This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Slower than slow PC

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

HI!

It takes ages to start up my computer 📎hp.png and to use it.

I do daily cleanups with ATFCleaner (in admin mode) and CCleaner.

No marks in 'Hide extensions for known file types' and in 'Hide protected operating system files' and I have cleared the Java cache.


A full scan is done with Malwarebytes' Anti-Malware 📎Malw.png (in admin mode) and computer restarted and still slow.

Please help - I'm going nuts!! :pullhair:

Best regards from Farmor

* LOG *


Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org

Database version: 4029

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18904

2010-04-24 15:33:33
mbam-log-2010-04-24 (15-33-33).txt

Scan type: Full scan (C:\|D:\|E:\|F:\|)
Objects scanned: 464156
Time elapsed: 5 hour(s), 48 minute(s), 25 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Public\Acer\MyWebFaceSetup2.3.64.1.NoSA.NoHP.GRfox000.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Users\Public\Acer\Diverse\Downloads\MyWebFaceSetup2.3.64.1.NoSA.NoHP.GRfox000.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Users\Public\Acer\Spel\Japan\pztrain.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
Hello there, Farmor

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

**In any case where you happen to be busy or unable to give us a reply, we would be more than grateful if you keep us informed in advance and we will be more than happy to wait. :)
Hi,

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

On your next reply please post :
OTL log
GMER log

Good Day!
Sorry I missed that you had answered! :smack: I was waiting for an email and just happened to sneak in. I'll be back as soon as I've performed your orders - LOL :wavey: Farmor
OK, here we go!

:thumbup: The OTL scanning worked just fine. I didn't start it in admin mode. Was I supposed to do that?

:wacko: The Gmer, however, didn't work. I've tried to run it twice - first with the common doubble click and then in administrator mode. Both times it stopped working after a while, saying something (not what) notgood it up. I would be noticed if there was a solution to the problem. No such notice yet (after a couple of hours).


Best regards
Farmor

___________

OTL logfile created on: 2010-04-30 07:30:47 - Run 1
OTL by OldTimer - Version 3.2.3.1 Folder = C:\Users\Annelie\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 0000041D | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 55,00% Memory free
6,00 Gb Paging File | 4,00 Gb Available in Paging File | 72,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 225,53 Gb Total Space | 102,60 Gb Free Space | 45,49% Space Free | Partition Type: NTFS
Drive D: | 7,36 Gb Total Space | 1,20 Gb Free Space | 16,33% Space Free | Partition Type: NTFS
Drive E: | 232,88 Gb Total Space | 227,68 Gb Free Space | 97,77% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive Z: | 225,53 Gb Total Space | 102,60 Gb Free Space | 45,49% Space Free | Partition Type: NTFS

Computer Name: KONTOR
Current User Name: Annelie
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Annelie\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
PRC - C:\Program Files\IncrediMail\bin\ImApp.exe (IncrediMail, Ltd.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ArcSoft Inc.)
PRC - C:\Users\Annelie\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files\RegCure\RegCure.exe ()
PRC - C:\Program Files\ArcSoft\MediaConverter 4 Platinum\Monitor.exe (ArcSoft Inc.)
PRC - C:\Program Files\Storegate\Autostore\AutoStoreSvc.exe (Storegate AB)
PRC - C:\Program Files\Storegate\Autostore\AutoStore.exe (Storegate AB)
PRC - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files\Sms och mms i datorn Desktop\mw.exe (Mobispine)
PRC - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
PRC - C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
PRC - C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools)
PRC - C:\Program Files\Rainlendar2\Rainlendar2.exe ()
PRC - C:\Program Files\Personal\bin\Personal.exe (Technology Nexus AB)
PRC - C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (CANON INC.)
PRC - C:\WINDOWS\System32\wisptis.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Program Files\Ad-Aware\aawservice.exe (Lavasoft)
PRC - C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe (Microsoft Corporation)
PRC - C:\Program Files\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)
PRC - C:\WINDOWS\System32\WTablet\Wacom_TabletUser.exe (Wacom Technology, Corp.)
PRC - C:\WINDOWS\System32\Wacom_Tablet.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.exe (Logitech Inc.)
PRC - C:\WINDOWS\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\WINDOWS\System32\PSIService.exe ()
PRC - C:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
PRC - C:\WINDOWS\System32\brss01a.exe (brother Industries Ltd)
PRC - C:\WINDOWS\System32\brsvc01a.exe (brother Industries Ltd)


========== Modules (SafeList) ==========

MOD - C:\Users\Annelie\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll (Microsoft Corporation)
MOD - C:\WINDOWS\System32\msi.dll (Microsoft Corporation)
MOD - C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4016_none_d0893820442e7fe
4\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4016_none_d0893820442e7fe
4\msvcp80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\System32\sfc_os.dll (Microsoft Corporation)
MOD - C:\Program Files\Logitech\SetPoint\lgscroll.dll (Logitech Inc.)
MOD - C:\WINDOWS\System32\sfc.dll (Microsoft Corporation)
MOD - C:\WINDOWS\System32\msiltcfg.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (AutoStore) – C:\Program Files\Storegate\Autostore\AutoStoreSvc.exe (Storegate AB)
SRV - (Browser Defender Update Service) – C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (FontCache) – C:\WINDOWS\System32\FntCache.dll (Microsoft Corporation)
SRV - (sdCoreService) – C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (aawservice) – C:\Program Files\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TabletServiceWacom) – C:\WINDOWS\System32\Wacom_Tablet.exe (Wacom Technology, Corp.)
SRV - (ProtexisLicensing) – C:\WINDOWS\System32\PSIService.exe ()
SRV - (PCLEPCI) – C:\WINDOWS\System32\drivers\Pclepci.sys (Pinnacle Systems GmbH)
SRV - (Brother XP spl Service) – C:\WINDOWS\System32\brsvc01a.exe (brother Industries Ltd)


========== Driver Services (SafeList) ==========

DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMonFlt) – C:\WINDOWS\System32\drivers\aswMonFlt.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (LVPr2Mon) – C:\WINDOWS\System32\drivers\LVPr2Mon.sys ()
DRV - (PCTCore) – C:\Windows\system32\drivers\PCTCore.sys (PC Tools)
DRV - (LVRS) – C:\WINDOWS\System32\drivers\lvrs.sys (Logitech Inc.)
DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\WINDOWS\System32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (pepifilter) – C:\WINDOWS\System32\drivers\lv302af.sys (Logitech Inc.)
DRV - (WSDScan) – C:\WINDOWS\System32\drivers\WSDScan.sys (Microsoft Corporation)
DRV - (usbaudio) USB-ljuddrivrutiner (WDM) – C:\WINDOWS\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (RTSTOR) – C:\WINDOWS\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (athr) – C:\WINDOWS\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\System32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (WSDPrintDevice) – C:\WINDOWS\System32\drivers\WSDPrint.sys (Microsoft Corporation)
DRV - (61883) – C:\WINDOWS\System32\drivers\61883.sys (Microsoft Corporation)
DRV - (Avc) – C:\WINDOWS\System32\drivers\avc.sys (Microsoft Corporation)
DRV - (MSDV) – C:\WINDOWS\System32\drivers\msdv.sys (Microsoft Corporation)
DRV - (nvlddmkm) – C:\WINDOWS\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (nvstor32) – C:\Windows\system32\drivers\nvstor32.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (LMouKE) – C:\WINDOWS\System32\drivers\LMouKE.Sys (Logitech Inc.)
DRV - (L8042mou) – C:\WINDOWS\System32\drivers\L8042mou.Sys (Logitech Inc.)
DRV - (L8042Kbd) – C:\WINDOWS\System32\drivers\L8042Kbd.sys (Logitech Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (wacommousefilter) – C:\WINDOWS\System32\drivers\wacommousefilter.sys (Wacom Technology)
DRV - (wacomvhid) – C:\WINDOWS\System32\drivers\wacomvhid.sys (Wacom Technology)
DRV - (WacomVKHid) – C:\WINDOWS\System32\drivers\WacomVKHid.sys (Wacom Technology)
DRV - (MarvinBus) – C:\WINDOWS\System32\drivers\MarvinBus.sys (Pinnacle Systems GmbH)
DRV - (Afc) – C:\WINDOWS\System32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® – C:\WINDOWS\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (Ps2) – C:\WINDOWS\System32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (Ser2pl) – C:\WINDOWS\System32\drivers\ser2pl.sys (Prolific Technology Inc.)
DRV - (PenClass) – C:\Windows\System32\Drivers\PenClass.sys (Wacom Technology Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://worldwinner.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost;*.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "MyStart Search"
FF - prefs.js..browser.search.selectedEngine: "MyStart Search"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://google.se"
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.98
FF - prefs.js..extensions.enabledItems: {F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}:[removed]
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7.3
FF - prefs.js..extensions.enabledItems: [removed]:1.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071101000055
FF - prefs.js..extensions.enabledItems: [removed]:2.0.0.11
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:[removed]
FF - prefs.js..extensions.enabledItems: {EBFCD017-BCAD-42C3-9ED5-89DBDFC59171}:1.0.0
FF - prefs.js..extensions.enabledItems: {0329E7D6-6F54-462D-93F6-F5C3118BADF2}:2.1.2
FF - prefs.js..extensions.enabledItems: {d37dc5d0-431d-44e5-8c91-49419370caa1}:2.5.46
FF - prefs.js..extensions.enabledItems: [removed]:1.11.6
FF - prefs.js..extensions.enabledItems: [removed]:4.0.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..keyword.URL: "http://mystart.incredimail.com/?loc=ff_address_bar&search;="

FF - user.js..keyword.enabled: true

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\ArcSoft\RAW Thumbnail Viewer\FireFox Extension [2010-02-17 16:31:50 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B728AB94-9BC7-49b7-B76A-422BB31B2FD0}: C:\Program Files\ArcSoft\Video Downloader\Plugin_FireFox [2010-02-17 16:33:21 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\RoboForm\Firefox [2007-10-29 12:18:30 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010-04-05 15:16:39 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-04-23 18:13:52 | 000,000,000 | —D | M]

[2009-11-18 18:37:37 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\mozilla\Extensions
[2009-11-18 18:37:37 | 000,000,000 | —D | M] (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\Extensions\{92650c4d-4b8e-4d2a-b7eb-24ecf4f6b63a}
[2010-04-29 19:03:25 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\rdyfc4m0.default\extensions
[2010-04-27 18:01:19 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\rdyfc4m0.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010-01-28 18:09:55 | 000,000,000 | —D | M] (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\rdyfc4m0.default\extensions\{2832ABCD-4444-1012-2D45-132D5447C445}
[2010-01-28 18:09:55 | 000,000,000 | —D | M] (Rapidlibrary Search ToolBar) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\rdyfc4m0.default\extensions\{2832ABCD-4444-1012-2D45-132D5447C445}-trash
[2010-01-29 09:34:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\rdyfc4m0.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}
[2010-01-29 09:34:51 | 000,000,000 | —D | M] (myBabylon English Toolbar) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\rdyfc4m0.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}-trash
[2010-04-17 16:02:03 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\rdyfc4m0.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010-02-20 12:07:01 | 000,000,000 | —D | M] (FoxClocks) – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\rdyfc4m0.default\extensions\{d37dc5d0-431d-44e5-8c91-49419370caa1}
[2010-01-24 19:06:35 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\rdyfc4m0.default\extensions\[removed]
[2009-10-04 00:30:27 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\rdyfc4m0.default\extensions\[removed]
[2010-02-20 11:59:43 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\rdyfc4m0.default\extensions\[removed]
[2010-02-20 12:06:56 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\rdyfc4m0.default\extensions\[removed]
[2010-04-01 09:20:53 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\mozilla\Firefox\Profiles\rdyfc4m0.default\extensions\[removed]
[2009-11-18 18:45:28 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\mozilla\SeaMonkey\Profiles\f498kzad.default\extensions
[2009-11-18 18:45:25 | 000,000,000 | —D | M] (FlashGot) – C:\Users\Annelie\AppData\Roaming\mozilla\SeaMonkey\Profiles\f498kzad.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
[2009-11-18 18:45:25 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Annelie\AppData\Roaming\mozilla\SeaMonkey\Profiles\f498kzad.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009-09-16 17:19:20 | 000,000,938 | —- | M] () – C:\Users\Annelie\AppData\Roaming\Mozilla\FireFox\Profiles\rdyfc4m0.default\searchplugins\facebook.xml
[2010-04-29 07:12:44 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010-04-23 18:13:57 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2009-10-28 19:42:56 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2010-04-12 17:29:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009-03-18 16:03:40 | 000,214,272 | —- | M] (Midasplayer Ltd) – C:\Program Files\Mozilla Firefox\plugins\npmidas.dll
[2009-03-30 18:13:54 | 000,098,304 | —- | M] (RealNetworks) – C:\Program Files\Mozilla Firefox\plugins\npraclient.dll
[2006-09-26 14:03:14 | 000,098,304 | —- | M] (Zylom) – C:\Program Files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
[2010-01-16 03:12:42 | 000,001,470 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\allaannonser-sv-SE.xml
[2010-01-16 03:12:42 | 000,002,670 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\prisjakt-sv-SE.xml
[2010-01-16 03:12:42 | 000,000,948 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\tyda-sv-SE.xml
[2010-01-16 03:12:42 | 000,001,174 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-sv-SE.xml
[2010-01-16 03:12:42 | 000,000,951 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-sv-SE.xml

