This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] HijackThis log

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

There are some Internet Explorer pop-ups, without me even browsing the internet, which I even do on Google Chrome.
My computer seems infected, I hope you can help me.


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:41:13, on 26-04-2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Program Files\DigitalPersona\Bin\DpAgent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Users\Steffen\AppData\Local\Temp\Vl0.exe
C:\Users\Steffen\AppData\Local\Temp\Vl1.exe
C:\Program Files\DAEMON Tools Pro\DTProShellHlp.exe
C:\Users\Steffen\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Steffen\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Steffen\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEUser.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Hjælp til tilmelding til Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [DpAgent] C:\Program Files\DigitalPersona\Bin\dpagent.exe
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [Canaveral] rundll32.exe C:\Users\Steffen\AppData\Local\Temp\sshnas21.dll,BackupReadW
O4 - HKCU\..\Run: [YVIBBBHA8C] C:\Users\Steffen\AppData\Local\Temp\Vl1.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send billede til &Bluetooth-enhed… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send siden til &Bluetooth-enhed… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O15 - Trusted Zone: *.danskebank.dk
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/DA-DK/a-UNO1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/…B/e-Safekey.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GoogleDesktopNetwork3.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Application Driver Auto Removal Service (01) (appdrvrem01) - Protection Technology - C:\Windows\System32\appdrvrem01.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: Google Desktop-administrator 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Tjenesten Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 8720 bytes
Hello Bro and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!
Please be advised I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
This may cause a delay in response time, but I will do my best to keep it as short as possible.

HijackThis has largely been replaced by other tools. Since being acquired by TrendMicro, HijackThis has not been regularly updated. Many infections are now able to hide partly, or completely from a HijackThis scan. OTL ncludes all the scan locations of HijackThis and more. It's not only a more comprehensive scan tool, but also offers more powerful removal features.

Download and Run OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in:

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\system32\drivers\*.sys /90
    %systemroot%\System32\config\*.sav

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

If you have CDEmulation drivers installed (such as Daemon Tools, Alcohol120) please follow the instructions below to run DeFogger prior to and after running GMER. If you do not have any CDEmulation drivers installed, you do not need to run DeFogger and you can go right to the instructions to run GMER.

Download DeFogger

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

Download and Run GMER

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Here are the two OTL scan logs


OTL log

OTL logfile created on: 28-04-2010 18:00:55 - Run 1
OTL by OldTimer - Version 3.2.3.0 Folder = C:\Program Files
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000406 | Country: Danmark | Language: DAN | Date Format: dd-MM-yyyy

3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 70,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 85,00% Paging File free
Paging file location(s): ?:\pagefile.sys

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223,08 Gb Total Space | 58,10 Gb Free Space | 26,04% Space Free | Partition Type: NTFS
Drive D: | 9,81 Gb Total Space | 2,93 Gb Free Space | 29,85% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: STEFFEN-PC
Current User Name: Steffen
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010-04-27 08:25:39 | 000,563,712 | —- | M] (OldTimer Tools) – C:\Program Files\OTL.exe
PRC - [2010-02-21 22:45:10 | 000,030,192 | —- | M] (Google) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
PRC - [2010-02-21 06:03:12 | 001,093,208 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2009-12-09 19:02:38 | 000,017,904 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2009-04-11 08:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2009-03-30 16:28:36 | 001,533,808 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
PRC - [2009-03-30 16:28:36 | 000,183,152 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
PRC - [2007-09-20 20:12:02 | 000,671,744 | —- | M] (DigitalPersona, Inc.) – C:\Program Files\DigitalPersona\Bin\DpAgent.exe
PRC - [2007-09-20 20:02:58 | 000,299,008 | —- | M] (DigitalPersona, Inc.) – C:\Program Files\DigitalPersona\Bin\DpHostW.exe
PRC - [2007-09-15 10:29:10 | 000,102,400 | —- | M] (Synaptics, Inc.) – C:\Program Files\Synaptics\SynTP\SynTPStart.exe
PRC - [2006-09-28 11:20:00 | 000,049,152 | —- | M] (Ulead Systems, Inc.) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe


========== Modules (SafeList) ==========

MOD - [2010-04-27 08:25:39 | 000,563,712 | —- | M] (OldTimer Tools) – C:\Program Files\OTL.exe
MOD - [2009-04-11 08:21:38 | 001,686,016 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2010-02-21 22:45:10 | 000,030,192 | —- | M] (Google) [On_Demand | Stopped] – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe – (GoogleDesktopManager-110309-193829)
SRV - [2009-12-09 19:02:38 | 000,017,904 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe – (MsMpSvc)
SRV - [2009-10-27 10:26:36 | 000,657,408 | —- | M] (Nokia) [On_Demand | Stopped] – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe – (ServiceLayer)
SRV - [2009-09-25 03:27:04 | 000,793,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\FntCache.dll – (FontCache)
SRV - [2009-07-19 02:58:54 | 000,304,528 | —- | M] (Protection Technology) [Auto | Stopped] – C:\Windows\System32\appdrvrem01.exe – (appdrvrem01) Application Driver Auto Removal Service (01)
SRV - [2009-03-30 16:28:36 | 001,533,808 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE – (wlidsvc)
SRV - [2008-01-19 09:38:24 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\mpsvc.dll – (WinDefend)
SRV - [2007-09-20 20:02:58 | 000,299,008 | —- | M] (DigitalPersona, Inc.) [Auto | Running] – C:\Program Files\DigitalPersona\Bin\DpHostW.exe – (DpHost)
SRV - [2007-03-05 19:30:06 | 000,110,592 | —- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe – (Com4Qlb)
SRV - [2006-09-28 11:20:00 | 000,049,152 | —- | M] (Ulead Systems, Inc.) [Auto | Running] – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe – (UleadBurningHelper)


========== Driver Services (SafeList) ==========

DRV - [2010-01-23 18:48:53 | 000,691,696 | —- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\System32\drivers\sptd.sys – (sptd)
DRV - [2009-12-02 16:23:40 | 000,149,040 | —- | M] (Microsoft Corporation) [File_System | System | Running] – C:\Windows\System32\drivers\MpFilter.sys – (MpFilter)
DRV - [2009-12-02 16:23:40 | 000,042,368 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Running] – C:\Windows\System32\drivers\MpNWMon.sys – (MpNWMon)
DRV - [2009-10-06 12:52:50 | 000,007,936 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\usbser_lowerfltj.sys – (UsbserFilt)
DRV - [2009-10-06 12:52:34 | 000,022,016 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ccdcmbo.sys – (nmwcdc)
DRV - [2009-10-06 12:52:34 | 000,017,664 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ccdcmb.sys – (nmwcd)
DRV - [2009-10-06 12:52:34 | 000,007,936 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\usbser_lowerflt.sys – (upperdev)
DRV - [2009-10-03 07:02:06 | 009,905,096 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2009-09-05 17:55:36 | 001,183,744 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\athr.sys – (athr)
DRV - [2009-07-19 02:58:54 | 002,915,944 | —- | M] (Protection Technology) [Kernel | System | Running] – C:\Windows\System32\drivers\appdrv01.sys – (appdrv01) Application Driver (01)
DRV - [2009-06-10 17:49:32 | 000,024,576 | —- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ANDROIDUSB.sys – (HTCAND32)
DRV - [2009-04-11 06:42:54 | 000,073,216 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\USBAUDIO.sys – (usbaudio) USB-lyddriver (WDM)
DRV - [2008-08-26 10:26:12 | 000,018,816 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\pccsmcfd.sys – (pccsmcfd)
DRV - [2008-03-04 02:32:00 | 000,188,416 | —- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\CHDRT32.sys – (CnxtHdAudService)
DRV - [2007-09-18 15:12:28 | 000,080,936 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\btwavdt.sys – (btwavdt)
DRV - [2007-09-18 15:12:28 | 000,080,424 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\btwaudio.sys – (btwaudio)
DRV - [2007-09-18 15:12:28 | 000,016,168 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\btwrchid.sys – (btwrchid)
DRV - [2007-09-15 10:50:56 | 000,191,408 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\SynTP.sys – (SynTP)
DRV - [2007-09-10 00:12:28 | 000,176,640 | —- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\CHDART.sys – (HdAudAddService)
DRV - [2007-08-29 00:47:36 | 000,146,560 | —- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\atswpdrv.sys – (ATSWPDRV) AuthenTec TruePrint USB Driver (SwipeSensor)
DRV - [2007-07-11 19:30:22 | 000,007,168 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HpqRemHid.sys – (HpqRemHid)
DRV - [2007-07-10 16:27:56 | 000,008,704 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\XAudio.sys – (XAudio)
DRV - [2007-06-20 13:29:56 | 000,984,064 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HSX_DPV.sys – (HSF_DPV)
DRV - [2007-06-20 13:28:34 | 000,208,896 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HSXHWAZL.sys – (HSXHWAZL)
DRV - [2007-06-20 13:28:22 | 000,660,480 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HSX_CNXT.sys – (winachsf)
DRV - [2007-06-19 02:12:04 | 000,016,768 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HpqKbFiltr.sys – (HpqKbFiltr)
DRV - [2007-06-08 14:15:20 | 000,194,362 | —- | M] (Jungo) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\windrvr6.sys – (WinDriver6)
DRV - [2007-03-22 07:02:04 | 000,037,376 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\System32\drivers\rixdptsk.sys – (rismxdp)
DRV - [2007-03-07 04:15:58 | 001,059,112 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvmfdx32.sys – (NVENETFD)
DRV - [2007-02-24 23:42:22 | 000,039,936 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\System32\drivers\rimmptsk.sys – (rimmptsk)
DRV - [2007-02-16 23:50:32 | 000,012,032 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvsmu.sys – (nvsmu)
DRV - [2007-02-06 17:38:02 | 000,028,288 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\emOEM.sys – (USB28xxOEM)
DRV - [2007-01-24 01:40:20 | 000,042,496 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\System32\drivers\rimsptsk.sys – (rimsptsk)
DRV - [2007-01-16 15:58:18 | 000,378,880 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\emBDA.sys – (USB28xxBGA)
DRV - [2006-11-02 11:51:45 | 000,900,712 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql2300.sys – (ql2300)
DRV - [2006-11-02 11:51:38 | 000,420,968 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adp94xx.sys – (adp94xx)
DRV - [2006-11-02 11:51:34 | 000,316,520 | —- | M] (Emulex) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\elxstor.sys – (elxstor)
DRV - [2006-11-02 11:51:32 | 000,297,576 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpahci.sys – (adpahci)
DRV - [2006-11-02 11:51:25 | 000,235,112 | —- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\uliahci.sys – (uliahci)
DRV - [2006-11-02 11:51:25 | 000,232,040 | —- | M] (Intel Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iastorv.sys – (iaStorV)
DRV - [2006-11-02 11:51:00 | 000,147,048 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu320.sys – (adpu320)
DRV - [2006-11-02 11:50:45 | 000,115,816 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata2.sys – (ulsata2)
DRV - [2006-11-02 11:50:41 | 000,112,232 | —- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\vsmraid.sys – (vsmraid)
DRV - [2006-11-02 11:50:35 | 000,106,088 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql40xx.sys – (ql40xx)
DRV - [2006-11-02 11:50:35 | 000,098,408 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata.sys – (UlSata)
DRV - [2006-11-02 11:50:35 | 000,098,408 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu160m.sys – (adpu160m)
DRV - [2006-11-02 11:50:24 | 000,088,680 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvraid.sys – (nvraid)
DRV - [2006-11-02 11:50:19 | 000,045,160 | —- | M] (IBM Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nfrd960.sys – (nfrd960)
DRV - [2006-11-02 11:50:17 | 000,041,576 | —- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iirsp.sys – (iirsp)
DRV - [2006-11-02 11:50:16 | 000,071,784 | —- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sisraid4.sys – (SiSRaid4)
DRV - [2006-11-02 11:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvstor.sys – (nvstor)
DRV - [2006-11-02 11:50:11 | 000,071,272 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\djsvs.sys – (aic78xx)
DRV - [2006-11-02 11:50:10 | 000,067,688 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arcsas.sys – (arcsas)
DRV - [2006-11-02 11:50:10 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_scsi.sys – (LSI_SCSI)
DRV - [2006-11-02 11:50:10 | 000,038,504 | —- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sisraid2.sys – (SiSRaid2)
DRV - [2006-11-02 11:50:10 | 000,037,480 | —- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\hpcisss.sys – (HpCISSs)
DRV - [2006-11-02 11:50:09 | 000,067,688 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arc.sys – (arc)
DRV - [2006-11-02 11:50:09 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteraid.sys – (iteraid)
DRV - [2006-11-02 11:50:07 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteatapi.sys – (iteatapi)
DRV - [2006-11-02 11:50:05 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_sas.sys – (LSI_SAS)
DRV - [2006-11-02 11:50:05 | 000,035,944 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\symc8xx.sys – (Symc8xx)
DRV - [2006-11-02 11:50:04 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_fc.sys – (LSI_FC)
DRV - [2006-11-02 11:50:03 | 000,034,920 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_u3.sys – (Sym_u3)
DRV - [2006-11-02 11:49:59 | 000,033,384 | —- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\mraid35x.sys – (Mraid35x)
DRV - [2006-11-02 11:49:56 | 000,031,848 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_hi.sys – (Sym_hi)
DRV - [2006-11-02 11:49:53 | 000,028,776 | —- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\megasas.sys – (megasas)
DRV - [2006-11-02 11:49:30 | 000,017,512 | —- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\viaide.sys – (viaide)
DRV - [2006-11-02 11:49:28 | 000,016,488 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\cmdide.sys – (cmdide)
DRV - [2006-11-02 11:49:20 | 000,014,952 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\aliide.sys – (aliide)
DRV - [2006-11-02 10:25:24 | 000,071,808 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserid.sys – (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006-11-02 10:24:47 | 000,011,904 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brusbser.sys – (BrUsbSer)
DRV - [2006-11-02 10:24:46 | 000,005,248 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltup.sys – (BrFiltUp)
DRV - [2006-11-02 10:24:45 | 000,013,568 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltlo.sys – (BrFiltLo)
DRV - [2006-11-02 10:24:44 | 000,062,336 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserwdm.sys – (BrSerWdm)
DRV - [2006-11-02 10:24:44 | 000,012,160 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brusbmdm.sys – (BrUsbMdm)
DRV - [2006-11-02 09:41:49 | 000,200,704 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\VSTAZL3.SYS – (HSFHWAZL)
DRV - [2006-11-02 09:36:50 | 000,020,608 | —- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ntrigdigi.sys – (ntrigdigi)
DRV - [2006-11-02 09:30:54 | 000,117,760 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\E1G60I32.sys – (E1G60) Intel®
DRV - [2006-11-02 09:30:53 | 000,464,384 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\BCMWL6.SYS – (BCM43XV)
DRV - [2006-10-19 04:10:57 | 001,380,864 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\igdkmd32.sys – (ialm)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 83 25 EC 16 40 4A F7 42 A2 2D 5F FC 79 4D 0B 38 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:0.9
FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.3
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:[removed]
FF - prefs.js..extensions.enabledItems: {6542b200-4374-11dd-ae16-0800200c9a66}:2.5b1
FF - prefs.js..extensions.enabledItems: {6E1A2A2E-AE2A-4A26-A812-46F54288379E}:3.5.1
FF - prefs.js..extensions.enabledItems: {d650973c-0444-4ac7-9d00-19e3613c83b9}:3.6.5
FF - prefs.js..extensions.enabledItems: {a81bafeb-b6ed-4501-aa17-15a2b3857e56}:3.5
FF - prefs.js..extensions.enabledItems: {74b288e6-77b6-41c7-8138-bb81f4539689}:3.5
FF - prefs.js..extensions.enabledItems: {d3d70bca-2d54-425e-b02c-b7e2f4b07688}:3.5
FF - prefs.js..extensions.enabledItems: {c9c58820-7bd4-11da-a72b-0800200c9a66}:2.20090109
FF - prefs.js..network.proxy.type: 4

