Halløj
Jeg prøver at rense min svigermors computer, den går meget langsomt, især når hun spiller spil på Facebook.
Jeg har kørt jeres rensning, og her er de to filer.
DDS:
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.5.1
Run by Lene at 11:47:57 on 2012-08-14
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.45.1030.18.3838.1948 [GMT 2:00]
.
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe
C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Windows\PLFSetI.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\HidFind.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
c:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Users\Lene\AppData\Local\Google\Update\1.3.21.115\GoogleCrashHandler.exe
C:\Users\Lene\AppData\Local\Google\Update\1.3.21.115\GoogleCrashHandler64.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe
C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Packard Bell GameZone\GameConsole\OberonGameConsoleService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerEvent.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\conhost.exe
C:\program files (x86)\avira\antivir desktop\avgnt.exe
C:\Program Files (x86)\Secunia\PSI\PSIA.exe
C:\Program Files (x86)\Secunia\PSI\PSI_TRAY.exe
C:\Program Files (x86)\Secunia\PSI\sua.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Users\Lene\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lene\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lene\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Users\Lene\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lene\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Windows Live\Companion\companionuser.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0406&m=easynote_tj72&r=27361011r9b6l04e0z105f44k1w26q
uDefault_Page_URL = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0406&m=easynote_tj72&r=27361011r9b6l04e0z105f44k1w26q
mDefault_Page_URL = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0406&m=easynote_tj72&r=27361011r9b6l04e0z105f44k1w26q
mStart Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0406&m=easynote_tj72&r=27361011r9b6l04e0z105f44k1w26q
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
BHO: Hjælp til logon til Windows Live ID: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [swg] “C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe”
uRun: [Google Update] “C:\Users\Lene\AppData\Local\Google\Update\GoogleUpdate.exe” /c
uRun: [msnmsgr] “C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe” /background
uRun: [EPSON SX130 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHJE.EXE /FU “C:\Windows\TEMP\E_SE42C.tmp” /EF “HKCU”
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [Adobe Reader Speed Launcher] “c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe”
mRun: [BackupManagerTray] “C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe” -h -k
mRun: [StartCCC] “C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” MSRun
mRun: [VideoWebCamera] “C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe” -a
mRun: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
mRun: [RemoteControl8] “c:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe”
mRun: [PDVD8LanguageShortcut] “c:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe”
mRun: [EEventManager] “C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe”
mRun: [SunJavaUpdateSched] “C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”
mRun: [avgnt] “C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe” /min
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SECUNI~1.LNK - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport; to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
TCP: DhcpNameServer = 212.10.10.5 212.10.10.4
TCP: Interfaces\{9EC63BEE-7AD9-41EE-88F7-EB85237D4AF0} : DhcpNameServer = 212.10.10.5 212.10.10.4
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
{9030D464-4C02-4ABF-8ECC-5164760863C6}
{9FDDE16B-836F-4806-AB1F-1455CBEFF289}
{AA58ED58-01DD-4d91-8333-CF10577473F7}
{DBC80044-A445-435b-BC74-9C25C1C588A9}
{2318C2B1-4965-11d4-9B18-009027A5CD4F}
mRun-x64: [Adobe Reader Speed Launcher] “c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe”
mRun-x64: [BackupManagerTray] “C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe” -h -k
mRun-x64: [StartCCC] “C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” MSRun
mRun-x64: [VideoWebCamera] “C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe” -a
mRun-x64: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
mRun-x64: [RemoteControl8] “c:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe”
mRun-x64: [PDVD8LanguageShortcut] “c:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe”
mRun-x64: [EEventManager] “C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe”
mRun-x64: [SunJavaUpdateSched] “C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”
mRun-x64: [avgnt] “C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe” /min
.
============= SERVICES / DRIVERS ===============
.
R1 avkmgr;avkmgr;C:\Windows\system32\DRIVERS\avkmgr.sys—> C:\Windows\system32\DRIVERS\avkmgr.sys [?]
R2 avgntflt;avgntflt;C:\Windows\system32\DRIVERS\avgntflt.sys—> C:\Windows\system32\DRIVERS\avgntflt.sys [?]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\k57nd60a.sys—> C:\Windows\system32\DRIVERS\k57nd60a.sys [?]
S3 ewusbmbb;HUAWEI USB-WWAN miniport;C:\Windows\system32\DRIVERS\ewusbwwan.sys—> C:\Windows\system32\DRIVERS\ewusbwwan.sys [?]
S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys—> C:\Windows\system32\DRIVERS\fssfltr.sys [?]
.
=============== Created Last 30 ================
.
2012-08-14 09:09:42 404640 ——a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-08-14 09:00:30 ———— d——-w- C:\Users\Lene\AppData\Local\Secunia PSI
2012-08-14 09:00:07 ———— d——-w- C:\Program Files (x86)\Secunia
2012-08-14 08:31:02 ———— d——-w- C:\Users\Lene\AppData\Local\{F62D68CF-5FDC-4F04-9E8E-E3FFF4A272F1}
2012-08-14 08:30:50 ———— d——-w- C:\Users\Lene\AppData\Local\{74F7B593-5275-42F8-A584-442FA792FDF3}
2012-08-14 05:55:52 ———— d——-w- C:\Users\Lene\AppData\Roaming\SUPERAntiSpyware.com
2012-08-14 05:55:41 ———— d——-w- C:\ProgramData\SUPERAntiSpyware.com
2012-08-14 05:55:41 ———— d——-w- C:\Program Files\SUPERAntiSpyware
2012-08-13 20:32:56 ———— d——-w- C:\Users\Lene\AppData\Roaming\Malwarebytes
2012-08-13 20:32:05 38224 ——a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2012-08-13 20:32:02 24904 ——a-w- C:\Windows\System32\drivers\mbam.sys
2012-08-13 20:32:02 ———— d——-w- C:\ProgramData\Malwarebytes
2012-08-13 20:32:02 ———— d——-w- C:\Program Files (x86)\Malwarebytes’ Anti-Malware
2012-08-13 20:30:00 ———— d——-w- C:\Users\Lene\AppData\Local\{38C128A9-2279-470C-AB15-CBB862DC262F}
2012-08-13 20:29:45 ———— d——-w- C:\Users\Lene\AppData\Local\{9877E779-43E7-4C13-8657-73370C097BC1}
2012-08-13 16:55:58 ———— d——-w- C:\Program Files (x86)\ESET
2012-08-13 16:55:30 ———— d——-w- C:\Users\Lene\AppData\Local\{1833E170-4CAA-4679-89A8-C2C4AE2963B3}
2012-08-13 16:55:18 ———— d——-w- C:\Users\Lene\AppData\Local\{6BD36E84-7E23-4D27-AD2F-E5596AE762D6}
2012-08-13 16:19:18 ———— d——-w- C:\Windows\da
2012-08-13 16:15:45 48488 ——a-w- C:\Windows\System32\drivers\fssfltr.sys
2012-08-13 16:10:39 15712 ——a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\2e4d81b61cd796e02\MeshBetaRemover.exe
2012-08-13 16:10:38 537432 ——a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\2d58e4f11cd796e01\DXSETUP.exe
2012-08-13 16:10:38 1801048 ——a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\2d58e4f11cd796e01\dsetup32.dll
2012-08-13 16:10:37 89944 ——a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\2d58e4f11cd796e01\DSETUP.dll
2012-08-13 14:23:35 ———— d——-w- C:\Users\Lene\AppData\Local\{F222F9B7-B821-4191-A162-7B2D78507C94}
2012-08-13 14:21:18 ———— d——-w- C:\Users\Lene\AppData\Local\{2906CD3F-CF0C-4159-9EFF-2016F0EE458D}
2012-08-13 14:13:24 ———— d——-w- C:\Users\Lene\AppData\Roaming\Avira
2012-08-13 14:09:02 98848 ——a-w- C:\Windows\System32\drivers\avgntflt.sys
2012-08-13 14:09:02 27760 ——a-w- C:\Windows\System32\drivers\avkmgr.sys
2012-08-13 14:09:01 ———— d——-w- C:\ProgramData\Avira
2012-08-13 14:09:01 ———— d——-w- C:\Program Files (x86)\Avira
2012-08-13 14:05:09 9133488 ——a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{9B508ADC-1390-41F1-B616-F3A0ABF81A67}\mpengine.dll
2012-08-12 17:13:32 ———— d——-w- C:\Program Files\CCleaner
2012-08-12 17:02:05 514560 ——a-w- C:\Windows\SysWow64\qdvd.dll
2012-08-12 17:02:05 366592 ——a-w- C:\Windows\System32\qdvd.dll
2012-08-12 16:45:50 ———— d——-w- C:\Program Files (x86)\Oracle
2012-08-12 16:43:33 687544 ——a-w- C:\Windows\SysWow64\deployJava1.dll
2012-08-12 16:43:31 772544 ——a-w- C:\Windows\SysWow64\npDeployJava1.dll
2012-08-12 16:24:56 ———— d——-w- C:\Users\Lene\AppData\Local\{6C637F67-34CF-4AB4-A042-089F36F68FAC}
2012-08-12 15:23:21 9133488 ——a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-08-09 13:17:16 ———— d——-w- C:\Users\Lene\AppData\Local\{CB4D618E-AE82-4B10-A144-E0106CAC02FD}
2012-08-09 12:44:38 ———— d——-w- C:\Users\Lene\AppData\Local\{D9E42D7C-C35B-4B23-9B79-9AA9C8A7753D}
2012-08-04 14:10:00 ———— d——-w- C:\Users\Lene\AppData\Local\{0D153D1F-3194-47D6-ACEC-5B0273A1525D}
2012-08-04 14:08:07 ———— d——-w- C:\Users\Lene\AppData\Local\{81F4DA08-C47A-49E4-9A79-561C8A8A2C41}
2012-08-02 09:30:22 ———— d——-w- C:\Users\Lene\AppData\Local\{38A99997-2E73-4AC3-8900-4892E71861A8}
2012-08-02 09:28:49 ———— d——-w- C:\Users\Lene\AppData\Local\{F290BDA7-F35C-4DB4-95F5-B80ED5B17A7E}
2012-08-02 07:48:43 ———— d——-w- C:\Users\Lene\AppData\Local\{C8CB42FF-8191-4892-B4AF-351063CA786E}
2012-08-02 07:48:07 ———— d——-w- C:\Users\Lene\AppData\Local\{BB450646-A0EA-439C-B1B1-4A16B8638229}
2012-08-01 13:15:53 ———— d——-w- C:\Users\Lene\AppData\Local\{BBE8D780-2BF1-4944-933A-7D6175C1D715}
2012-08-01 13:14:19 ———— d——-w- C:\Users\Lene\AppData\Local\{B8E5B899-9466-4EFE-95D3-258335D7E907}
2012-08-01 10:51:27 ———— d——-w- C:\Users\Lene\AppData\Local\{458F9927-9167-45AE-9262-C656753648B5}
2012-08-01 10:46:28 ———— d——-w- C:\Users\Lene\AppData\Local\{1B07AF86-0495-4253-97E3-45362486D58C}
2012-08-01 09:44:33 ———— d——-w- C:\Users\Lene\AppData\Local\{07EC7D24-145E-44A0-A478-5E648956C4F2}
2012-08-01 09:42:36 ———— d——-w- C:\Users\Lene\AppData\Local\{A2865559-C1FA-4690-B434-E8D30716E2D4}
2012-07-30 20:13:09 ———— d——-w- C:\Users\Lene\AppData\Local\{363A2A74-C798-4791-90A1-436B033D7BF0}
2012-07-30 20:12:57 ———— d——-w- C:\Users\Lene\AppData\Local\{61CD6370-4189-4295-BA90-60F66E70AADE}
2012-07-28 07:54:07 ———— d——-w- C:\Users\Lene\AppData\Local\{9733D563-0D01-406D-9E2F-A04F9782AA03}
2012-07-28 07:52:46 ———— d——-w- C:\Users\Lene\AppData\Local\{D0640B03-974C-4212-BD58-2CF1E30FE179}
2012-07-27 19:41:22 ———— d——-w- C:\Users\Lene\AppData\Local\{3CAE39B1-6224-4D1A-9420-85FEA2786F5E}
2012-07-27 19:38:06 ———— d——-w- C:\Users\Lene\AppData\Local\{336E6CC2-2976-4DFB-95DD-B8A0AD5E6F79}
2012-07-23 17:05:16 ———— d——-w- C:\Users\Lene\AppData\Local\{EACC8D70-CEA9-44F0-A758-D0106226AB0C}
2012-07-23 05:02:35 ———— d——-w- C:\Users\Lene\AppData\Local\{A6B38C5B-5DE1-47E9-8EC0-B4970263ECFB}
2012-07-23 04:39:33 ———— d——-w- C:\Users\Lene\AppData\Local\{2013BD69-9A89-4CA9-9FAB-7D7BF04D126F}
2012-07-23 04:39:23 ———— d——-w- C:\Users\Lene\AppData\Local\{487F376E-3D3C-4000-9DFB-CCAFD473300C}
2012-07-22 04:58:16 ———— d——-w- C:\Users\Lene\AppData\Local\{43F82A1B-7C0C-4B06-B784-B4CC39E3E625}
2012-07-21 04:57:47 ———— d——-w- C:\Users\Lene\AppData\Local\{59AA0E17-45E7-400B-B8F0-5B7FA9BA7074}
2012-07-20 16:57:47 ———— d——-w- C:\Users\Lene\AppData\Local\{F67050D7-EFF5-4667-AA18-FF89579DDC19}
2012-07-20 04:57:50 ———— d——-w- C:\Users\Lene\AppData\Local\{C787E188-9E82-4649-9464-CECE2FFD0667}
2012-07-19 16:57:47 ———— d——-w- C:\Users\Lene\AppData\Local\{48BC8825-E8B3-44E9-BA39-0F175999D78A}
2012-07-19 04:57:49 ———— d——-w- C:\Users\Lene\AppData\Local\{5C7FC875-0A55-4A5C-ABB3-DFCEF92E3541}
2012-07-18 17:00:03 ———— d——-w- C:\Users\Lene\AppData\Local\{A6A6F1B0-5B0B-489F-996B-0D6DC2A16300}
2012-07-18 16:59:53 ———— d——-w- C:\Users\Lene\AppData\Local\{A8D1EC4B-6B2B-461D-B70D-48DC6A9A3B29}
2012-07-18 16:59:43 ———— d——-w- C:\Users\Lene\AppData\Local\{987963A9-C337-4149-B179-97B4121B48DE}
2012-07-18 04:23:01 ———— d——-w- C:\Users\Lene\AppData\Local\{3300BE2F-03F4-4882-A231-7F0A6C7415C4}
2012-07-16 05:08:07 ———— d——-w- C:\Users\Lene\AppData\Local\{232F7553-57B3-40AA-BFC6-E0667266AD8F}
2012-07-15 17:08:33 ———— d——-w- C:\Users\Lene\AppData\Local\{988972CC-11C5-40B8-8357-4BB7ECCC3DC2}
.
==================== Find3M ====================
.
2012-06-12 03:08:36 3148800 ——a-w- C:\Windows\System32\win32k.sys
2012-06-08 12:35:35 421888 ——a-w- C:\Windows\System32\drivers\ewusbwwan.sys
2012-06-08 12:35:34 1490656 ——a-w- C:\Windows\System32\WdfCoInstaller01007.dll
2012-06-08 12:35:34 1490656 ——a-w- C:\Windows\System32\drivers\WdfCoInstaller01007.dll
2012-06-06 06:06:16 2004480 ——a-w- C:\Windows\System32\msxml6.dll
2012-06-06 06:06:16 1881600 ——a-w- C:\Windows\System32\msxml3.dll
2012-06-06 06:02:54 1133568 ——a-w- C:\Windows\System32\cdosys.dll
2012-06-06 05:05:52 1390080 ——a-w- C:\Windows\SysWow64\msxml6.dll
2012-06-06 05:05:52 1236992 ——a-w- C:\Windows\SysWow64\msxml3.dll
2012-06-06 05:03:06 805376 ——a-w- C:\Windows\SysWow64\cdosys.dll
2012-06-02 22:15:31 2622464 ——a-w- C:\Windows\System32\wucltux.dll
2012-06-02 22:15:08 99840 ——a-w- C:\Windows\System32\wudriver.dll
2012-06-02 13:19:42 186752 ——a-w- C:\Windows\System32\wuwebv.dll
2012-06-02 13:15:12 36864 ——a-w- C:\Windows\System32\wuapp.exe
2012-06-02 12:12:17 2311680 ——a-w- C:\Windows\System32\jscript9.dll
2012-06-02 12:05:28 1392128 ——a-w- C:\Windows\System32\wininet.dll
2012-06-02 12:04:50 1494528 ——a-w- C:\Windows\System32\inetcpl.cpl
2012-06-02 12:01:40 173056 ——a-w- C:\Windows\System32\ieUnatt.exe
2012-06-02 11:57:08 2382848 ——a-w- C:\Windows\System32\mshtml.tlb
2012-06-02 08:33:25 1800192 ——a-w- C:\Windows\SysWow64\jscript9.dll
2012-06-02 08:25:08 1129472 ——a-w- C:\Windows\SysWow64\wininet.dll
2012-06-02 08:25:03 1427968 ——a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-06-02 08:20:33 142848 ——a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-06-02 08:16:52 2382848 ——a-w- C:\Windows\SysWow64\mshtml.tlb
2012-06-02 05:50:10 458704 ——a-w- C:\Windows\System32\drivers\cng.sys
2012-06-02 05:48:16 95600 ——a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-06-02 05:48:16 151920 ——a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-06-02 05:45:31 340992 ——a-w- C:\Windows\System32\schannel.dll
2012-06-02 05:44:21 307200 ——a-w- C:\Windows\System32\ncrypt.dll
2012-06-02 04:40:42 22016 ——a-w- C:\Windows\SysWow64\secur32.dll
2012-06-02 04:40:39 225280 ——a-w- C:\Windows\SysWow64\schannel.dll
2012-06-02 04:39:10 219136 ——a-w- C:\Windows\SysWow64\ncrypt.dll
2012-06-02 04:34:09 96768 ——a-w- C:\Windows\SysWow64\sspicli.dll
.
============= FINISH: 11:49:11,13 ===============