O1 HOSTS File: ([2007-11-10 17:34:34 | 000,000,761 | —- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Länkhjälp till Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (IEPlugin Class) - {11222041-111B-46E3-BD29-EFB2449479B1} - C:\Program Files\ArcSoft\Video Downloader\ArcURLRecord.dll (ArcSoft, Inc.)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (SBCONVERT Class) - {31B27F2D-6BC6-451B-B3D2-4EAB36B2FC3B} - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll ()
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (SPEEDBIT1 Class) - {425E30F0-CCC6-4E24-BBEB-BCBD31720B37} - C:\Program Files\SpeedBit Toolbar\Toolbar\Speedbit.dll ()
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (ToolbarBHO Class) - {9519AF7E-638D-4933-BAD6-D33D23C79FE5} - C:\Program Files\ArcSoft\RAW Thumbnail Viewer\EXIFToolBar.dll (ArcSoft Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
O2 - BHO: (TBHelper Class) - {E46A2169-E328-471A-9788-F2B52BB9C681} - C:\Program Files\Sms och mms i datorn Desktop\miebho1.dll (Mobispine)
O2 - BHO: (DAPIELoader Class) - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\DAP\dapieloader.dll (SpeedBit Ltd.)
O2 - BHO: (GrabberObj Class) - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\SpeedBit Video Downloader\Toolbar\Grabber.dll (Speedbit Ltd.)
O3 - HKLM\..\Toolbar: (SpeedBit Video Downloader) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (Sms och mms i datorn) - {6B49F76B-190A-4FC6-83EA-BAAD234BAFF8} - C:\Program Files\Sms och mms i datorn Desktop\mie1.dll (Mobispine)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (SpeedBit) - {EBFCD017-BCAD-42C3-9ED5-89DBDFC59171} - C:\Program Files\SpeedBit Toolbar\Toolbar\Speedbit.dll ()
O3 - HKLM\..\Toolbar: (RAW Thumbnail Viewer) - {F301665A-12F8-4331-804A-5BCBD379668C} - C:\Program Files\ArcSoft\RAW Thumbnail Viewer\EXIFToolBar.dll (ArcSoft Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (SpeedBit Video Downloader) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (SpeedBit) - {EBFCD017-BCAD-42C3-9ED5-89DBDFC59171} - C:\Program Files\SpeedBit Toolbar\Toolbar\Speedbit.dll ()
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (CANON INC.)
O4 - HKLM..\Run: [ISTray] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKCU..\Run: [DriverMax] File not found
O4 - HKCU..\Run: [DriverMax_RESTART] File not found
O4 - HKCU..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O4 - HKCU..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe ()
O4 - HKCU..\Run: [RoboForm] C:\Program Files\RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [Sms och mms i datorn Desktop] C:\Program Files\Sms och mms i datorn Desktop\mw.exe (Mobispine)
O4 - Startup: C:\Users\Annelie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Picture Motion Browser verktyg för mediekontroll.lnk = C:\Program Files\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Add; animation to IncrediMail Style Box - C:\Program Files\IncrediMail\bin\resources\WebMenuImg.htm ()
O8 - Extra context menu item: &Clean; Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm ()
O8 - Extra context menu item: &Download; with &DAP; - C:\Program Files\DAP\dapextie.htm ()
O8 - Extra context menu item: Anpassa meny - C:\Program Files\RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Download &all; with DAP - C:\Program Files\DAP\dapextie2.htm ()
O8 - Extra context menu item: Fyll i formulär - C:\Program Files\RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: Läs EXIF - C:\Program Files\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm ()
O8 - Extra context menu item: RF verktygsfält - C:\Program Files\RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Skicka som mms… - C:\Program Files\Sms och mms i datorn Desktop\sendmms.htm ()
O8 - Extra context menu item: Skicka som sms… - C:\Program Files\Sms och mms i datorn Desktop\sendsms.htm ()
O8 - Extra context menu item: Spara formulär - C:\Program Files\RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fyll i formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fyll i formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Spara - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Spara formulär - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: PrimeScratchCards - {3c69c7a4-0fb3-4fe0-bc90-9739726e4570} - Reg Error: Key error. File not found
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RF verktygsfält - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\RoboForm\RoboFormComShowToolbar.html ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {038E2507-7A48-41E2-94AD-7F23D199AF4E} http://www.worldwinner.com/games/v54/zengems/zengems.cab (ZenGems Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/5/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {18C3FD15-74F6-4280-9C98-3590C966B7B8} http://www.worldwinner.com/games/v47/skillgam/skillgam.cab (SkillGam Control)
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} http://www.worldwinner.com/games/v47/share…GamesLoader.cab (FunGamesLoader Object)
O16 - DPF: {2C153C75-8476-434B-B3C3-57B63A3D1939} http://www.worldwinner.com/games/v48/brickout/brickout.cab (Brickout Control)
O16 - DPF: {3D3DBC64-0D21-4EA4-94EE-86D6D9B31C0C} http://www.worldwinner.com/games/v45/moneylist/moneylist.cab (MoneyList Control)
O16 - DPF: {42FDC231-A411-45F8-B8B6-3B5026111DA8} http://www.worldwinner.com/games/v47/solit…litairerush.cab (SolitaireRush Control)
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} http://www.worldwinner.com/games/v51/bejeweled/bejeweled.cab (Bejeweled Control)
O16 - DPF: {61900274-3323-4446-BDCD-91548D32AF1B} http://www.worldwinner.com/games/v56/spide…ersolitaire.cab (SpiderSolitaire Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1232485024879 (WUWebControl Class)
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab (HpProductDetection Class)
O16 - DPF: {6C6FE41A-0DA6-42A1-9AD8-792026B2B2A7} http://www.worldwinner.com/games/v41/freecell/freecell.cab (FreeCell Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1203119953193 (MUWebControl Class)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} https://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} http://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab (WordMojo Control)
O16 - DPF: {95A311CD-EC8E-452A-BCEC-B844EB616D03} http://www.worldwinner.com/games/v51/bejew…eweledtwist.cab (BejeweledTwist Control)
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} http://www.worldwinner.com/games/v57/wof/wof.cab (WoF Control)
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} http://www.worldwinner.com/games/v67/swapit/swapit.cab (SwapIt Control)
O16 - DPF: {BE9B2B7C-6680-44E6-9F51-05384AD9C2FF} http://eu.mywayfinder.com/MapConnect.ocx (MapConnect Control)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…swflash5r42.cab (Shockwave Flash Object)
O16 - DPF: {E12EB891-D000-421B-A8ED-EDE1BDCA14A0} http://www.worldwinner.com/games/v44/golfsol/golfsol.cab (GolfSol Control)
O16 - DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} http://www.worldwinner.com/games/v54/wwspades/wwspades.cab (WWSpades Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\img27b.jpg
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\img27b.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-01-04 01:58:35 | 000,000,458 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2007-10-27 17:37:44 | 000,000,000 | —- | M] () - E:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{07fe6fd3-aee8-11dc-8b47-b18601f633f3}\Shell\AutoRun\command - "" = C:\Windows\System32\setupSNK.exe – [2008-01-18 23:33:30 | 000,013,312 | —- | M] (Microsoft Corporation)
O33 - MountPoints2\{2281330a-20d6-11de-8f1f-9438b544fef3}\Shell - "" = AutoRun
O33 - MountPoints2\{2281330a-20d6-11de-8f1f-9438b544fef3}\Shell\AutoRun\command - "" = M:\LaunchU3.exe – File not found
O33 - MountPoints2\{2cd78a53-b95f-11de-b1fa-001d603192c9}\Shell - "" = AutoRun
O33 - MountPoints2\{2cd78a66-b95f-11de-b1fa-001d603192c9}\Shell - "" = AutoRun
O33 - MountPoints2\{6edc6417-f8ab-11dd-9b11-001d603192c9}\Shell\AutoRun\command - "" = C:\Windows\System32\setupSNK.exe – [2008-01-18 23:33:30 | 000,013,312 | —- | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\WINDOWS\System32\ias [2008-04-19 18:33:40 | 000,000,000 | —D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