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2009-12-30 19:09:29 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2009-12-30 19:32:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Program Files\Firefox\components [2010-02-21 22:45:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files\Firefox\plugins [2010-04-18 13:21:39 | 000,000,000 | —D | M]

[2009-04-12 14:26:46 | 000,000,000 | —D | M] – C:\Users\Steffen\AppData\Roaming\mozilla\Extensions
[2009-04-12 14:26:46 | 000,000,000 | —D | M] – C:\Users\Steffen\AppData\Roaming\mozilla\Extensions\[removed]
[2010-04-20 17:01:11 | 000,000,000 | —D | M] – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions
[2009-04-04 16:29:57 | 000,000,000 | —D | M] (Elementary) – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{05e38d80-09c1-11dd-bd0b-0800200c9a66}
[2008-09-07 14:07:41 | 000,000,000 | —D | M] (Just Black (A Cylence theme for Firefox 3)) – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{1a45a8a0-3278-11dd-bd11-0800200c9a66}
[2009-06-24 21:26:03 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008-09-07 14:03:07 | 000,000,000 | —D | M] (Abstract Classic) – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{2fbc1200-ad13-11db-abbd-0800200c9a66}
[2009-09-15 07:10:22 | 000,000,000 | —D | M] (Boost for Facebook) – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{47624dda-b77e-4feb-820a-e4f077d5d4ca}
[2009-07-16 12:59:45 | 000,000,000 | —D | M] (Flook Theme) – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{6542b200-4374-11dd-ae16-0800200c9a66}
[2009-08-23 13:32:45 | 000,000,000 | —D | M] (Full Flat) – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{6E1A2A2E-AE2A-4A26-A812-46F54288379E}
[2009-08-22 16:06:24 | 000,000,000 | —D | M] (iFox Graphite) – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{74b288e6-77b6-41c7-8138-bb81f4539689}
[2010-04-02 17:52:49 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2009-08-22 16:05:36 | 000,000,000 | —D | M] (iFox) – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{a81bafeb-b6ed-4501-aa17-15a2b3857e56}
[2009-10-09 10:56:32 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009-07-15 11:55:00 | 000,000,000 | —D | M] (Answers) – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{C0D0F6D1-9FC9-4b0a-B485-D5E13AF40D51}
[2009-08-02 19:42:10 | 000,000,000 | —D | M] (Fast Video Download) – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}
[2009-08-22 16:09:12 | 000,000,000 | —D | M] (iPox) – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{c9c58820-7bd4-11da-a72b-0800200c9a66}
[2009-08-13 14:28:56 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009-08-22 16:08:48 | 000,000,000 | —D | M] (iFox Smooth) – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{d3d70bca-2d54-425e-b02c-b7e2f4b07688}
[2009-09-15 07:10:26 | 000,000,000 | —D | M] (Whitehart) – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{d650973c-0444-4ac7-9d00-19e3613c83b9}
[2009-08-22 16:16:13 | 000,000,000 | —D | M] (No name found) – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2009-08-22 16:16:14 | 000,000,000 | —D | M] (CustomizeMySpace) – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{E57ED083-98E8-4670-A871-E8D306879F71}
[2009-08-22 16:16:12 | 000,000,000 | —D | M] – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\[removed]
[2008-09-07 14:23:56 | 000,000,000 | —D | M] – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\[removed]
[2009-12-07 23:29:02 | 000,000,000 | —D | M] – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\[removed]
[2009-10-04 14:22:31 | 000,000,000 | —D | M] – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\[removed]
[2010-04-02 17:45:54 | 000,000,000 | —D | M] – C:\Users\Steffen\AppData\Roaming\mozilla\Firefox\Profiles\s0kfb21q.default\extensions\[removed]
[2010-04-19 22:09:34 | 000,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions

O1 HOSTS File: ([2006-09-18 23:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKLM..\Run: [DpAgent] C:\Program Files\DigitalPersona\Bin\dpagent.exe (DigitalPersona, Inc.)
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Send billede til &Bluetooth-enhed… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send siden til &Bluetooth-enhed… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: danskebank.dk ([]* in Websteder, du har tillid til)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/DA-DK/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} https://netbank.danskebank.dk/html/activex/…B/e-Safekey.cab (e-Safekey)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~3\GoogleDesktopNetwork3.dll) - C:\PROGRA~1\Google\GOOGLE~3\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Steffen\AppData\Roaming\Microsoft\Windows Photo Gallery\Skrivebordsbaggrund med Windows Billedgalleri.jpg
O24 - Desktop BackupWallPaper: C:\Users\Steffen\AppData\Roaming\Microsoft\Windows Photo Gallery\Skrivebordsbaggrund med Windows Billedgalleri.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006-09-18 23:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2005-09-11 17:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE – [ NTFS ]
O33 - MountPoints2\{1de8a949-4ea1-11df-989e-0021860bd92f}\Shell - "" = AutoRun
O33 - MountPoints2\{1de8a949-4ea1-11df-989e-0021860bd92f}\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2008-09-08 22:17:04 | 000,000,000 | —D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
OTL cannot create restorepoints on Vista OSs!

========== Files/Folders - Created Within 30 Days ==========

[2010-04-27 08:25:17 | 000,563,712 | —- | C] (OldTimer Tools) – C:\Program Files\OTL.exe
[2010-04-25 21:11:31 | 000,000,000 | —D | C] – C:\ComboFix
[2010-04-25 20:49:45 | 000,000,000 | —D | C] – C:\Users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156
[2010-04-23 08:31:24 | 000,000,000 | —D | C] – C:\Users\Steffen\AppData\Roaming\U3
[2010-04-22 07:23:49 | 000,000,000 | —D | C] – C:\Users\Steffen\AppData\Local\Adobe
[2010-04-20 17:08:32 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2010-04-20 17:08:26 | 000,000,000 | —D | C] – C:\Windows\temp
[2010-04-20 17:08:26 | 000,000,000 | —D | C] – C:\Users\Steffen\AppData\Local\temp
[2010-04-20 16:44:43 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2010-04-20 16:44:43 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2010-04-20 16:44:43 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2010-04-20 16:44:23 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010-04-20 16:40:25 | 000,000,000 | —D | C] – C:\Qoobox
[2010-04-20 16:40:06 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2010-04-19 21:46:48 | 000,000,000 | —D | C] – C:\Users\Steffen\AppData\Roaming\Malwarebytes
[2010-04-19 21:46:31 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010-04-19 21:46:25 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010-04-19 21:46:24 | 000,020,824 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010-04-19 21:46:24 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010-04-18 13:14:00 | 000,000,000 | —D | C] – C:\Program Files\Musikprogrammer
[2010-04-18 12:39:00 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010-04-15 17:30:57 | 000,000,000 | —D | C] – C:\ProgramData\{87784988-8668-411D-B26A-0C946ED2BE3C}
[2010-04-15 17:30:55 | 000,000,000 | —D | C] – C:\Program Files\Skoleprinter
[2010-04-15 12:12:07 | 000,000,000 | —D | C] – C:\Program Files\Grafværktøj
[2010-04-15 12:11:15 | 000,299,520 | —- | C] (InstallShield Corporation, Inc.) – C:\Windows\uninst.exe
[2010-04-14 07:23:28 | 000,430,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2010-04-14 07:23:03 | 003,600,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2010-04-14 07:23:03 | 003,548,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2010-04-14 07:22:58 | 000,220,672 | —- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\Windows\System32\l3codecp.acm
[2010-04-14 07:22:58 | 000,062,464 | —- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\Windows\System32\l3codeca.acm
[2010-04-11 16:18:50 | 000,000,000 | —D | C] – C:\a0c698d600d463d0cf
[2010-04-09 12:59:07 | 000,000,000 | -HSD | C] – C:\ProgramData\SysWoW32
[2010-04-09 12:58:41 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010-04-07 07:29:29 | 000,000,000 | —D | C] – C:\Users\Steffen\Documents\Ting
[2010-04-05 17:47:06 | 000,095,024 | —- | C] (Sunbelt Software) – C:\Windows\System32\drivers\SBREDrv.sys
[2010-04-05 17:43:08 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2010-04-05 17:43:08 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2010-04-02 23:14:53 | 000,000,000 | —D | C] – C:\Program Files\GIMP-2.0
[2010-04-02 23:12:23 | 000,000,000 | —D | C] – C:\Program Files\Common Files\GTK
[2010-04-02 23:04:40 | 000,000,000 | —D | C] – C:\Users\Steffen\Documents\gegl-0.0
[2010-04-02 23:04:40 | 000,000,000 | —D | C] – C:\Users\Steffen\Documents\.gimp-2.6
[2010-04-01 17:39:08 | 000,180,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010-04-01 17:39:04 | 000,193,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010-04-01 17:39:02 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieencode.dll
[2010-04-01 17:38:56 | 000,380,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll

========== Files - Modified Within 30 Days ==========

[2010-04-28 18:04:04 | 003,932,160 | -HS- | M] () – C:\Users\Steffen\NTUSER.DAT
[2010-04-28 17:43:57 | 000,050,477 | —- | M] () – C:\Users\Steffen\Desktop\Defogger.exe
[2010-04-28 17:18:03 | 000,000,922 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010-04-28 17:17:49 | 000,032,061 | —- | M] () – C:\ProgramData\nvModes.001
[2010-04-28 17:17:40 | 000,032,061 | —- | M] () – C:\ProgramData\nvModes.dat
[2010-04-28 17:17:35 | 000,000,918 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010-04-28 17:17:32 | 000,000,910 | —- | M] () – C:\Windows\tasks\Google Software Updater.job
[2010-04-28 17:14:38 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010-04-28 17:14:38 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010-04-28 17:14:32 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010-04-28 17:14:27 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010-04-28 17:14:26 | 3220,152,320 | -HS- | M] () – C:\hiberfil.sys
[2010-04-28 14:17:54 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2010-04-28 14:17:52 | 000,524,288 | -HS- | M] () – C:\Users\Steffen\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms
[2010-04-28 14:17:52 | 000,065,536 | -HS- | M] () – C:\Users\Steffen\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010-04-28 14:17:47 | 003,131,463 | -H– | M] () – C:\Users\Steffen\AppData\Local\IconCache.db
[2010-04-28 14:12:00 | 000,000,950 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-142386170-2914611657-1622844314-1000UA.job
[2010-04-28 13:07:16 | 000,002,659 | —- | M] () – C:\Users\Steffen\Desktop\Microsoft Office Word 2007.lnk
[2010-04-28 12:10:08 | 001,244,986 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010-04-28 12:10:08 | 000,590,082 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010-04-28 12:10:08 | 000,479,574 | —- | M] () – C:\Windows\System32\perfh006.dat
[2010-04-28 12:10:08 | 000,102,094 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010-04-28 12:10:08 | 000,082,814 | —- | M] () – C:\Windows\System32\perfc006.dat
[2010-04-28 12:04:40 | 000,416,184 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010-04-27 23:12:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-142386170-2914611657-1622844314-1000Core.job
[2010-04-27 08:25:39 | 000,563,712 | —- | M] (OldTimer Tools) – C:\Program Files\OTL.exe
[2010-04-25 21:19:54 | 000,102,912 | —- | M] () – C:\Users\Steffen\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-04-25 21:15:48 | 000,009,952 | -HS- | M] () – C:\Users\Steffen\AppData\Local\UJ0QRjYY
[2010-04-25 21:15:48 | 000,009,952 | -HS- | M] () – C:\ProgramData\UJ0QRjYY
[2010-04-25 20:50:11 | 000,223,232 | -HS- | M] () – C:\Users\Steffen\AppData\Local\ave.exe
[2010-04-22 13:53:26 | 000,002,415 | —- | M] () – C:\Users\Steffen\Desktop\Gads Bogskab.lnk
[2010-04-21 00:46:36 | 000,002,052 | —- | M] () – C:\Users\Steffen\Desktop\Google Chrome.lnk
[2010-04-20 17:02:28 | 000,000,215 | —- | M] () – C:\Windows\system.ini
[2010-04-20 16:07:34 | 003,921,705 | R— | M] () – C:\Program Files\ComboFix.exe
[2010-04-19 22:06:25 | 000,000,817 | —- | M] () – C:\ProgramData\1925965306
[2010-04-19 16:05:58 | 000,001,023 | -HS- | M] () – C:\ProgramData\580629930
[2010-04-18 12:55:24 | 000,011,026 | —- | M] () – C:\Users\Steffen\Documents\hijackthis_log
[2010-04-09 12:59:07 | 000,000,113 | —- | M] () – C:\ProgramData\sl1132078904
[2010-04-09 12:58:52 | 000,203,776 | -HS- | M] () – C:\ProgramData\unrar.exe
[2010-04-06 16:52:17 | 000,000,330 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForSteffen.job
[2010-04-05 17:47:03 | 000,095,024 | —- | M] (Sunbelt Software) – C:\Windows\System32\drivers\SBREDrv.sys
[2010-03-30 00:46:30 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010-03-30 00:45:52 | 000,020,824 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys

========== Files Created - No Company Name ==========

[2010-04-28 17:43:57 | 000,050,477 | —- | C] () – C:\Users\Steffen\Desktop\Defogger.exe
[2010-04-25 20:50:11 | 000,223,232 | -HS- | C] () – C:\Users\Steffen\AppData\Local\ave.exe
[2010-04-25 20:50:11 | 000,009,952 | -HS- | C] () – C:\Users\Steffen\AppData\Local\UJ0QRjYY
[2010-04-25 20:50:11 | 000,009,952 | -HS- | C] () – C:\ProgramData\UJ0QRjYY
[2010-04-20 16:44:43 | 000,261,632 | —- | C] () – C:\Windows\PEV.exe
[2010-04-20 16:44:43 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2010-04-20 16:44:43 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2010-04-20 16:44:43 | 000,077,312 | —- | C] () – C:\Windows\MBR.exe
[2010-04-20 16:44:43 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2010-04-20 16:07:32 | 003,921,705 | R— | C] () – C:\Program Files\ComboFix.exe
[2010-04-18 12:51:28 | 000,011,026 | —- | C] () – C:\Users\Steffen\Documents\hijackthis_log
[2010-04-09 12:59:19 | 000,001,023 | -HS- | C] () – C:\ProgramData\580629930
[2010-04-09 12:59:18 | 000,000,817 | —- | C] () – C:\ProgramData\1925965306
[2010-04-09 12:59:07 | 000,000,113 | —- | C] () – C:\ProgramData\sl1132078904
[2010-04-09 12:58:52 | 000,203,776 | -HS- | C] () – C:\ProgramData\unrar.exe
[2009-08-03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009-07-08 21:56:40 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009-05-12 12:24:19 | 000,087,552 | —- | C] () – C:\Windows\System32\cpwmon2k.dll
[2009-02-22 21:05:56 | 000,077,824 | —- | C] () – C:\Windows\System32\CamTraxAPI.dll
[2008-09-10 22:45:14 | 000,000,209 | —- | C] () – C:\Windows\Ic32.ini
[2008-05-21 06:18:30 | 000,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll
[2007-09-05 21:52:04 | 000,389,120 | —- | C] () – C:\Windows\System32\btwhidcs.dll
[2006-11-02 14:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006-11-02 12:25:21 | 000,061,440 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006-11-02 09:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006-03-10 00:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2001-11-14 22:56:00 | 001,802,240 | —- | C] () – C:\Windows\System32\lcppn21.dll

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008-01-19 09:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008-01-19 09:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008-01-19 09:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008-01-19 09:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2008-02-26 06:22:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=313FF294978EA6AF715722D708FB249F – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.20494_none_b858f78adaed51b3\AGP440.sys
[2008-02-26 06:22:53 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=CE71AFD6738AA025D742CDBCFBDC8B9C – C:\Windows\System32\DriverStore\FileRepository\machine.inf_f2490cb0\AGP440.sys
[2008-02-26 06:22:53 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=CE71AFD6738AA025D742CDBCFBDC8B9C – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.16399_none_b7d45c31c1cb309c\AGP440.sys
[2006-11-02 11:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\ERDNT\cache\AGP440.sys
[2006-11-02 11:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\drivers\AGP440.sys
[2006-11-02 11:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009-04-11 08:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\ERDNT\cache\atapi.sys
[2009-04-11 08:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\System32\drivers\atapi.sys
[2009-04-11 08:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009-04-11 08:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008-01-19 09:41:30 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008-01-19 09:41:30 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006-11-02 11:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008-08-31 21:44:20 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008-08-31 21:44:20 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008-08-31 21:44:20 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006-11-02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\ERDNT\cache\cngaudit.dll
[2006-11-02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\System32\cngaudit.dll
[2006-11-02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: EVENTLOG.DLL >
[2007-01-13 08:30:08 | 000,007,216 | —- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 – C:\Program Files\CyberLink\PowerDirector\EventLog.dll

< MD5 for: IASTORV.SYS >
[2008-01-19 09:42:51 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008-01-19 09:42:51 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006-11-02 11:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\drivers\iaStorV.sys
[2006-11-02 11:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2006-11-02 11:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009-04-11 08:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\ERDNT\cache\netlogon.dll
[2009-04-11 08:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\System32\netlogon.dll
[2009-04-11 08:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008-01-19 09:35:36 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2006-11-02 11:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\drivers\nvstor.sys
[2006-11-02 11:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008-01-19 09:42:09 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008-01-19 09:42:09 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008-01-19 09:36:19 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006-11-02 11:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009-04-11 08:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\ERDNT\cache\scecli.dll
[2009-04-11 08:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\System32\scecli.dll
[2009-04-11 08:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009-04-11 08:27:47 | 000,241,128 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\rsaenh.dll
[2009-04-11 08:28:23 | 000,228,352 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\SLC.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\system32\drivers\*.sys /90 >
[2010-02-20 22:53:34 | 000,411,648 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\http.sys
[2010-03-30 00:45:52 | 000,020,824 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010-03-30 00:46:30 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010-02-23 13:10:13 | 000,106,496 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb.sys
[2010-02-23 13:10:19 | 000,212,992 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb10.sys
[2010-02-23 13:10:13 | 000,079,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb20.sys
[2010-04-05 17:47:03 | 000,095,024 | —- | M] (Sunbelt Software) – C:\Windows\System32\drivers\SBREDrv.sys
[2010-02-18 16:07:16 | 000,904,576 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tcpip.sys
[2010-02-18 13:28:13 | 000,025,088 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tunnel.sys

< %systemroot%\System32\config\*.sav >
[2006-11-02 12:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006-11-02 12:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006-11-02 12:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006-11-02 12:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006-11-02 12:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< End of report >









OTL Extras log

OTL Extras logfile created on: 28-04-2010 18:00:55 - Run 1
OTL by OldTimer - Version 3.2.3.0 Folder = C:\Program Files
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000406 | Country: Danmark | Language: DAN | Date Format: dd-MM-yyyy

3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 70,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 85,00% Paging File free
Paging file location(s): ?:\pagefile.sys

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223,08 Gb Total Space | 58,10 Gb Free Space | 26,04% Space Free | Partition Type: NTFS
Drive D: | 9,81 Gb Total Space | 2,93 Gb Free Space | 29,85% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: STEFFEN-PC
Current User Name: Steffen
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – C:\Users\Steffen\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [MediaMonkey.1Play] – "C:\Program Files\MediaMonkey\MediaMonkey.exe" "%1" (Ventis Media Inc.)
Directory [MediaMonkey.2PlayNext] – "C:\Program Files\MediaMonkey\MediaMonkey.exe" /NEXT "%1" (Ventis Media Inc.)
Directory [MediaMonkey.3Enqueue] – "C:\Program Files\MediaMonkey\MediaMonkey.exe" /ADD "%1" (Ventis Media Inc.)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" File not found
Directory [PlayWithVLC] – "C:\Program Files\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0EE3FAAA-ED70-4E72-A17B-B6644C5E9A4D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{1B984952-714F-4D66-85A4-00577E5289C3}" = lport=2869 | protocol=6 | dir=in | app=system |
"{7F139A9D-4CE3-4E93-BADE-8EE7BE4D8947}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{13711F38-DA50-40D8-B52F-2FC12903D2F5}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{18FEF160-435F-4B9E-81A1-0C67ED369BF2}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{2E9EAC23-5680-471D-AAF3-D74EB8C5D9F8}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{3D36E307-89D3-4117-8E1E-B5D5834C2BEB}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{3F7EFE90-2043-4147-9E14-4D76E1E26586}" = protocol=17 | dir=in | app=c:\program files\cyanide\pro cycling manager 2008 demo\autorun\exe\autorun.exe |
"{4D1894C1-66F9-4E09-B604-6BEB1A23F3FC}" = protocol=6 | dir=in | app=c:\program files\sports interactive\football manager 2009\fm.exe |
"{531BFC3D-77FF-4694-924F-E9248715E174}" = protocol=6 | dir=in | app=c:\program files\cyanide\pro cycling manager 2008 demo\autorun\exe\autorun.exe |
"{60CBFAE7-3052-464B-A32E-BAB0CD41573F}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{66C9904E-1D8C-4A4C-9CB0-F3BFB92EA519}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6D5471FF-DE17-4FA1-AA9D-12F8EFB527DB}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{77BE3E79-6E80-4212-8F05-80BBD9E2F270}" = dir=in | app=c:\windows\explorer.exe |
"{7859B83B-6C69-41CF-8F92-432DD5A67197}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"{7ACC6E87-8C12-4adb-91B7-EFC3F2F4705A}" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"{803FF1C4-9B5C-4274-901F-D9906FFD06DE}" = dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{8EEE34C0-869E-42D0-8100-D112976677BC}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{8F63BBF0-AF8A-4BBC-8A8F-BCEEECE7EA61}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{92459C5E-D350-4cba-AA74-C8F989C9336F}" = protocol=17 | dir=out | app=c:\windows\explorer.exe |
"{93290AE3-D6A7-45C9-8F4B-F580A03A2FFD}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{9BACAEA6-ED07-4861-8BEC-91E0B6AFC9A8}" = protocol=17 | dir=in | app=c:\program files\dna\btdna.exe |
"{9E454685-3750-45E1-8367-A3313818A7C7}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{A1ACCB87-01A2-4FC4-A427-99F1D0373600}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{B078B2B6-A878-44ff-9BCC-458257924F96}" = protocol=17 | dir=in | app=c:\windows\explorer.exe |
"{B1A40E4F-58DB-490f-9D18-55B5194E8BD5}" = protocol=6 | dir=out | app=c:\windows\explorer.exe |
"{B423B02E-4707-482F-AF0F-57B3A2E45A17}" = protocol=17 | dir=in | app=c:\program files\sports interactive\football manager 2009\fm.exe |
"{B5EED1B9-283E-45BC-B820-68EA1D1E928D}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{C3E9B20A-B7E2-4aab-9835-3C548937E46F}" = dir=out | app=c:\windows\explorer.exe |
"{D0423801-2759-4637-B8CB-0C503E67DCDC}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{D131A829-12E4-4C3C-9F7D-192653C6684B}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{D3BD9A52-BF18-4D2E-B840-8B82F9584144}" = protocol=6 | dir=in | app=c:\program files\dna\btdna.exe |
"{EE05EBA7-3068-40D5-8776-AED16B7832B3}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe |
"{F36F87EE-CDE8-4C0F-9AD2-6D4050D9A59A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F8EFF380-0E94-49BA-9F5C-CCA2195F396B}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{04E43AFD-4FDE-429C-B644-015597886CF0}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"TCP Query User{06D5E214-24A7-4A47-807C-FB7E7281A92E}C:\users\steffen\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\steffen\program files\dna\btdna.exe |
"TCP Query User{14536191-1C85-48A8-BC9D-533F6EC38E98}C:\program files\cyanide\pro cycling manager 2008 demo\pcmdemo.exe" = protocol=6 | dir=in | app=c:\program files\cyanide\pro cycling manager 2008 demo\pcmdemo.exe |
"TCP Query User{35936477-09BA-4280-8364-724560EBBE89}C:\program files\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=6 | dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe |
"TCP Query User{4C75D045-374B-4D44-9D1E-FF416DEB1CBE}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{534955C0-D955-4C4E-A27E-E58B4FA05197}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"TCP Query User{5468973E-A8A5-4F5B-B1D1-E17B2C570750}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"TCP Query User{592D2F46-146A-41D7-A3E0-BA14670D163B}C:\program files\age of empires ii\age2_x1.exe" = protocol=6 | dir=in | app=c:\program files\age of empires ii\age2_x1.exe |
"TCP Query User{5C62B999-4335-436B-B787-7B50A1FCCEDD}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{6C594245-52F3-4E16-9CDC-858F246C27F9}C:\program files\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
"TCP Query User{7330A322-2232-4C8A-AE3F-5CDEF4ADF20D}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{7D4922B4-7637-4466-BFED-37E81D2175C1}C:\users\steffen\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\steffen\program files\dna\btdna.exe |
"TCP Query User{95D77540-AD8A-4ACF-A40A-305D47C3CF42}C:\program files\age of empires ii\age2_x1.exe" = protocol=6 | dir=in | app=c:\program files\age of empires ii\age2_x1.exe |
"TCP Query User{9EB0E4B4-2EB3-401B-A9A3-A5BA5E12F318}C:\program files\nokia\nokia software updater\nsu_ui_client.exe" = protocol=6 | dir=in | app=c:\program files\nokia\nokia software updater\nsu_ui_client.exe |
"TCP Query User{B2F6C29C-E319-4EC4-ACB1-5376D36545D6}C:\program files\age of empires ii\empires2.exe" = protocol=6 | dir=in | app=c:\program files\age of empires ii\empires2.exe |
"TCP Query User{B403DFC5-237A-49DF-980E-BFACAAD2D1E2}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"TCP Query User{C948930D-306E-4D4A-A37E-EE4FF8F3F221}C:\users\steffen\documents\age of empires ii\age2_x1.exe" = protocol=6 | dir=in | app=c:\users\steffen\documents\age of empires ii\age2_x1.exe |
"TCP Query User{E063B356-3E7F-42FB-8100-83BFD1776E2B}C:\program files\nokia\nokia ovi suite\nokiaovisuite.exe" = protocol=6 | dir=in | app=c:\program files\nokia\nokia ovi suite\nokiaovisuite.exe |
"TCP Query User{EE82CF3E-CEBE-4EA3-80CF-F06E64D5EB08}C:\program files\ea games\need for speed most wanted\speed.exe" = protocol=6 | dir=in | app=c:\program files\ea games\need for speed most wanted\speed.exe |
"TCP Query User{F78CDF7D-44F5-408A-805A-76865D0B8513}C:\program files\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
"UDP Query User{2D725728-6333-42A8-BA80-81AD80A770F7}C:\program files\age of empires ii\empires2.exe" = protocol=17 | dir=in | app=c:\program files\age of empires ii\empires2.exe |
"UDP Query User{2E0A7B4E-D1C1-4E72-8FAE-35CEAB5F90AB}C:\users\steffen\documents\age of empires ii\age2_x1.exe" = protocol=17 | dir=in | app=c:\users\steffen\documents\age of empires ii\age2_x1.exe |
"UDP Query User{319DE5BE-1107-4FE1-B565-09725EF867F2}C:\program files\ea games\need for speed most wanted\speed.exe" = protocol=17 | dir=in | app=c:\program files\ea games\need for speed most wanted\speed.exe |
"UDP Query User{38AAC7AF-5BE1-4E7F-A346-86A065E2D12D}C:\program files\common files\nokia\service layer\a\nsl_host_process.exe" = protocol=17 | dir=in | app=c:\program files\common files\nokia\service layer\a\nsl_host_process.exe |
"UDP Query User{3F6A6252-7E06-4868-8D33-B3A858C25D63}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe |
"UDP Query User{3AA6AD2F-FCCB-47BC-BEAC-E5EF1437E080}C:\program files\nokia\nokia software updater\nsu_ui_client.exe" = protocol=17 | dir=in | app=c:\program files\nokia\nokia software updater\nsu_ui_client.exe |
"UDP Query User{447B3943-D912-4E2A-B923-3754017BEC05}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{45C04F9C-B6F1-4819-8C1B-D850224B2B22}C:\program files\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
"UDP Query User{5155D19D-0CF3-4152-AA33-988B58AEAD63}C:\users\steffen\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\steffen\program files\dna\btdna.exe |
"UDP Query User{57A77FE7-AFDE-4F79-9AE3-69B04BA63641}C:\program files\age of empires ii\age2_x1.exe" = protocol=17 | dir=in | app=c:\program files\age of empires ii\age2_x1.exe |
"UDP Query User{65E771F2-7E3B-4B92-8B4A-D850C704CBC7}C:\program files\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=c:\program files\tmnationsforever\tmforever.exe |
"UDP Query User{69B4D4E7-DA96-424D-AB2D-3F58013249B6}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"UDP Query User{6FB58C86-13D6-4C3C-AD46-04CD5FF40E67}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"UDP Query User{7073843B-FEA3-41D7-AD14-A811CA1AF903}C:\program files\nokia\nokia ovi suite\nokiaovisuite.exe" = protocol=17 | dir=in | app=c:\program files\nokia\nokia ovi suite\nokiaovisuite.exe |
"UDP Query User{8C3B0E6C-E2DD-41C6-B3FD-5D079908A99A}C:\program files\age of empires ii\age2_x1.exe" = protocol=17 | dir=in | app=c:\program files\age of empires ii\age2_x1.exe |
"UDP Query User{93CDE006-406B-438E-8967-DEDA506109E7}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"UDP Query User{952B7883-0F97-4A26-AB0A-C8E2D98E8057}C:\program files\cyanide\pro cycling manager 2008 demo\pcmdemo.exe" = protocol=17 | dir=in | app=c:\program files\cyanide\pro cycling manager 2008 demo\pcmdemo.exe |
"UDP Query User{B8C472F0-A925-48AF-9F09-DC0F894A7B9D}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{F918BF7D-AAE6-4431-B21D-CFCF0490D089}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{FBC035E6-3023-4F05-8708-992136C8280B}C:\users\steffen\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\steffen\program files\dna\btdna.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = HP Integrated Module with Bluetooth wireless technology 6.0.1.5500
"{069B5108-7632-43EC-00BF-8EB469977F1C}" = NBA Live 2003 Demo
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{08C0729E-3E50-11DF-9D81-005056806466}" = Google Earth
"{10A44844-4465-456E-8C97-80BDD4F68845}" = Tilmeldingsassistent til Windows Live ID
"{11202615-E557-4ECF-9B86-F59C81E52909}" = FIFA 10
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 2.5.3
"{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Overførselsværktøj til Windows Live
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java™ 6 Update 16
"{2758691A-2CDE-4942-A4AC-0E8F61FE2067}" = easycap video grabber
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{2987EE84-C4EE-4FF5-8160-32DE00D6ABC6}" = GTA2
"{2CDC68A4-3CE7-4F7B-A5BE-ECB05ABB8719}" = Windows Live Movie Maker
"{2F3082BF-4A3B-45CA-805F-52DBBFD3C645}" = Windows Live Essentials
"{2FE5DDEF-64E3-45BF-B3E9-39C64905A45C}" = Gads Bogskab
"{31216452-5540-4C96-B754-94890A63D5AB}" = HP Help and Support
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{33198339-567F-43C4-9CF8-B23E721F2714}" = HTC Sync
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 E1
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3CCB26F5-E2A7-4C91-8340-9149D7B7C2BE}" = Virtual Earth 3D (Beta)
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{3F130AD2-89C9-47E3-A3B7-C18E4DBA60A4}" = Politikens Engelsk-Dansk Dansk-Engelsk Ordbog
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{45A2D49C-8124-4015-A8B3-073A827EC5C1}" = Windows Live Sync
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.6
"{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}" = Nokia Software Updater
"{4CE6B3C4-D8E2-4A5D-BEF5-5B69AF843B0C}" = PC Connectivity Solution
"{4D49757C-367A-4333-BDB3-68966162B14E}" = HP User Guides 0087
"{51E43DA1-CAEA-4264-9BB8-3F47ED57E2A4}" = TI InterActive!™
"{564B16F4-6B5B-47B0-9AB6-FF2E943947F7}" = Nokia Ovi Suite Software Updater
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
"{5A438E06-0BB3-4C5F-0085-B14F1F4077E6}" = FIFA 06
"{6522F10D-3EB1-4FF4-8758-ABFB227CD8B5}" = Microsoft Antimalware Service DA-DK Language Pack
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{69352F8B-66AD-493C-9138-5FE0D300FB17}" = FIFA 09 Demo
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer
"{703A59AA-E839-47BF-90BE-932A15B2D216}" = Drive 3 professional KatBS
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{782DDB70-3DF4-4366-00BF-E3767BCD173B}" = FIFA 2004
"{7DC4A410-9986-4329-9E5D-687B2C42CA39}" = HP QuickTouch 1.00 C4
"{7F362F06-A9A3-440F-8B19-6A01A72723C4}" = AuthenTec Fingerprint Sensor Minimum Install
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{865DB1C9-D5E4-408B-B37D-9927E605BD2D}" = ESU for Microsoft Vista
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D100E0C-1A5A-43AD-93EF-76F94AE61C30}" = OviMPlatform
"{8F8D9297-FDD2-405A-97E7-E52C7B2F97B3}" = Ulead VideoStudio SE DVD
"{90120000-0015-0406-0000-0000000FF1CE}" = Microsoft Office Access MUI (Danish) 2007
"{90120000-0015-0406-0000-0000000FF1CE}_ENTERPRISER_{652017DD-E99F-4420-9CC8-AC25CE8375A5}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0406-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Danish) 2007
"{90120000-0016-0406-0000-0000000FF1CE}_ENTERPRISER_{652017DD-E99F-4420-9CC8-AC25CE8375A5}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0406-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Danish) 2007
"{90120000-0018-0406-0000-0000000FF1CE}_ENTERPRISER_{652017DD-E99F-4420-9CC8-AC25CE8375A5}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0406-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Danish) 2007
"{90120000-0019-0406-0000-0000000FF1CE}_ENTERPRISER_{652017DD-E99F-4420-9CC8-AC25CE8375A5}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0406-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Danish) 2007
"{90120000-001A-0406-0000-0000000FF1CE}_ENTERPRISER_{652017DD-E99F-4420-9CC8-AC25CE8375A5}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0406-0000-0000000FF1CE}" = Microsoft Office Word MUI (Danish) 2007
"{90120000-001B-0406-0000-0000000FF1CE}_ENTERPRISER_{652017DD-E99F-4420-9CC8-AC25CE8375A5}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0406-0000-0000000FF1CE}" = Microsoft Office Proof (Danish) 2007
"{90120000-001F-0406-0000-0000000FF1CE}_ENTERPRISER_{25E093C2-374E-44A9-9BCE-3881BD442F3F}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISER_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0406-0000-0000000FF1CE}" = Kompatibilitetspakke til Office 2007-systemet
"{90120000-002C-0406-0000-0000000FF1CE}" = Microsoft Office Proofing (Danish) 2007
"{90120000-0044-0406-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Danish) 2007
"{90120000-0044-0406-0000-0000000FF1CE}_ENTERPRISER_{652017DD-E99F-4420-9CC8-AC25CE8375A5}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0406-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Danish) 2007
"{90120000-006E-0406-0000-0000000FF1CE}_ENTERPRISER_{50865937-2EBB-4BBF-8861-BF5972C95D4B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0406-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Danish) 2007
"{90120000-00A1-0406-0000-0000000FF1CE}_ENTERPRISER_{652017DD-E99F-4420-9CC8-AC25CE8375A5}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0406-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Danish) 2007
"{90120000-00BA-0406-0000-0000000FF1CE}_ENTERPRISER_{652017DD-E99F-4420-9CC8-AC25CE8375A5}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}" = Nokia PC Suite
"{924EAD66-F854-4605-8493-696DD59A113B}" = RollerCoaster Tycoon Deluxe
"{94B8F069-F223-4F48-BC88-7104CBA77F30}" = Windows Live Messenger
"{95120000-00AF-0406-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (Danish)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
"{9AF218F0-4536-4731-89A1-CD6DA0A1E2BB}" = Printer og drev (Sct. Knuds Gymnasium)
"{9CD9CD94-76CC-4524-8617-DEB9C2D7C389}" = FIFA 10 - Demo
"{A48B9CD8-C2BA-4EC9-0081-7260D238C7CF}" = Need for Speed™ Most Wanted
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1030-7B44-A93000000001}" = Adobe Reader 9.3.2 - Dansk
"{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}" = Microsoft Office Live Add-in 1.4
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B238D61F-3EEF-4716-BFEA-9903DEF045D9}" = Microsoft Works
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}" = Nokia Ovi Suite
"{B69349AE-2D41-3708-8BA4-4DC22645CA04}" = Microsoft .NET Framework 3.5 Language Pack SP1 - dan
"{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements
"{BFD09E5B-6D40-4CAD-A349-103BFEF1C574}" = Windows Live Mail
"{C30E6A9F-D2BE-4DC3-826B-5DC0BA556791}" = Gads Tysk Small/Medium
"{C50EF365-2898-489A-B6C7-30DAA466E9A2}" = Nokia Connectivity Cable Driver
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C7AF7F33-9092-997E-2D29-DE8095863FE3}" = DigitalPersona Personal 3.0.0
"{C8E95BF5-C07F-4D98-BB42-F58FC98BC03E}" = Google Apps
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant
"{CBE48FF8-521A-4AE1-92B5-7008D8529630}" = Logger Pro 3.6.1
"{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library
"{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}" = Full Tilt Poker
"{D7EC54D8-3D95-4F9D-A191-59C9BB7F5AC9}" = Windows Live Photo Gallery
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E590FD1C-E8C6-4D2E-8CA9-77B403F7EE01}" = Microsoft Antimalware
"{E7B74193-BE99-425E-93E8-F3430414A02C}" = Tropico 2: Pirate Cove Demo
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F1C3541D-5B93-4131-B440-692FBA3DD250}" = Ovi Desktop Sync Engine
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F439D7AF-03F3-4F8E-AEC4-571BFE977C61}" = iTunes
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
"05B59228C7E1C21DFBE89260F879BD95880548D8" = Windows-driverpakke - Nokia Modem (10/05/2009 4.2)
"504244733D18C8F63FF584AEB290E3904E791693" = Windows-driverpakke - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"7CA796BB949C28BF49AB1F5C63987DDCDB6198D2" = Windows-driverpakke - eMPIA Technology Inc, (emAudio) MEDIA (01/29/2007 5.7.0129.0)
"82A44D22-9452-49FB-00FB-CEC7DCAF7E23" = EA SPORTS online 2004
"8CDCFB95BB84DD9C0F88F22266A0CA86035E55BA" = Windows-driverpakke - Nokia Modem (06/01/2009 7.01.0.4)
"ACDLabs in C__Program_Files_ACDFREE12_" = ACD/Labs Software in C:\Program Files\ACDFREE12\
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.10 (Unicode)
"CamSpace" = CamSpace
"CCleaner" = CCleaner
"ClassicPro" = ClassicPro© v1.12
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"CutePDF Writer Installation" = CutePDF Writer 2.7
"ENTERPRISER" = Microsoft Office Enterprise 2007
"FBL Training session demo_is1" = FBL Training session demo (build 100126.2882)
"FIFA MANAGER 08" = FIFA MANAGER 08
"Football Manager 2009" = Football Manager 2009
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.2
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.2
"GeoMeter 1.2" = GeoMeter 1.2
"Google Desktop" = Google Desktop
"Google Updater" = Google Updater
"Grafværktøj" = Grafværktøj
"Guitar Guru_is1" = Guitar Guru Version 2.2.5.0
"Hauppauge MCE2005 Software Encoder" = Hauppauge MCE XP/Vista Software Encoder (2.0.25149)
"HijackThis" = HijackThis 2.0.2
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"LimeWire" = LimeWire 5.5.8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaMonkey_is1" = MediaMonkey 3.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - dan" = Sprogpakke til Microsoft .NET Framework 3.5 SP1 - dansk
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Essentials" = Microsoft Security Essentials
"Mozilla Firefox (3.5.3)" = Mozilla Firefox (3.5.3)
"Musicnotes Player_is1" = Musicnotes Player V1.23.2
"Nokia Ovi Suite" = Nokia Ovi Suite
"Nokia PC Suite" = Nokia PC Suite
"NVIDIA Drivers" = NVIDIA Drivers
"OJOsoft Total Video Converter_is1" = OJOsoft Total Video Converter
"OpenAL" = OpenAL
"PokerStars" = PokerStars
"PopCap Browser Plugin" = PopCap Browser Plugin
"Printer og drev (Sct. Knuds Gymnasium)" = Printer og drev (Sct. Knuds Gymnasium)
"Pro Cycling Manager 2008 - Demo_is1" = [Demo] Pro Cycling Manager - Season 2008 1.0.1.4
"QuicktimeAlt_is1" = QuickTime Alternative 2.7.0
"RealAlt_is1" = Real Alternative 1.9.0
"RealPlayer 12.0" = RealPlayer
"SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.4
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TmNationsForever_is1" = TmNationsForever
"Tropico3 Demo" = Tropico 3 Demo 1.01
"Uninstall_is1" = Uninstall 1.0.0.1
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.0.1
"Winamp" = Winamp
"WinGimp-2.0_is1" = GIMP 2.6.8
"WinGTK-2_is1" = GTK+ 2.10.13 runtime environment
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR arkivering
"WM Converter 2.0" = WM Converter 2.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 16-02-2010 05:19:19 | Computer Name = Steffen-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 16-02-2010 05:21:09 | Computer Name = Steffen-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 16-02-2010 05:21:10 | Computer Name = Steffen-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 16-02-2010 05:21:14 | Computer Name = Steffen-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 16-02-2010 13:38:45 | Computer Name = Steffen-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 16-02-2010 13:38:46 | Computer Name = Steffen-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 18-02-2010 04:48:57 | Computer Name = Steffen-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 18-02-2010 17:15:15 | Computer Name = Steffen-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 21-02-2010 08:06:05 | Computer Name = Steffen-PC | Source = Google Update | ID = 20
Description =

Error - 21-02-2010 12:06:05 | Computer Name = Steffen-PC | Source = Google Update | ID = 20
Description =

[ DigitalPersona Pro Events ]
Error - 24-04-2010 06:58:40 | Computer Name = Steffen-PC | Source = DigitalPersona Pro | ID = 17827075
Description = Agent cannot start. Description: Found other running Agent.

Error - 25-04-2010 05:44:23 | Computer Name = Steffen-PC | Source = DigitalPersona Pro | ID = 17827075
Description = Agent cannot start. Description: Found other running Agent.

Error - 25-04-2010 09:03:32 | Computer Name = Steffen-PC | Source = DigitalPersona Pro | ID = 17827075
Description = Agent cannot start. Description: Found other running Agent.

Error - 26-04-2010 02:43:20 | Computer Name = Steffen-PC | Source = DigitalPersona Pro | ID = 17827075
Description = Agent cannot start. Description: Found other running Agent.

Error - 27-04-2010 06:02:29 | Computer Name = Steffen-PC | Source = DigitalPersona Pro | ID = 17827075
Description = Agent cannot start. Description: Found other running Agent.

Error - 27-04-2010 11:40:20 | Computer Name = Steffen-PC | Source = DigitalPersona Pro | ID = 17827075
Description = Agent cannot start. Description: Found other running Agent.

Error - 28-04-2010 00:46:26 | Computer Name = Steffen-PC | Source = DigitalPersona Pro | ID = 17827075
Description = Agent cannot start. Description: Found other running Agent.

Error - 28-04-2010 01:14:59 | Computer Name = Steffen-PC | Source = DigitalPersona Pro | ID = 17827075
Description = Agent cannot start. Description: Found other running Agent.

Error - 28-04-2010 06:04:30 | Computer Name = Steffen-PC | Source = DigitalPersona Pro | ID = 17827075
Description = Agent cannot start. Description: Found other running Agent.

Error - 28-04-2010 11:17:44 | Computer Name = Steffen-PC | Source = DigitalPersona Pro | ID = 17827075
Description = Agent cannot start. Description: Found other running Agent.

[ OSession Events ]
Error - 20-01-2009 03:22:59 | Computer Name = Steffen-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 25
seconds with 0 seconds of active time. This session ended with a crash.

Error - 23-01-2009 07:02:47 | Computer Name = Steffen-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 11
seconds with 0 seconds of active time. This session ended with a crash.

Error - 22-09-2009 07:28:22 | Computer Name = Steffen-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 10
seconds with 0 seconds of active time. This session ended with a crash.

Error - 10-11-2009 08:31:26 | Computer Name = Steffen-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4219
seconds with 1140 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 28-04-2010 08:09:36 | Computer Name = Steffen-PC | Source = cdrom | ID = 262151
Description = Enheden \Device\CdRom0 havde en fejlbehæftet blok.

Error - 28-04-2010 08:09:43 | Computer Name = Steffen-PC | Source = cdrom | ID = 262151
Description = Enheden \Device\CdRom0 havde en fejlbehæftet blok.

Error - 28-04-2010 08:09:50 | Computer Name = Steffen-PC | Source = cdrom | ID = 262151
Description = Enheden \Device\CdRom0 havde en fejlbehæftet blok.

Error - 28-04-2010 08:09:57 | Computer Name = Steffen-PC | Source = cdrom | ID = 262151
Description = Enheden \Device\CdRom0 havde en fejlbehæftet blok.

Error - 28-04-2010 08:10:04 | Computer Name = Steffen-PC | Source = cdrom | ID = 262151
Description = Enheden \Device\CdRom0 havde en fejlbehæftet blok.

Error - 28-04-2010 08:10:11 | Computer Name = Steffen-PC | Source = cdrom | ID = 262151
Description = Enheden \Device\CdRom0 havde en fejlbehæftet blok.

Error - 28-04-2010 08:10:18 | Computer Name = Steffen-PC | Source = cdrom | ID = 262151
Description = Enheden \Device\CdRom0 havde en fejlbehæftet blok.

Error - 28-04-2010 08:10:25 | Computer Name = Steffen-PC | Source = cdrom | ID = 262151
Description = Enheden \Device\CdRom0 havde en fejlbehæftet blok.

Error - 28-04-2010 11:16:02 | Computer Name = Steffen-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 28-04-2010 12:14:34 | Computer Name = Steffen-PC | Source = Microsoft Antimalware | ID = 1008
Description = %%861 har fundet en fejl under handlingen mod spyware eller anden
potentielt uønsket software. Du kan finde flere oplysninger i det følgende: http://go.microsoft.com/fwlink/?linkid=370…atid=2147607809

Bruger:
NT AUTHORITY\SYSTEM Navn: Trojan:Win32/FakeRean Id: 2147607809 Alvorlighed: Høj Kategori:
Trojan Sti: Handling: %%808 Fejlkode: 0x80508023 Fejlbeskrivelse: Programmet kunne
ikke finde spyware og anden uønsket software på computeren. Status: Signaturversion:
AV: 1.81.547.0, AS: 1.81.547.0 Programversion: 1.1.5703.0


< End of report >
P2P - I see you have P2P software ( Limewire, BitTorrent, µTorrent ) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.

Please be sure that when you run GMER you have disabled any anti-virus and/or other security programs you may have running, and be sure that you have run it as administrator (by right-clicking the desktop icon and choosing "run as administrator". If it will still not run properly, please do the following:

Boot your computer in Safe Mode
  • Turn the computer on or Restart the computer
  • As soon as BIOS is loaded, start tapping the F8 key.
  • The Windows Advanced Options Menu appears.
    If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Use the arrow keys to select the Safe Mode menu option.
  • Press Enter.
  • The computer then begins to start in Safe mode.
  • Log into your usual account

Try running GMER again - make sure to right-click the desktop icon and choose "Run as Administrator".

Reboot into normal mode when you are done. If you are still unable to get it to run just let me know.

I see you have Malwarebytes already on your machine. Please run it by right-clicking the the icon on the desktop and choosing "Run as Administrator".
  • Click on the tab labeled Update and then click on the button Check for updates. Allow it to check for and apply any updates.
  • Select the Scanner tab, and Perform Quick Scan
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Please post the log in your next reply.
GMER log:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-30 15:10:21
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\Steffen\AppData\Local\Temp\kwddrfob.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Dynamisk WDF/Microsoft Corporation)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0021860bd92f
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xE6 0x22 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xAD 0x0B 0xA6 0xE1 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x40 0x66 0xCA 0x20 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x7F 0x24 0xD5 0xFC …
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0021860bd92f (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xE6 0x22 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xAD 0x0B 0xA6 0xE1 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x40 0x66 0xCA 0x20 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x7F 0x24 0xD5 0xFC …

—- EOF - GMER 1.0.15 —-



Malwarebytes' Anti-Malware log:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4054

Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

30-04-2010 16:41:32
mbam-log-2010-04-30 (16-41-32).txt

Skanningstype: Hurtig skanning
Objekter skannet: 125351
Tid gået: 9 minut(ter), 2 sekund(er)

Hukommelses Processorer Inficeret: 0
Hukommelses Moduler Inficeret: 0
Registreringsdatabasenøgler Inficeret: 4
Registreringsdatabaseværdier Inficeret: 0
Registreringsdatabasedata Objekter Inficeret: 0
Inficerede Mapper: 0
Inficerede Filer: 3

Hukommelses Processorer Inficeret:
(Ingen skadelige objekter blev fundet)

Hukommelses Moduler Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabasenøgler Inficeret:
HKEY_CURRENT_USER\Software\YVIBBBHA8C (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\QZAIB7KITK (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registreringsdatabaseværdier Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabasedata Objekter Inficeret:
(Ingen skadelige objekter blev fundet)

Inficerede Mapper:
(Ingen skadelige objekter blev fundet)

Inficerede Filer:
C:\Users\Steffen\AppData\Local\temp\amowcxsren.exe (Adware.AdRotator) -> Quarantined and deleted successfully.
C:\Users\Steffen\AppData\Local\temp\stp4cf45.exe (Trojan.FraudTool) -> Quarantined and deleted successfully.
C:\Users\Steffen\AppData\Local\temp\Vlz.exe (Trojan.Fraudpack) -> Quarantined and deleted successfully.
I see you had Combofix on your computer. This tool is updated regularly and it is important to have the latest version, so please right click the icon on your desktop and delete it. Then do the following:

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Right click on ComboFix.exe choose Run as Administrator & follow the prompts.
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
My computer seems to be running normally, there aren't pop-ups anymore.

Combofix log

ComboFix 10-05-01.01 - Steffen 01-05-2010 19:52:45.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.45.1030.18.3070.2024 [GMT 2:00]
Kører fra: c:\users\Steffen\Desktop\ComboFix.exe
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((( Filer skabt fra 2010-04-01 til 2010-05-01 )))))))))))))))))))))))))))))))))))
.

2010-05-01 18:10 . 2010-05-01 18:11 ——– d—–w- c:\users\Steffen\AppData\Local\temp
2010-05-01 18:10 . 2010-05-01 18:10 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-05-01 18:10 . 2010-05-01 18:10 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-04-30 14:25 . 2010-04-30 14:25 6153352 —-a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-04-29 22:11 . 2010-04-29 22:11 ——– d—–w- c:\program files\Foosball
2010-04-29 22:09 . 2010-04-29 22:09 ——– d—–w- c:\program files\Rats!
2010-04-27 06:25 . 2010-04-27 06:25 563712 —-a-w- c:\program files\OTL.exe
2010-04-26 09:40 . 2010-04-26 09:40 388096 —-a-r- c:\users\Steffen\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-04-25 18:49 . 2010-04-25 18:49 730624 —-a-w- c:\users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156\newupdate1142C.exe
2010-04-25 18:49 . 2010-04-25 18:49 ——– d—–w- c:\users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156
2010-04-23 06:32 . 2006-12-14 08:00 110592 —-a-w- c:\users\Steffen\AppData\Roaming\U3\temp\cleanup.exe
2010-04-23 06:31 . 2007-02-12 15:46 3096576 —ha-w- c:\users\Steffen\AppData\Roaming\U3\temp\Launchpad Removal.exe
2010-04-23 06:31 . 2010-04-23 06:32 ——– d—–w- c:\users\Steffen\AppData\Roaming\U3
2010-04-22 05:23 . 2010-04-22 05:23 ——– d—–w- c:\users\Steffen\AppData\Local\Adobe
2010-04-19 19:46 . 2010-04-19 19:46 ——– d—–w- c:\users\Steffen\AppData\Roaming\Malwarebytes
2010-04-19 19:46 . 2010-04-29 13:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-19 19:46 . 2010-04-19 19:46 ——– d—–w- c:\programdata\Malwarebytes
2010-04-19 19:46 . 2010-04-30 14:29 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-19 19:46 . 2010-04-29 13:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-18 11:14 . 2010-04-18 23:09 ——– d—–w- c:\program files\Musikprogrammer
2010-04-18 10:39 . 2010-04-18 10:39 ——– d—–w- c:\program files\Trend Micro
2010-04-15 15:30 . 2010-04-15 15:30 ——– d—–w- c:\programdata\{87784988-8668-411D-B26A-0C946ED2BE3C}
2010-04-15 15:30 . 2009-03-31 16:02 575004 —-a-w- c:\programdata\{87784988-8668-411D-B26A-0C946ED2BE3C}\mia.dll
2010-04-15 15:30 . 2009-03-31 16:02 2131640 —-a-w- c:\programdata\{87784988-8668-411D-B26A-0C946ED2BE3C}\printer og drev (sct. knuds gymnasium).exe
2010-04-15 15:30 . 2010-04-15 15:30 ——– d—–w- c:\program files\Skoleprinter
2010-04-15 10:12 . 2010-04-15 10:12 ——– d—–w- c:\program files\Grafværktøj
2010-04-15 10:11 . 1999-03-23 06:12 299520 —-a-w- c:\windows\uninst.exe
2010-04-14 05:23 . 2010-03-04 17:33 430080 —-a-w- c:\windows\system32\vbscript.dll
2010-04-14 05:23 . 2010-02-23 11:10 79360 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-14 05:23 . 2010-02-23 11:10 212992 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-14 05:23 . 2010-02-23 11:10 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-14 05:23 . 2010-02-18 14:07 3600776 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-14 05:23 . 2010-02-18 14:07 3548040 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-04-14 05:22 . 2009-12-23 11:33 172032 —-a-w- c:\windows\system32\wintrust.dll
2010-04-14 05:22 . 2010-02-18 14:07 904576 —-a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-14 05:22 . 2010-02-18 13:30 200704 —-a-w- c:\windows\system32\iphlpsvc.dll
2010-04-14 05:22 . 2010-02-18 11:28 25088 —-a-w- c:\windows\system32\drivers\tunnel.sys
2010-04-14 05:19 . 2010-01-13 17:34 98304 —-a-w- c:\windows\system32\cabview.dll
2010-04-11 14:18 . 2010-04-11 14:19 ——– d—–w- C:\a0c698d600d463d0cf
2010-04-09 10:59 . 2010-04-19 14:06 ——– d-sh–w- c:\programdata\SysWoW32
2010-04-09 10:58 . 2010-04-09 10:58 203776 –sh–w- c:\programdata\unrar.exe
2010-04-05 15:47 . 2010-04-05 15:47 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-04-05 15:43 . 2010-04-05 22:16 ——– d—–w- c:\programdata\Lavasoft
2010-04-05 15:43 . 2010-04-05 15:44 ——– d—–w- c:\program files\Lavasoft
2010-04-02 21:14 . 2010-04-02 21:15 ——– d—–w- c:\program files\GIMP-2.0
2010-04-02 21:12 . 2010-04-02 21:12 ——– d—–w- c:\program files\Common Files\GTK
2010-04-02 15:52 . 2010-03-29 07:59 52224 —-a-w- c:\users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
2010-04-02 15:52 . 2010-03-29 07:59 101376 —-a-w- c:\users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-01 17:43 . 2008-12-26 20:54 32061 —-a-w- c:\programdata\nvModes.dat
2010-05-01 10:18 . 2008-05-21 04:08 12 —-a-w- c:\windows\bthservsdp.dat
2010-05-01 10:15 . 2008-02-26 01:47 82814 —-a-w- c:\windows\system32\perfc006.dat
2010-05-01 10:15 . 2008-02-26 01:47 479574 —-a-w- c:\windows\system32\perfh006.dat
2010-04-28 16:17 . 2010-04-28 16:17 78808 —-a-w- c:\program files\Extras.Txt
2010-04-28 16:16 . 2010-04-28 16:16 110164 —-a-w- c:\program files\OTL.Txt
2010-04-19 07:54 . 2009-07-10 09:44 ——– d—–w- c:\program files\Microsoft Silverlight
2010-04-18 23:05 . 2009-08-03 10:44 ——– d—–w- c:\users\Steffen\AppData\Roaming\vlc
2010-04-18 21:12 . 2008-11-26 20:05 ——– d—–w- c:\users\Steffen\AppData\Roaming\LimeWire
2010-04-17 20:55 . 2009-12-27 11:58 ——– d—–w- c:\program files\Google
2010-04-15 10:12 . 2010-04-15 10:12 ——– d—–w- c:\program files\Grafværktøj
2010-04-14 06:08 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-04-14 05:36 . 2008-10-27 17:38 ——– d—–w- c:\programdata\Microsoft Help
2010-04-09 10:46 . 2008-11-26 20:04 ——– d—–w- c:\program files\LimeWire
2010-04-02 11:55 . 2010-03-28 17:47 ——– d—–w- c:\users\Steffen\AppData\Roaming\uTorrent
2010-03-28 17:50 . 2010-03-28 17:50 ——– d—–w- c:\program files\uTorrent
2010-03-26 16:25 . 2008-05-21 04:35 ——– d—–w- c:\programdata\NVIDIA
2010-03-26 10:31 . 2008-10-10 11:44 ——– d—–w- c:\program files\CCleaner
2010-03-19 16:35 . 2010-03-08 19:34 439816 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\setup.exe
2010-03-19 16:35 . 2010-03-19 16:35 5971968 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\chr\ChromeInstaller.exe
2010-03-19 16:34 . 2010-03-19 16:34 79368 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\vista.exe
2010-03-19 16:34 . 2010-03-19 16:34 64000 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\gcapi_dll.dll
2010-03-19 16:34 . 2010-03-19 16:34 52288 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\gtapi.dll
2010-03-19 16:34 . 2010-03-19 16:34 50688 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\fftbapi.dll
2010-03-19 16:34 . 2010-03-19 16:34 118784 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\compat.dll
2010-03-19 16:34 . 2010-03-19 16:34 49152 —-a-w- c:\users\Steffen\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\CarboniteCompatibility.dll
2010-03-18 17:33 . 2010-03-18 17:27 ——– d—–w- c:\users\Steffen\AppData\Roaming\Teleca
2010-03-18 17:32 . 2010-03-18 17:32 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
2010-03-18 17:26 . 2010-03-18 17:26 ——– d—–w- c:\program files\Common Files\Teleca Shared
2010-03-18 17:26 . 2010-03-18 17:26 ——– d—–w- c:\programdata\HTC
2010-03-18 17:26 . 2010-03-18 17:26 ——– d—–w- c:\programdata\Teleca
2010-03-18 17:26 . 2010-03-18 17:24 ——– d—–w- c:\program files\HTC
2010-03-18 17:24 . 2010-03-18 17:24 ——– d—–w- c:\program files\Spirent Communications
2010-03-12 15:40 . 2010-03-12 15:39 ——– d—–w- c:\program files\Common Files\DVDVideoSoft
2010-03-12 15:39 . 2010-03-12 15:39 ——– d—–w- c:\program files\DVDVideoSoft
2010-03-12 15:31 . 2010-03-12 15:30 ——– d—–w- c:\program files\YouTube Downloader
2010-03-11 18:47 . 2010-03-11 18:47 444952 —-a-w- c:\windows\system32\wrap_oal.dll
2010-03-11 18:47 . 2010-03-11 18:47 109080 —-a-w- c:\windows\system32\OpenAL32.dll
2010-03-11 18:47 . 2010-03-11 18:47 ——– d—–w- c:\program files\OpenAL
2010-03-11 18:46 . 2010-03-11 18:46 ——– d—–w- c:\program files\Prodigium Game Studios
2010-03-11 07:17 . 2010-02-15 14:13 64164264 —-a-w- c:\users\Steffen\AppData\Roaming\Nokia\Ovi Suite\Software Updater\NokiaOviSuite2Installer.exe
2010-03-09 16:25 . 2010-04-01 15:39 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-03-09 15:42 . 2010-04-01 15:39 834048 —-a-w- c:\windows\system32\wininet.dll
2010-02-26 16:13 . 2010-03-16 16:35 17160 —-a-w- c:\windows\Help\OEM\scripts\HPHCDisableObject.exe
2010-02-24 19:55 . 2008-08-29 17:17 121072 —-a-w- c:\users\Steffen\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-24 08:16 . 2009-10-03 14:37 181632 ——w- c:\windows\system32\MpSigStub.exe
2010-02-22 18:16 . 2008-11-13 12:44 680 —-a-w- c:\users\Steffen\AppData\Local\d3d9caps.dat
2010-02-22 12:28 . 2010-03-09 09:47 1282824 —-a-w- c:\windows\Help\OEM\scripts\SamsungHDDFW1HC.exe
2010-02-20 23:06 . 2010-03-10 11:18 24064 —-a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:05 . 2010-03-10 11:17 30720 —-a-w- c:\windows\system32\httpapi.dll
2010-02-20 20:53 . 2010-03-10 11:17 411648 —-a-w- c:\windows\system32\drivers\http.sys
2010-02-12 10:32 . 2010-03-05 08:52 293376 —-a-w- c:\windows\system32\browserchoice.exe
2010-02-05 13:45 . 2010-02-05 13:45 72488 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-04 15:51 . 2010-03-09 09:47 49152 —-a-w- c:\windows\Help\OEM\scripts\Interop.TaskScheduler.dll
2008-02-26 02:57 . 2008-02-26 02:37 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((( Start steder i reg.basen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2007-09-20 671744]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-21 1093208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-10-03 13826664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~3\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Steffen^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Screen Clipper and Launcher til OneNote 2007.lnk]
path=c:\users\Steffen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Screen Clipper and Launcher til OneNote 2007.lnk
backup=c:\windows\pss\Screen Clipper and Launcher til OneNote 2007.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-04 05:42 36272 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CamSpace]
2009-09-08 16:41 1404928 —-a-w- c:\program files\CamSpace\CamSpaceAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
2009-12-18 10:24 427328 —-a-w- c:\program files\DAEMON Tools Pro\DTProAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-19 07:33 125952 —-a-w- c:\windows\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2010-02-21 20:45 30192 —-a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-09-28 17:45 133104 —-atw- c:\users\Steffen\AppData\Local\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 09:44 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
2008-10-09 05:58 75008 —-a-w- c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 14:24 54840 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-01-22 18:16 141608 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2007-08-23 15:36 455968 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-04-29 13:39 1090952 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mobile Connectivity Suite]
2009-11-19 15:19 598016 —-a-r- c:\program files\HTC\HTC Sync\Application Launcher\Application Launcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2009-10-03 10:40 13826664 —-a-w- c:\windows\System32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2009-10-03 10:40 92776 —-a-w- c:\windows\System32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OnScreenDisplay]
2007-09-04 20:54 554320 —-a-w- c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2007-10-01 02:34 181544 —-a-w- c:\program files\HP\QuickPlay\QPService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 22:08 417792 —-a-w- c:\program files\QuickTime & Real Alternative\QuickTime Alternative\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-07-31 13:23 149280 —-a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-02-15 18:12 198160 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
2007-08-17 06:13 218408 ——w- c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WAWifiMessage]
2007-01-08 23:53 311296 —-a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2009-07-01 16:37 37888 —-a-w- c:\program files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-19 07:33 202240 —-a-w- c:\program files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):8d,99,72,53,18,00,ca,01

R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-01-23 691696]
R2 appdrvrem01;Application Driver Auto Removal Service (01);c:\windows\System32\appdrvrem01.exe svc [x]
R2 gupdate;Tjenesten Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-12-27 133104]
R3 GoogleDesktopManager-110309-193829;Google Desktop-administrator 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-02-21 30192]
R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-06-10 24576]
S1 appdrv01;Application Driver (01);c:\windows\system32\Drivers\appdrv01.sys [2009-07-19 2915944]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2009-12-02 42368]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 15:34 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Indhold af mappen 'Planlagte Opgaver'

2010-05-01 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-27 05:56]

2010-05-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-27 11:59]

2010-05-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-27 11:59]

2010-04-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-142386170-2914611657-1622844314-1000Core.job
- c:\users\Steffen\AppData\Local\Google\Update\GoogleUpdate.exe [2009-09-28 17:45]

2010-05-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-142386170-2914611657-1622844314-1000UA.job
- c:\users\Steffen\AppData\Local\Google\Update\GoogleUpdate.exe [2009-09-28 17:45]

2010-04-06 c:\windows\Tasks\HPCeeScheduleForSteffen.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-02-26 19:58]
.
.
——- Yderligere scanning ——-
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_dk&c=81&bd=Pavilion&pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=da_dk&c=81&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
IE: E&ksporter til Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send billede til &Bluetooth-enhed… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send siden til &Bluetooth-enhed… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: danskebank.dk
DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} - hxxps://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
FF - ProfilePath - c:\users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\s0kfb21q.default\
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\Firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\program files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\components\FirefoxExtension.dll
FF - component: c:\users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
FF - component: c:\users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\s0kfb21q.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLITIKKER —-
c:\program files\Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-01 20:11
Windows 6.0.6002 Service Pack 2 NTFS

scanner skjulte processer …

scanner skjulte autostarter …

scanner skjulte filer …


c:\users\Steffen\AppData\Local\Temp\catchme.dll 53248 bytes executable

scanning gennemført med succes
skjulte filer: 1

**************************************************************************
.
——————— LÅSTE REGISTRERINGS NØGLER ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs startet under kørende Processer ———————

- - - - - - - > 'lsass.exe'(696)
c:\windows\system32\DPPWDFLT.dll

- - - - - - - > 'Explorer.exe'(1728)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
c:\program files\MediaMonkey\DeskPlayer.dll
.
Gennemført tid: 2010-05-01 20:17:14
ComboFix-quarantined-files.txt 2010-05-01 18:17
ComboFix2.txt 2010-04-20 15:08

Pre-Kørsel: 64.812.265.472 byte ledig
Post-Kørsel: 64.842.977.280 byte ledig

- - End Of File - - FCCD9EFAC68644D9CFF46240FFB4956E
There are a few files that I'd like you to have checked before we move on.

Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.


Please go to: VirusTotal
  • [external image: Posted Image]
  • Click the Browse button and search for the following file:
    C:\ProgramData\1925965306
    C:\ProgramData\580629930
    C:\ProgramData\sl1132078904
  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Please post the results in your next reply.

After you have uploaded the files, please remember to reverse the steps to once again hide the hidden and protected system files.
File 1925965306 received on 2010.05.02 11:43:19 (UTC) Antivirus Version Last Update Result a-squared 4.5.0.50 2010.05.02 - AhnLab-V3 2010.05.02.00 2010.05.01 - AntiVir 8.2.1.224 2010.04.30 - Antiy-AVL 2.0.3.7 2010.04.30 - Authentium 5.2.0.5 2010.05.01 - Avast 4.8.1351.0 2010.05.02 - Avast5 5.0.332.0 2010.05.02 - AVG 9.0.0.787 2010.05.02 - BitDefender 7.2 2010.05.02 - CAT-QuickHeal 10.00 2010.05.01 - ClamAV 0.96.0.3-git 2010.05.02 - Comodo 4739 2010.05.02 - DrWeb 5.0.2.03300 2010.05.02 - eSafe 7.0.17.0 2010.04.29 - eTrust-Vet 35.2.7462 2010.04.30 - F-Prot 4.5.1.85 2010.05.01 - F-Secure 9.0.15370.0 2010.05.02 - Fortinet 4.0.14.0 2010.05.01 - GData 21 2010.05.02 - Ikarus T3.1.1.80.0 2010.05.02 - Jiangmin 13.0.900 2010.05.02 - Kaspersky 7.0.0.125 2010.05.02 - McAfee 5.400.0.1158 2010.05.02 - McAfee-GW-Edition 6.8.5 2010.05.01 - Microsoft 1.5703 2010.05.02 - NOD32 5079 2010.05.02 - Norman 6.04.12 2010.05.01 - nProtect 2010-05-02.01 2010.05.02 - Panda 10.0.2.7 2010.05.01 - PCTools 7.0.3.5 2010.05.02 - Prevx 3.0 2010.05.02 - Rising 22.45.04.03 2010.04.30 - Sophos 4.53.0 2010.05.02 - Sunbelt 6249 2010.05.02 - Symantec 20091.2.0.41 2010.05.02 - TheHacker 6.5.2.0.275 2010.05.02 - TrendMicro 9.120.0.1004 2010.05.01 - TrendMicro-HouseCall 9.120.0.1004 2010.05.02 - VBA32 3.12.12.4 2010.04.30 - ViRobot 2010.5.1.2299 2010.05.02 - VirusBuster 5.0.27.0 2010.05.01 - Additional information File size: 817 bytes MD5…: 672c1e7e48e2884aadf5a1007d4eadfc SHA1..: 6199b1c92cbcdcd95a8b0d7540f8dc02d910d454 SHA256: 3db65629d26f99c9e67b64ef561ede0a484facf5d1726caf2f1d86ade01a7a84 ssdeep: 12:5ZEbTKLz+eSG9vh3J9nJQoiSu5n9W8UFlRRVPPPjIhO0cuE:3EbTC+CX9JQb/
U3RRNIhO0cn
PEiD..: - PEInfo: - RDS…: NSRL Reference Data Set
- pdfid.: - trid..: MP3 audio (100.0%) sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned
File 580629930 received on 2010.05.02 11:40:54 (UTC) Antivirus Version Last Update Result a-squared 4.5.0.50 2010.05.02 - AhnLab-V3 2010.05.02.00 2010.05.01 - AntiVir 8.2.1.224 2010.04.30 - Antiy-AVL 2.0.3.7 2010.04.30 - Authentium 5.2.0.5 2010.05.01 - Avast 4.8.1351.0 2010.05.02 - Avast5 5.0.332.0 2010.05.02 - AVG 9.0.0.787 2010.05.02 - BitDefender 7.2 2010.05.02 - CAT-QuickHeal 10.00 2010.05.01 - ClamAV 0.96.0.3-git 2010.05.02 - Comodo 4739 2010.05.02 - DrWeb 5.0.2.03300 2010.05.02 - eSafe 7.0.17.0 2010.04.29 - eTrust-Vet 35.2.7462 2010.04.30 - F-Prot 4.5.1.85 2010.05.01 - F-Secure 9.0.15370.0 2010.05.02 - Fortinet 4.0.14.0 2010.05.01 - GData 21 2010.05.02 - Ikarus T3.1.1.80.0 2010.05.02 - Jiangmin 13.0.900 2010.05.02 - Kaspersky 7.0.0.125 2010.05.02 - McAfee 5.400.0.1158 2010.05.02 - McAfee-GW-Edition 6.8.5 2010.05.01 - Microsoft 1.5703 2010.05.02 - NOD32 5079 2010.05.02 - Norman 6.04.12 2010.05.01 - nProtect 2010-05-02.01 2010.05.02 - Panda 10.0.2.7 2010.05.01 - PCTools 7.0.3.5 2010.05.02 - Prevx 3.0 2010.05.02 - Rising 22.45.04.03 2010.04.30 - Sophos 4.53.0 2010.05.02 - Sunbelt 6249 2010.05.02 - Symantec 20091.2.0.41 2010.05.02 - TheHacker 6.5.2.0.275 2010.05.02 - TrendMicro 9.120.0.1004 2010.05.01 - TrendMicro-HouseCall 9.120.0.1004 2010.05.02 - VBA32 3.12.12.4 2010.04.30 - ViRobot 2010.5.1.2299 2010.05.02 - VirusBuster 5.0.27.0 2010.05.01 - Additional information File size: 1023 bytes MD5…: 5f65b01c59c8b3c331d1f8c058fb2d96 SHA1..: 9809dbf3a54085f85c1a18c25d0e4c1262568793 SHA256: 999e3d3ef27f2a9e7c3be6a1059f98f91aedbcda006955389c239751bf62cbaf ssdeep: 12:JKAL/Oji16Q6jH3tr42NmNbfXr+Y6NLWreNfDMkwk08w69O8QS8/vNKjs:oDi
AQ6T3t8gQbfSppop8QS8nNKjs
PEiD..: - PEInfo: - RDS…: NSRL Reference Data Set
- pdfid.: - trid..: file seems to be plain text/ASCII (0.0%) sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned
File sl1132078904 received on 2010.05.02 11:47:48 (UTC) Antivirus Version Last Update Result a-squared 4.5.0.50 2010.05.02 - AhnLab-V3 2010.05.02.00 2010.05.01 - AntiVir 8.2.1.224 2010.04.30 - Antiy-AVL 2.0.3.7 2010.04.30 - Authentium 5.2.0.5 2010.05.01 - Avast 4.8.1351.0 2010.05.02 - Avast5 5.0.332.0 2010.05.02 - AVG 9.0.0.787 2010.05.02 - BitDefender 7.2 2010.05.02 - CAT-QuickHeal 10.00 2010.05.01 - ClamAV 0.96.0.3-git 2010.05.02 - Comodo 4739 2010.05.02 - DrWeb 5.0.2.03300 2010.05.02 - eSafe 7.0.17.0 2010.04.29 - eTrust-Vet 35.2.7462 2010.04.30 - F-Prot 4.5.1.85 2010.05.01 - F-Secure 9.0.15370.0 2010.05.02 - Fortinet 4.0.14.0 2010.05.01 - GData 21 2010.05.02 - Ikarus T3.1.1.80.0 2010.05.02 - Jiangmin 13.0.900 2010.05.02 - Kaspersky 7.0.0.125 2010.05.02 - McAfee 5.400.0.1158 2010.05.02 - McAfee-GW-Edition 6.8.5 2010.05.01 - Microsoft 1.5703 2010.05.02 - NOD32 5079 2010.05.02 - Norman 6.04.12 2010.05.01 - nProtect 2010-05-02.01 2010.05.02 - Panda 10.0.2.7 2010.05.01 - PCTools 7.0.3.5 2010.05.02 - Prevx 3.0 2010.05.02 - Rising 22.45.04.03 2010.04.30 - Sophos 4.53.0 2010.05.02 - Sunbelt 6249 2010.05.02 - Symantec 20091.2.0.41 2010.05.02 - TheHacker 6.5.2.0.275 2010.05.02 - TrendMicro 9.120.0.1004 2010.05.01 - TrendMicro-HouseCall 9.120.0.1004 2010.05.02 - VBA32 3.12.12.4 2010.04.30 - ViRobot 2010.5.1.2299 2010.05.02 - VirusBuster 5.0.27.0 2010.05.01 - Additional information File size: 113 bytes MD5…: ca140f2455b62bcc84b95128a6ca05a4 SHA1..: 04f9ebf37742816dc3a4505633ec33ba333c7d3a SHA256: 408722726b2023cd8bc54c8d12cec6db09c56ae78df1ab98cdaf77fbc92e50b4 ssdeep: 3:9eoxBuPv7+9uoxMJm7FyyvHnthv3vknvHnthSj:iXa9VI6vB
PEiD..: - PEInfo: - RDS…: NSRL Reference Data Set
- pdfid.: - trid..: Unknown! sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned
Run OTL.exe (Be sure to right-click and Run as Administrator)
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    [2010-04-25 20:50:11 | 000,223,232 | -HS- | C] () – C:\Users\Steffen\AppData\Local\ave.exe
    [2010-04-25 20:50:11 | 000,009,952 | -HS- | C] () – C:\Users\Steffen\AppData\Local\UJ0QRjYY
    [2010-04-25 20:50:11 | 000,009,952 | -HS- | C] () – C:\ProgramData\UJ0QRjYY
    [2010-04-09 12:59:07 | 000,000,000 | -HSD | C] – C:\ProgramData\SysWoW32
    [2010-04-19 22:06:25 | 000,000,817 | —- | M] () – C:\ProgramData\1925965306
    [2010-04-19 16:05:58 | 000,001,023 | -HS- | M] () – C:\ProgramData\580629930
    [2010-04-09 12:59:07 | 000,000,113 | —- | M] () – C:\ProgramData\sl1132078904
    :Files
    c:\users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156\newupdate1142C.exe
    c:\users\Steffen\AppData\Roaming\5AC9C292A6E601BE626B81738E046156
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log

Please do a scan with Kaspersky Online Scanner
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
  • Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:
  • Text file [*.txt] Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply.

Also, along with the OTL and Kaspersky logs, please let me know how your machine is behaving now.
Are you having and trouble with or do you have any questions about the last set of instructions?

Reminder: Threads with no replies in 4 days will be closed.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI