indstillinger\Application Data\fusioncache.dat
========== LOP Check ==========
[2012-08-11 11:00:30 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\036DFF9800095B9E632D786C7B07D329
[2012-08-04 15:34:57 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\AVG Secure Search
[2012-05-24 18:02:25 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2012-07-29 13:41:28 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\Common Files
[2009-01-19 11:42:27 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\DriverScanner
[2008-12-23 11:48:52 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\e-Safekey
[2011-01-18 14:35:41 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\F-Secure
[2012-02-09 09:36:57 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\Fighters
[2012-02-10 17:28:26 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\InstallMate
[2011-10-31 21:55:42 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\MYPCTuneUp
[2010-07-23 20:54:12 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\Panasonic
[2010-11-17 10:48:39 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\ReviverSoft
[2009-01-31 16:39:48 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\SBT
[2012-07-21 17:11:44 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\TEMP
[2012-08-11 11:01:36 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\WRData
[2009-01-21 21:23:19 | 000,000,000 |—-D | M]—C:\Documents and Settings\All Users\Application Data\{D5ABFFAD-D592-4F98-B02B-587125B4801F}
[2012-02-09 09:37:13 | 000,000,000 |—-D | M]—C:\Documents and Settings\LocalService\Application Data\Fighters
[2011-01-08 21:40:52 | 000,000,000 |—-D | M]—C:\Documents and Settings\LocalService\Application Data\Foxit Software
[2009-02-24 15:17:06 | 000,000,000 |—-D | M]—C:\Documents and Settings\Otto\Application Data\Acubix PicoBackup
[2012-07-27 16:55:26 | 000,000,000 |—-D | M]—C:\Documents and Settings\Otto\Application Data\Acubix PicoBackup Outlook Express Edition
[2011-03-24 16:18:48 | 000,000,000 |—-D | M]—C:\Documents and Settings\Otto\Application Data\Auslogics
[2012-07-29 13:49:16 | 000,000,000 |—-D | M]—C:\Documents and Settings\Otto\Application Data\AVG Secure Search
[2009-01-20 21:54:20 | 000,000,000 |—-D | M]—C:\Documents and Settings\Otto\Application Data\com.codeode
[2011-06-10 13:50:33 | 000,000,000 |—-D | M]—C:\Documents and Settings\Otto\Application Data\f-secure
[2012-02-09 09:37:06 | 000,000,000 |—-D | M]—C:\Documents and Settings\Otto\Application Data\Fighters
[2012-03-04 00:35:28 | 000,000,000 |—-D | M]—C:\Documents and Settings\Otto\Application Data\Foxit Software
[2011-02-23 15:57:04 | 000,000,000 |—-D | M]—C:\Documents and Settings\Otto\Application Data\OfficeUpdate12
[2012-02-21 22:27:14 | 000,000,000 |—-D | M]—C:\Documents and Settings\Otto\Application Data\Oracle
[2011-08-02 13:25:24 | 000,000,000 |—-D | M]—C:\Documents and Settings\Otto\Application Data\PCCleaner
[2012-08-02 21:08:49 | 000,000,000 |—-D | M]—C:\Documents and Settings\Otto\Application Data\QuickScan
[2010-05-16 21:10:08 | 000,000,000 |—-D | M]—C:\Documents and Settings\Otto\Application Data\SystemRequirementsLab
[2011-06-22 09:46:52 | 000,000,000 |—-D | M]—C:\Documents and Settings\Otto\Application Data\Uniblue
[2011-06-22 13:02:41 | 000,000,000 |—-D | M]—C:\Documents and Settings\Otto\Application Data\WinPatrol
[2009-05-27 12:39:51 | 000,000,000 |—-D | M]—C:\Documents and Settings\Otto\Application Data\wsInspector
[2011-08-07 12:26:00 | 000,000,000 |—-D | M]—C:\Documents and Settings\Otto\Application Data\XnView
[2011-08-02 10:19:22 | 000,000,334 |——| M] ()—C:\WINDOWS\Tasks\Driver Robot.job
[2012-08-12 10:24:00 | 000,031,906 |——| M] ()—C:\WINDOWS\Tasks\SCHEDLGU.TXT
[2012-08-05 19:13:00 | 000,000,376 |——| M] ()—C:\WINDOWS\Tasks\UPCC-AutoCheckUpdate7Days.job
[2012-08-12 10:32:00 | 000,000,414 | -H—| M] ()—C:\WINDOWS\Tasks\User_Feed_Synchronization-{546A936A-57DD-4930-88B4-54613D6DE3ED}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: EXPLORER.EXE >
[2008-04-14 18:05:49 | 001,034,752 |——| M] (Microsoft Corporation) MD5=1D9BD1CAA1E4CF63370F201DF742DC7D—C:\WINDOWS\ERDNT\cache\explorer.exe
[2008-04-14 18:05:49 | 001,034,752 |——| M] (Microsoft Corporation) MD5=1D9BD1CAA1E4CF63370F201DF742DC7D—C:\WINDOWS\explorer.exe
[2008-04-14 18:05:49 | 001,034,752 |——| M] (Microsoft Corporation) MD5=1D9BD1CAA1E4CF63370F201DF742DC7D—C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008-04-14 18:05:49 | 001,034,752 |——| M] (Microsoft Corporation) MD5=1D9BD1CAA1E4CF63370F201DF742DC7D—C:\WINDOWS\system32\dllcache\cache\explorer.exe
[2008-04-14 18:05:49 | 001,034,752 |——| M] (Microsoft Corporation) MD5=1D9BD1CAA1E4CF63370F201DF742DC7D—C:\WINDOWS\system32\dllcache\explorer.exe
[2004-08-27 14:00:00 | 001,033,216 |——| M] (Microsoft Corporation) MD5=DA77B9561CC9AC54584C86CAB36EBF25—C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: SERVICES >
[2004-08-27 14:00:00 | 000,007,121 |——| M] () MD5=1E69A758C46292C470ADA77FC147029C—C:\WINDOWS\system32\drivers\etc\services
< MD5 for: SERVICES.ASFX >
[2012-04-04 07:54:02 | 000,002,560 |——| M] () MD5=D5642B1BFE0A70231D14C11D3D3FD60D—C:\Programmer\Adobe\Reader 10.0\Reader\Locale\da_DK\Services\Services.asfx
< MD5 for: SERVICES.ASFX23 >
[2011-06-06 13:55:34 | 000,000,599 | R—- | M] () MD5=8CEF86FF4BBA687F844CDD2FBC9E2901—C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA70301B744AA0100000010\10.1.0\services.asfx23
< MD5 for: SERVICES.CFG >
[2012-04-04 07:53:54 | 000,585,987 |——| M] () MD5=7BAB089A4F862C6BC86E0201D5BF1779—C:\Programmer\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011-06-06 13:55:30 | 000,584,045 | R—- | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E—C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA70301B744AA0100000010\10.1.0\services.cfg
< MD5 for: SERVICES.EXE >
[2009-02-09 13:25:40 | 000,110,592 |——| M] (Microsoft Corporation) MD5=32F091E3425759B126760F44B5E931C9—C:\WINDOWS\ERDNT\cache\services.exe
[2009-02-09 13:25:40 | 000,110,592 |——| M] (Microsoft Corporation) MD5=32F091E3425759B126760F44B5E931C9—C:\WINDOWS\system32\dllcache\cache\services.exe
[2009-02-09 13:25:40 | 000,110,592 |——| M] (Microsoft Corporation) MD5=32F091E3425759B126760F44B5E931C9—C:\WINDOWS\system32\dllcache\services.exe
[2009-02-09 13:25:40 | 000,110,592 |——| M] (Microsoft Corporation) MD5=32F091E3425759B126760F44B5E931C9—C:\WINDOWS\system32\services.exe
[2004-08-27 14:00:00 | 000,108,032 |——| M] (Microsoft Corporation) MD5=55BBE54A196B1A9F99EC2E01F4AC1215—C:\WINDOWS\$NtServicePackUninstall$\services.exe
[2008-04-14 18:06:01 | 000,108,544 |——| M] (Microsoft Corporation) MD5=AB2B6ABF3FCDA803FF0E2251F9A5274E—C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009-02-09 13:18:41 | 000,110,592 |——| M] (Microsoft Corporation) MD5=F8BCC407FCB4CDBF17163FAE3C820D80—C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
< MD5 for: SERVICES.HTML >
[2008-04-16 18:29:04 | 000,004,166 |——| M] () MD5=DB0CABD236311DDEB186C9B8A13F39A6—C:\Programmer\BillP Studios\WinPatrol\services.html
< MD5 for: SERVICES.MSC >
[2004-08-27 14:00:00 | 000,033,075 |——| M] () MD5=CF09D7C1F7BC198C080C2603AFF7EAAE—C:\WINDOWS\system32\services.msc
< MD5 for: SVCHOST.EXE >
[2012-04-04 15:56:38 | 000,199,240 |——| M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D—C:\Programmer\Malwarebytes’ Anti-Malware\Chameleon\svchost.exe
[2004-08-27 14:00:00 | 000,014,336 |——| M] (Microsoft Corporation) MD5=46FE2ED518FDFBFD289F014A3078575C—C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
[2008-04-14 18:06:03 | 000,014,336 |——| M] (Microsoft Corporation) MD5=555F8F4CB284FE94059DCACF6074F9EC—C:\WINDOWS\ERDNT\cache\svchost.exe
[2008-04-14 18:06:03 | 000,014,336 |——| M] (Microsoft Corporation) MD5=555F8F4CB284FE94059DCACF6074F9EC—C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008-04-14 18:06:03 | 000,014,336 |——| M] (M