========== Files/Folders - Created Within 30 Days ==========

[2010-04-30 07:27:51 | 000,562,176 | —- | C] (OldTimer Tools) – C:\Users\Annelie\Desktop\OTL.exe
[2010-04-29 23:58:22 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\Adobe
[2010-04-29 06:59:48 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\ArcSoft
[2010-04-29 00:42:00 | 000,000,000 | —D | C] – C:\Users\Annelie\AppData\Local\Cooliris
[2010-04-28 18:44:55 | 000,000,000 | —D | C] – C:\Users\Annelie\Desktop\Canon
[2010-04-28 18:25:53 | 000,000,000 | —D | C] – C:\ProgramData\CanonIJPLM
[2010-04-28 18:01:35 | 001,310,720 | —- | C] (CANON INC.) – C:\Windows\System32\CNC640C.dll
[2010-04-28 18:01:35 | 000,303,104 | —- | C] (CANON INC.) – C:\Windows\System32\CNC640L.dll
[2010-04-28 18:01:35 | 000,110,592 | —- | C] (CANON INC.) – C:\Windows\System32\CNC640I.dll
[2010-04-28 18:01:35 | 000,106,496 | —- | C] (CANON INC.) – C:\Windows\System32\CNC640U.dll
[2010-04-28 18:01:35 | 000,015,872 | —- | C] (CANON INC.) – C:\Windows\System32\CNHMCA.dll
[2010-04-28 16:23:32 | 000,178,176 | —- | C] (CANON INC.) – C:\Windows\System32\CNMIUA2.DLL
[2010-04-23 18:13:52 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2010-04-23 18:13:52 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010-04-23 18:13:52 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010-04-23 18:13:52 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010-04-14 08:24:29 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010-04-14 08:24:29 | 000,000,000 | -HSD | C] – \Config.Msi
[2010-04-14 04:31:11 | 000,420,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2010-04-14 04:31:01 | 003,600,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2010-04-14 04:31:01 | 003,548,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2010-04-14 04:30:58 | 000,220,672 | —- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\Windows\System32\l3codecp.acm
[2010-04-14 04:30:58 | 000,062,464 | —- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\Windows\System32\l3codeca.acm
[2010-04-11 21:28:43 | 000,000,000 | —D | C] – C:\ProgramData\Alwil Software
[2010-04-02 08:14:40 | 000,000,000 | —D | C] – C:\Kasta
[2010-04-02 08:14:40 | 000,000,000 | —D | C] – \Kasta
[2010-04-01 14:13:42 | 000,000,000 | —D | C] – C:\Users\Annelie\Dokument\HP Photosmart Projects
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010-04-30 07:46:06 | 011,534,336 | —- | M] () – C:\Users\Annelie\ntuser.dat
[2010-04-30 07:45:55 | 000,000,426 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{ED6E7C9B-18AF-493F-875E-109641BDF724}.job
[2010-04-30 07:27:54 | 000,562,176 | —- | M] (OldTimer Tools) – C:\Users\Annelie\Desktop\OTL.exe
[2010-04-30 07:27:02 | 000,000,968 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-20667866-41827632-2920184442-1000UA.job
[2010-04-30 07:10:23 | 000,000,152 | —- | M] () – C:\RACREPCATALOG
[2010-04-30 06:55:08 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010-04-30 06:55:08 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010-04-30 04:00:00 | 000,000,444 | —- | M] () – C:\Windows\tasks\SpyHunter Scanner.job
[2010-04-30 02:15:00 | 000,000,444 | —- | M] () – C:\Windows\tasks\SpyHunter.job
[2010-04-29 23:59:00 | 000,004,566 | —- | M] () – C:\Users\Annelie\Desktop\minamedicinerpdf.pdf
[2010-04-29 17:00:08 | 000,000,394 | —- | M] () – C:\Windows\tasks\RegCure Program Check.job
[2010-04-29 11:27:02 | 000,000,916 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-20667866-41827632-2920184442-1000Core.job
[2010-04-29 07:00:19 | 000,136,680 | —- | M] () – C:\Users\Annelie\AppData\Local\GDIPFONTCACHEV1.DAT
[2010-04-29 06:57:21 | 000,000,382 | —- | M] () – C:\Windows\tasks\RegCure Startup.job
[2010-04-29 06:55:17 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010-04-29 06:54:53 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010-04-29 00:44:36 | 000,002,592 | —- | M] () – C:\Windows\System32\settings.aaw
[2010-04-29 00:44:36 | 000,001,840 | —- | M] () – C:\Windows\System32\history.aaw
[2010-04-29 00:44:35 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2010-04-29 00:42:33 | 000,524,288 | -HS- | M] () – C:\Users\Annelie\ntuser.dat{2a5cf3ad-2381-11df-85d5-001d603192c9}.TMContainer00000000000000000001.regtrans-ms
[2010-04-29 00:42:33 | 000,065,536 | -HS- | M] () – C:\Users\Annelie\ntuser.dat{2a5cf3ad-2381-11df-85d5-001d603192c9}.TM.blf
[2010-04-29 00:42:08 | 002,766,446 | -H– | M] () – C:\Users\Annelie\AppData\Local\IconCache.db
[2010-04-28 23:32:23 | 000,095,744 | —- | M] () – C:\Users\Annelie\Desktop\Hello there.doc
[2010-04-25 04:53:01 | 000,000,376 | —- | M] () – C:\Windows\tasks\RegCure.job
[2010-04-24 09:13:47 | 001,395,246 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010-04-24 09:13:47 | 000,597,598 | —- | M] () – C:\Windows\System32\perfh01D.dat
[2010-04-24 09:13:47 | 000,586,980 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010-04-24 09:13:47 | 000,117,210 | —- | M] () – C:\Windows\System32\perfc01D.dat
[2010-04-24 09:13:47 | 000,101,052 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010-04-19 10:35:10 | 000,030,208 | —- | M] () – C:\Users\Annelie\Desktop\Chat.doc
[2010-04-19 09:53:31 | 000,024,576 | —- | M] () – C:\Users\Annelie\Desktop\Roll call.doc
[2010-04-17 14:03:00 | 000,184,494 | —- | M] () – C:\Users\Annelie\Dokument\Jonathan2.png
[2010-04-15 05:04:40 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2010-04-14 18:47:23 | 000,038,848 | —- | M] (ALWIL Software) – C:\Windows\System32\avastSS.scr
[2010-04-14 18:47:03 | 000,153,184 | —- | M] (ALWIL Software) – C:\Windows\System32\aswBoot.exe
[2010-04-14 18:35:47 | 000,046,672 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswTdi.sys
[2010-04-14 18:35:25 | 000,162,768 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswSP.sys
[2010-04-14 18:31:39 | 000,023,376 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswRdr.sys
[2010-04-14 18:31:23 | 000,051,792 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2010-04-14 18:31:01 | 000,019,024 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2010-04-12 17:29:27 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010-04-12 17:29:26 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010-04-12 17:29:25 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010-04-12 17:29:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2010-04-12 10:18:04 | 000,024,064 | —- | M] () – C:\Users\Annelie\Desktop\rygg.doc
[2010-04-10 12:29:06 | 000,136,680 | —- | M] () – C:\Users\Annelie\AppData\Roaming\GDIPFONTCACHEV1.DAT
[2010-04-08 07:32:43 | 000,085,100 | —- | M] () – C:\Users\Annelie\Desktop\fat-man-alongside-pool.jpg
[2010-04-06 18:38:52 | 000,024,064 | —- | M] () – C:\Users\Annelie\Desktop\Farkle 10_04_06.doc
[2010-04-01 14:11:15 | 000,019,525 | —- | M] () – C:\Windows\hpqins13.dat
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010-04-29 23:59:00 | 000,004,566 | —- | C] () – C:\Users\Annelie\Desktop\minamedicinerpdf.pdf
[2010-04-28 23:32:23 | 000,095,744 | —- | C] () – C:\Users\Annelie\Desktop\Hello there.doc
[2010-04-28 18:01:35 | 000,013,312 | —- | C] () – C:\Windows\System32\CNC173FD.TBL
[2010-04-19 09:53:30 | 000,024,576 | —- | C] () – C:\Users\Annelie\Desktop\Roll call.doc
[2010-04-17 14:02:59 | 000,184,494 | —- | C] () – C:\Users\Annelie\Dokument\Jonathan2.png
[2010-04-12 10:18:04 | 000,024,064 | —- | C] () – C:\Users\Annelie\Desktop\rygg.doc
[2010-04-08 07:23:47 | 000,085,100 | —- | C] () – C:\Users\Annelie\Desktop\fat-man-alongside-pool.jpg
[2010-04-06 18:38:52 | 000,024,064 | —- | C] () – C:\Users\Annelie\Desktop\Farkle 10_04_06.doc
[2010-04-02 09:01:37 | 000,000,152 | —- | C] () – C:\RACREPCATALOG
[2010-04-02 09:01:37 | 000,000,152 | —- | C] () – \RACREPCATALOG
[2010-02-12 14:58:23 | 000,000,075 | —- | C] () – C:\Windows\PhotoJam3.ini
[2009-10-25 11:04:25 | 000,767,952 | —- | C] () – C:\Windows\BDTSupport.dll
[2009-10-07 02:46:36 | 000,025,752 | —- | C] () – C:\Windows\System32\drivers\LVPr2Mon.sys
[2009-10-07 02:23:08 | 000,013,584 | —- | C] () – C:\Windows\System32\drivers\iKeyLFT2.dll
[2009-09-11 03:37:16 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009-08-03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009-04-30 23:39:36 | 000,082,289 | —- | C] () – C:\Windows\System32\lvcoinst.ini
[2009-01-30 12:16:37 | 000,087,552 | —- | C] () – C:\Windows\System32\cpwmon2k.dll
[2009-01-23 00:20:44 | 000,000,250 | —- | C] () – C:\Windows\gmer.ini
[2009-01-23 00:20:42 | 000,884,736 | —- | C] () – C:\Windows\gmer.dll
[2008-05-16 03:03:38 | 000,000,118 | —- | C] () – C:\Windows\System32\MRT.INI
[2008-01-18 12:22:43 | 000,057,856 | —- | C] () – C:\Windows\Fce32.dll
[2008-01-18 12:22:41 | 000,057,856 | —- | C] () – C:\Windows\System32\Fce32.dll
[2008-01-18 12:22:40 | 000,092,672 | —- | C] () – C:\Windows\System32\See32.dll
[2008-01-09 23:06:32 | 000,010,752 | —- | C] () – C:\Windows\System32\BASSMOD.dll
[2008-01-09 23:04:16 | 000,000,088 | RHS- | C] () – C:\Windows\System32\3E8B532E94.sys
[2008-01-09 23:04:15 | 000,003,140 | -HS- | C] () – C:\Windows\System32\KGyGaAvL.sys
[2007-12-23 02:00:11 | 000,053,248 | —- | C] () – C:\Windows\System32\TabUnst.dll
[2007-12-23 01:59:01 | 000,013,408 | —- | C] () – C:\Windows\System32\tabinst.dll
[2007-12-23 01:59:01 | 000,004,032 | —- | C] () – C:\Windows\System32\tabins16.dll
[2007-11-29 11:32:11 | 000,005,729 | —- | C] () – C:\Windows\mgxoschk.ini
[2007-11-24 19:12:36 | 000,002,706 | —- | C] () – C:\Windows\FontExpert.INI
[2007-11-12 14:44:06 | 000,086,016 | —- | C] () – C:\Windows\System32\DVResampleru.dll
[2007-11-12 13:19:38 | 000,000,017 | —- | C] () – C:\Windows\MovingPicture.ini
[2007-11-12 09:27:44 | 000,196,096 | —- | C] () – C:\Windows\System32\macd32.dll
[2007-11-12 09:27:44 | 000,138,752 | —- | C] () – C:\Windows\System32\mase32.dll
[2007-11-12 09:27:44 | 000,136,192 | —- | C] () – C:\Windows\System32\mamc32.dll
[2007-11-12 09:27:44 | 000,057,856 | —- | C] () – C:\Windows\System32\masd32.dll
[2007-11-12 09:27:42 | 000,027,648 | —- | C] () – C:\Windows\System32\ma32.dll
[2007-11-05 13:59:33 | 000,000,000 | —- | C] () – C:\Windows\kasta.dll
[2007-10-29 14:17:04 | 000,524,288 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2007-10-29 14:17:04 | 000,139,264 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2007-10-28 09:02:14 | 000,000,072 | —- | C] () – C:\Windows\Klienthanterare.ini
[2007-10-28 08:53:16 | 000,000,722 | —- | C] () – C:\Windows\ODBC.INI
[2007-10-28 02:20:20 | 000,000,474 | —- | C] () – C:\Windows\BRWMARK.INI
[2007-10-28 02:20:20 | 000,000,030 | —- | C] () – C:\Windows\System32\brss01a.ini
[2007-10-28 02:20:20 | 000,000,027 | —- | C] () – C:\Windows\BRPP2KA.INI
[2007-10-28 02:11:01 | 000,106,496 | —- | C] () – C:\Windows\System32\BrMuSNMP.dll
[2007-10-28 01:52:01 | 000,027,024 | —- | C] () – C:\Windows\maxlink.ini
[2007-06-19 05:14:40 | 000,102,400 | —- | C] () – C:\Windows\System32\pywintypes24.dll
[2007-06-19 05:14:39 | 000,327,680 | —- | C] () – C:\Windows\System32\pythoncom24.dll
[2007-03-06 10:47:24 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2007-02-10 18:32:52 | 001,494,016 | —- | C] () – C:\Windows\System32\vspdfx.dll
[2007-01-12 07:07:48 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2007-01-12 07:07:48 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2006-11-02 14:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006-11-02 09:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006-03-06 11:41:02 | 000,073,728 | —- | C] () – C:\Windows\System32\AMV_DecDLL.dll
[2004-09-16 14:26:40 | 000,012,634 | —- | C] () – C:\Windows\System32\drivers\ADFUUD.SYS
[2004-08-20 21:04:14 | 000,319,488 | —- | C] () – C:\Windows\System32\VLMenuRes.dll
[2004-07-10 19:55:38 | 000,252,416 | —- | C] () – C:\Windows\System32\wsiShared.dll
[2002-10-05 13:49:14 | 000,024,576 | —- | C] () – C:\Windows\System32\VlUtils.dll
[2002-03-04 10:16:34 | 000,110,592 | R— | C] () – C:\Windows\System32\Jpeg32.dll

========== LOP Check ==========

[2008-01-09 17:17:43 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\.bittorrent
[2007-11-11 14:52:50 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Acoustica
[2007-11-01 14:21:24 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Axialis
[2008-01-14 12:53:03 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Azureus
[2010-04-19 07:59:11 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\BPFTP
[2010-04-28 15:54:22 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Canon
[2009-12-10 12:46:27 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\CD-LabelPrint
[2010-02-20 12:36:09 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Facebook
[2010-01-31 13:15:18 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\GoodSync
[2010-02-12 14:55:25 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Jalbum AB
[2007-10-29 13:01:54 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Jasc
[2008-09-16 15:14:54 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Leadertech
[2010-03-09 01:53:18 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\MozBackup
[2008-10-09 21:04:04 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\muvee Technologies
[2007-10-31 01:24:46 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Netscape
[2007-12-23 01:28:37 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\PeerNetworking
[2009-08-17 14:43:20 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Personal
[2009-01-15 12:52:59 | 000,000,000 | R–D | M] – C:\Users\Annelie\AppData\Roaming\Pictures
[2007-11-12 13:18:12 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\proDAD
[2007-10-29 18:19:40 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Proxima Software
[2007-12-01 12:13:11 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\ScanSoft
[2008-09-17 12:05:27 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\SEW
[2010-02-12 14:58:08 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\shockwave.com
[2007-12-12 18:23:55 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Skerryvore Software
[2009-12-10 12:28:20 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Spotify
[2010-01-05 14:38:05 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\SYSteam CAB
[2007-10-28 00:47:48 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Template
[2007-10-28 09:07:16 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Visma Xor
[2010-02-24 13:50:39 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\WinBatch
[2010-04-15 11:13:56 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\wsInspector
[2009-11-30 16:36:40 | 000,000,000 | —D | M] – C:\Users\Annelie\AppData\Roaming\Zylom
[2010-04-29 17:00:08 | 000,000,394 | —- | M] () – C:\WINDOWS\Tasks\RegCure Program Check.job
[2010-04-29 06:57:21 | 000,000,382 | —- | M] () – C:\WINDOWS\Tasks\RegCure Startup.job
[2010-04-25 04:53:01 | 000,000,376 | —- | M] () – C:\WINDOWS\Tasks\RegCure.job
[2010-04-29 00:44:36 | 000,032,578 | —- | M] () – C:\WINDOWS\Tasks\SCHEDLGU.TXT
[2010-04-30 04:00:00 | 000,000,444 | —- | M] () – C:\WINDOWS\Tasks\SpyHunter Scanner.job
[2010-04-30 02:15:00 | 000,000,444 | —- | M] () – C:\WINDOWS\Tasks\SpyHunter.job
[2010-04-30 07:45:55 | 000,000,426 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{ED6E7C9B-18AF-493F-875E-109641BDF724}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008-01-18 23:42:26 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008-01-18 23:42:26 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008-01-18 23:42:26 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\WINDOWS\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008-01-18 23:42:26 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\WINDOWS\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006-11-02 11:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\WINDOWS\System32\drivers\AGP440.sys
[2006-11-02 11:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\WINDOWS\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009-04-11 08:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\WINDOWS\System32\drivers\atapi.sys
[2009-04-11 08:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009-04-11 08:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008-01-18 23:41:32 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008-01-18 23:41:32 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006-11-02 11:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008-02-14 04:15:03 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 – C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008-02-14 04:15:03 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 – C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008-02-14 04:15:02 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F – C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006-11-02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\WINDOWS\System32\cngaudit.dll
[2006-11-02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\WINDOWS\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: IASTORV.SYS >
[2008-01-18 23:42:52 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\WINDOWS\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008-01-18 23:42:52 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\WINDOWS\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006-11-02 11:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\WINDOWS\System32\drivers\iaStorV.sys
[2006-11-02 11:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\WINDOWS\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2006-11-02 11:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\WINDOWS\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009-04-11 08:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\WINDOWS\System32\netlogon.dll
[2009-04-11 08:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\WINDOWS\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008-01-18 23:35:38 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\WINDOWS\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll

< MD5 for: NVRD32.SYS >
[2007-10-26 19:51:26 | 000,131,616 | —- | M] (NVIDIA Corporation) MD5=049E81B6FB41C73619ED3FE4DF7D8638 – C:\WINDOWS\System32\DriverStore\FileRepository\nvrd32.inf_0f6358b4\nvrd32.sys

< MD5 for: NVSTOR.SYS >
[2006-11-02 11:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\WINDOWS\System32\drivers\nvstor.sys
[2006-11-02 11:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\WINDOWS\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008-01-18 23:42:10 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\WINDOWS\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008-01-18 23:42:10 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\WINDOWS\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys

< MD5 for: NVSTOR32.SYS >
[2007-03-19 15:58:50 | 000,101,672 | —- | M] (NVIDIA Corporation) MD5=019054D997F65358DCA63ECAE5103F97 – C:\hp\DRIVERS\NVIDIA_Serial_ATA\nvstor32.sys
[2007-03-19 15:58:50 | 000,101,672 | —- | M] (NVIDIA Corporation) MD5=019054D997F65358DCA63ECAE5103F97 – C:\WINDOWS\System32\DriverStore\FileRepository\nvstor32.inf_1306af02\nvstor32.sys
[2007-10-26 19:51:24 | 000,110,624 | —- | M] (NVIDIA Corporation) MD5=7EBA6C9A0A295B1559EFB9062E701218 – C:\WINDOWS\System32\drivers\nvstor32.sys
[2007-10-26 19:51:24 | 000,110,624 | —- | M] (NVIDIA Corporation) MD5=7EBA6C9A0A295B1559EFB9062E701218 – C:\WINDOWS\System32\DriverStore\FileRepository\nvrd32.inf_0f6358b4\nvstor32.sys

< MD5 for: SCECLI.DLL >
[2008-01-18 23:36:20 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\WINDOWS\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006-11-02 11:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\WINDOWS\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009-04-11 08:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\WINDOWS\System32\scecli.dll
[2009-04-11 08:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\WINDOWS\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009-03-08 13:31:42 | 000,348,160 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\System32\dxtmsft.dll
[2009-03-08 13:31:37 | 000,216,064 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\System32\dxtrans.dll
[2009-04-11 08:27:47 | 000,241,128 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\System32\rsaenh.dll
[2009-04-11 08:28:23 | 000,228,352 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\System32\SLC.dll
[2009-04-11 08:28:25 | 000,443,392 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\System32\win32spl.dll
[1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2006-11-02 12:34:05 | 000,008,192 | —- | M] () – C:\WINDOWS\System32\config\COMPONENTS.SAV
[2006-11-02 12:34:05 | 000,020,480 | —- | M] () – C:\WINDOWS\System32\config\DEFAULT.SAV
[2006-11-02 12:34:05 | 000,008,192 | —- | M] () – C:\WINDOWS\System32\config\SECURITY.SAV
[2006-11-02 12:34:08 | 010,133,504 | —- | M] () – C:\WINDOWS\System32\config\SOFTWARE.SAV
[2006-11-02 12:34:08 | 001,826,816 | —- | M] () – C:\WINDOWS\System32\config\SYSTEM.SAV

< %systemroot%\system32\drivers\*.sys /90 >
[2010-04-14 18:31:01 | 000,019,024 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010-04-14 18:31:23 | 000,051,792 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswMonFlt.sys
[2010-04-14 18:31:39 | 000,023,376 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2010-04-14 18:35:25 | 000,162,768 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2010-04-14 18:35:47 | 000,046,672 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2010-02-20 22:53:34 | 000,411,648 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\http.sys
[2010-03-30 00:45:52 | 000,020,824 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010-03-30 00:46:30 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010-02-23 13:10:13 | 000,106,496 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\mrxsmb.sys
[2010-02-23 13:10:19 | 000,212,992 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\mrxsmb10.sys
[2010-02-23 13:10:13 | 000,079,360 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\mrxsmb20.sys
[2010-02-18 16:07:16 | 000,904,576 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\tcpip.sys
[2010-02-18 13:28:13 | 000,025,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\tunnel.sys

========== Alternate Data Streams ==========

@Alternate Data Stream - 247 bytes -> C:\ProgramData\TEMP:D74B6CF5
@Alternate Data Stream - 236 bytes -> C:\ProgramData\TEMP:0F8F5844
@Alternate Data Stream - 169 bytes -> C:\ProgramData\TEMP:F4CE9946
@Alternate Data Stream - 164 bytes -> C:\ProgramData\TEMP:BEF4B0E7
@Alternate Data Stream - 161 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:D1B5B4F1
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:73F5BDC3
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:A8ADE5D8
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:1CD23587
< End of report >

____________

OTL Extras logfile created on: 2010-04-30 07:30:47 - Run 1
OTL by OldTimer - Version 3.2.3.1 Folder = C:\Users\Annelie\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 0000041D | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 55,00% Memory free
6,00 Gb Paging File | 4,00 Gb Available in Paging File | 72,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 225,53 Gb Total Space | 102,60 Gb Free Space | 45,49% Space Free | Partition Type: NTFS
Drive D: | 7,36 Gb Total Space | 1,20 Gb Free Space | 16,33% Space Free | Partition Type: NTFS
Drive E: | 232,88 Gb Total Space | 227,68 Gb Free Space | 97,77% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive Z: | 225,53 Gb Total Space | 102,60 Gb Free Space | 45,49% Space Free | Partition Type: NTFS

Computer Name: KONTOR
Current User Name: Annelie
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –no-playlist-enqueue "%1" ()
Directory [Porta.MakeAlbum] – "C:\Program Files\Porta\Porta.exe" "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 1
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-20667866-41827632-2920184442-1000]
"EnableNotificationsRef" = 3
"EnableNotifications" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
"DisabledInterfaces" = {B755EA1E-9E30-4D81-9821-4BDCB04431C0},{22F6E4A3-750B-412E-B5DA-828BB2D3D979}

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DisabledInterfaces" = {B755EA1E-9E30-4D81-9821-4BDCB04431C0},{22F6E4A3-750B-412E-B5DA-828BB2D3D979}

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04FD5580-24BD-4AC6-8CAA-CD3CCFC2ECE9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{1D9AC748-A62C-47F5-8FDF-F6B6C46894D0}" = lport=2869 | protocol=6 | dir=in | app=system |
"{23FB837D-6534-44D2-B85E-39BD32E47557}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2D95CFBD-A824-47F0-9754-0A0E97F264F8}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=c:\windows\system32\svchost.exe |
"{401A945A-567A-4AF3-B0A2-A8DD79FE729D}" = lport=2869 | protocol=6 | dir=in | app=system |
"{442CA1DB-B3E4-4662-AE77-6CB8AA5081C4}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=c:\windows\system32\svchost.exe |
"{569F97D7-29E3-466C-8EBA-4044059CBA57}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{5C1DF4E8-6B4C-4CD1-8D7F-F723788A09AE}" = rport=10243 | protocol=6 | dir=out | app=system |
"{732FB33A-2533-4DA1-8DAC-86B400CCE8E4}" = lport=10243 | protocol=6 | dir=in | app=system |
"{75DC3642-BD98-464D-95D3-07CC7A40088D}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A0C7B6E4-2423-449D-B778-68E63A9A1833}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=c:\windows\system32\svchost.exe |
"{A38E4E72-D4FE-46E5-A9A3-32EDCC14336A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{A6385AF3-FB3C-4199-B964-408A91F410A3}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{ACCE0823-295F-424D-AE89-20817F579C5D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{BEDCBFE3-487C-4ED3-80FB-4399AE74EBE6}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{C733383E-2927-4762-9E97-0B30F4C0EEE6}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{CD2A7750-AB96-460F-876E-B16235AB6412}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{D7F60FD2-8238-4392-8590-EC65F936A32F}" = lport=2869 | protocol=6 | dir=in | app=system |
"{DF9FCE3B-0C3B-4D39-9B0D-C6B0000171BE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E88AD5FA-69D1-4B3F-A39E-8D1C9DFBE1F4}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=c:\windows\system32\svchost.exe |
"{EB743AAC-F4F9-44AE-907A-461DD583EDB5}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EFAD8B33-FEA5-4805-BA5A-FE07D56560F9}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{FA4D211D-2EB7-40CD-9B49-D3DC058E268F}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=c:\windows\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{033430EC-CECB-44A0-96A2-9E0CBA4CE352}" = protocol=17 | dir=in | app=c:\program files\enigma software group\spyhunter\spyhunter3.exe |
"{071BF2C6-EB04-4976-ABA3-B4D7EF633D3C}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpsapp.exe |
"{0B9B6437-8942-4967-99CD-7C982C996B1E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{183D6FB4-61EF-4E68-9E55-EBDC1A7FE475}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1E65E4DB-8157-40FA-885F-ACE16C146F4B}" = protocol=17 | dir=in | app=c:\program files\dap\dap.exe |
"{246DC344-8357-448C-8F71-EA4BBF8B1DD5}" = protocol=6 | dir=in | app=c:\users\annelie\appdata\local\temp\iminstaller\incredimail\incredimail_install.exe |
"{257BEE6F-7C1F-4983-9F27-462650F22F2B}" = protocol=17 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |
"{2587C7CD-408D-44A6-9B99-A8805E07F5C4}" = protocol=6 | dir=in | app=c:\program files\pinnacle\studio 11\programs\rm.exe |
"{266DBB43-D8E7-4DAA-9DF6-E33A4AF4132E}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{30822FFD-4DFD-4593-8AAA-9DBE895A5F42}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{332E8E72-C990-4A68-B649-D9E01123B610}" = protocol=17 | dir=in | app=c:\program files\pinnacle\studio 11\programs\studio.exe |
"{48AFFD82-1B46-4C86-B917-90EB363043F0}" = protocol=6 | dir=in | app=c:\users\annelie\documents\incredimail transferred data\kopiaim\incredimail\bin\incmail.exe |
"{4C910AA9-C900-4905-B6E1-944FCC30AF84}" = protocol=6 | dir=out | app=system |
"{4F5E437C-AC0E-457D-96CF-A47059840DF2}" = protocol=6 | dir=in | app=c:\program files\pinnacle\studio 11\programs\umi.exe |
"{595B2A70-2991-4FC8-8308-14EE0EC5BB9F}" = protocol=6 | dir=in | app=c:\program files\dap\dap.exe |
"{5AFD3E6D-6707-4937-B37E-90EE62FC63F6}" = protocol=6 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |
"{5F78588D-14EE-433C-8F8E-A2217A84F501}" = protocol=17 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |
"{61EEF040-FE69-46EA-9D74-14E9A83BFB11}" = protocol=6 | dir=in | app=c:\program files\pinnacle\studio 11\programs\studio.exe |
"{641CC9AB-5F20-4BAE-87AD-7D58A12541D8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{65D5B45B-0029-4BC8-BE16-2ED08DCFDE6B}" = protocol=17 | dir=in | app=c:\program files\pinnacle\studio 11\programs\rm.exe |
"{6F64C04E-F4AD-4B6F-BD16-BE3ADEB1684B}" = protocol=6 | dir=out | app=c:\windows\system32\wudfhost.exe |
"{6F908D50-93A7-4CA5-AAF7-28BDD0DFF17E}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqsudi.exe |
"{71120939-9B68-4B4A-8F09-C246665DBF89}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpse.exe |
"{774A870D-EE11-46EC-A17E-735575ECB84A}" = protocol=17 | dir=in | app=c:\program files\pinnacle\studio 11\programs\pmsregisterfile.exe |
"{7AD7369F-4F4D-41C1-B7C5-4631EBCCB49B}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{80FA2A32-DBFD-4507-AF7D-40BC63DB19DE}" = protocol=17 | dir=in | app=c:\program files\smileypad\smileypad.exe |
"{84F7F895-E0E0-4386-8C46-72D1DC867612}" = protocol=17 | dir=in | app=c:\program files\dap\dap.exe |
"{87D07B89-A91B-459A-BFEE-35A077898431}" = protocol=6 | dir=in | app=d:\program files\spotify\spotify.exe |
"{8B8FE781-51F6-4E32-B20B-4DE40991FB86}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{8F5A1EBE-D0A9-44FF-BA40-900FC519112C}" = protocol=17 | dir=in | app=d:\program files\spotify\spotify.exe |
"{903C024C-8443-49BD-B595-A02A722593EC}" = protocol=17 | dir=in | app=c:\program files\magentic\bin\magentic.exe |
"{9D741745-C1EB-4E0F-9350-248F9B047523}" = protocol=6 | dir=in | app=c:\program files\skype\phone\skype.exe |
"{A1FFD58F-241C-4D20-BD74-DAB1AC09FD3C}" = dir=in | app=c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{A300F16F-F5B6-41B7-B9E8-12B736E67F85}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A7E69356-DA9B-4E2B-B6B2-39F8AD4E8DAA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B207B25C-8A8F-4F54-9113-F46419DB7BAE}" = protocol=6 | dir=in | app=c:\program files\dap\dap.exe |
"{B276E15E-40DC-4A6D-8391-53449E2098F9}" = protocol=6 | dir=in | app=c:\program files\enigma software group\spyhunter\spyhunter3.exe |
"{B886ADA3-7A33-4548-9579-025A55B7D916}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BA57E442-DAA3-40AB-AF0C-5E4A6E2B527A}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{BD53B193-C840-43D9-9D45-B93D26E72CFE}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{CB5E0704-8E9F-4F0B-B0E7-D0F4AE4CCC12}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D0475081-2522-41A7-AFA1-92CDDA890C78}" = protocol=17 | dir=in | app=c:\program files\skype\phone\skype.exe |
"{D3570280-A22F-4DFE-BF34-005FDE173859}" = protocol=6 | dir=out | app=system |
"{D38CEFE2-FD0F-4ACF-A6CF-FED2CA75CE43}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D5BEDFD8-FDCE-4814-903B-845C43BE112E}" = protocol=6 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |
"{DE337B1E-54B9-4CD1-BB62-0A8073221A37}" = protocol=17 | dir=in | app=c:\program files\pinnacle\studio 11\programs\umi.exe |
"{E5F6D9DC-5743-451E-8A32-05411EEB4E5A}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{EBBF0595-D8DA-43B2-83FA-3D3EDC721932}" = protocol=17 | dir=in | app=c:\users\annelie\appdata\local\temp\iminstaller\incredimail\incredimail_install.exe |
"{ED94EF2C-0AAD-45E7-B1BA-AB922DAAEE57}" = protocol=6 | dir=in | app=c:\program files\magentic\bin\magentic.exe |
"{EE520D65-0B9F-4379-816B-6F769486A32B}" = protocol=17 | dir=in | app=c:\users\annelie\documents\incredimail transferred data\kopiaim\incredimail\bin\incmail.exe |
"{F461BD80-31B3-454B-8C4B-36FD2EDA252B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{F52DB15E-52D7-4F77-9500-E2BC4AE7ECDE}" = protocol=6 | dir=in | app=c:\program files\pinnacle\studio 11\programs\pmsregisterfile.exe |
"{F70D8FB9-26A8-474F-859E-9CFA9F03675E}" = protocol=6 | dir=in | app=c:\program files\smileypad\smileypad.exe |
"{F9531467-5EAD-45E9-A677-CD421D6CB5B3}" = protocol=6 | dir=out | app=system |
"TCP Query User{02977BDC-0101-42AD-992D-0B14F964427F}C:\program files\windows sidebar\sidebar.exe" = protocol=6 | dir=in | app=c:\program files\windows sidebar\sidebar.exe |
"TCP Query User{03D33AEF-9C7A-4CAF-A772-B9A1BC78E269}C:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe" = protocol=6 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |
"TCP Query User{08D9777B-7BE5-4F03-853C-27BF398BDE1B}C:\program files\bittorrent\btdownloadgui.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\btdownloadgui.exe |
"TCP Query User{3909C15D-8D7F-4BA3-A2AB-D1BBB0F4E2B5}C:\windows\lmid400.tmp\lmi_rescue.exe" = protocol=6 | dir=in | app=c:\windows\lmid400.tmp\lmi_rescue.exe |
"TCP Query User{5D239968-5BED-43FD-8E11-D14B335BDF52}C:\program files\azureus\azureus.exe" = protocol=6 | dir=in | app=c:\program files\azureus\azureus.exe |
"TCP Query User{75AD1443-EC78-4D62-B327-3066F1E4936A}C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe" = protocol=6 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe |
"TCP Query User{76AD78B9-FD7B-42F9-9C17-5DC66E73B894}C:\program files\bitdownload\bitdownload.exe" = protocol=6 | dir=in | app=c:\program files\bitdownload\bitdownload.exe |
"TCP Query User{8DC7F5D1-AA05-4D1E-B9A5-A3D4299D2837}C:\program files\easy web cam\easywebcam.exe" = protocol=6 | dir=in | app=c:\program files\easy web cam\easywebcam.exe |
"TCP Query User{A2D5D455-B6B2-453B-B842-437064DEFB77}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{B962BFE5-F9B5-4F51-A007-C477B8B9A6B9}C:\users\annelie\program\dreambox control center\dcc.exe" = protocol=6 | dir=in | app=c:\users\annelie\program\dreambox control center\dcc.exe |
"TCP Query User{DE754233-4EE8-459A-ADD6-E2958475C9E7}C:\program files\bitdownload\bitdownload.exe" = protocol=6 | dir=in | app=c:\program files\bitdownload\bitdownload.exe |
"TCP Query User{E912DDFB-064E-44C0-9A14-4E26AB6DBADD}C:\windows\lmid400.tmp\lmi_rescue.exe" = protocol=6 | dir=in | app=c:\windows\lmid400.tmp\lmi_rescue.exe |
"UDP Query User{00D2C444-D821-478C-BD26-BFC9C4D651D0}C:\program files\bittorrent\btdownloadgui.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\btdownloadgui.exe |
"UDP Query User{11A9E240-5316-472A-B75C-D454DB2B103C}C:\program files\bitdownload\bitdownload.exe" = protocol=17 | dir=in | app=c:\program files\bitdownload\bitdownload.exe |
"UDP Query User{1958AF74-34FD-4BDC-ACD1-B7894D60E6B1}C:\program files\easy web cam\easywebcam.exe" = protocol=17 | dir=in | app=c:\program files\easy web cam\easywebcam.exe |
"UDP Query User{1F2D7F58-DE0A-4005-8D9D-4884356D8E04}C:\program files\azureus\azureus.exe" = protocol=17 | dir=in | app=c:\program files\azureus\azureus.exe |
"UDP Query User{25BBECFE-4512-4FB5-95A9-CD3001D41D68}C:\windows\lmid400.tmp\lmi_rescue.exe" = protocol=17 | dir=in | app=c:\windows\lmid400.tmp\lmi_rescue.exe |
"UDP Query User{642DA0EE-A94A-43A4-8E33-750F8A0A5923}C:\program files\bitdownload\bitdownload.exe" = protocol=17 | dir=in | app=c:\program files\bitdownload\bitdownload.exe |
"UDP Query User{7087742C-B6D1-4BE6-B137-B8F6CEFEA471}C:\users\annelie\program\dreambox control center\dcc.exe" = protocol=17 | dir=in | app=c:\users\annelie\program\dreambox control center\dcc.exe |
"UDP Query User{7BC869D4-8270-43E5-9A04-707FA9741F08}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{A11D15E8-C8B1-499A-A2A8-9C9B3C69C302}C:\windows\lmid400.tmp\lmi_rescue.exe" = protocol=17 | dir=in | app=c:\windows\lmid400.tmp\lmi_rescue.exe |
"UDP Query User{A811DE39-64D6-4FD4-BC2F-0749342E885B}C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe" = protocol=17 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe |
"UDP Query User{BA51B35B-5E44-4170-BB54-B748FC42E5D4}C:\program files\windows sidebar\sidebar.exe" = protocol=17 | dir=in | app=c:\program files\windows sidebar\sidebar.exe |
"UDP Query User{F6268BED-50AF-4423-9104-BE7C60469E90}C:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe" = protocol=17 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0012041D-78E1-11D2-B60F-006097C998E7}" = Microsoft FrontPage 2000
"{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card
"{01A1A019-E1D8-482A-BE17-5E118D17C0A0}" = ArcSoft Print Creations - Brochures & Flyers
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{03D2B71D-BB42-4F4A-B25A-DAAC7247E98E}" = MinSläkt V3.5
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{110B1ADF-2EAE-4E8F-B501-D2A1E6D8ED9D}" = Studio 11
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP640_series" = Canon MP640 series MP Drivers
"{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}" = Roxio Creator EasyArchive
"{15382D89-6EF6-4D21-9484-B500F2B10E46}" = PhotoMail Maker
"{15AF2ADF-5164-4EF7-9AB4-9FDF779615B1}" = ArcSoft Print Creations
"{1E04F83B-2AB9-4301-9EF7-E86307F79C72}" = Google Earth
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23970E31-948B-466E-8376-1224D32FDF0C}" = Convert
"{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0
"{26A24AE4-039D-4CA4-87B4-2F83216019FF}" = Java™ 6 Update 20
"{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}" = Logitech SetPoint
"{30B056AF-F414-4B68-B9B0-6EFDB9FCDF18}" = ArcSoft MediaImpression 2
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Roxio Activation Module
"{363188E4-1A27-4DE6-BA48-823D2E205385}" = ArcSoft Scan-n-Stitch Deluxe
"{37530151-56A6-4CE4-9F9F-CE1F5A1356C6}" = ArcSoft Panorama Maker 4
"{3796E3A3-1EE5-40E7-9E82-EE035C94393B}" = Studio 11
"{3CE47E6B-AE27-4E40-AC54-329EED96B933}" = ArcSoft Print Creations - Funhouse II
"{40DA94AF-34B7-4BA7-A37F-26F899C031FF}" = ArcSoft PhotoStudio Darkroom 2
"{40F7AED3-0C7D-4582-99F6-484A515C73F2}" = HP Easy Setup - Frontend
"{45A1BF92-700A-4408-B95E-79F462E3D67D}" = Studio 11 Bonus DVD
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book
"{56918C0C-0D87-4CA6-92BF-4975A43AC719}" = KhalInstallWrapper
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5D1C82E7-7EC0-4404-A8AD-36C3B444BC34}" = ArcSoft Print Creations - Poster Creator
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{71310D9B-7555-44FE-914C-A1B55CB7BC5D}" = Scrapbook
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75E71ADD-042C-4F30-BFAC-A9EC42351313}" = Python 2.4.3
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{771F0F26-3798-46F3-9278-91361210D80C}" = Simply Calenders v5.1
"{7B312BFD-6C04-4409-AB6F-DD41CCD67463}" = muvee autoProducer 6.1
"{7D7152AF-581B-316F-8CA4-15342C3EFA4B}" = Microsoft .NET Framework 3.5 Language Pack SP1 - sve
"{82FAC25D-D0E1-4D60-9268-F3DD958BF052}" = ArcSoft RAW Thumbnail Viewer
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{886EA322-81B7-4DB8-BA8E-5300243A3CFD}" = muvee Kids stylePack
"{8A29BF7A-6C8B-4557-96C1-84C2FE15FDF8}" = Jalbum
"{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}" = MP3 Player Utilities 4.18
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}" = CDDRV_Installer
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90190409-6000-11D3-8CFE-0050048383C9}" = Microsoft Publisher 2002
"{9112041D-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Standard
"{92518780-C904-409C-B674-528822FEA6E2}" = muvee coolStyles 1
"{938B1CD7-7C60-491E-AA90-1F1888168240}" = Roxio MyDVD Basic v9
"{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse
"{95F875CC-1B85-43E6-B3E0-13EA04F3D995}" = ArcSoft Print Creations - Photo Prints
"{9A1686DD-E593-4556-8BD1-426A3F28A263}" = muvee Pro Modern stylePack
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{A17EABB6-D0C6-44E5-820C-72DC7F495064}" = PaperPort
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A67C32B0-C7E5-4AE1-82E2-8F60A04BECA0}" = ArcSoft MediaConverter 4 Platinum
"{AB5E289E-76BF-4251-9F3F-9B763F681AE0}" = HP Customer Experience Enhancements
"{AC6F131E-0376-4C4F-A6C9-BFFD37A361AE}" = PrimeScratchCards
"{AC76BA86-7AD7-1053-7B44-A93000000001}" = Adobe Reader 9.3.2 - Svenska
"{B0D64B63-E5D3-43E8-8E70-07E4103C2692}" = DesignPro 5
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4E96960-5F6B-48B9-A5BD-6A5A9BB4F027}" = Avery Wizard 3.1
"{BAA81B01-7B27-4E49-89FA-D1C331E000A7}" = IncrediMail
"{BAC84156-BB11-436C-8752-24357F6BAD02}" = XOR Compact 5
"{C27BC2A2-30DD-4014-B22E-63EB0DB572F9}" = Logitech Webcam Software
"{C867F57B-39C1-4341-A164-F569839BCCBF}" = Cards
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator Basic v9
"{C8B44566-839A-459C-A73D-49764CE216CC}" = ArcSoft Video Downloader
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CE2121C6-C94D-4A73-8EA4-6943F33EE335}" = Picture Package Music Transfer
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{DE114695-AE58-4B66-8E0F-2505188602FB}_is1" = Uninstall Startup Inspector
"{E2EE273D-E111-4FFD-ACD4-78E1D35E01D2}" = ArcSoft Photo Book Screen Saver
"{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page
"{EF781A5C-58F5-4BFD-87F9-E4F14D382F25}" = Pinnacle Instant DVD Recorder
"{F03EC055-F34E-4F6B-A684-8A370E11A304}" = ArcSoft Print Creations
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2EC3CA2-1136-45C1-B5AE-AB03DED6E98C}" = Logitech QuickCapture Gadget
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4AD1D69-B6AF-48C3-AF65-CB39C2BFFEC3}" = muvee Pro Classic StylePack
"{F5AEB5A7-D4EA-49A5-89F2-A799F1C620B9}" = TViXiE
"{F9AEEC34-CF00-4CBD-9E36-DF9DC4002685}" = Yahoo! Desktop Login
"Acoustica CD/DVD Label Maker" = Acoustica CD/DVD Label Maker
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Age Of Japan_is1" = Age Of Japan
"AI RoboForm" = AI RoboForm (All Users)
"alohasolitaire" = Aloha Solitaire
"AU9_is1" = Advanced Uninstaller PRO - Version 9
"avast5" = avast! Free Antivirus
"Belltech Greeting Card Designer - Extra Templates_is1" = Belltech Greeting Card Designer - Extra Templates
"Belltech Greeting Card Designer 5.0_is1" = Belltech Greeting Card Designer 5.0
"Browser Defender_is1" = Browser Defender [removed]
"BulletProof FTP Client 2009_is1" = BulletProof FTP Client 2009 (remove only)
"BulletProof FTP Client_is1" = BulletProof FTP Client (remove only)
"Canon_IJ_Network_Scan_UTILITY" = Canon IJ Network Scan Utility
"Canon_IJ_Network_UTILITY" = Canon IJ Network Tool
"CANONIJPLM100" = Canon Inkjet Printer/Scanner/Fax Extended Survey Program
"CanonMyPrinter" = Canon Utilities My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"casinoaction" = Casino Action
"CCleaner" = CCleaner
"CutePDF Writer Installation" = CutePDF Writer 2.7
"DMX5_is1" = DriverMax 5
"Download Accelerator Plus (DAP)" = Download Accelerator Plus (DAP)
"DVD Cover Searcher3.3.1" = DVD Cover Searcher
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"FontExpert 2007" = FontExpert 2007
"FontExpert 2009" = FontExpert 2009
"IncrediMail" = IncrediMail 2.0
"Incredimail Backup Pro_is1" = Incredimail Backup Pro V3.1
"InstallShield_{B0D64B63-E5D3-43E8-8E70-07E4103C2692}" = DesignPro 5
"king.com" = king.com (remove only)
"legacyqcam_11.10" = Logitech Legacy USB Camera drivrutinspaket
"LIVE TV_is1" = Live TV
"lvdrivers_11.80" = Logitech QuickCam drivrutinspaket
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaNavigation.CDLabelPrint" = CD-LabelPrint
"Microsoft .NET Framework 3.5 Language Pack SP1 - sve" = Språkpaket för Microsoft .NET Framework 3.5 SP 1 - sve
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"MozBackup" = MozBackup 1.4.9
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"MP Navigator EX 3.0" = Canon MP Navigator EX 3.0
"NVIDIA Drivers" = NVIDIA Drivers
"OsdMaestro" = HP On-Screen Cap/Num/Scroll Lock Indicator
"Personal" = Personal 4.10.3
"PhotoJam 3" = PhotoJam 3
"PhotoMail" = PhotoMail Maker
"Porta" = Porta
"PrimeScratchCards" = PrimeScratchCards
"proDAD-Heroglyph-2.5" = proDAD Heroglyph 2.5
"proDAD-Vitascene-1.0" = proDAD Vitascene 1.0
"QuickMenuBuilder" = Quick Menu Builder 1.2
"Rainlendar2" = Rainlendar2 (remove only)
"RealArcade" = RealArcade
"RegCure" = RegCure
"Revo Uninstaller" = Revo Uninstaller 1.85
"ShapeCollage" = Shape Collage
"Shockwave.com JigsawMaker" = Shockwave.com JigsawMaker
"SmileyPad_is1" = SmileyPad v2.28
"SpeedBit Toolbar" = SpeedBit Toolbar
"SpeedBit Video Downloader" = SpeedBit Video Downloader
"Spotify" = Spotify
"Spyware Doctor" = Spyware Doctor 7.0
"Super Collapse! from GameHouse" = Super Collapse! from GameHouse
"SystemRequirementsLab" = System Requirements Lab
"Wacom Tablet Driver" = Wacom Tablet
"William Hill CASINO CLUB" = William Hill CASINO CLUB
"WinAce Archiver" = WinAce Archiver
"WinUndelete" = WinUndelete
"WinZip" = WinZip
"VLC media player" = VLC media player 0.9.8a
"Zylom puzzles Deluxe" = Zylom puzzles Deluxe

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"Google Chrome" = Google Chrome
"Sms och mms i datorn Desktop" = Sms och mms i datorn Desktop

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 2009-05-11 18:09:25 | Computer Name = Kontor | Source = avast! | ID = 33554522
Description =

Error - 2009-07-22 16:04:09 | Computer Name = Kontor | Source = avast! | ID = 33554522
Description =

Error - 2009-08-07 17:04:02 | Computer Name = Kontor | Source = avast! | ID = 33554522
Description =

Error - 2010-02-07 03:22:23 | Computer Name = Kontor | Source = avast! | ID = 33554522
Description =

[ Application Events ]
Error - 2008-08-01 07:42:07 | Computer Name = Kontor | Source = Windows Search Service | ID = 1006
Description =

Error - 2008-08-01 07:42:38 | Computer Name = Kontor | Source = Windows Search Service | ID = 1006
Description =

Error - 2008-08-01 07:43:08 | Computer Name = Kontor | Source = Windows Search Service | ID = 1006
Description =

Error - 2008-08-01 20:31:58 | Computer Name = Kontor | Source = Windows Search Service | ID = 1006
Description =

Error - 2008-08-01 21:02:31 | Computer Name = Kontor | Source = MsiInstaller | ID = 11706
Description =

Error - 2008-08-03 03:57:21 | Computer Name = Kontor | Source = Windows Search Service | ID = 1006
Description =

Error - 2008-08-03 03:57:56 | Computer Name = Kontor | Source = Windows Search Service | ID = 1006
Description =

Error - 2008-08-03 03:58:00 | Computer Name = Kontor | Source = Windows Search Service | ID = 1006
Description =

Error - 2008-08-03 03:58:27 | Computer Name = Kontor | Source = Windows Search Service | ID = 1006
Description =

Error - 2008-08-03 08:57:38 | Computer Name = Kontor | Source = Windows Search Service | ID = 1006
Description =

[ Media Center Events ]
Error - 2008-08-29 09:53:18 | Computer Name = Kontor | Source = ehSched | ID = 5
Description = CResourceMgr::GetEhepgdat Error GetEhepgdatDispatcher 0x80131534

Error - 2008-08-29 09:53:18 | Computer Name = Kontor | Source = Media Center Guide | ID = 0
Description = Händelseinformation: Error reprocessing guide: System.TypeInitializationException:
Ett undantagsfel inträffade för typkonstruktorn. vid ehiProxy.ResourceMgrClass.GetEhepgdat(IEhepgdat&
ppEhepgdatDisp) vid Microsoft.Ehome.Epg.Helper.EhepgdatHelper.GetEhepgdat()
vid Microsoft.Ehome.Epg.Helper.EhepgdatBase.Retry(EhepgdatCall action) vid Microsoft.Ehome.Epg.Guide.ReprocessGuideImp()
Process: DefaultDomain Objektnamn: Media Center Guide

Error - 2008-08-29 09:53:18 | Computer Name = Kontor | Source = Media Center Guide | ID = 0
Description = Händelseinformation: Error: Failed to reprocess guide! Process: DefaultDomain
Objektnamn:
Media Center Guide

Error - 2008-08-29 09:53:25 | Computer Name = Kontor | Source = ehSched | ID = 5
Description = CResourceMgr::GetEhepgdat Error GetEhepgdatDispatcher 0x80040154

Error - 2008-12-31 20:02:45 | Computer Name = Kontor | Source = ehSched | ID = 5
Description = CResourceMgr::GetEhepgdat Error GetEhepgdatDispatcher 0x80131534

Error - 2008-12-31 20:02:45 | Computer Name = Kontor | Source = ehSched | ID = 5
Description = CResourceMgr::GetEhepgdat Error GetEhepgdatDispatcher 0x80040154

Error - 2008-12-31 20:02:47 | Computer Name = Kontor | Source = Media Center Guide | ID = 0
Description = Händelseinformation: COMException trying to call ehepgdat. Process:
DefaultDomain Objektnamn: Microsoft.Ehome.Epg.Helper.EhepgdatHelper

Error - 2008-12-31 20:02:47 | Computer Name = Kontor | Source = ehSched | ID = 5
Description = CResourceMgr::GetEhepgdat Error GetEhepgdatDispatcher 0x80131534

Error - 2008-12-31 20:02:47 | Computer Name = Kontor | Source = Media Center Guide | ID = 0
Description = Händelseinformation: Error reprocessing guide: System.TypeInitializationException:
Ett undantagsfel inträffade för typkonstruktorn. vid ehiProxy.ResourceMgrClass.GetEhepgdat(IEhepgdat&
ppEhepgdatDisp) vid Microsoft.Ehome.Epg.Helper.EhepgdatHelper.GetEhepgdat()
vid Microsoft.Ehome.Epg.Helper.EhepgdatBase.Retry(EhepgdatCall action) vid Microsoft.Ehome.Epg.Guide.ReprocessGuideImp()
Process: DefaultDomain Objektnamn: Media Center Guide

Error - 2008-12-31 20:02:47 | Computer Name = Kontor | Source = Media Center Guide | ID = 0
Description = Händelseinformation: Error: Failed to reprocess guide! Process: DefaultDomain
Objektnamn:
Media Center Guide

[ System Events ]
Error - 2010-04-28 17:45:33 | Computer Name = Kontor | Source = WMPNetworkSvc | ID = 866312
Description =

Error - 2010-04-28 18:42:51 | Computer Name = Kontor | Source = DCOM | ID = 10010
Description =

Error - 2010-04-29 00:55:31 | Computer Name = Kontor | Source = Print | ID = 19
Description = Utskriftsbufferthanteraren kunde inte dela ut skrivaren CutePDF Writer
med resursnamnet CutePDF Writer. Fel 2114. Skrivaren kan inte användas av andra
i nätverket.

Error - 2010-04-29 00:56:08 | Computer Name = Kontor | Source = Service Control Manager | ID = 7000
Description =

Error - 2010-04-29 00:56:30 | Computer Name = Kontor | Source = DCOM | ID = 10016
Description =

Error - 2010-04-29 00:56:49 | Computer Name = Kontor | Source = DCOM | ID = 10016
Description =

Error - 2010-04-29 00:59:41 | Computer Name = Kontor | Source = Service Control Manager | ID = 7009
Description =

Error - 2010-04-29 00:59:41 | Computer Name = Kontor | Source = Service Control Manager | ID = 7000
Description =

Error - 2010-04-29 01:01:24 | Computer Name = Kontor | Source = WMPNetworkSvc | ID = 866312
Description =

Error - 2010-04-29 01:01:25 | Computer Name = Kontor | Source = WMPNetworkSvc | ID = 866312
Description =


< End of report >
Please re-run GMER under Safe Mode this time and ensure that all the boxes are checked aside from "Sections" and "C:\" drive box. Then, post the GMER log back here. Thanks.
Hi Conspire,


I've tried for hours (as the pc is so darn slow - both to start and to work with), but nada ….. :smack:

I've uninstalled Gmer and downloaded and installed it again. I've ran it as admin and as common user. I've run it in safe mode, both as admin and not.


Same result every time. Gmer stops working after a while. 📎Image1.png The sign with Swedish text says: gmer.exe has stopped working Windows is looking for a solution to the problem…


Now I'm really pulling my hair!!! :pullhair:


ANYWAY - best regards from an angry, old lady in Sweden
Hi,

I understand your frustrations of having a slow computer but don't worry, we will go through this together. :)

Please read through these instructions to familarize yourself with what to expect when this tool runs


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hi,

Gosh, it took an hour and a half to finish the ComboFix - AND - it didn't disconnect from the Internet, so I was kind of worried, during the work proceeded, as my antivirus was disabled.

Here's the log, anyway! Hope you can get something out of it - I can't:

ComboFix 10-05-02.02 - Annelie 2010-05-03 9:13.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.46.1053.18.3070.1805 [GMT 2:00]
Körs från: c:\users\Annelie\Desktop\ComboFix.exe
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-20667866-41827632-2920184442-1003
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\$recycle.bin\S-1-5-21-3646087156-1547817475-3345862645-500
c:\program files\SpeedBit Toolbar\Toolbar\tbhelper.dll
c:\program files\SpeedBit Video Downloader\Toolbar\tbhelper.dll
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.0.inf
c:\windows\system32\SHELLLNK.TLB
c:\windows\TEMP\logishrd\LVPrcInj01.dll

.
(((((((((((((((((((((((( Filer Skapade från 2010-04-03 till 2010-05-03 ))))))))))))))))))))))))))))))
.

2010-05-02 07:46 . 2010-05-02 07:46 93056 —-a-w- C:\uxldqpow.sys
2010-05-01 22:54 . 2010-05-01 22:54 ——– d—–w- c:\users\Annelie\AppData\Local\Adobe
2010-05-01 05:48 . 2010-05-01 05:48 ——– d—–w- c:\users\Annelie\AppData\Local\Cooliris
2010-05-01 05:24 . 2010-05-01 05:24 136680 —-a-w- c:\users\Annelie\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-01 05:21 . 2010-05-01 05:21 ——– d—–w- c:\users\Annelie\AppData\Local\ArcSoft
2010-04-28 16:25 . 2010-05-01 07:42 ——– d—–w- c:\progra~2\CanonIJPLM
2010-04-28 16:01 . 2009-04-28 13:41 303104 —-a-w- c:\windows\system32\CNC640L.dll
2010-04-28 16:01 . 2009-04-03 14:00 1310720 —-a-w- c:\windows\system32\CNC640C.dll
2010-04-28 16:01 . 2009-04-03 13:59 110592 —-a-w- c:\windows\system32\CNC640I.dll
2010-04-28 16:01 . 2009-04-03 13:57 106496 —-a-w- c:\windows\system32\CNC640U.dll
2010-04-28 16:01 . 2008-08-25 16:02 15872 —-a-w- c:\windows\system32\CNHMCA.dll
2010-04-28 14:23 . 2009-03-18 00:09 178176 —-a-w- c:\windows\system32\CNMIUA2.DLL
2010-04-23 16:13 . 2010-04-12 15:29 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-04-14 02:31 . 2010-02-23 11:10 79360 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-14 02:31 . 2010-02-23 11:10 212992 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-14 02:31 . 2010-02-23 11:10 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-14 02:31 . 2010-03-05 14:01 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-04-14 02:31 . 2010-02-18 14:07 3600776 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-14 02:31 . 2010-02-18 14:07 3548040 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-04-14 02:30 . 2010-02-18 14:07 904576 —-a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-14 02:30 . 2010-02-18 11:28 25088 —-a-w- c:\windows\system32\drivers\tunnel.sys
2010-04-14 02:30 . 2010-02-18 13:30 200704 —-a-w- c:\windows\system32\iphlpsvc.dll
2010-04-14 02:29 . 2009-12-23 11:33 172032 —-a-w- c:\windows\system32\wintrust.dll
2010-04-14 02:28 . 2010-01-13 17:34 98304 —-a-w- c:\windows\system32\cabview.dll
2010-04-11 19:28 . 2010-04-11 19:28 ——– d—–w- c:\progra~2\Alwil Software

.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-03 08:11 . 2009-01-13 12:25 ——– d—–w- c:\program files\Spyware Doctor
2010-05-03 08:00 . 2007-11-24 17:30 12 —-a-w- c:\windows\bthservsdp.dat
2010-05-02 11:26 . 2010-02-20 10:36 ——– d—–w- c:\users\Annelie\AppData\Roaming\Facebook
2010-05-02 10:05 . 2008-01-15 22:43 ——– d—–w- c:\program files\Paint Shop Pro 7
2010-05-01 07:41 . 2009-08-15 14:25 32608 —-a-w- c:\windows\king-uninstall.exe
2010-04-30 13:22 . 2009-12-03 15:34 ——– d–h–w- c:\progra~2\CanonIJScan
2010-04-30 13:22 . 2009-12-03 15:33 ——– d—–w- c:\users\Annelie\AppData\Roaming\Canon
2010-04-28 16:44 . 2009-12-03 14:37 ——– d—–w- c:\program files\Canon
2010-04-24 07:13 . 2007-06-19 12:48 597598 —-a-w- c:\windows\system32\perfh01D.dat
2010-04-24 07:13 . 2007-06-19 12:48 117210 —-a-w- c:\windows\system32\perfc01D.dat
2010-04-24 06:18 . 2010-02-23 13:36 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-23 19:59 . 2008-02-08 16:05 ——– d—–w- c:\program files\IncrediMail
2010-04-23 16:13 . 2007-10-31 13:05 ——– d—–w- c:\program files\Java
2010-04-19 05:59 . 2007-10-29 11:18 ——– d—–w- c:\users\Annelie\AppData\Roaming\BPFTP
2010-04-17 13:57 . 2007-12-01 09:36 ——– d—–w- c:\program files\Greeting Card Designer
2010-04-15 09:13 . 2007-11-16 07:38 ——– d—–w- c:\users\Annelie\AppData\Roaming\wsInspector
2010-04-14 16:47 . 2009-02-12 10:36 38848 —-a-w- c:\windows\system32\avastSS.scr
2010-04-14 16:47 . 2009-02-12 10:36 153184 —-a-w- c:\windows\system32\aswBoot.exe
2010-04-14 16:35 . 2009-02-12 10:37 46672 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2010-04-14 16:35 . 2009-02-12 10:36 162768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2010-04-14 16:31 . 2009-02-12 10:37 23376 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2010-04-14 16:31 . 2009-02-12 10:36 51792 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-04-14 16:31 . 2009-02-12 10:36 19024 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-04-14 06:41 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-04-11 19:39 . 2009-02-12 10:36 ——– d—–w- c:\program files\Alwil Software
2010-04-06 16:28 . 2007-06-19 03:35 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-04-02 06:29 . 2009-03-03 14:34 ——– d—–w- c:\program files\BulletProof FTP Client 2009
2010-04-02 06:04 . 2007-10-29 12:15 ——– d—–w- c:\program files\AVS4YOU
2010-04-02 06:04 . 2007-10-29 12:15 ——– d—–w- c:\program files\Common Files\AVSMedia
2010-04-01 12:35 . 2010-02-17 14:21 ——– d—–w- c:\progra~2\HP
2010-04-01 12:11 . 2007-06-19 03:41 19525 —-a-w- c:\windows\hpqins13.dat
2010-03-30 15:30 . 2007-11-02 22:05 ——– d—–w- c:\program files\FontExpert
2010-03-29 22:46 . 2010-02-23 13:36 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-29 22:45 . 2010-02-23 13:36 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-16 20:10 . 2010-03-16 20:10 ——– d—–w- c:\program files\Common Files\Java
2010-03-12 21:39 . 2009-12-09 15:53 ——– d—–w- c:\program files\RegCure
2010-03-08 23:53 . 2010-03-08 23:53 ——– d—–w- c:\users\Annelie\AppData\Roaming\MozBackup
2010-03-08 23:53 . 2010-03-08 23:53 ——– d—–w- c:\program files\MozBackup
2010-03-08 16:32 . 2007-10-29 11:25 ——– d—–w- c:\program files\Spel
2010-03-08 16:32 . 2009-10-28 17:38 ——– d—–w- c:\program files\RealArcade
2010-03-08 16:31 . 2010-03-08 16:31 ——– d—–w- c:\progra~2\JollyBear
2010-03-08 16:31 . 2010-03-08 16:31 ——– d—–w- c:\progra~2\Trymedia
2010-03-08 15:17 . 2007-10-29 10:17 ——– d—–w- c:\program files\RoboForm
2010-02-23 06:39 . 2010-03-30 21:26 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-23 06:33 . 2010-03-30 21:26 109056 —-a-w- c:\windows\system32\iesysprep.dll
2010-02-23 06:33 . 2010-03-30 21:26 71680 —-a-w- c:\windows\system32\iesetup.dll
2010-02-23 04:55 . 2010-03-30 21:26 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2010-02-20 23:06 . 2010-03-13 07:01 24064 —-a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:05 . 2010-03-13 07:01 30720 —-a-w- c:\windows\system32\httpapi.dll
2010-02-20 20:53 . 2010-03-13 07:01 411648 —-a-w- c:\windows\system32\drivers\http.sys
2010-02-12 13:53 . 2010-02-12 13:53 1114576 —-a-w- c:\users\Annelie\revosetup.exe
2010-02-12 10:32 . 2010-03-24 07:01 293376 —-a-w- c:\windows\system32\browserchoice.exe
2008-01-09 21:20 . 2008-01-09 21:04 88 –sha-r- c:\windows\System32\3E8B532E94.sys
2008-01-09 21:20 . 2008-01-09 21:04 3140 –sha-w- c:\windows\System32\KGyGaAvL.sys
.

(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Not* Tomma poster & legitima standardposter visas inte.
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{31B27F2D-6BC6-451B-B3D2-4EAB36B2FC3B}]
2009-10-19 05:10 2655736 —-a-w- c:\program files\SpeedBit Video Downloader\Toolbar\tbcore3.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EBFCD017-BCAD-42C3-9ED5-89DBDFC59171}"= "c:\program files\SpeedBit Toolbar\Toolbar\SpeedBit.dll" [2009-08-27 2598896]

[HKEY_CLASSES_ROOT\clsid\{ebfcd017-bcad-42c3-9ed5-89dbdfc59171}]
[HKEY_CLASSES_ROOT\SPEEDBIT1.SPEEDBIT1.3]
[HKEY_CLASSES_ROOT\TypeLib\{77AA25E8-6083-4949-A831-9CB11861DC10}]
[HKEY_CLASSES_ROOT\SPEEDBIT1.SPEEDBIT1]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{EBFCD017-BCAD-42C3-9ED5-89DBDFC59171}"= "c:\program files\SpeedBit Toolbar\Toolbar\SpeedBit.dll" [2009-08-27 2598896]

[HKEY_CLASSES_ROOT\clsid\{ebfcd017-bcad-42c3-9ed5-89dbdfc59171}]
[HKEY_CLASSES_ROOT\SPEEDBIT1.SPEEDBIT1.3]
[HKEY_CLASSES_ROOT\TypeLib\{77AA25E8-6083-4949-A831-9CB11861DC10}]
[HKEY_CLASSES_ROOT\SPEEDBIT1.SPEEDBIT1]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2010-04-23 353736]
"Google Update"="c:\users\Annelie\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-04-27 133104]
"Rainlendar2"="c:\program files\Rainlendar2\Rainlendar2.exe" [2009-08-22 5148672]
"Sms och mms i datorn Desktop"="c:\program files\Sms och mms i datorn Desktop\mw.exe" [2009-10-09 2078208]
"RoboForm"="c:\program files\RoboForm\RoboTaskBarIcon.exe" [2010-03-08 160328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-01 4390912]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 65536]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-09-22 1243088]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 56080]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2008-01-10 92704]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-01-10 8530464]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-01-10 88608]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-04-14 2790472]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-03-23 1983816]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-17 767312]
"IJNetworkScanUtility"="c:\program files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe" [2009-05-19 136544]

c:\users\Annelie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Picture Motion Browser verktyg f”r mediekontroll.lnk - c:\program files\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2008-8-31 385024]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Device Monitor.lnk - c:\program files\ArcSoft\MediaConverter 4 Platinum\Monitor.exe [2010-2-18 139264]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-10-13 692224]
Personal.lnk - c:\program files\Personal\bin\Personal.exe [2009-8-19 939920]
Telia AutoStore.lnk - c:\program files\Storegate\Autostore\AutoStore.exe [2009-11-3 832792]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=c:\windows\pss\WinZip Quick Pick.lnk.CommonStartup
backupExtension=.CommonStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 09:45 39792 —-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator]
2009-10-19 05:11 2803200 —-a-w- c:\program files\DAP\DAP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-02-16 21:11 49152 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-18 21:33 202240 —-a-w- c:\program files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"FirewallOverride"=dword:00000001
"VistaSp2"=hex(B):97,59,aa,e4,b7,36,ca,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-20667866-41827632-2920184442-1000]
"EnableNotificationsRef"=dword:00000003
"EnableNotifications"=dword:00000001

R3 WSDPrintDevice;WSD-utksriftsstöd via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2008-01-18 16896]
R3 WSDScan;WSD-inskanningsstöd via UMB;c:\windows\system32\DRIVERS\WSDScan.sys [2009-04-11 19968]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-09-23 207280]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-04-14 51792]
S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [2009-10-08 112592]
S2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-09-23 358600]
S2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2007-09-07 1373480]


— Övriga tjänster/drivrutiner i minnet —

*Deregistered* - PCTSDInjDriver32

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Innehållet i mappen 'Schemalagda aktiviteter':

2010-05-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-20667866-41827632-2920184442-1000Core.job
- c:\users\Annelie\AppData\Local\Google\Update\GoogleUpdate.exe [2009-04-27 22:08]

2010-05-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-20667866-41827632-2920184442-1000UA.job
- c:\users\Annelie\AppData\Local\Google\Update\GoogleUpdate.exe [2009-04-27 22:08]

2010-05-02 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2010-02-23 23:20]

2010-05-03 c:\windows\Tasks\RegCure Startup.job
- c:\program files\RegCure\RegCure.exe [2010-02-23 23:20]

2010-04-25 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2010-02-23 23:20]

2010-05-03 c:\windows\Tasks\User_Feed_Synchronization-{ED6E7C9B-18AF-493F-875E-109641BDF724}.job
- c:\windows\system32\msfeedssync.exe [2010-03-30 04:54]
.
.
——- Extra genomsökning ——-
.
uStart Page = hxxp://worldwinner.com/
uInternet Settings,ProxyOverride = localhost;*.local
IE: &Add; animation to IncrediMail Style Box - c:\program files\IncrediMail\bin\resources\WebMenuImg.htm
IE: &Clean; Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download; with &DAP; - c:\program files\DAP\dapextie.htm
IE: Anpassa meny - file://c:\program files\RoboForm\RoboFormComCustomizeIEMenu.html
IE: Download &all; with DAP - c:\program files\DAP\dapextie2.htm
IE: Fyll i formulär - file://c:\program files\RoboForm\RoboFormComFillForms.html
IE: Läs EXIF - c:\program files\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm
IE: RF verktygsfält - file://c:\program files\RoboForm\RoboFormComShowToolbar.html
IE: Skicka som mms… - file://c:\program files\Sms och mms i datorn Desktop\sendmms.htm
IE: Skicka som sms… - file://c:\program files\Sms och mms i datorn Desktop\sendsms.htm
IE: Spara formulär - file://c:\program files\RoboForm\RoboFormComSavePass.html
IE: {{3c69c7a4-0fb3-4fe0-bc90-9739726e4570} - c:\program files\PrimeScratchCards\PSC.exe {77BF5300-1474-4EC7-9980-D32B130E9B47} - {77bf5300-1474-4ec7-9980-d32b130e9b47}\inprocserver32 does not exist!
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {BE9B2B7C-6680-44E6-9F51-05384AD9C2FF} - hxxp://eu.mywayfinder.com/MapConnect.ocx
FF - ProfilePath - c:\users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\rdyfc4m0.default\
FF - prefs.js: browser.search.selectedEngine - MyStart Search
FF - prefs.js: browser.startup.homepage - hxxp://google.se
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar&search;=
FF - component: c:\program files\ArcSoft\RAW Thumbnail Viewer\FireFox Extension\components\FirefoxMenu.dll
FF - component: c:\program files\DAP\DAPFireFox\components\DAPFireFox.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\program files\RoboForm\Firefox\components\rfproxy_27.dll
FF - component: c:\program files\RoboForm\Firefox\components\rfproxy_31.dll
FF - component: c:\users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\rdyfc4m0.default\extensions\[removed]\components\coolirisstub.dll
FF - plugin: c:\program files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmidas.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF - plugin: c:\program files\Personal\bin\np_prsnl.dll
FF - plugin: c:\users\Annelie\AppData\Local\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\users\Annelie\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\users\Annelie\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\rdyfc4m0.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\users\Annelie\AppData\Roaming\Mozilla\Firefox\Profiles\rdyfc4m0.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - plugin: c:\users\Annelie\AppData\Roaming\RealArcade\npraclient.dll
FF - plugin: c:\users\Annelie\AppData\Roaming\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICY —-
FF - user.js: keyword.enabled - true
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - FÖRÄLDRALÖSA POSTER SOM TAGITS BORT - - - -

WebBrowser-{FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - (no file)
HKCU-Run-DriverMax - (no file)
HKCU-Run-DriverMax_RESTART - (no file)
MSConfigStartUp-ControlCenter3 - c:\program files\Brother\ControlCenter3\brctrcen.exe
AddRemove-Google Chrome - c:\users\Annelie\AppData\Local\Google\Chrome\Application\4.1.249.1064\Installer\setup.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-03 10:05
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LÅSTA REGISTERNYCKLAR ———————

[HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLer som "laddats" under processer som körs ———————

- - - - - - - > 'Explorer.exe'(1004)
c:\program files\Logitech\SetPoint\lgscroll.dll
.
———————— Andra processer som körs ————————
.
c:\windows\SYSTEM32\WISPTIS.EXE
c:\program files\Common Files\microsoft shared\ink\TabTip.exe
c:\program files\Ad-Aware\aawservice.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\SYSTEM32\WISPTIS.EXE
c:\program files\Common Files\microsoft shared\ink\TabTip.exe
c:\windows\system32\brss01a.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\PSIService.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\windows\system32\WTablet\Wacom_TabletUser.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\windows\System32\rundll32.exe
c:\program files\Alwil Software\Avast5\AvastUI.exe
c:\windows\System32\rundll32.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
c:\windows\ehome\ehmsas.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
c:\program files\Storegate\Autostore\AutoStoreSvc.exe
c:\users\Annelie\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe
c:\program files\IncrediMail\bin\ImApp.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Sluttid: 2010-05-03 10:26:20 - datorn startades om.
ComboFix-quarantined-files.txt 2010-05-03 08:26

Före genomsökningen: 108 650 713 088 byte ledigt
Efter genomsökningen: 108 398 649 344 byte ledigt

Current=3 Default=3 Failed=1 LastKnownGood=61 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,
29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,
56,57,58,59,60,61
- - End Of File - - 161ECBC04E351D9462726F93D19606A4



Best regards
Annelie
Hi,

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


===================================================


**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply

===================================================

On your next reply please post :
MBAM log
Kaspersky log

Good Day!
Hi, It took some time with the Kaspersky. 📎Kaspersky.png - over 16 hours without an active anti-virus software. Isn't that dangerous? :o Anyway, here's the two logs: ____________________ Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4052 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18904 2010-05-04 14:49:57 mbam-log-2010-05-04 (14-49-57).txt Scan type: Quick scan Objects scanned: 129772 Time elapsed: 15 minute(s), 36 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) __________________________ ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Wednesday, May 5, 2010 Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Tuesday, May 04, 2010 10:00:11 Records in database: 4045743 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ Z:\ Scan statistics: Objects scanned: 375009 Threats found: 2 Infected objects found: 4 Suspicious objects found: 0 Scan duration: 16:14:28 File name / Threat / Threats count C:\Program Files\DAP\Offers\spo3.exe Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.bk 1 C:\Users\Annelie\Downloads\FullReleases\Deamon Tools\daemon400.exe Infected: not-a-virus:WebToolbar.Win32.WhenU.a 1 C:\Users\Public\Acer\Diverse\Downloads\FullReleases\Deamon Tools\daemon400.exe Infected: not-a-virus:WebToolbar.Win32.WhenU.a 1 Z:\Acer\Diverse\Downloads\FullReleases\Deamon Tools\daemon400.exe Infected: not-a-virus:WebToolbar.Win32.WhenU.a 1 Selected area has been scanned. ____________________ Best regards :wavey: Farmor
Your log appears to be clean. :)

Follow these steps to uninstall Combofix
  • Click START then RUN
  • Now copy/paste the code into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.
Combofix /Uninstall
[external image: Posted Image]

===================================================

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
===================================================

Here are some tips to reduce the potential for spyware infection in the future:
  • Make your Internet Explorer More Secure
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab.
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.

      • Change the Download signed ActiveX controls to Prompt.
      • Change the Download unsigned ActiveX controls to Disable.
      • Change the Initialise and script ActiveX controls not marked as safe to Disable.
      • Change the Installation of desktop items to Prompt.
      • Change the Launching programs and files in an IFRAME to Prompt.
      • Change the Navigate sub-frames across different domains to Prompt.
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.

  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Consider a custom hosts file such as MVPS HOSTS - This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
    For information on how to download and install, please read this tutorial by WinHelp2002
    Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Please also read Tony Klein's excellent article:
How I got
Infected in the First Place



Follow this list and your potential for being infected again will reduce dramatically.

Hopefully this should take care of your problems! Good luck.

Do you have any questions or problems to ask? Please do not hesitate to do so. :)

**Please respond this one more time to ensure it is resolved.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI