This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Probably a keylogger, need help

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello.

Would really appriciate if you could help me resolve the situation I am in.

Yesterday my WoW account was comprimized and everything points toward a keylogger. Have run AVG, Ad-Aware and a few other spyware programs. Got indications of infected files and they have been fixed. Just want to make sure that every trace is gone before I start talking to Blizzard about retrieving all my gold and items.

Hope you can help me. The HJT log is attached below.

Thanks in advance! /O

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:26:34, on 2010-09-07
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe
C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Olof\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
O2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ANT Agent] C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe
O4 - Startup: CurseClientStartup.ccip
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll
O23 - Service: SAS Core Service (!SASCORE) - Unknown owner - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files (x86)\AVG\AVG9\Toolbar\ToolbarBroker.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 7459 bytes
Hi olfie

:welcome:

Sorry for the delay in replying, we are very busy at the moment. My name is Blottedisk, I'll be happy to assist you with all your malware problems you have on your computer. Solving any malware-related problem may or may not solve other issues you have with your machine. Before we start fixing your computer, there are a few points you need to know:

  • The forum is busy and we need to have replies as soon as possible. If I haven't had a reply after 3 days I will bump the topic and if you do not reply by the following day after that then the thread will be locked due to inactivity. However, if you will be away, let us know and we will be sure to keep the thread open.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Options box to the right of your topic title and selecting Track This Topic.. Please don't start a new topic, but reply on this one.
  • Malware Logs can sometimes take a lot of time to research and interpret. Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • If you don't understand something, please ask! If you find any new problems and/or details, please post them!
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process. Please do not delete anything unless instructed to. Do not use the comptuer exept for downloading tools and checking this topic
  • Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice. This may cause a delay in response time, but I will do my best to keep it as short as possible.

Remember: absence of symptoms does not mean your computer is clean.

Reply to this topic until I say your computer is clean. Please bear with me, I will post back to you as soon as I can.
Hi again olfie :)


I notice there's software from Curse.com in your machine. It is my understanding that this is some kind of addon-client for WoW. Although the site and it's software may appear legit, there are some comments in WOT (Web of Trust) Scorecard that connects this site to key-logger activity, like this one:

This site/network tend to invite key-loggers, not a safe or trustworthy website. Although it has some good gaming info, take a careful approach while browsing and scan your system often for malicious content if u value your MMO accounts. Personally I would choose a different site for mmo news and downloads.



I would also like to share this recent topic from the official WoW-Europe forum about Curse.com:
Curse.com = u Get hacked


Regarding the preceding, I would therefore suggest you to stop using any software from this developer, and from visiting their site. Just in case, please refrain from trying to login at other services (like your email, msn, online accounts), as we don't know what kind of information this keylogger can collect apart from WoW accounts. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:

  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps


This also leads me to ask you the following questions:

1 - Wich software from Curse.com have you installed in the computer?
2 - Is there any other third-party WoW-software that doesn't belong to Blizzard installed in the computer?
3 - What antyspyware/security software have you run so far?


Please do the following:


Step 1 | Please post the SUPERAntiSpyware log:

  • Open SUPERAntySpyware.
  • Click on Preferences and then click the Statistics/Logs tab.
  • Click the dated log and press View Log and a txt file will appear.
  • Please paste it's content's in your next reply.

Step 2 | Please post the Ad-Aware log:

  • Navigate to the following folder:
    • C:\Documents and Settings\[YOUR USERNAME]\Application Data\Lavasoft\Ad-Aware\Logs
  • You'll probably find several logs. They are dated.
  • Please open the newest one and paste it's content's in your next reply.

Step 3 | Please download OTL from one of the following mirrors:

This is THE Mirror

——————————————————————–

  • Save it to your desktop.
  • Double click on the [external image: Posted Image] icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Push the [external image: Posted Image] button.
  • Two reports will open, copy and paste them in your next reply:

OTListIt.txt <– Will be opened
Extra.txt <– Will be minimized


Please post back with:

SUPERAntySpyware log
Ad-Aware log
otl.txt
extras.txt
Hey Blottedisk.

Will try to support you with answers to your questions…

Yes I have been using Curse Client to manage my addons but stopped using it after I was infected. Now Im not using any other third party programs related to WoW.

For protection I use AVG-Free and Ad-Aware. When I was infected I used a few others cause Ad-Aware and AVG couldnt find the source. Dont recall all of them but I used the SuperAntiSpyware trial version that just let me detect the problem not fix it. It pointe towards a set-up.exe for my portable usb harddrive. Trialversion didnt clean it and I got a bit shaky and just deleted it. Maybe that was a bad thing to do?

SuperAntiSpyware log. (I did un-installed the program but reinstalled it so the log is from just recently)

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/09/2010 at 08:05 PM

Application Version : 4.42.1000

Core Rules Database Version : 5478
Trace Rules Database Version: 3290

Scan type : Quick Scan
Total Scan Time : 00:10:04

Memory items scanned : 729
Memory threats detected : 0
Registry items scanned : 2489
Registry threats detected : 0
File items scanned : 19308
File threats detected : 1

Adware.Tracking Cookie
C:\Users\Olof\AppData\Roaming\Microsoft\Windows\Cookies\olof@imrworldwide[1].txt


Regarding the Ad-Aware log I am a bit lost. Cant enter those locations!!! Really confused and it wont let me edit permissions!! I have attached a ss of the folders that are locked. Could the virus have done this? So I cant reach the logs!

OTL logfile created on: 2010-09-09 20:22:18 - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Olof\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 0000041d | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

6,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 57,00% Memory free
15,00 Gb Paging File | 12,00 Gb Available in Paging File | 82,00% Paging File free
Paging file location(s): e:\pagefile.sys 9202 9202 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 119,14 Gb Total Space | 81,97 Gb Free Space | 68,80% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 698,63 Gb Total Space | 643,79 Gb Free Space | 92,15% Space Free | Partition Type: NTFS
Drive F: | 465,65 Gb Total Space | 355,93 Gb Free Space | 76,44% Space Free | Partition Type: FAT32
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OLOF-PC
Current User Name: Olof
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010-09-09 20:08:16 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Olof\Desktop\OTL.exe
PRC - [2010-09-08 23:19:55 | 000,910,296 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2010-08-11 23:32:37 | 007,704,216 | —- | M] (Blizzard Entertainment) – C:\World of Warcraft\Wow.exe
PRC - [2010-08-11 16:08:20 | 000,723,296 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe
PRC - [2010-08-11 16:08:11 | 002,065,760 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgtray.exe
PRC - [2010-08-11 16:07:59 | 000,921,952 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgemc.exe
PRC - [2010-08-11 16:07:55 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
PRC - [2010-05-20 14:34:30 | 012,026,216 | —- | M] (GARMIN Corp.) – C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe
PRC - [2010-04-16 22:12:46 | 003,872,080 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
PRC - [2010-04-16 22:10:28 | 000,114,000 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
PRC - [2010-04-16 18:36:42 | 000,026,480 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
PRC - [2010-02-09 18:38:56 | 003,465,384 | —- | M] (Thorvald Natvig) – C:\Program Files (x86)\Mumble\mumble.exe
PRC - [2010-01-22 12:29:40 | 000,106,496 | —- | M] (NEC Electronics Corporation) – C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe


========== Modules (SafeList) ==========

MOD - [2010-09-09 20:08:16 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Olof\Desktop\OTL.exe
MOD - [2009-07-14 03:14:10 | 000,095,232 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\msscript.ocx
MOD - [2009-07-14 03:03:50 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010-08-04 03:51:20 | 000,203,264 | —- | M] (AMD) [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2010-06-29 19:49:27 | 000,128,752 | —- | M] (SUPERAntiSpyware.com) [Auto | Stopped] – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE – (!SASCORE)
SRV - [2010-09-06 18:21:49 | 001,355,928 | —- | M] (Lavasoft) [On_Demand | Stopped] – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service)
SRV - [2010-08-11 16:07:59 | 000,921,952 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG9\avgemc.exe – (avg9emc)
SRV - [2010-08-11 16:07:55 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010-06-30 14:22:46 | 000,431,432 | —- | M] () [On_Demand | Stopped] – C:\Program Files (x86)\AVG\AVG9\Toolbar\ToolbarBroker.exe – (AVG Security Toolbar Service)


========== Driver Services (SafeList) ==========

DRV:64bit: - File not found [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RKHit.sys – (RkHit)
DRV:64bit: - [2010-08-11 16:08:51 | 000,317,520 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgtdia.sys – (AvgTdiA)
DRV:64bit: - [2010-08-11 16:08:48 | 000,269,904 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgldx64.sys – (AvgLdx64)
DRV:64bit: - [2010-08-11 16:08:48 | 000,035,536 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\Windows\SysNative\drivers\avgmfx64.sys – (AvgMfx64)
DRV:64bit: - [2010-08-04 04:22:36 | 007,451,648 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmdag.sys – (amdkmdag)
DRV:64bit: - [2010-08-04 03:15:44 | 000,268,288 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmpag.sys – (amdkmdap)
DRV:64bit: - [2010-07-15 14:47:42 | 000,116,240 | —- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\AtihdW76.sys – (AtiHDAudioService)
DRV:64bit: - [2010-05-06 11:21:46 | 000,125,456 | —- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\AtiHdmi.sys – (AtiHdmiService)
DRV:64bit: - [2010-01-22 12:22:22 | 000,180,224 | —- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\nusb3xhc.sys – (nusb3xhc)
DRV:64bit: - [2010-01-22 12:22:18 | 000,077,824 | —- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\nusb3hub.sys – (nusb3hub)
DRV:64bit: - [2009-12-25 09:05:40 | 000,297,512 | —- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\mv91xx.sys – (mv91xx)
DRV:64bit: - [2009-10-29 10:14:38 | 000,115,824 | —- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\jraid.sys – (JRAID)
DRV:64bit: - [2009-10-20 07:22:54 | 000,289,496 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\e1y62x64.sys – (e1yexpress) Intel®
DRV:64bit: - [2009-09-24 17:55:00 | 000,212,072 | —- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\tosrfbd.sys – (tosrfbd)
DRV:64bit: - [2009-09-14 14:30:26 | 000,058,744 | —- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\tosrfusb.sys – (Tosrfusb)
DRV:64bit: - [2009-08-05 12:56:04 | 000,063,856 | —- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TosRfSnd.sys – (TosRfSnd)
DRV:64bit: - [2009-07-28 20:02:10 | 000,081,768 | —- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\tosrfcom.sys – (Tosrfcom)
DRV:64bit: - [2009-07-24 11:33:14 | 000,026,472 | —- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\tosrfnds.sys – (tosrfnds)
DRV:64bit: - [2009-07-16 05:38:40 | 000,015,416 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\ASACPI.sys – (MTsensor)
DRV:64bit: - [2009-07-14 03:52:21 | 000,106,576 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2009-07-14 03:52:21 | 000,028,752 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2009-07-14 03:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009-07-14 03:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009-07-14 03:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2009-07-14 03:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009-06-19 10:00:26 | 000,094,336 | —- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\Tosrfhid.sys – (Tosrfhid)
DRV:64bit: - [2009-06-19 09:59:32 | 000,050,664 | —- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\tosrfbnp.sys – (tosrfbnp)
DRV:64bit: - [2009-06-17 12:01:04 | 000,054,664 | —- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\tosporte.sys – (tosporte)
DRV:64bit: - [2009-06-10 22:38:56 | 000,000,308 | —- | M] () [File_System | On_Demand | Running] – C:\Windows\SysNative\wbem\ntfs.mof – (Ntfs)
DRV:64bit: - [2009-06-10 22:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009-06-10 22:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009-06-10 22:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009-06-10 22:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2007-09-06 22:53:12 | 000,016,384 | —- | M] (Silicon Laboratories) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\DSI_SiUSBXp_3_1.sys – (DSI_SiUSBXp_3_1)
DRV - [2010-08-12 14:15:22 | 000,016,928 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys – (Lavasoft Kernexplorer)
DRV - [2010-02-17 20:23:05 | 000,014,920 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program\SUPERAntiSpyware\sasdifsv64.sys – (SASDIFSV)
DRV - [2010-02-17 20:23:05 | 000,012,360 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program\SUPERAntiSpyware\saskutil64.sys – (SASKUTIL)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-286741208-470331320-231057659-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
IE - HKU\S-1-5-21-286741208-470331320-231057659-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://se.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-286741208-470331320-231057659-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = sv
IE - HKU\S-1-5-21-286741208-470331320-231057659-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B0 C9 36 D4 61 39 CB 01 [binary data]
IE - HKU\S-1-5-21-286741208-470331320-231057659-1000\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKU\S-1-5-21-286741208-470331320-231057659-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.fraternitas-ferreus.net/forum2/index.php"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.19

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010-09-08 23:19:55 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010-09-08 23:19:55 | 000,000,000 | —D | M]

[2010-08-11 16:13:56 | 000,000,000 | —D | M] – C:\Users\Olof\AppData\Roaming\mozilla\Extensions
[2010-09-08 21:25:44 | 000,000,000 | —D | M] – C:\Users\Olof\AppData\Roaming\mozilla\Firefox\Profiles\c7rhcubc.default\extensions
[2010-08-18 18:31:28 | 000,000,000 | —D | M] – C:\Users\Olof\AppData\Roaming\mozilla\Firefox\Profiles\c7rhcubc.default\extensions\[removed]
[2010-09-06 21:08:13 | 000,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions
[2010-08-14 10:41:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010-08-14 13:10:52 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010-07-17 05:00:04 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010-07-23 02:48:26 | 000,001,470 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\allaannonser-sv-SE.xml
[2010-07-23 02:48:26 | 000,002,670 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\prisjakt-sv-SE.xml
[2010-07-23 02:48:26 | 000,000,948 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\tyda-sv-SE.xml
[2010-07-23 02:48:26 | 000,001,174 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-sv-SE.xml
[2010-07-23 02:48:26 | 000,000,951 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-sv-SE.xml

O1 HOSTS File: ([2010-09-07 18:28:00 | 000,417,891 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 14417 more lines…
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKU\S-1-5-21-286741208-470331320-231057659-1000\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-286741208-470331320-231057659-1000..\Run: [ANT Agent] C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe (GARMIN Corp.)
O4 - HKU\S-1-5-21-286741208-470331320-231057659-1000..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-286741208-470331320-231057659-1000..\Run: [SUPERAntiSpyware] C:\Program\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found
O4 - Startup: C:\Users\Olof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-01-24 10:08:56 | 000,000,000 | —D | M] - F:\autorun – [ FAT32 ]
O32 - AutoRun File - [2007-05-18 10:37:12 | 000,000,069 | RH– | M] () - F:\autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010-09-09 20:08:16 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\Olof\Desktop\OTL.exe
[2010-09-09 19:54:07 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\SUPERAntiSpyware.com
[2010-09-09 19:54:01 | 000,000,000 | —D | C] – C:\Program\SUPERAntiSpyware
[2010-09-09 17:21:36 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\avg
[2010-09-08 16:33:43 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\Mumble
[2010-09-08 16:33:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mumble
[2010-09-07 22:41:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Click-N-Type
[2010-09-07 19:58:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010-09-07 18:28:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Instant Spyware Removal
[2010-09-07 17:52:09 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010-09-07 17:52:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2010-09-06 23:12:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\NoAdware5.0
[2010-09-06 20:30:41 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\Malwarebytes
[2010-09-06 20:30:29 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010-09-06 20:30:28 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010-09-06 20:23:57 | 000,000,000 | —D | C] – C:\ProgramData\SecTaskMan
[2010-09-06 20:23:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Security Task Manager
[2010-09-06 20:04:42 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2010-09-06 20:04:39 | 000,000,000 | —D | C] – C:\ProgramData\!SASCORE
[2010-09-06 18:05:48 | 000,000,000 | -H-D | C] – C:\ProgramData\{ECC164E0-3133-4C70-A831-F08DB2940F70}
[2010-09-06 18:05:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lavasoft
[2010-09-06 17:23:25 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\Sunbelt Software
[2010-09-06 17:23:09 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2010-09-05 12:20:18 | 000,000,000 | —D | C] – C:\ProgramData\ATI
[2010-09-05 12:17:32 | 077,752,952 | —- | C] (Advanced Micro Devices, Inc.) – C:\Users\Olof\Desktop\10-8_vista64_win7_64_dd_ccc_enu.exe
[2010-08-24 09:05:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSECache
[2010-08-16 17:32:28 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2010-08-14 13:11:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2010-08-14 13:10:51 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2010-08-14 13:10:51 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2010-08-14 13:10:51 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2010-08-14 11:41:24 | 000,000,000 | —D | C] – C:\ProgramData\Adobe
[2010-08-14 11:41:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe
[2010-08-14 11:41:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2010-08-14 11:40:56 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\Adobe
[2010-08-14 10:42:12 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2010-08-14 10:42:12 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2010-08-14 10:41:08 | 000,423,656 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2010-08-14 02:25:11 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\OpenOffice.org
[2010-08-14 01:55:03 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010-08-14 01:54:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Java
[2010-08-14 01:48:38 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\TS3Client
[2010-08-14 00:52:12 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\Macromedia
[2010-08-12 17:50:37 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Macromed
[2010-08-12 17:42:19 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\Deployment
[2010-08-12 17:10:00 | 000,000,000 | —D | C] – C:\Users\Olof\Documents\Mina mottagna filer
[2010-08-11 23:07:23 | 000,000,000 | —D | C] – C:\ProgramData\Blizzard Entertainment
[2010-08-11 22:41:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\CCleaner
[2010-08-11 22:33:59 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Blizzard Entertainment
[2010-08-11 22:26:33 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\GARMIN
[2010-08-11 22:25:18 | 000,000,000 | —D | C] – C:\Program\DIFX
[2010-08-11 22:25:05 | 000,024,576 | —- | C] (Silicon Laboratories) – C:\Windows\SysNative\drivers\SiLib.sys
[2010-08-11 22:25:05 | 000,016,384 | —- | C] (Silicon Laboratories) – C:\Windows\SysNative\drivers\DSI_SiUSBXp_3_1.sys
[2010-08-11 22:25:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Garmin
[2010-08-11 22:14:21 | 000,000,000 | —D | C] – C:\ProgramData\Blizzard
[2010-08-11 21:28:43 | 000,000,000 | —D | C] – C:\World of Warcraft
[2010-08-11 21:27:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\World of Warcraft
[2010-08-11 21:27:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Blizzard Entertainment
[2010-08-11 21:20:59 | 001,942,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dfshim.dll
[2010-08-11 21:20:59 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2010-08-11 21:20:59 | 000,320,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHost.exe
[2010-08-11 21:20:59 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2010-08-11 21:20:59 | 000,109,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHostProxy.dll
[2010-08-11 21:20:59 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2010-08-11 21:20:59 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2010-08-11 21:20:59 | 000,048,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netfxperf.dll
[2010-08-11 21:20:53 | 000,294,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\browserchoice.exe
[2010-08-11 21:19:36 | 001,736,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2010-08-11 21:19:36 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2010-08-11 21:19:36 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2010-08-11 21:19:36 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2010-08-11 21:19:36 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2010-08-11 21:19:36 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2010-08-11 21:19:36 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2010-08-11 21:19:35 | 014,629,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmp.dll
[2010-08-11 21:19:35 | 011,406,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmp.dll
[2010-08-11 21:19:34 | 012,625,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmploc.DLL
[2010-08-11 21:19:34 | 012,625,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmploc.DLL
[2010-08-11 21:19:34 | 001,975,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CertEnroll.dll
[2010-08-11 21:19:34 | 001,320,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CertEnroll.dll
[2010-08-11 21:19:30 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2010-08-11 21:19:30 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2010-08-11 21:19:30 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2010-08-11 21:19:30 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2010-08-11 21:19:30 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2010-08-11 21:19:30 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2010-08-11 21:19:28 | 005,507,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2010-08-11 21:19:28 | 003,955,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2010-08-11 21:19:28 | 003,899,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2010-08-11 21:19:26 | 002,870,272 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2010-08-11 21:19:26 | 002,614,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\explorer.exe
[2010-08-11 21:19:26 | 001,572,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\quartz.dll
[2010-08-11 21:19:26 | 001,328,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\quartz.dll
[2010-08-11 21:19:26 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winlogon.exe
[2010-08-11 21:19:26 | 000,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\avifil32.dll
[2010-08-11 21:19:26 | 000,084,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mciavi32.dll
[2010-08-11 21:19:25 | 000,612,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2010-08-11 21:19:25 | 000,427,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\vbscript.dll
[2010-08-11 21:19:25 | 000,148,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\t2embed.dll
[2010-08-11 21:19:25 | 000,108,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\t2embed.dll
[2010-08-11 21:19:25 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rtutils.dll
[2010-08-11 21:19:25 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rtutils.dll
[2010-08-11 21:19:23 | 001,446,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2010-08-11 21:19:16 | 000,852,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2010-08-11 21:19:16 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2010-08-11 21:19:15 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2010-08-11 21:19:15 | 000,082,944 | —- | C] (Radius Inc.) – C:\Windows\SysWow64\iccvid.dll
[2010-08-11 21:18:33 | 000,366,080 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2010-08-11 21:18:33 | 000,293,888 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2010-08-11 21:18:33 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fontsub.dll
[2010-08-11 21:18:33 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fontsub.dll
[2010-08-11 21:18:33 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msasn1.dll
[2010-08-11 21:18:33 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2010-08-11 21:18:33 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2010-08-11 21:17:02 | 000,000,000 | R-SD | C] – C:\Users\Olof\Documents\My Stationery
[2010-08-11 21:11:19 | 000,000,000 | —D | C] – C:\Users\Olof\Tracing
[2010-08-11 21:10:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2010-08-11 21:09:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft
[2010-08-11 21:09:41 | 000,000,000 | —D | C] – C:\Users\Public\Documents\microsoft
[2010-08-11 21:09:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Live SkyDrive
[2010-08-11 21:09:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Live
[2010-08-11 21:09:18 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2010-08-11 16:13:41 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\Mozilla
[2010-08-11 16:13:41 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\Mozilla
[2010-08-11 16:13:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2010-08-11 16:08:51 | 000,013,048 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\avgrssta.dll
[2010-08-11 16:08:50 | 000,317,520 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgtdia.sys
[2010-08-11 16:08:48 | 000,269,904 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgldx64.sys
[2010-08-11 16:08:47 | 000,035,536 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgmfx64.sys
[2010-08-11 16:08:47 | 000,000,000 | —D | C] – C:\ProgramData\AVG Security Toolbar
[2010-08-11 16:08:47 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\Avg
[2010-08-11 16:06:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG
[2010-08-11 16:06:48 | 000,000,000 | —D | C] – C:\ProgramData\avg9
[2010-08-11 16:03:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Windows Live
[2010-08-11 15:59:40 | 000,220,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2010-08-11 15:59:40 | 000,172,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wintrust.dll
[2010-08-11 15:59:40 | 000,139,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cabview.dll
[2010-08-11 15:59:40 | 000,132,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cabview.dll
[2010-08-11 15:51:41 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\InstallShield
[2010-08-11 15:48:48 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\Adobe
[2010-08-11 15:47:31 | 000,012,744 | R— | C] (EnTech Taiwan) – C:\Windows\SysNative\drivers\Entech64.sys
[2010-08-11 15:47:31 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Futuremark
[2010-08-11 15:46:36 | 001,860,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_37.dll
[2010-08-11 15:46:36 | 001,420,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_37.dll
[2010-08-11 15:46:36 | 000,489,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_0.dll
[2010-08-11 15:46:36 | 000,479,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_0.dll
[2010-08-11 15:46:36 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_0.dll
[2010-08-11 15:46:36 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_0.dll
[2010-08-11 15:46:36 | 000,028,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_3.dll
[2010-08-11 15:46:36 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_3.dll
[2010-08-11 15:46:35 | 005,081,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_36.dll
[2010-08-11 15:46:35 | 004,910,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_37.dll
[2010-08-11 15:46:35 | 003,786,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_37.dll
[2010-08-11 15:46:35 | 003,734,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_36.dll
[2010-08-11 15:46:35 | 002,006,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_36.dll
[2010-08-11 15:46:35 | 001,985,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_35.dll
[2010-08-11 15:46:35 | 001,374,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_36.dll
[2010-08-11 15:46:35 | 001,358,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_35.dll
[2010-08-11 15:46:35 | 000,529,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_37.dll
[2010-08-11 15:46:35 | 000,508,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_36.dll
[2010-08-11 15:46:35 | 000,508,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_35.dll
[2010-08-11 15:46:35 | 000,462,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_37.dll
[2010-08-11 15:46:35 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_36.dll
[2010-08-11 15:46:35 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_35.dll
[2010-08-11 15:46:35 | 000,411,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_10.dll
[2010-08-11 15:46:35 | 000,411,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_9.dll
[2010-08-11 15:46:35 | 000,267,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_10.dll
[2010-08-11 15:46:35 | 000,267,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_9.dll
[2010-08-11 15:46:34 | 005,073,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_35.dll
[2010-08-11 15:46:34 | 004,496,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_34.dll
[2010-08-11 15:46:34 | 004,494,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_33.dll
[2010-08-11 15:46:34 | 003,727,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_35.dll
[2010-08-11 15:46:34 | 003,497,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_34.dll
[2010-08-11 15:46:34 | 003,495,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_33.dll
[2010-08-11 15:46:34 | 001,401,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_34.dll
[2010-08-11 15:46:34 | 001,400,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_33.dll
[2010-08-11 15:46:34 | 001,124,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_34.dll
[2010-08-11 15:46:34 | 001,123,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_33.dll
[2010-08-11 15:46:34 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_34.dll
[2010-08-11 15:46:34 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_33.dll
[2010-08-11 15:46:34 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_34.dll
[2010-08-11 15:46:34 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_33.dll
[2010-08-11 15:46:34 | 000,409,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_8.dll
[2010-08-11 15:46:34 | 000,403,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_7.dll
[2010-08-11 15:46:34 | 000,266,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_8.dll
[2010-08-11 15:46:34 | 000,261,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_7.dll
[2010-08-11 15:46:34 | 000,107,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_3.dll
[2010-08-11 15:46:34 | 000,081,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_3.dll
[2010-08-11 15:46:34 | 000,021,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_2.dll
[2010-08-11 15:46:34 | 000,017,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_2.dll
[2010-08-11 15:46:33 | 004,398,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_32.dll
[2010-08-11 15:46:33 | 003,977,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_31.dll
[2010-08-11 15:46:33 | 003,426,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_32.dll
[2010-08-11 15:46:33 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_31.dll
[2010-08-11 15:46:33 | 000,469,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10.dll
[2010-08-11 15:46:33 | 000,440,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10.dll
[2010-08-11 15:46:33 | 000,393,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_6.dll
[2010-08-11 15:46:33 | 000,390,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_5.dll
[2010-08-11 15:46:33 | 000,364,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_4.dll
[2010-08-11 15:46:33 | 000,363,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_3.dll
[2010-08-11 15:46:33 | 000,354,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_2.dll
[2010-08-11 15:46:33 | 000,352,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_1.dll
[2010-08-11 15:46:33 | 000,255,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_6.dll
[2010-08-11 15:46:33 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_5.dll
[2010-08-11 15:46:33 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_4.dll
[2010-08-11 15:46:33 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_3.dll
[2010-08-11 15:46:33 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_2.dll
[2010-08-11 15:46:33 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_1.dll
[2010-08-11 15:46:33 | 000,083,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_2.dll
[2010-08-11 15:46:33 | 000,083,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_1.dll
[2010-08-11 15:46:33 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_2.dll
[2010-08-11 15:46:33 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_1.dll
[2010-08-11 15:46:33 | 000,017,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_1.dll
[2010-08-11 15:46:33 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_1.dll
[2010-08-11 15:46:32 | 003,927,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_30.dll
[2010-08-11 15:46:32 | 003,830,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_29.dll
[2010-08-11 15:46:32 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_30.dll
[2010-08-11 15:46:32 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_29.dll
[2010-08-11 15:46:32 | 000,355,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_0.dll
[2010-08-11 15:46:32 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_0.dll
[2010-08-11 15:46:32 | 000,016,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_0.dll
[2010-08-11 15:46:32 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_0.dll
[2010-08-11 15:46:31 | 003,823,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_25.dll
[2010-08-11 15:46:31 | 003,815,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_28.dll
[2010-08-11 15:46:31 | 003,807,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_27.dll
[2010-08-11 15:46:31 | 003,767,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_26.dll
[2010-08-11 15:46:31 | 003,544,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_24.dll
[2010-08-11 15:46:31 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_25.dll
[2010-08-11 15:46:31 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_28.dll
[2010-08-11 15:46:31 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_27.dll
[2010-08-11 15:46:31 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_26.dll
[2010-08-11 15:46:31 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_24.dll
[2010-08-11 06:40:18 | 000,000,000 | —D | C] – C:\Windows\Panther
[2010-08-11 05:49:51 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2010-08-11 05:41:29 | 000,000,000 | —D | C] – C:\Windows\Prefetch
[2010-08-11 05:41:21 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2010-08-11 00:43:42 | 000,000,000 | —D | C] – C:\Users\Olof\Documents\Bluetooth
[2010-08-11 00:43:23 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\Toshiba
[2010-08-11 00:43:23 | 000,000,000 | —D | C] – C:\ProgramData\TOSHIBA
[2010-08-11 00:36:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\ASUS
[2010-08-11 00:33:46 | 000,000,000 | —D | C] – C:\Program\Intel
[2010-08-11 00:33:43 | 000,345,800 | R— | C] (Intel Corporation) – C:\Windows\SysNative\PROUnstl.exe
[2010-08-11 00:33:18 | 000,289,496 | —- | C] (Intel Corporation) – C:\Windows\SysNative\drivers\e1y62x64.sys
[2010-08-11 00:33:18 | 000,121,440 | —- | C] (Intel Corporation) – C:\Windows\SysNative\e1000msg.dll
[2010-08-11 00:33:18 | 000,036,472 | —- | C] (Intel Corporation) – C:\Windows\SysNative\NicCo36.dll
[2010-08-11 00:33:16 | 000,078,016 | —- | C] (Intel Corporation) – C:\Windows\SysNative\NicInstY.dll
[2010-08-11 00:31:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\NEC Electronics
[2010-08-11 00:31:35 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\Downloaded Installations
[2010-08-11 00:31:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Marvell
[2010-08-11 00:30:58 | 000,315,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Difx2b63.rra
[2010-08-11 00:30:58 | 000,000,000 | —D | C] – C:\RaidTool
[2010-08-11 00:30:56 | 000,115,824 | —- | C] (JMicron Technology Corp.) – C:\Windows\SysNative\drivers\jraid.sys
[2010-08-11 00:30:55 | 000,000,000 | —D | C] – C:\Windows\RaidTool
[2010-08-11 00:30:21 | 000,016,896 | —- | C] (ASUS) – C:\Windows\AsTaskSched.dll
[2010-08-11 00:30:10 | 000,000,000 | —D | C] – C:\Windows\SysWow64\RTCOM
[2010-08-11 00:30:10 | 000,000,000 | —D | C] – C:\Program\Realtek
[2010-08-11 00:30:04 | 002,719,504 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\WavesGUILib.dll
[2010-08-11 00:30:04 | 000,518,896 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSTSX64.dll
[2010-08-11 00:30:04 | 000,211,184 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSTSH64.dll
[2010-08-11 00:30:04 | 000,198,896 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSHP64.dll
[2010-08-11 00:30:04 | 000,155,888 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSWOW64.dll
[2010-08-11 00:30:03 | 001,814,560 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtPgEx64.dll
[2010-08-11 00:30:03 | 001,631,264 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkAPO64.dll
[2010-08-11 00:30:03 | 001,206,304 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RTCOM64.dll
[2010-08-11 00:30:03 | 000,477,216 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkApi64.dll
[2010-08-11 00:30:03 | 000,332,320 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtlCPAPI64.dll
[2010-08-11 00:30:03 | 000,149,536 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkCfg64.dll
[2010-08-11 00:30:02 | 000,612,384 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RTSnMg64.cpl
[2010-08-11 00:30:02 | 000,372,936 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEP64A.dll
[2010-08-11 00:30:02 | 000,307,920 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RP3DHT64.dll
[2010-08-11 00:30:02 | 000,307,920 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RP3DAA64.dll
[2010-08-11 00:30:02 | 000,201,928 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEED64A.dll
[2010-08-11 00:30:02 | 000,099,016 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEL64A.dll
[2010-08-11 00:30:02 | 000,076,488 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEG64A.dll
[2010-08-11 00:30:02 | 000,068,640 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RCoInst64.dll
[2010-08-11 00:30:01 | 002,197,264 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioEQ.dll
[2010-08-11 00:30:01 | 000,325,904 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioAPO20.dll
[2010-08-11 00:30:00 | 001,325,328 | —- | C] (DTS) – C:\Windows\SysNative\DTSS2SpeakerDLL64.dll
[2010-08-11 00:30:00 | 001,178,384 | —- | C] (DTS) – C:\Windows\SysNative\DTSS2HeadphoneDLL64.dll
[2010-08-11 00:30:00 | 001,110,800 | —- | C] (DTS) – C:\Windows\SysNative\DTSBoostDLL64.dll
[2010-08-11 00:30:00 | 000,504,592 | —- | C] (DTS) – C:\Windows\SysNative\DTSBassEnhancementDLL64.dll
[2010-08-11 00:30:00 | 000,474,896 | —- | C] (DTS) – C:\Windows\SysNative\DTSVoiceClarityDLL64.dll
[2010-08-11 00:30:00 | 000,321,440 | —- | C] (Fortemedia Corporation) – C:\Windows\SysNative\FMAPO64.dll
[2010-08-11 00:30:00 | 000,315,152 | —- | C] (DTS) – C:\Windows\SysNative\DTSNeoPCDLL64.dll
[2010-08-11 00:30:00 | 000,268,560 | —- | C] (DTS) – C:\Windows\SysNative\DTSLimiterDLL64.dll
[2010-08-11 00:30:00 | 000,265,488 | —- | C] (DTS) – C:\Windows\SysNative\DTSGainCompensatorDLL64.dll
[2010-08-11 00:30:00 | 000,168,288 | —- | C] (Andrea Electronics Corporation) – C:\Windows\SysNative\AERTAC64.dll
[2010-08-11 00:30:00 | 000,123,664 | —- | C] (DTS) – C:\Windows\SysNative\DTSLFXAPO64.dll
[2010-08-11 00:30:00 | 000,123,152 | —- | C] (DTS) – C:\Windows\SysNative\DTSGFXAPO64.dll
[2010-08-11 00:30:00 | 000,108,960 | —- | C] (Andrea Electronics Corporation) – C:\Windows\SysNative\AERTAR64.dll
[2010-08-11 00:30:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Realtek
[2010-08-11 00:29:59 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\InstallShield Installation Information
[2010-08-11 00:29:53 | 001,247,776 | R— | C] (Realtek Semiconductor Corp.) – C:\Windows\RtlExUpd.dll
[2010-08-11 00:29:53 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Temp
[2010-08-11 00:29:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InstallShield
[2010-08-11 00:29:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Intel
[2010-08-11 00:28:28 | 000,000,000 | —D | C] – C:\Intel
[2010-08-11 00:15:56 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\ATI
[2010-08-11 00:15:56 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\ATI
[2010-08-11 00:14:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\ATI Technologies
[2010-08-11 00:14:20 | 000,000,000 | -HSD | C] – C:\Windows\Installer
[2010-08-11 00:14:20 | 000,000,000 | —D | C] – C:\Program\ATI
[2010-08-11 00:13:17 | 000,000,000 | —D | C] – C:\Program\ATI Technologies
[2010-08-11 00:12:35 | 000,000,000 | —D | C] – C:\ATI
[2010-08-11 00:08:56 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\Apps
[2010-08-10 23:51:21 | 000,000,000 | R–D | C] – C:\Users\Olof\Searches
[2010-08-10 23:51:16 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\Identities
[2010-08-10 23:51:15 | 000,000,000 | R–D | C] – C:\Users\Olof\Contacts
[2010-08-10 23:51:14 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\VirtualStore
[2010-08-10 23:51:12 | 000,000,000 | –SD | C] – C:\Users\Olof\AppData\Roaming\Microsoft
[2010-08-10 23:51:12 | 000,000,000 | R–D | C] – C:\Users\Olof\Videos
[2010-08-10 23:51:12 | 000,000,000 | R–D | C] – C:\Users\Olof\Saved Games
[2010-08-10 23:51:12 | 000,000,000 | R–D | C] – C:\Users\Olof\Pictures
[2010-08-10 23:51:12 | 000,000,000 | R–D | C] – C:\Users\Olof\Music
[2010-08-10 23:51:12 | 000,000,000 | R–D | C] – C:\Users\Olof\Links
[2010-08-10 23:51:12 | 000,000,000 | R–D | C] – C:\Users\Olof\Favorites
[2010-08-10 23:51:12 | 000,000,000 | R–D | C] – C:\Users\Olof\Downloads
[2010-08-10 23:51:12 | 000,000,000 | R–D | C] – C:\Users\Olof\Documents
[2010-08-10 23:51:12 | 000,000,000 | R–D | C] – C:\Users\Olof\Desktop
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\AppData\Local\Tidigare
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\AppData\Local\Temporary Internet Files
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Start-meny
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Skrivare
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\SendTo
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Recent
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Programdata
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\AppData\Local\Programdata
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Nätverket
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Documents\Mina videoklipp
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Mina dokument
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Documents\Mina bilder
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Documents\Min musik
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Mallar
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Lokala inställningar
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Cookies
[2010-08-10 23:51:12 | 000,000,000 | -H-D | C] – C:\Users\Olof\AppData
[2010-08-10 23:51:12 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\Temp
[2010-08-10 23:51:12 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\Microsoft
[2010-08-10 23:51:12 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\Media Center Programs
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\ProgramData\Start-meny
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\ProgramData\Skrivbord
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\Recovery
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\ProgramData\Programdata
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\Program
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\Users\Public\Documents\Mina videoklipp
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\Users\Public\Documents\Mina bilder
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\Users\Public\Documents\Min musik
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\ProgramData\Mallar
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\ProgramData\Favoriter
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\ProgramData\Dokument
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\Program\Delade filer

========== Files - Modified Within 30 Days ==========

[2010-09-09 20:22:34 | 005,505,024 | -HS- | M] () – C:\Users\Olof\NTUSER.DAT
[2010-09-09 20:08:16 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Olof\Desktop\OTL.exe
[2010-09-09 19:54:02 | 000,001,808 | —- | M] () – C:\Users\Olof\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010-09-09 19:23:17 | 000,015,024 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010-09-09 19:23:17 | 000,015,024 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010-09-09 19:21:25 | 000,000,751 | —- | M] () – C:\Users\Public\Desktop\World of Warcraft.lnk
[2010-09-09 19:20:25 | 001,442,452 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010-09-09 19:20:25 | 000,617,232 | —- | M] () – C:\Windows\SysNative\perfh01D.dat
[2010-09-09 19:20:25 | 000,606,992 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010-09-09 19:20:25 | 000,120,596 | —- | M] () – C:\Windows\SysNative\perfc01D.dat
[2010-09-09 19:20:25 | 000,103,370 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010-09-09 19:16:10 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010-09-09 19:16:03 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010-09-09 19:16:01 | 529,879,039 | -HS- | M] () – C:\hiberfil.sys
[2010-09-09 19:15:00 | 005,204,454 | -H– | M] () – C:\Users\Olof\AppData\Local\IconCache.db
[2010-09-09 17:21:48 | 064,468,357 | —- | M] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010-09-08 17:28:51 | 000,004,813 | —- | M] () – C:\Users\Olof\Desktop\lösenord_2.odt
[2010-09-08 16:33:43 | 000,000,975 | —- | M] () – C:\Users\Public\Desktop\Mumble.lnk
[2010-09-07 22:42:41 | 000,001,063 | —- | M] () – C:\Users\Olof\Desktop\Click-N-Type Keyboard.lnk
[2010-09-07 19:32:59 | 000,005,080 | —- | M] () – C:\Users\Olof\Documents\cc_20100907_193254.reg
[2010-09-07 18:28:38 | 000,000,042 | —- | M] () – C:\Windows\SysWow64\scud.udf
[2010-09-07 18:28:00 | 000,417,891 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2010-09-07 18:02:07 | 000,417,891 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts.20100907-182800.backup
[2010-09-06 22:15:09 | 000,013,169 | —- | M] () – C:\Users\Olof\Desktop\lösenord.odt
[2010-09-06 20:45:40 | 000,002,292 | —- | M] () – C:\Users\Olof\Documents\cc_20100906_204534.reg
[2010-09-06 18:05:47 | 000,001,148 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2010-09-05 12:18:22 | 077,752,952 | —- | M] (Advanced Micro Devices, Inc.) – C:\Users\Olof\Desktop\10-8_vista64_win7_64_dd_ccc_enu.exe
[2010-09-05 12:14:08 | 000,000,235 | —- | M] () – C:\Users\Olof\Desktop\Options.ini
[2010-09-05 12:13:40 | 000,001,300 | —- | M] () – C:\Users\Olof\Documents\cc_20100905_121337.reg
[2010-09-05 12:13:00 | 000,001,003 | —- | M] () – C:\Users\Olof\Desktop\CCleaner.lnk
[2010-08-24 09:14:30 | 000,000,846 | —- | M] () – C:\Users\Olof\Documents\cc_20100824_091426.reg
[2010-08-18 21:34:32 | 000,011,461 | —- | M] () – C:\Users\Olof\Desktop\Träningskalender.ods
[2010-08-15 20:00:50 | 000,000,045 | —- | M] () – C:\Windows\SysWow64\initdebug.nfo
[2010-08-14 16:33:49 | 000,007,598 | —- | M] () – C:\Users\Olof\AppData\Local\Resmon.ResmonCfg
[2010-08-14 13:00:12 | 000,004,032 | —- | M] () – C:\Users\Olof\Documents\cc_20100814_130000.reg
[2010-08-14 12:59:48 | 000,008,186 | —- | M] () – C:\Users\Olof\Documents\cc_20100814_125933.reg
[2010-08-14 12:03:52 | 000,001,178 | —- | M] () – C:\Users\Olof\Desktop\prime95 - genväg.lnk
[2010-08-14 10:34:35 | 000,289,608 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010-08-14 02:14:07 | 000,062,952 | —- | M] () – C:\Users\Olof\AppData\Local\GDIPFONTCACHEV1.DAT
[2010-08-14 01:08:02 | 000,001,195 | —- | M] () – C:\Users\Olof\Desktop\RealTemp - genväg.lnk
[2010-08-12 17:43:14 | 000,000,000 | —- | M] () – C:\Users\Olof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip
[2010-08-12 17:09:14 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010-08-12 14:15:20 | 000,015,880 | —- | M] () – C:\Windows\SysNative\lsdelete.exe
[2010-08-11 23:17:43 | 000,002,376 | —- | M] () – C:\Users\Olof\Documents\MumbleAutomaticCertificateBackup.p12
[2010-08-11 16:08:52 | 000,013,048 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\avgrssta.dll
[2010-08-11 16:08:51 | 000,317,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgtdia.sys
[2010-08-11 16:08:48 | 000,269,904 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgldx64.sys
[2010-08-11 16:08:48 | 000,035,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgmfx64.sys
[2010-08-11 16:08:47 | 000,113,461 | —- | M] () – C:\Windows\SysNative\drivers\Avg\iavichjw.avm
[2010-08-11 15:45:18 | 000,001,769 | —- | M] () – C:\Windows\Language_trs.ini
[2010-08-11 15:44:59 | 000,034,135 | —- | M] () – C:\Windows\Ascd_tmp.ini
[2010-08-11 05:43:22 | 000,046,520 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2010-08-11 05:43:22 | 000,046,520 | —- | M] () – C:\Windows\SysNative\license.rtf
[2010-08-11 00:30:21 | 000,016,896 | —- | M] (ASUS) – C:\Windows\AsTaskSched.dll
[2010-08-11 00:15:42 | 000,000,000 | —- | M] () – C:\Windows\ativpsrm.bin
[2010-08-10 23:56:55 | 000,524,288 | -HS- | M] () – C:\Users\Olof\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010-08-10 23:56:55 | 000,524,288 | -HS- | M] () – C:\Users\Olof\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010-08-10 23:56:55 | 000,065,536 | -HS- | M] () – C:\Users\Olof\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010-08-10 23:51:12 | 000,000,020 | -HS- | M] () – C:\Users\Olof\ntuser.ini

========== Files Created - No Company Name ==========

[2010-09-09 19:54:02 | 000,001,808 | —- | C] () – C:\Users\Olof\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010-09-08 17:28:51 | 000,004,813 | —- | C] () – C:\Users\Olof\Desktop\lösenord_2.odt
[2010-09-08 16:33:43 | 000,000,975 | —- | C] () – C:\Users\Public\Desktop\Mumble.lnk
[2010-09-07 22:42:41 | 000,001,063 | —- | C] () – C:\Users\Olof\Desktop\Click-N-Type Keyboard.lnk
[2010-09-07 19:32:57 | 000,005,080 | —- | C] () – C:\Users\Olof\Documents\cc_20100907_193254.reg
[2010-09-07 18:28:38 | 000,000,042 | —- | C] () – C:\Windows\SysWow64\scud.udf
[2010-09-06 20:45:38 | 000,002,292 | —- | C] () – C:\Users\Olof\Documents\cc_20100906_204534.reg
[2010-09-06 19:32:31 | 000,015,880 | —- | C] () – C:\Windows\SysNative\lsdelete.exe
[2010-09-06 18:05:47 | 000,001,148 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2010-09-05 12:13:38 | 000,001,300 | —- | C] () – C:\Users\Olof\Documents\cc_20100905_121337.reg
[2010-08-24 09:14:28 | 000,000,846 | —- | C] () – C:\Users\Olof\Documents\cc_20100824_091426.reg
[2010-08-18 21:34:30 | 000,011,461 | —- | C] () – C:\Users\Olof\Desktop\Träningskalender.ods
[2010-08-15 20:00:50 | 000,000,045 | —- | C] () – C:\Windows\SysWow64\initdebug.nfo
[2010-08-15 10:08:31 | 000,023,906 | —- | C] () – C:\Users\Olof\Desktop\Allmänna tips_instruktioner.odt
[2010-08-14 13:00:02 | 000,004,032 | —- | C] () – C:\Users\Olof\Documents\cc_20100814_130000.reg
[2010-08-14 12:59:45 | 000,008,186 | —- | C] () – C:\Users\Olof\Documents\cc_20100814_125933.reg
[2010-08-14 12:03:52 | 000,001,178 | —- | C] () – C:\Users\Olof\Desktop\prime95 - genväg.lnk
[2010-08-14 11:14:15 | 000,000,235 | —- | C] () – C:\Users\Olof\Desktop\Options.ini
[2010-08-14 11:13:36 | 004,960,446 | —- | C] () – C:\Users\Olof\Desktop\WarriorDPS2.602Excel07_Oruk.xlsm
[2010-08-14 11:13:26 | 000,009,323 | —- | C] () – C:\Users\Olof\Desktop\Utgiftslogg.xlsx
[2010-08-14 11:13:15 | 000,022,528 | —- | C] () – C:\Users\Olof\Desktop\Utgifter Ö-vik.xls
[2010-08-14 11:13:07 | 000,009,264 | —- | C] () – C:\Users\Olof\Desktop\MC-logg.xlsx
[2010-08-14 11:12:50 | 000,013,169 | —- | C] () – C:\Users\Olof\Desktop\lösenord.odt
[2010-08-14 11:12:36 | 000,014,848 | —- | C] () – C:\Users\Olof\Desktop\Fridas Bank.xls
[2010-08-14 11:12:18 | 002,549,270 | —- | C] () – C:\Users\Olof\Desktop\familjen.odt
[2010-08-14 11:12:12 | 000,019,456 | —- | C] () – C:\Users\Olof\Desktop\Aktier.xls
[2010-08-14 01:08:02 | 000,001,195 | —- | C] () – C:\Users\Olof\Desktop\RealTemp - genväg.lnk
[2010-08-12 17:43:14 | 000,000,000 | —- | C] () – C:\Users\Olof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip
[2010-08-12 17:09:14 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010-08-11 23:17:43 | 000,002,376 | —- | C] () – C:\Users\Olof\Documents\MumbleAutomaticCertificateBackup.p12
[2010-08-11 22:42:01 | 000,001,003 | —- | C] () – C:\Users\Olof\Desktop\CCleaner.lnk
[2010-08-11 21:45:33 | 000,000,751 | —- | C] () – C:\Users\Public\Desktop\World of Warcraft.lnk
[2010-08-11 16:08:47 | 064,468,357 | —- | C] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010-08-11 16:08:47 | 000,113,461 | —- | C] () – C:\Windows\SysNative\drivers\Avg\iavichjw.avm
[2010-08-11 05:41:21 | 529,879,039 | -HS- | C] () – C:\hiberfil.sys
[2010-08-11 00:36:40 | 000,024,576 | R— | C] () – C:\Windows\SysWow64\AsIO.dll
[2010-08-11 00:36:40 | 000,013,440 | R— | C] () – C:\Windows\SysWow64\drivers\AsIO.sys
[2010-08-11 00:36:37 | 000,011,832 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2010-08-11 00:36:37 | 000,010,216 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2010-08-11 00:33:43 | 000,001,904 | —- | C] () – C:\Windows\SysNative\SetupBD.din
[2010-08-11 00:33:18 | 000,003,315 | —- | C] () – C:\Windows\SysNative\e1y62x64.din
[2010-08-11 00:28:08 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2010-08-11 00:28:06 | 000,034,135 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2010-08-11 00:27:00 | 000,007,598 | —- | C] () – C:\Users\Olof\AppData\Local\Resmon.ResmonCfg
[2010-08-11 00:15:42 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010-08-10 23:51:12 | 005,505,024 | -HS- | C] () – C:\Users\Olof\NTUSER.DAT
[2010-08-10 23:51:12 | 000,524,288 | -HS- | C] () – C:\Users\Olof\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010-08-10 23:51:12 | 000,524,288 | -HS- | C] () – C:\Users\Olof\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010-08-10 23:51:12 | 000,262,144 | -HS- | C] () – C:\Users\Olof\ntuser.dat.LOG1
[2010-08-10 23:51:12 | 000,065,536 | -HS- | C] () – C:\Users\Olof\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010-08-10 23:51:12 | 000,000,020 | -HS- | C] () – C:\Users\Olof\ntuser.ini
[2010-08-10 23:51:12 | 000,000,000 | -HS- | C] () – C:\Users\Olof\ntuser.dat.LOG2
[2009-07-14 01:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009-07-13 23:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009-04-02 14:30:14 | 000,010,296 | —- | C] () – C:\Windows\SysWow64\drivers\ASUSHWIO.SYS
[2008-02-05 13:28:20 | 000,000,051 | —- | C] () – C:\Users\Olof\AppData\Local\setup.txt

OTL Extras logfile created on: 2010-09-09 20:22:18 - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Olof\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 0000041d | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

6,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 57,00% Memory free
15,00 Gb Paging File | 12,00 Gb Available in Paging File | 82,00% Paging File free
Paging file location(s): e:\pagefile.sys 9202 9202 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 119,14 Gb Total Space | 81,97 Gb Free Space | 68,80% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 698,63 Gb Total Space | 643,79 Gb Free Space | 92,15% Space Free | Partition Type: NTFS
Drive F: | 465,65 Gb Total Space | 355,93 Gb Free Space | 76,44% Space Free | Partition Type: FAT32
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OLOF-PC
Current User Name: Olof
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-286741208-470331320-231057659-1000\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8882ED04-FE2B-478C-AF10-E7BE2A3C7AD4}" = Intel® Network Connections [removed]
"{897BE4A7-682B-7375-BBAF-05A44FC2B524}" = ATI Catalyst Install Manager
"{914C25C6-603C-16C9-BE33-8A09E5632350}" = ccc-utility64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"24DA573F901348FFDFF7717497830D45BE0C362E" = Windows Driver Package - Dynastream Innovations (libusb0) LibUsbDevices (07/07/2009 1.12.2)
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"PROSetDX" = Intel® Network Connections 15.0.4.0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0E93710D-31E5-477C-8A4B-5032B484BE74}" = Windows Live inloggningsassistenten
"{12444FB2-997D-7BB2-0CEB-453E31307929}" = ccc-core-static
"{12CEE8C7-8983-4FEC-A046-3FB4AE3A691C}" = Windows Live Sync
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 21
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{30C4509E-2124-4743-83E8-2EDCBD39D3F7}" = Windows Live Photo Gallery
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMicron JMB36X Driver
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{510D2239-6C2E-457B-9590-485EC552D94D}" = Garmin USB Drivers
"{51399947-35EF-10B8-FC7F-0D435C701A2D}" = Catalyst Control Center InstallProxy
"{707790EF-9E51-1548-F90C-57B38065F38C}" = Catalyst Control Center Graphics Previews Vista
"{7B5999EE-F2DD-4677-675D-51F11C6F6181}" = Catalyst Control Center Graphics Previews Common
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{9BBE7AA1-AFA8-4D76-8FC2-1FDFD9BD3371}" = Windows Live Mail
"{9D71329D-95A5-4297-8F79-DCDBD156420A}" = Windows Live Essentials
"{AC76BA86-7AD7-1053-7B44-A93000000001}" = Adobe Reader 9.3.4 - Svenska
"{AE096DBF-8878-6943-3858-7EE9D54D70B7}" = CCC Help English
"{C2CE8D52-BD18-4D4B-A3B0-4FDFD7CCC34F}" = Garmin ANT Agent
"{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
"{DDA34038-89BD-4804-B0B8-DC48D5DFB463}" = Catalyst Control Center - Branding
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{ED8CCEA2-D5FB-498B-9F44-8FBBA07047AF}" = Click-N-Type
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F13225E2-6533-4923-A657-083A151E667E}" = Windows Live Messenger
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F7338FA3-DAB5-49B2-900D-0AFB5760C166}" = PC Probe II
"{FF4E9560-6A50-478B-86D5-68D7DEFF10D1}" = Windows Live Movie Maker
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AVG9Uninstall" = AVG Free 9.0
"CCleaner" = CCleaner
"InstallShield_{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
"MagniDriver" = marvell 91xx driver
"Mozilla Firefox (3.6.9)" = Mozilla Firefox (3.6.9)
"Mumble" = Mumble and Murmur
"WinLiveSuite_Wave3" = Windows Live Essentials
"World of Warcraft" = World of Warcraft

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2010-08-31 13:11:26 | Computer Name = OLOF-PC | Source = SideBySide | ID = 16842787
Description = Det gick inte att skapa aktiveringskontext för c:\program files (x86)\windows
live\photo gallery\MovieMaker.Exe. Det finns ett fel i manifest- eller principfilen
c:\program files (x86)\windows live\photo gallery\WLMFDS.DLL på rad 8. Den komponentidentitet
som hittades i manifestet matchar inte identiteten i den komponent som begärdes.
Referens
är WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
är WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Använd sxstrace.exe
om du vill diagnostisera ytterligare.

Error - 2010-09-02 12:35:08 | Computer Name = OLOF-PC | Source = SideBySide | ID = 16842787
Description = Det gick inte att skapa aktiveringskontext för c:\program files (x86)\windows
live\photo gallery\MovieMaker.Exe. Det finns ett fel i manifest- eller principfilen
c:\program files (x86)\windows live\photo gallery\WLMFDS.DLL på rad 8. Den komponentidentitet
som hittades i manifestet matchar inte identiteten i den komponent som begärdes.
Referens
är WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
är WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Använd sxstrace.exe
om du vill diagnostisera ytterligare.

Error - 2010-09-05 07:32:47 | Computer Name = OLOF-PC | Source = SideBySide | ID = 16842787
Description = Det gick inte att skapa aktiveringskontext för c:\program files (x86)\windows
live\photo gallery\MovieMaker.Exe. Det finns ett fel i manifest- eller principfilen
c:\program files (x86)\windows live\photo gallery\WLMFDS.DLL på rad 8. Den komponentidentitet
som hittades i manifestet matchar inte identiteten i den komponent som begärdes.
Referens
är WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
är WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Använd sxstrace.exe
om du vill diagnostisera ytterligare.

Error - 2010-09-06 11:20:29 | Computer Name = OLOF-PC | Source = MsiInstaller | ID = 11935
Description =

Error - 2010-09-06 11:23:20 | Computer Name = OLOF-PC | Source = Lavasoft Ad-Aware Service | ID = 0
Description =

Error - 2010-09-06 11:30:36 | Computer Name = OLOF-PC | Source = Application Hang | ID = 1002
Description = Programmet Ad-AwareAdmin.exe, version 8.0.0.0, avslutades eftersom
det slutade att samverka med Windows. Ytterligare information kan finnas i problemhistoriken
på kontrollpanelen för Åtgärdscentret och lösningar. Process-ID: 1788 Starttid: 01cb4dd76fead8bd

Avslutningstid:
46 Programsökväg: E:\Mina Dokument\Program\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Rapport-ID:


Error - 2010-09-06 11:32:19 | Computer Name = OLOF-PC | Source = Application Hang | ID = 1002
Description = Programmet Ad-AwareAdmin.exe, version 8.0.0.0, avslutades eftersom
det slutade att samverka med Windows. Ytterligare information kan finnas i problemhistoriken
på kontrollpanelen för Åtgärdscentret och lösningar. Process-ID: 1594 Starttid: 01cb4dd88cfa9f38

Avslutningstid:
0 Programsökväg: E:\Mina Dokument\Program\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Rapport-ID:


Error - 2010-09-06 12:05:54 | Computer Name = OLOF-PC | Source = Lavasoft Ad-Aware Service | ID = 0
Description =

Error - 2010-09-06 15:39:49 | Computer Name = OLOF-PC | Source = MsiInstaller | ID = 10005
Description =

Error - 2010-09-08 12:08:49 | Computer Name = OLOF-PC | Source = SideBySide | ID = 16842787
Description = Det gick inte att skapa aktiveringskontext för c:\program files (x86)\windows
live\photo gallery\MovieMaker.Exe. Det finns ett fel i manifest- eller principfilen
c:\program files (x86)\windows live\photo gallery\WLMFDS.DLL på rad 8. Den komponentidentitet
som hittades i manifestet matchar inte identiteten i den komponent som begärdes.
Referens
är WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
är WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Använd sxstrace.exe
om du vill diagnostisera ytterligare.

[ System Events ]
Error - 2010-09-08 01:17:19 | Computer Name = OLOF-PC | Source = Service Control Manager | ID = 7000
Description = Tjänsten SAS Core Service kunde inte startas på grund av följande
fel: %%2

Error - 2010-09-08 09:57:59 | Computer Name = OLOF-PC | Source = Service Control Manager | ID = 7000
Description = Tjänsten SAS Core Service kunde inte startas på grund av följande
fel: %%2

Error - 2010-09-08 10:17:14 | Computer Name = OLOF-PC | Source = Service Control Manager | ID = 7031
Description = Tjänsten Windows Media Player Network Sharing Service avslutades oväntat.
Den har gjort detta 1 gång(er). Följande åtgärd kommer att utföras om 30000 millisekunder:
Starta om tjänsten.

Error - 2010-09-08 11:16:24 | Computer Name = OLOF-PC | Source = Service Control Manager | ID = 7000
Description = Tjänsten SAS Core Service kunde inte startas på grund av följande
fel: %%2

Error - 2010-09-08 13:41:38 | Computer Name = OLOF-PC | Source = Service Control Manager | ID = 7000
Description = Tjänsten SAS Core Service kunde inte startas på grund av följande
fel: %%2

Error - 2010-09-09 11:15:56 | Computer Name = OLOF-PC | Source = Service Control Manager | ID = 7000
Description = Tjänsten SAS Core Service kunde inte startas på grund av följande
fel: %%2

Error - 2010-09-09 12:55:42 | Computer Name = OLOF-PC | Source = Service Control Manager | ID = 7000
Description = Tjänsten SAS Core Service kunde inte startas på grund av följande
fel: %%2

Error - 2010-09-09 13:06:59 | Computer Name = OLOF-PC | Source = Disk | ID = 262155
Description = Drivrutinen hittade ett styrenhetsfel på \Device\Harddisk2\DR2.

Error - 2010-09-09 13:07:00 | Computer Name = OLOF-PC | Source = Disk | ID = 262155
Description = Drivrutinen hittade ett styrenhetsfel på \Device\Harddisk2\DR2.

Error - 2010-09-09 13:16:10 | Computer Name = OLOF-PC | Source = Service Control Manager | ID = 7000
Description = Tjänsten SAS Core Service kunde inte startas på grund av följande
fel: %%2


< End of report >

Attachments:

Sorted that with the locked folders: Obviously they are just bad links in w7. My Bad. Anyway here is the log for Ad-Aware: MSG [2036] 2010/09/06 18:22:18: Configure new scan with profile: full MSG [2036] 2010/09/06 18:22:19: -> scanning critical objects MSG [2036] 2010/09/06 18:22:19: -> scanning running processes MSG [2036] 2010/09/06 18:22:19: -> scanning registry MSG [2036] 2010/09/06 18:22:19: -> scanning lsp MSG [2036] 2010/09/06 18:22:19: -> scanning ads MSG [2036] 2010/09/06 18:22:19: -> scanning hosts file MSG [2036] 2010/09/06 18:22:19: -> scanning mru objects MSG [2036] 2010/09/06 18:22:19: -> scanning browser hijacks MSG [2036] 2010/09/06 18:22:19: -> scanning cookies MSG [2036] 2010/09/06 18:22:19: -> neutralizing rootkits MSG [2036] 2010/09/06 18:22:19: -> use mild rootkit detection MSG [2036] 2010/09/06 18:22:19: -> use spyware heuristics MSG [2036] 2010/09/06 18:22:19: -> use medium heuristics MSG [2036] 2010/09/06 18:22:19: -> scan archives MSG [2036] 2010/09/06 18:22:19: -> file size limit = 20480 kB (0 = unlimited) MSG [2036] 2010/09/06 18:22:19: -> scan file/path = C:\ MSG [2036] 2010/09/06 18:22:19: -> scan file/path = E:\ MSG [2036] 2010/09/06 18:22:19: -> scan file/path = F:\ ERR [2036] 2010/09/06 18:22:19: SDKController::GetInfectionList -> Not in found infections state MSG [2720] 2010/09/06 19:32:29: Scan was completed in 4210 seconds MSG [2720] 2010/09/06 19:32:29: Objects processed: 148370, infections detected: 20 MSG [4904] 2010/09/06 19:32:30: Remediating 20 infections MSG [4904] 2010/09/06 19:32:31: Clean failed for: *adserv* MSG [4904] 2010/09/06 19:32:31: Clean failed for: *adtech* MSG [4904] 2010/09/06 19:32:31: Clean failed for: *adserve* MSG [4904] 2010/09/06 19:32:31: Clean failed for: *atdmt* MSG [4904] 2010/09/06 19:32:31: Clean failed for: *bs.serving-sys* MSG [4904] 2010/09/06 19:32:31: Clean failed for: *serving-sys* MSG [4904] 2010/09/06 19:32:31: Clean failed for: *doubleclick* MSG [4904] 2010/09/06 19:32:31: Clean failed for: *.adform* MSG [4904] 2010/09/06 19:32:31: Infections quarantined: 2, removed: 18, repaired: 0 MSG [4904] 2010/09/06 19:32:31: Infections ignored by remediation: 0 (0 whitelisted, 0 skipped). MSG [2036] 2010/09/06 19:32:31: Dumping scan report: >>> Logfile created: 2010-09-06 18:22:19 >>> Ad-Aware version: 8.3.2 >>> Extended engine: 3 >>> Extended engine version: 3.1.2770 >>> User performing scan: Olof >>> >>> *********************** Definitions database information *********************** >>> Lavasoft definition file: 150.75 >>> Genotype definition file version: 2010/08/31 14:13:17 >>> Extended engine definition file: 6838.0 >>> >>> ******************************** Scan results: ********************************* >>> Scan profile name: Komplett genomsökning (ID: full) >>> Objects scanned: 148370 >>> Objects detected: 20 >>> >>> >>> Type Detected >>> ========================== >>> Processes…….: 0 >>> Registry entries: 0 >>> Hostfile entries: 0 >>> Files………..: 2 >>> Folders………: 0 >>> LSPs…………: 0 >>> Cookies………: 18 >>> Browser hijacks.: 0 >>> MRU objects…..: 0 >>> >>> >>> >>> Removed items: >>> Description: *adserver* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 408737 Family ID: 0 >>> Description: *adserv* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 408921 Family ID: 0 >>> Description: *adtech* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 409018 Family ID: 0 >>> Description: *adserve* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 409020 Family ID: 0 >>> Description: *atdmt* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 408910 Family ID: 0 >>> Description: *bs.serving-sys* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 408902 Family ID: 0 >>> Description: *serving-sys* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 409130 Family ID: 0 >>> Description: *doubleclick* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 408875 Family ID: 0 >>> Description: *.adform* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 409300 Family ID: 0 >>> Description: *adserver* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 408737 Family ID: 0 >>> Description: *adserv* Family Name: Cookies Engine: 1 Clean status: Failed Item ID: 408921 Family ID: 0 >>> Description: *adtech* Family Name: Cookies Engine: 1 Clean status: Failed Item ID: 409018 Family ID: 0 >>> Description: *adserve* Family Name: Cookies Engine: 1 Clean status: Failed Item ID: 409020 Family ID: 0 >>> Description: *atdmt* Family Name: Cookies Engine: 1 Clean status: Failed Item ID: 408910 Family ID: 0 >>> Description: *bs.serving-sys* Family Name: Cookies Engine: 1 Clean status: Failed Item ID: 408902 Family ID: 0 >>> Description: *serving-sys* Family Name: Cookies Engine: 1 Clean status: Failed Item ID: 409130 Family ID: 0 >>> Description: *doubleclick* Family Name: Cookies Engine: 1 Clean status: Failed Item ID: 408875 Family ID: 0 >>> Description: *.adform* Family Name: Cookies Engine: 1 Clean status: Failed Item ID: 409300 Family ID: 0 >>> >>> Quarantined items: >>> Description: f:\frida\running in your vains.au Family Name: Trojan.ASF.Wimad (v) Engine: 3 Clean status: Success Item ID: 1 Family ID: 0 MD5: 67c73314ff22d67fe772b06819216f61 >>> Description: f:\frida\spara , till hårddisken2\min musik\running in your vains.au Family Name: Trojan.ASF.Wimad (v) Engine: 3 Clean status: Success Item ID: 1 Family ID: 0 MD5: 67c73314ff22d67fe772b06819216f61 >>> >>> Scan and cleaning complete: Finished correctly after 4210 seconds >>> >>> *********************************** Settings *********************************** >>> >>> Scan profile: >>> ID: full, enabled:1, value: Komplett genomsökning >>> ID: folderstoscan, enabled:1, value: C:\,E:\,F:\ >>> ID: useantivirus, enabled:1, value: true >>> ID: sections, enabled:1 >>> ID: scancriticalareas, enabled:1, value: true >>> ID: scanrunningapps, enabled:1, value: true >>> ID: scanregistry, enabled:1, value: true >>> ID: scanlsp, enabled:1, value: true >>> ID: scanads, enabled:1, value: true >>> ID: scanhostsfile, enabled:1, value: true >>> ID: scanmru, enabled:1, value: true >>> ID: scanbrowserhijacks, enabled:1, value: true >>> ID: scantrackingcookies, enabled:1, value: true >>> ID: closebrowsers, enabled:1, value: false >>> ID: filescanningoptions, enabled:1 >>> ID: archives, enabled:1, value: true >>> ID: onlyexecutables, enabled:1, value: false >>> ID: skiplargerthan, enabled:1, value: 20480 >>> ID: scanrootkits, enabled:1, value: true >>> ID: rootkitlevel, enabled:1, value: mild, domain: medium,mild,strict >>> ID: usespywareheuristics, enabled:1, value: true >>> >>> Scan global: >>> ID: global, enabled:1 >>> ID: addtocontextmenu, enabled:1, value: true >>> ID: playsoundoninfection, enabled:1, value: false >>> ID: soundfile, enabled:0, value: N/A >>> >>> Scheduled scan settings: >>> >>> >>> Update settings: >>> ID: updates, enabled:1 >>> ID: launchthreatworksafterscan, enabled:1, value: off, domain: normal,off,silently >>> ID: deffiles, enabled:1, value: downloadandinstall, domain: dontcheck,downloadandinstall >>> ID: licenseandinfo, enabled:1, value: downloadandinstall, domain: dontcheck,downloadandinstall >>> ID: schedules, enabled:1, value: true >>> ID: updatedaily1, enabled:1, value: Daily 1 >>> ID: time, enabled:1, value: Mon Sep 06 18:21:00 2010 >>> ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systemstart,weekly >>> ID: weekdays, enabled:1 >>> ID: monday, enabled:1, value: false >>> ID: tuesday, enabled:1, value: false >>> ID: wednesday, enabled:1, value: false >>> ID: thursday, enabled:1, value: false >>> ID: friday, enabled:1, value: false >>> ID: saturday, enabled:1, value: false >>> ID: sunday, enabled:1, value: false >>> ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 >>> ID: scanprofile, enabled:1, value: >>> ID: auto_deal_with_infections, enabled:1, value: false >>> ID: updatedaily2, enabled:1, value: Daily 2 >>> ID: time, enabled:1, value: Mon Sep 06 00:21:00 2010 >>> ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systemstart,weekly >>> ID: weekdays, enabled:1 >>> ID: monday, enabled:1, value: false >>> ID: tuesday, enabled:1, value: false >>> ID: wednesday, enabled:1, value: false >>> ID: thursday, enabled:1, value: false >>> ID: friday, enabled:1, value: false >>> ID: saturday, enabled:1, value: false >>> ID: sunday, enabled:1, value: false >>> ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 >>> ID: scanprofile, enabled:1, value: >>> ID: auto_deal_with_infections, enabled:1, value: false >>> ID: updatedaily3, enabled:1, value: Daily 3 >>> ID: time, enabled:1, value: Mon Sep 06 06:21:00 2010 >>> ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systemstart,weekly >>> ID: weekdays, enabled:1 >>> ID: monday, enabled:1, value: false >>> ID: tuesday, enabled:1, value: false >>> ID: wednesday, enabled:1, value: false >>> ID: thursday, enabled:1, value: false >>> ID: friday, enabled:1, value: false >>> ID: saturday, enabled:1, value: false >>> ID: sunday, enabled:1, value: false >>> ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 >>> ID: scanprofile, enabled:1, value: >>> ID: auto_deal_with_infections, enabled:1, value: false >>> ID: updatedaily4, enabled:1, value: Daily 4 >>> ID: time, enabled:1, value: Mon Sep 06 12:21:00 2010 >>> ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systemstart,weekly >>> ID: weekdays, enabled:1 >>> ID: monday, enabled:1, value: false >>> ID: tuesday, enabled:1, value: false >>> ID: wednesday, enabled:1, value: false >>> ID: thursday, enabled:1, value: false >>> ID: friday, enabled:1, value: false >>> ID: saturday, enabled:1, value: false >>> ID: sunday, enabled:1, value: false >>> ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 >>> ID: scanprofile, enabled:1, value: >>> ID: auto_deal_with_infections, enabled:1, value: false >>> ID: updateweekly1, enabled:1, value: Weekly >>> ID: time, enabled:1, value: Mon Sep 06 18:21:00 2010 >>> ID: frequency, enabled:1, value: weekly, domain: daily,monthly,once,systemstart,weekly >>> ID: weekdays, enabled:1 >>> ID: monday, enabled:1, value: true >>> ID: tuesday, enabled:1, value: false >>> ID: wednesday, enabled:1, value: false >>> ID: thursday, enabled:1, value: true >>> ID: friday, enabled:1, value: false >>> ID: saturday, enabled:1, value: false >>> ID: sunday, enabled:1, value: false >>> ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 >>> ID: scanprofile, enabled:1, value: >>> ID: auto_deal_with_infections, enabled:1, value: false >>> >>> Appearance settings: >>> ID: appearance, enabled:1 >>> ID: skin, enabled:1, value: default.egl, reglocation: HKEY_LOCAL_MACHINE\SOFTWARE\Lavasoft\Ad-Aware\Resource >>> ID: showtrayicon, enabled:1, value: true >>> ID: autoentertainmentmode, enabled:1, value: true >>> ID: guimode, enabled:1, value: mode_simple, domain: mode_advanced,mode_simple >>> ID: language, enabled:1, value: sv, reglocation: HKEY_LOCAL_MACHINE\SOFTWARE\Lavasoft\Ad-Aware\Language >>> >>> Realtime protection settings: >>> ID: realtime, enabled:1 >>> ID: layers, enabled:1 >>> ID: useantivirus, enabled:1, value: true >>> ID: usespywareheuristics, enabled:1, value: true >>> ID: infomessages, enabled:1, value: onlyimportant, domain: display,dontnotify,onlyimportant >>> ID: modules, enabled:1 >>> ID: processprotection, enabled:0, value: true >>> ID: onaccessprotection, enabled:0, value: false >>> ID: registryprotection, enabled:0, value: true >>> ID: networkprotection, enabled:0, value: true >>> >>> >>> ****************************** System information ****************************** >>> Computer name: OLOF-PC >>> Processor name: Intel® Core™ i7 CPU 930 @ 2.80GHz >>> Processor identifier: Intel64 Family 6 Model 26 Stepping 5 >>> Processor speed: ~3808MHZ >>> Raw info: processorarchitecture 9, processortype 8664, processorlevel 6, processor revision 6661, number of processors 8, processor features: [MMX,SSE,SSE2,SSE3] >>> Physical memory available: 4912844800 bytes >>> Physical memory total: 6433128448 bytes >>> Virtual memory available: 1786359808 bytes >>> Virtual memory total: 2147352576 bytes >>> Memory load: 23% >>> Microsoft (build 7600) >>> Windows startup mode: >>> >>> Running processes: >>> PID: 268 name: C:\Windows\System32\smss.exe owner: SYSTEM domain: NT instans >>> PID: 408 name: C:\Windows\System32\csrss.exe owner: SYSTEM domain: NT instans >>> PID: 480 name: C:\Windows\System32\wininit.exe owner: SYSTEM domain: NT instans >>> PID: 496 name: C:\Windows\System32\csrss.exe owner: SYSTEM domain: NT instans >>> PID: 508 name: C:\Program Files (x86)\AVG\AVG9\avgchsva.exe owner: SYSTEM domain: NT instans >>> PID: 516 name: C:\Program Files (x86)\AVG\AVG9\avgrsa.exe owner: SYSTEM domain: NT instans >>> PID: 568 name: C:\Program Files (x86)\AVG\AVG9\avgcsrva.exe owner: SYSTEM domain: NT instans >>> PID: 624 name: C:\Windows\System32\services.exe owner: SYSTEM domain: NT instans >>> PID: 640 name: C:\Windows\System32\lsass.exe owner: SYSTEM domain: NT instans >>> PID: 648 name: C:\Windows\System32\lsm.exe owner: SYSTEM domain: NT instans >>> PID: 312 name: C:\Windows\System32\winlogon.exe owner: SYSTEM domain: NT instans >>> PID: 1052 name: C:\Windows\System32\svchost.exe owner: SYSTEM domain: NT instans >>> PID: 1132 name: C:\Windows\System32\svchost.exe owner: Nätverkstjänst domain: NT instans >>> PID: 1200 name: C:\Windows\System32\atiesrxx.exe owner: SYSTEM domain: NT instans >>> PID: 1240 name: C:\Windows\System32\svchost.exe owner: Lokal tjänst domain: NT instans >>> PID: 1272 name: C:\Windows\System32\svchost.exe owner: SYSTEM domain: NT instans >>> PID: 1300 name: C:\Windows\System32\svchost.exe owner: SYSTEM domain: NT instans >>> PID: 1416 name: C:\Windows\System32\svchost.exe owner: Lokal tjänst domain: NT instans >>> PID: 1684 name: C:\Windows\System32\atieclxx.exe owner: SYSTEM domain: NT instans >>> PID: 1772 name: C:\Windows\System32\svchost.exe owner: Nätverkstjänst domain: NT instans >>> PID: 1884 name: C:\Windows\System32\spoolsv.exe owner: SYSTEM domain: NT instans >>> PID: 1916 name: C:\Windows\System32\svchost.exe owner: Lokal tjänst domain: NT instans >>> PID: 2024 name: C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe owner: SYSTEM domain: NT instans >>> PID: 1580 name: C:\Windows\System32\svchost.exe owner: Lokal tjänst domain: NT instans >>> PID: 2180 name: C:\Program Files (x86)\AVG\AVG9\avgemc.exe owner: SYSTEM domain: NT instans >>> PID: 2224 name: C:\Program Files (x86)\AVG\AVG9\avgnsa.exe owner: SYSTEM domain: NT instans >>> PID: 2536 name: C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe owner: SYSTEM domain: NT instans >>> PID: 2932 name: C:\Windows\System32\svchost.exe owner: Lokal tjänst domain: NT instans >>> PID: 3004 name: C:\Windows\System32\dwm.exe owner: Olof domain: OLOF-PC >>> PID: 1628 name: C:\Windows\explorer.exe owner: Olof domain: OLOF-PC >>> PID: 1616 name: C:\Windows\System32\taskhost.exe owner: Olof domain: OLOF-PC >>> PID: 3120 name: C:\Windows\System32\WUDFHost.exe owner: Lokal tjänst domain: NT instans >>> PID: 3168 name: C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe owner: Olof domain: OLOF-PC >>> PID: 3180 name: C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe owner: Olof domain: OLOF-PC >>> PID: 3240 name: C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe owner: Olof domain: OLOF-PC >>> PID: 3388 name: C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe owner: Olof domain: OLOF-PC >>> PID: 3396 name: C:\Program Files (x86)\AVG\AVG9\avgtray.exe owner: Olof domain: OLOF-PC >>> PID: 3452 name: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe owner: Olof domain: OLOF-PC >>> PID: 3504 name: C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe owner: Olof domain: OLOF-PC >>> PID: 3520 name: E:\Mina Dokument\Program\Open Office\OpenOffice.org 3\program\soffice.exe owner: Olof domain: OLOF-PC >>> PID: 3604 name: E:\Mina Dokument\Program\Open Office\OpenOffice.org 3\program\soffice.bin owner: Olof domain: OLOF-PC >>> PID: 3824 name: C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe owner: Olof domain: OLOF-PC >>> PID: 3940 name: C:\Program Files\Windows Media Player\wmpnetwk.exe owner: Nätverkstjänst domain: NT instans >>> PID: 2260 name: C:\Windows\System32\svchost.exe owner: Lokal tjänst domain: NT instans >>> PID: 4148 name: C:\Windows\System32\svchost.exe owner: Lokal tjänst domain: NT instans >>> PID: 4720 name: C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe owner: Olof domain: OLOF-PC >>> PID: 4896 name: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\dfsvc.exe owner: Olof domain: OLOF-PC >>> PID: 4840 name: C:\Program Files (x86)\Mozilla Firefox\firefox.exe owner: Olof domain: OLOF-PC >>> PID: 4384 name: C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe owner: SYSTEM domain: NT instans >>> PID: 4884 name: C:\Windows\System32\wbem\unsecapp.exe owner: SYSTEM domain: NT instans >>> PID: 3372 name: C:\Windows\System32\wbem\WmiPrvSE.exe owner: SYSTEM domain: NT instans >>> PID: 4260 name: C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-Aware.exe owner: Olof domain: OLOF-PC >>> PID: 1396 name: C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe owner: Olof domain: OLOF-PC >>> >>> Startup items: >>> Name: WebCheck >>> imagepath: {E6FB5E20-DE35-11CF-9C87-00AA005127ED} >>> Name: JMB36X IDE Setup >>> imagepath: C:\Windows\RaidTool\xInsIDE.exe >>> Name: NUSB3MON >>> imagepath: "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" >>> Name: AVG9_TRAY >>> imagepath: C:\PROGRA~2\AVG\AVG9\avgtray.exe >>> Name: Adobe Reader Speed Launcher >>> imagepath: "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" >>> Name: Adobe ARM >>> imagepath: "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" >>> Name: SunJavaUpdateSched >>> imagepath: "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" >>> Name: StartCCC >>> imagepath: "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun >>> Name: >>> imagepath: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini >>> >>> Bootexecute items: >>> Name: >>> imagepath: autocheck autochk * >>> >>> Running services: >>> Name: AeLookupSvc >>> displayname: Application Experience >>> Name: AMD External Events Utility >>> displayname: AMD External Events Utility >>> Name: Appinfo >>> displayname: Application Information >>> Name: AudioEndpointBuilder >>> displayname: Windows Audio Endpoint Builder >>> Name: AudioSrv >>> displayname: Windows Audio >>> Name: avg9emc >>> displayname: AVG Free E-mail Scanner >>> Name: avg9wd >>> displayname: AVG Free WatchDog >>> Name: BFE >>> displayname: Base Filtering Engine >>> Name: BITS >>> displayname: Background Intelligent Transfer Service >>> Name: Browser >>> displayname: Computer Browser >>> Name: bthserv >>> displayname: Bluetooth Support Service >>> Name: CryptSvc >>> displayname: Cryptographic Services >>> Name: DcomLaunch >>> displayname: DCOM Server Process Launcher >>> Name: Dhcp >>> displayname: DHCP Client >>> Name: Dnscache >>> displayname: DNS Client >>> Name: DPS >>> displayname: Diagnostic Policy Service >>> Name: eventlog >>> displayname: Windows Event Log >>> Name: EventSystem >>> displayname: COM+ Event System >>> Name: fdPHost >>> displayname: Function Discovery Provider Host >>> Name: FDResPub >>> displayname: Function Discovery Resource Publication >>> Name: gpsvc >>> displayname: Group Policy Client >>> Name: hidserv >>> displayname: Human Interface Device Access >>> Name: HomeGroupListener >>> displayname: HomeGroup Listener >>> Name: HomeGroupProvider >>> displayname: HomeGroup Provider >>> Name: iphlpsvc >>> displayname: IP Helper >>> Name: KeyIso >>> displayname: CNG Key Isolation >>> Name: LanmanServer >>> displayname: Server >>> Name: LanmanWorkstation >>> displayname: Workstation >>> Name: lmhosts >>> displayname: TCP/IP NetBIOS Helper >>> Name: MpsSvc >>> displayname: Windows Firewall >>> Name: Netman >>> displayname: Network Connections >>> Name: netprofm >>> displayname: Network List Service >>> Name: NlaSvc >>> displayname: Network Location Awareness >>> Name: nsi >>> displayname: Network Store Interface Service >>> Name: p2pimsvc >>> displayname: Peer Networking Identity Manager >>> Name: p2psvc >>> displayname: Peer Networking Grouping >>> Name: PcaSvc >>> displayname: Program Compatibility Assistant Service >>> Name: PlugPlay >>> displayname: Plug and Play >>> Name: PNRPsvc >>> displayname: PNRP (Peer Name Resolution Protocol) >>> Name: Power >>> displayname: Power >>> Name: ProfSvc >>> displayname: User Profile Service >>> Name: RpcEptMapper >>> displayname: RPC Endpoint Mapper >>> Name: RpcSs >>> displayname: Remote Procedure Call (RPC) >>> Name: SamSs >>> displayname: Security Accounts Manager >>> Name: Schedule >>> displayname: Task Scheduler >>> Name: seclogon >>> displayname: Secondary Logon Service >>> Name: SENS >>> displayname: System Event Notification Service >>> Name: ShellHWDetection >>> displayname: Shell Hardware Detection >>> Name: Spooler >>> displayname: Print Spooler >>> Name: SSDPSRV >>> displayname: SSDP Discovery >>> Name: stisvc >>> displayname: Windows Image Acquisition (WIA) >>> Name: Themes >>> displayname: Themes >>> Name: TrkWks >>> displayname: Distributed Link Tracking Client >>> Name: upnphost >>> displayname: UPnP Device Host >>> Name: UxSms >>> displayname: Desktop Window Manager Session Manager >>> Name: wcncsvc >>> displayname: Windows Connect Now - Config Registrar >>> Name: WdiServiceHost >>> displayname: Diagnostic Service Host >>> Name: WdiSystemHost >>> displayname: Diagnostic System Host >>> Name: WinHttpAutoProxySvc >>> displayname: WinHTTP Web Proxy Auto-Discovery Service >>> Name: Winmgmt >>> displayname: Windows Management Instrumentation >>> Name: WMPNetworkSvc >>> displayname: Windows Media Player Network Sharing Service >>> Name: wscsvc >>> displayname: Security Center >>> Name: wuauserv >>> displayname: Windows Update >>> Name: wudfsvc >>> displayname: Windows Driver Foundation - UMDF (User-mode Driver Framework) >>> Name: Lavasoft Ad-Aware Service >>> displayname: Lavasoft Ad-Aware Service >>> >>>
Hi olfie,

Thanks for those logs :thumbup:

Please follow the steps below in order:


Step 1 | As you have Malwarebytes' Anti-Malware installed on your computer. Could you please do a scan using these settings:

  • Open Malwarebytes' Anti-Malware
  • Select the Update tab
  • Click Check for Updates
  • After the update have been completed, Select the Scanner tab.
  • Select Perform Quick scan, then click on Scan
  • When done, you will be prompted. Click OK. If Items are found, then click on Show Results
  • Check all items then click on Remove Selected
  • After it has removed the items, Notepad will open. Please post this log in your next reply.
The log can also be found here:

  • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when the application is started.
Note: MBAM may ask to reboot your computer so it can continue with the removal process, please do so immediately.
Failure to reboot will prevent MBAM from removing all the malware.


Step 2 | Double click on OTL icon to run it.

  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    C:\ProgramData|curse;true;true;true /FP
    C:\Program Files (x86)|curse;true;true;true /FP
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open a notepad window. OTL.Txt. This is saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of this file and post it with your next reply.
Hello Blottedisk.

Thanks for the help and quick reply ;)

Malwarebytes and OTL logs attached as per your request:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Databasversion: 4590

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

2010-09-10 18:08:53
mbam-log-2010-09-10 (18-08-53).txt

Skanningstyp: Snabbskanning
Antal skannade objekt: 130093
Förfluten tid: 1 minut(er), 10 sekund(er)

Infekterade minnesprocesser: 0
Infekterade minnesmoduler: 0
Infekterade registernycklar: 1
Infekterade registervärden: 0
Infekterade registerdataposter: 0
Infekterade mappar: 0
Infekterade filer: 0

Infekterade minnesprocesser:
(Inga illasinnade poster hittades)

Infekterade minnesmoduler:
(Inga illasinnade poster hittades)

Infekterade registernycklar:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RkHit (Rogue.SpywareCease) -> Quarantined and deleted successfully.

Infekterade registervärden:
(Inga illasinnade poster hittades)

Infekterade registerdataposter:
(Inga illasinnade poster hittades)

Infekterade mappar:
(Inga illasinnade poster hittades)

Infekterade filer:
(Inga illasinnade poster hittades)


OTL logfile created on: 2010-09-10 18:14:13 - Run 2
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Olof\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 0000041d | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

6,00 Gb Total Physical Memory | 5,00 Gb Available Physical Memory | 78,00% Memory free
15,00 Gb Paging File | 14,00 Gb Available in Paging File | 90,00% Paging File free
Paging file location(s): e:\pagefile.sys 9202 9202 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 119,14 Gb Total Space | 81,93 Gb Free Space | 68,77% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 698,63 Gb Total Space | 643,79 Gb Free Space | 92,15% Space Free | Partition Type: NTFS
Drive F: | 465,65 Gb Total Space | 355,93 Gb Free Space | 76,44% Space Free | Partition Type: FAT32
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OLOF-PC
Current User Name: Olof
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Olof\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe (GARMIN Corp.)
PRC - C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Windows Live\Mail\wlmail.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Olof\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (avg9emc) – C:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVG Security Toolbar Service) – C:\Program Files (x86)\AVG\AVG9\Toolbar\ToolbarBroker.exe ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (AvgTdiA) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgLdx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgMfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (ATI Technologies, Inc.)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (nusb3xhc) – C:\Windows\SysNative\drivers\nusb3xhc.sys (NEC Electronics Corporation)
DRV:64bit: - (nusb3hub) – C:\Windows\SysNative\drivers\nusb3hub.sys (NEC Electronics Corporation)
DRV:64bit: - (mv91xx) – C:\Windows\SysNative\drivers\mv91xx.sys (Marvell Semiconductor, Inc.)
DRV:64bit: - (JRAID) – C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (e1yexpress) Intel® – C:\Windows\SysNative\drivers\e1y62x64.sys (Intel Corporation)
DRV:64bit: - (tosrfbd) – C:\Windows\SysNative\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV:64bit: - (Tosrfusb) – C:\Windows\SysNative\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV:64bit: - (TosRfSnd) – C:\Windows\SysNative\drivers\TosRfSnd.sys (TOSHIBA Corporation)
DRV:64bit: - (Tosrfcom) – C:\Windows\SysNative\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV:64bit: - (tosrfnds) – C:\Windows\SysNative\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (Tosrfhid) – C:\Windows\SysNative\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
DRV:64bit: - (tosrfbnp) – C:\Windows\SysNative\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV:64bit: - (tosporte) – C:\Windows\SysNative\drivers\tosporte.sys (TOSHIBA Corporation)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (DSI_SiUSBXp_3_1) – C:\Windows\SysNative\drivers\DSI_SiUSBXp_3_1.sys (Silicon Laboratories)
DRV - (Lavasoft Kernexplorer) – C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys ()
DRV - (SASDIFSV) – C:\Program\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://se.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = sv
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B0 C9 36 D4 61 39 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.fraternitas-ferreus.net/forum2/index.php"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.19

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010-09-08 23:19:55 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010-09-08 23:19:55 | 000,000,000 | —D | M]

[2010-08-11 16:13:56 | 000,000,000 | —D | M] – C:\Users\Olof\AppData\Roaming\mozilla\Extensions
[2010-09-09 21:30:10 | 000,000,000 | —D | M] – C:\Users\Olof\AppData\Roaming\mozilla\Firefox\Profiles\c7rhcubc.default\extensions
[2010-08-18 18:31:28 | 000,000,000 | —D | M] – C:\Users\Olof\AppData\Roaming\mozilla\Firefox\Profiles\c7rhcubc.default\extensions\[removed]
[2010-09-06 21:08:13 | 000,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions
[2010-08-14 10:41:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010-08-14 13:10:52 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010-07-17 05:00:04 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010-07-23 02:48:26 | 000,001,470 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\allaannonser-sv-SE.xml
[2010-07-23 02:48:26 | 000,002,670 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\prisjakt-sv-SE.xml
[2010-07-23 02:48:26 | 000,000,948 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\tyda-sv-SE.xml
[2010-07-23 02:48:26 | 000,001,174 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-sv-SE.xml
[2010-07-23 02:48:26 | 000,000,951 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-sv-SE.xml

O1 HOSTS File: ([2010-09-07 18:28:00 | 000,417,891 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 14417 more lines…
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [ANT Agent] C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe (GARMIN Corp.)
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-01-24 10:08:56 | 000,000,000 | —D | M] - F:\autorun – [ FAT32 ]
O32 - AutoRun File - [2007-05-18 10:37:12 | 000,000,069 | RH– | M] () - F:\autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010-09-10 18:06:02 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010-09-10 18:06:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010-09-10 16:03:00 | 000,000,000 | —D | C] – C:\Windows\pss
[2010-09-10 16:01:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\TeamSpeak 3 Client
[2010-09-09 20:08:16 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\Olof\Desktop\OTL.exe
[2010-09-09 19:54:07 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\SUPERAntiSpyware.com
[2010-09-09 19:54:01 | 000,000,000 | —D | C] – C:\Program\SUPERAntiSpyware
[2010-09-09 17:21:36 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\avg
[2010-09-08 16:33:43 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\Mumble
[2010-09-08 16:33:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mumble
[2010-09-07 22:41:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Click-N-Type
[2010-09-07 19:58:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010-09-07 18:28:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Instant Spyware Removal
[2010-09-07 17:52:09 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010-09-07 17:52:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2010-09-06 23:12:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\NoAdware5.0
[2010-09-06 20:30:41 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\Malwarebytes
[2010-09-06 20:30:29 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010-09-06 20:30:28 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010-09-06 20:23:57 | 000,000,000 | —D | C] – C:\ProgramData\SecTaskMan
[2010-09-06 20:23:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Security Task Manager
[2010-09-06 20:04:42 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2010-09-06 20:04:39 | 000,000,000 | —D | C] – C:\ProgramData\!SASCORE
[2010-09-06 18:05:48 | 000,000,000 | -H-D | C] – C:\ProgramData\{ECC164E0-3133-4C70-A831-F08DB2940F70}
[2010-09-06 18:05:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lavasoft
[2010-09-06 17:23:25 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\Sunbelt Software
[2010-09-06 17:23:09 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2010-09-05 12:20:18 | 000,000,000 | —D | C] – C:\ProgramData\ATI
[2010-09-05 12:17:32 | 077,752,952 | —- | C] (Advanced Micro Devices, Inc.) – C:\Users\Olof\Desktop\10-8_vista64_win7_64_dd_ccc_enu.exe
[2010-08-24 09:05:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSECache
[2010-08-16 17:32:28 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2010-08-14 13:11:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2010-08-14 13:10:51 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2010-08-14 13:10:51 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2010-08-14 13:10:51 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2010-08-14 11:41:24 | 000,000,000 | —D | C] – C:\ProgramData\Adobe
[2010-08-14 11:41:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe
[2010-08-14 11:41:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2010-08-14 11:40:56 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\Adobe
[2010-08-14 10:42:12 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2010-08-14 10:42:12 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2010-08-14 10:41:08 | 000,423,656 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2010-08-14 02:25:11 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\OpenOffice.org
[2010-08-14 01:55:03 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010-08-14 01:54:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Java
[2010-08-14 01:48:38 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\TS3Client
[2010-08-14 00:52:12 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\Macromedia
[2010-08-12 17:50:37 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Macromed
[2010-08-12 17:42:19 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\Deployment
[2010-08-12 17:10:00 | 000,000,000 | —D | C] – C:\Users\Olof\Documents\Mina mottagna filer
[2010-08-11 23:07:23 | 000,000,000 | —D | C] – C:\ProgramData\Blizzard Entertainment
[2010-08-11 22:41:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\CCleaner
[2010-08-11 22:33:59 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Blizzard Entertainment
[2010-08-11 22:26:33 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\GARMIN
[2010-08-11 22:25:18 | 000,000,000 | —D | C] – C:\Program\DIFX
[2010-08-11 22:25:05 | 000,024,576 | —- | C] (Silicon Laboratories) – C:\Windows\SysNative\drivers\SiLib.sys
[2010-08-11 22:25:05 | 000,016,384 | —- | C] (Silicon Laboratories) – C:\Windows\SysNative\drivers\DSI_SiUSBXp_3_1.sys
[2010-08-11 22:25:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Garmin
[2010-08-11 22:14:21 | 000,000,000 | —D | C] – C:\ProgramData\Blizzard
[2010-08-11 21:28:43 | 000,000,000 | —D | C] – C:\World of Warcraft
[2010-08-11 21:27:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\World of Warcraft
[2010-08-11 21:27:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Blizzard Entertainment
[2010-08-11 21:20:59 | 001,942,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dfshim.dll
[2010-08-11 21:20:59 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2010-08-11 21:20:59 | 000,320,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHost.exe
[2010-08-11 21:20:59 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2010-08-11 21:20:59 | 000,109,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHostProxy.dll
[2010-08-11 21:20:59 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2010-08-11 21:20:59 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2010-08-11 21:20:59 | 000,048,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netfxperf.dll
[2010-08-11 21:20:53 | 000,294,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\browserchoice.exe
[2010-08-11 21:19:36 | 001,736,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2010-08-11 21:19:36 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2010-08-11 21:19:36 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2010-08-11 21:19:36 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2010-08-11 21:19:36 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2010-08-11 21:19:36 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2010-08-11 21:19:36 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2010-08-11 21:19:35 | 014,629,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmp.dll
[2010-08-11 21:19:35 | 011,406,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmp.dll
[2010-08-11 21:19:34 | 012,625,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmploc.DLL
[2010-08-11 21:19:34 | 012,625,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmploc.DLL
[2010-08-11 21:19:34 | 001,975,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CertEnroll.dll
[2010-08-11 21:19:34 | 001,320,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CertEnroll.dll
[2010-08-11 21:19:30 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2010-08-11 21:19:30 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2010-08-11 21:19:30 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2010-08-11 21:19:30 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2010-08-11 21:19:30 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2010-08-11 21:19:30 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2010-08-11 21:19:28 | 005,507,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2010-08-11 21:19:28 | 003,955,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2010-08-11 21:19:28 | 003,899,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2010-08-11 21:19:26 | 002,870,272 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2010-08-11 21:19:26 | 002,614,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\explorer.exe
[2010-08-11 21:19:26 | 001,572,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\quartz.dll
[2010-08-11 21:19:26 | 001,328,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\quartz.dll
[2010-08-11 21:19:26 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winlogon.exe
[2010-08-11 21:19:26 | 000,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\avifil32.dll
[2010-08-11 21:19:26 | 000,084,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mciavi32.dll
[2010-08-11 21:19:25 | 000,612,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2010-08-11 21:19:25 | 000,427,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\vbscript.dll
[2010-08-11 21:19:25 | 000,148,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\t2embed.dll
[2010-08-11 21:19:25 | 000,108,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\t2embed.dll
[2010-08-11 21:19:25 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rtutils.dll
[2010-08-11 21:19:25 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rtutils.dll
[2010-08-11 21:19:23 | 001,446,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2010-08-11 21:19:16 | 000,852,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2010-08-11 21:19:16 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2010-08-11 21:19:15 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2010-08-11 21:19:15 | 000,082,944 | —- | C] (Radius Inc.) – C:\Windows\SysWow64\iccvid.dll
[2010-08-11 21:18:33 | 000,366,080 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2010-08-11 21:18:33 | 000,293,888 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2010-08-11 21:18:33 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fontsub.dll
[2010-08-11 21:18:33 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fontsub.dll
[2010-08-11 21:18:33 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msasn1.dll
[2010-08-11 21:18:33 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2010-08-11 21:18:33 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2010-08-11 21:17:02 | 000,000,000 | R-SD | C] – C:\Users\Olof\Documents\My Stationery
[2010-08-11 21:11:19 | 000,000,000 | —D | C] – C:\Users\Olof\Tracing
[2010-08-11 21:10:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2010-08-11 21:09:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft
[2010-08-11 21:09:41 | 000,000,000 | —D | C] – C:\Users\Public\Documents\microsoft
[2010-08-11 21:09:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Live SkyDrive
[2010-08-11 21:09:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Live
[2010-08-11 21:09:18 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH

========== Files - Modified Within 30 Days ==========

[2010-09-10 18:11:01 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010-09-10 18:11:00 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010-09-10 18:10:53 | 529,879,039 | -HS- | M] () – C:\hiberfil.sys
[2010-09-10 18:09:48 | 005,505,024 | -HS- | M] () – C:\Users\Olof\NTUSER.DAT
[2010-09-10 18:09:47 | 005,218,688 | -H– | M] () – C:\Users\Olof\AppData\Local\IconCache.db
[2010-09-10 18:06:04 | 000,001,005 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010-09-10 17:33:44 | 000,015,024 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010-09-10 17:33:44 | 000,015,024 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010-09-10 17:30:48 | 001,442,452 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010-09-10 17:30:48 | 000,617,232 | —- | M] () – C:\Windows\SysNative\perfh01D.dat
[2010-09-10 17:30:48 | 000,606,992 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010-09-10 17:30:48 | 000,120,596 | —- | M] () – C:\Windows\SysNative\perfc01D.dat
[2010-09-10 17:30:48 | 000,103,370 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010-09-10 16:01:03 | 000,001,158 | —- | M] () – C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2010-09-10 15:46:00 | 064,510,518 | —- | M] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010-09-09 20:08:16 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Olof\Desktop\OTL.exe
[2010-09-09 19:54:02 | 000,001,808 | —- | M] () – C:\Users\Olof\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010-09-09 19:21:25 | 000,000,751 | —- | M] () – C:\Users\Public\Desktop\World of Warcraft.lnk
[2010-09-08 17:28:51 | 000,004,813 | —- | M] () – C:\Users\Olof\Desktop\lösenord_2.odt
[2010-09-08 16:33:43 | 000,000,975 | —- | M] () – C:\Users\Public\Desktop\Mumble.lnk
[2010-09-07 22:42:41 | 000,001,063 | —- | M] () – C:\Users\Olof\Desktop\Click-N-Type Keyboard.lnk
[2010-09-07 19:32:59 | 000,005,080 | —- | M] () – C:\Users\Olof\Documents\cc_20100907_193254.reg
[2010-09-07 18:28:38 | 000,000,042 | —- | M] () – C:\Windows\SysWow64\scud.udf
[2010-09-07 18:28:00 | 000,417,891 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2010-09-07 18:02:07 | 000,417,891 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts.20100907-182800.backup
[2010-09-06 22:15:09 | 000,013,169 | —- | M] () – C:\Users\Olof\Desktop\lösenord.odt
[2010-09-06 20:45:40 | 000,002,292 | —- | M] () – C:\Users\Olof\Documents\cc_20100906_204534.reg
[2010-09-06 18:05:47 | 000,001,148 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2010-09-05 12:18:22 | 077,752,952 | —- | M] (Advanced Micro Devices, Inc.) – C:\Users\Olof\Desktop\10-8_vista64_win7_64_dd_ccc_enu.exe
[2010-09-05 12:14:08 | 000,000,235 | —- | M] () – C:\Users\Olof\Desktop\Options.ini
[2010-09-05 12:13:40 | 000,001,300 | —- | M] () – C:\Users\Olof\Documents\cc_20100905_121337.reg
[2010-09-05 12:13:00 | 000,001,003 | —- | M] () – C:\Users\Olof\Desktop\CCleaner.lnk
[2010-08-24 09:14:30 | 000,000,846 | —- | M] () – C:\Users\Olof\Documents\cc_20100824_091426.reg
[2010-08-18 21:34:32 | 000,011,461 | —- | M] () – C:\Users\Olof\Desktop\Träningskalender.ods
[2010-08-15 20:00:50 | 000,000,045 | —- | M] () – C:\Windows\SysWow64\initdebug.nfo
[2010-08-14 16:33:49 | 000,007,598 | —- | M] () – C:\Users\Olof\AppData\Local\Resmon.ResmonCfg
[2010-08-14 13:00:12 | 000,004,032 | —- | M] () – C:\Users\Olof\Documents\cc_20100814_130000.reg
[2010-08-14 12:59:48 | 000,008,186 | —- | M] () – C:\Users\Olof\Documents\cc_20100814_125933.reg
[2010-08-14 10:34:35 | 000,289,608 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010-08-14 02:14:07 | 000,062,952 | —- | M] () – C:\Users\Olof\AppData\Local\GDIPFONTCACHEV1.DAT
[2010-08-12 17:09:14 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010-08-12 14:15:20 | 000,015,880 | —- | M] () – C:\Windows\SysNative\lsdelete.exe
[2010-08-11 23:17:43 | 000,002,376 | —- | M] () – C:\Users\Olof\Documents\MumbleAutomaticCertificateBackup.p12

========== Files Created - No Company Name ==========

[2010-09-10 18:06:04 | 000,001,005 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010-09-10 16:01:03 | 000,001,158 | —- | C] () – C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2010-09-09 19:54:02 | 000,001,808 | —- | C] () – C:\Users\Olof\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010-09-08 17:28:51 | 000,004,813 | —- | C] () – C:\Users\Olof\Desktop\lösenord_2.odt
[2010-09-08 16:33:43 | 000,000,975 | —- | C] () – C:\Users\Public\Desktop\Mumble.lnk
[2010-09-07 22:42:41 | 000,001,063 | —- | C] () – C:\Users\Olof\Desktop\Click-N-Type Keyboard.lnk
[2010-09-07 19:32:57 | 000,005,080 | —- | C] () – C:\Users\Olof\Documents\cc_20100907_193254.reg
[2010-09-07 18:28:38 | 000,000,042 | —- | C] () – C:\Windows\SysWow64\scud.udf
[2010-09-06 20:45:38 | 000,002,292 | —- | C] () – C:\Users\Olof\Documents\cc_20100906_204534.reg
[2010-09-06 19:32:31 | 000,015,880 | —- | C] () – C:\Windows\SysNative\lsdelete.exe
[2010-09-06 18:05:47 | 000,001,148 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2010-09-05 12:13:38 | 000,001,300 | —- | C] () – C:\Users\Olof\Documents\cc_20100905_121337.reg
[2010-08-24 09:14:28 | 000,000,846 | —- | C] () – C:\Users\Olof\Documents\cc_20100824_091426.reg
[2010-08-18 21:34:30 | 000,011,461 | —- | C] () – C:\Users\Olof\Desktop\Träningskalender.ods
[2010-08-15 20:00:50 | 000,000,045 | —- | C] () – C:\Windows\SysWow64\initdebug.nfo
[2010-08-15 10:08:31 | 000,023,906 | —- | C] () – C:\Users\Olof\Desktop\Allmänna tips_instruktioner.odt
[2010-08-14 13:00:02 | 000,004,032 | —- | C] () – C:\Users\Olof\Documents\cc_20100814_130000.reg
[2010-08-14 12:59:45 | 000,008,186 | —- | C] () – C:\Users\Olof\Documents\cc_20100814_125933.reg
[2010-08-14 11:14:15 | 000,000,235 | —- | C] () – C:\Users\Olof\Desktop\Options.ini
[2010-08-14 11:13:36 | 004,960,446 | —- | C] () – C:\Users\Olof\Desktop\WarriorDPS2.602Excel07_Oruk.xlsm
[2010-08-14 11:13:26 | 000,009,323 | —- | C] () – C:\Users\Olof\Desktop\Utgiftslogg.xlsx
[2010-08-14 11:13:15 | 000,022,528 | —- | C] () – C:\Users\Olof\Desktop\Utgifter Ö-vik.xls
[2010-08-14 11:13:07 | 000,009,264 | —- | C] () – C:\Users\Olof\Desktop\MC-logg.xlsx
[2010-08-14 11:12:50 | 000,013,169 | —- | C] () – C:\Users\Olof\Desktop\lösenord.odt
[2010-08-14 11:12:36 | 000,014,848 | —- | C] () – C:\Users\Olof\Desktop\Fridas Bank.xls
[2010-08-14 11:12:18 | 002,549,270 | —- | C] () – C:\Users\Olof\Desktop\familjen.odt
[2010-08-14 11:12:12 | 000,019,456 | —- | C] () – C:\Users\Olof\Desktop\Aktier.xls
[2010-08-12 17:09:14 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010-08-11 23:17:43 | 000,002,376 | —- | C] () – C:\Users\Olof\Documents\MumbleAutomaticCertificateBackup.p12
[2010-08-11 22:42:01 | 000,001,003 | —- | C] () – C:\Users\Olof\Desktop\CCleaner.lnk
[2010-08-11 21:45:33 | 000,000,751 | —- | C] () – C:\Users\Public\Desktop\World of Warcraft.lnk
[2010-08-11 00:36:40 | 000,024,576 | R— | C] () – C:\Windows\SysWow64\AsIO.dll
[2010-08-11 00:36:40 | 000,013,440 | R— | C] () – C:\Windows\SysWow64\drivers\AsIO.sys
[2010-08-11 00:36:37 | 000,011,832 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2010-08-11 00:36:37 | 000,010,216 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2010-08-11 00:28:08 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2010-08-11 00:28:06 | 000,034,135 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2010-08-11 00:27:00 | 000,007,598 | —- | C] () – C:\Users\Olof\AppData\Local\Resmon.ResmonCfg
[2009-07-14 01:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009-07-13 23:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009-04-02 14:30:14 | 000,010,296 | —- | C] () – C:\Windows\SysWow64\drivers\ASUSHWIO.SYS
[2008-02-05 13:28:20 | 000,000,051 | —- | C] () – C:\Users\Olof\AppData\Local\setup.txt

========== LOP Check ==========

[2010-08-11 22:26:33 | 000,000,000 | —D | M] – C:\Users\Olof\AppData\Roaming\GARMIN
[2010-09-09 23:06:36 | 000,000,000 | —D | M] – C:\Users\Olof\AppData\Roaming\Mumble
[2010-08-14 02:25:11 | 000,000,000 | —D | M] – C:\Users\Olof\AppData\Roaming\OpenOffice.org
[2010-08-14 01:50:11 | 000,000,000 | —D | M] – C:\Users\Olof\AppData\Roaming\TS3Client
[2010-09-08 19:41:38 | 000,032,634 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< C:\ProgramData|curse;true;true;true /FP >
[2010-08-12 17:42:45 | 000,000,000 | —D | M] – C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_setup_curse_clie_d821d9e18af8a56bd06ca155ee4eb6709e839d9_cab_0a
6c4af4
[2010-09-06 20:25:35 | 000,000,107 | —- | M] () – C:\ProgramData\SecTaskMan\_CurseClientStartuppD5A50

< C:\Program Files (x86)|curse;true;true;true /FP >
< End of report >
Hi olfie,


You're welcome. Please follow these steps:


Step 1 | Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O4 - Startup: C:\Users\Olof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
    
    :Files
    C:\Windows\SysNative\drivers\RKHit.sys
    C:\Program Files (x86)\Instant Spyware Removal
    C:\Program Files (x86)\NoAdware5.0
    
    :Commands
    [EmptyFlash]
    [emptytemp]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered, reboot when it is done.
  • It will produce a log for you on reboot, please post that log in your next reply.

Step 2 | Please go to Kaspersky website and perform an online antivirus scan. Note: Internet Explorer should be used.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan and then put the kettle on!
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place like your Desktop. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Copy and paste the report into your next.

[external image: Posted Image]

Hello Blottedisk. Here are the logs that you requested Thanks /O All processes killed ========== OTL ========== File C:\Users\Olof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip not found. ========== FILES ========== File\Folder C:\Windows\SysNative\drivers\RKHit.sys not found. C:\Program Files (x86)\Instant Spyware Removal folder moved successfully. C:\Program Files (x86)\NoAdware5.0 folder moved successfully. ========== COMMANDS ========== [EMPTYFLASH] User: All Users User: Default User: Default User User: Olof ->Flash cache emptied: 962 bytes User: Public Total Flash Files Cleaned = 0,00 mb [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Olof ->Temp folder emptied: 494328 bytes ->Temporary Internet Files folder emptied: 28364392 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 92970668 bytes ->Flash cache emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 66762 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50416 bytes RecycleBin emptied: 81530 bytes Total Files Cleaned = 116,00 mb OTL by OldTimer - Version 3.2.11.0 log created on 09112010_013014 Files\Folders moved on Reboot… C:\Users\Olof\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot… ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Saturday, September 11, 2010 Operating system: Microsoft (build 7600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Friday, September 10, 2010 09:38:55 Records in database: 4207554 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ Scan statistics: Objects scanned: 139342 Threats found: 1 Infected objects found: 2 Suspicious objects found: 0 Scan duration: 03:01:12 File name / Threat / Threats count F:\Frida\union square deceit.wma Infected: Trojan-Downloader.WMA.Wimad.x 1 F:\Frida\SPARA , till hårddisken2\Min musik\union square deceit.wma Infected: Trojan-Downloader.WMA.Wimad.x 1 Selected area has been scanned.
Hi olfie,


Sorry for the delay. Apparently the keylogger (which might be Curse client itself) is gone. Please follow these steps:


Step 1 | Please download and install Spybot-S&D©®


  • Be sure to UNCHECK TeaTimer when presented with the option to install. You can enable it after you are clean.
  • Run Spybot-S&D©® , go to the Menu Bar at the top choose Mode and make certain that "Default mode" has a check mark beside it.
  • Click the button "Search for Updates".
  • If any updates are found, install them by placing a check mark next to each one and clicking "Download Updates".
  • If you encounter any error messages while downloading the updates, manually download them from here.
  • Click on "Immunize". When it detects what has or has not been blocked, block all remaining items by clicking the green plus sign next to immunize at the top.
  • Click the button "Check for Problems".
  • When Spybot-S&D©® is complete, it will be showing RED entries, bold BLACK entries and GREEN entries in the window.
  • Make certain there is a check mark beside all of the RED entries ONLY.
  • Choose "Fix Selected Problems" and allow Spybot-S&D©® to fix the RED entries.
  • REBOOT to complete the scan and clear memory.
  • Note: After Windows loads, Spybot-S&D©® may run again to clean some files that it could not clean during the prior session. Follow the same procedure.

When finished, navigate to the following location:

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Logs

Copy the contents of your last fixes and checks logfiles and paste them in your next reply. You will recognize the last ones because they are dated, in this format:

Checks.yymmdd-hhmm and Fixes.yymmdd-hhmm



Step 2 | Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    
    :Files
    F:\Frida\union square deceit.wma
    F:\Frida\SPARA , till hårddisken2\Min musik\union square deceit.wma
    
    :Commands
    [CREATERESTOREPOINT]
    [EmptyFlash]
    [emptytemp]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered, reboot when it is done.
  • It will produce a log for you on reboot, please post that log in your next reply.


Please post back with:

-Spybot S&D logs
-OTL log
Morning Blottedisk.

No need to be sorry! I am very impressed about the speed you guys at WhatTheTech are helping me and other users around the world :thumbup:

Here are the logs you requested:

2010-09-12 10:19:49 Downloaded update info file. (http://www.safer-networking.org/updates/spybotsd.ini)
2010-09-12 10:20:18 downloaded update Advanced detection library 1.6.5
2010-09-12 10:20:18 - URL: http://imp.betanews.com/updates/files/advcheck165.zip
2010-09-12 10:20:18 - Local file: C:\Program Files (x86)\Spybot - Search & Destroy\Updates\advcheck165.zip
2010-09-12 10:20:19 downloaded update Detection rules: iPhone
2010-09-12 10:20:19 - URL: http://imp.betanews.com/updates/files/includes.iPhone.zip
2010-09-12 10:20:19 - Local file: C:\Program Files (x86)\Spybot - Search & Destroy\Updates\includes.iPhone.zip
2010-09-12 10:20:20 downloaded update Immunization database
2010-09-12 10:20:20 - URL: http://imp.betanews.com/updates/files/clsid.zip
2010-09-12 10:20:20 - Local file: C:\Program Files (x86)\Spybot - Search & Destroy\Updates\clsid.zip

12.09.2010 10:24:00 - ##### check started #####
12.09.2010 10:24:00 - ### Version: 1.6.2
12.09.2010 10:24:00 - ### Date: 2010-09-12 10:24:00
12.09.2010 10:24:01 - ##### checking bots #####
12.09.2010 10:33:53 - ##### check finished #####

— Report generated: 2010-09-12 10:33 —

Congratulations!: No immediate threats were found. (Status)



— Spybot - Search & Destroy version: 1.6.2 (build: 20090126) —

2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-01-26 TeaTimer.exe ([removed])
2010-09-12 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll ([removed])
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll ([removed])
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2010-06-29 Includes\Adware.sbi (*)
2010-08-24 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2009-11-03 Includes\Dialer.sbi (*)
2010-07-27 Includes\DialerC.sbi (*)
2010-01-25 Includes\HeavyDuty.sbi (*)
2009-05-26 Includes\Hijackers.sbi (*)
2010-07-27 Includes\HijackersC.sbi (*)
2010-06-29 Includes\iPhone.sbi (*)
2010-08-02 Includes\Keyloggers.sbi (*)
2010-08-31 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2010-06-01 Includes\Malware.sbi (*)
2010-09-07 Includes\MalwareC.sbi (*)
2010-05-18 Includes\PUPS.sbi (*)
2010-07-20 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2010-07-27 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2010-06-29 Includes\Spyware.sbi (*)
2010-07-27 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2010-08-04 Includes\Trojans.sbi (*)
2010-07-28 Includes\TrojansC-02.sbi (*)
2010-07-28 Includes\TrojansC-03.sbi (*)
2010-07-28 Includes\TrojansC-04.sbi (*)
2010-09-07 Includes\TrojansC-05.sbi (*)
2010-08-16 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll


================================================================================
=========================

All processes killed
========== OTL ==========
========== FILES ==========
F:\Frida\union square deceit.wma moved successfully.
F:\Frida\SPARA , till hårddisken2\Min musik\union square deceit.wma moved successfully.
========== COMMANDS ==========
Error creating restore point.

[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Olof
->Flash cache emptied: 1232 bytes

User: Public

Total Flash Files Cleaned = 0,00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Olof
->Temp folder emptied: 412329 bytes
->Temporary Internet Files folder emptied: 728996 bytes
->Java cache emptied: 128101 bytes
->FireFox cache emptied: 95968828 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 4633 bytes

Total Files Cleaned = 93,00 mb


OTL by OldTimer - Version 3.2.11.0 log created on 09122010_103635

Files\Folders moved on Reboot…
C:\Users\Olof\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot…
Hi olfie :)


We're almost done. Please double click on the OTL icon to run it. Make sure all other windows are closed and to let it run uninterrupted.

  • Click the Quick Scan button without changing any settings. The scan wont take long.
    • When the scan completes, it will open a notepad window: OTL.Txt. It is saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of OTL.Txt, and post it in your next reply.
  • Note: there will only be an OTL.txt this time
Great to hear Blottedisk!

Here is the OTL log:

OTL logfile created on: 2010-09-12 23:44:04 - Run 3
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Olof\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 0000041d | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

6,00 Gb Total Physical Memory | 5,00 Gb Available Physical Memory | 77,00% Memory free
15,00 Gb Paging File | 13,00 Gb Available in Paging File | 88,00% Paging File free
Paging file location(s): e:\pagefile.sys 9202 9202 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 119,14 Gb Total Space | 81,89 Gb Free Space | 68,74% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 698,63 Gb Total Space | 643,79 Gb Free Space | 92,15% Space Free | Partition Type: NTFS
Drive F: | 465,65 Gb Total Space | 355,94 Gb Free Space | 76,44% Space Free | Partition Type: FAT32
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OLOF-PC
Current User Name: Olof
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win32.exe (TeamSpeak Systems GmbH)
PRC - C:\Users\Olof\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe (GARMIN Corp.)
PRC - C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Windows Live\Mail\wlmail.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Olof\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (avg9emc) – C:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVG Security Toolbar Service) – C:\Program Files (x86)\AVG\AVG9\Toolbar\ToolbarBroker.exe ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (AvgTdiA) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgLdx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgMfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (ATI Technologies, Inc.)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (nusb3xhc) – C:\Windows\SysNative\drivers\nusb3xhc.sys (NEC Electronics Corporation)
DRV:64bit: - (nusb3hub) – C:\Windows\SysNative\drivers\nusb3hub.sys (NEC Electronics Corporation)
DRV:64bit: - (mv91xx) – C:\Windows\SysNative\drivers\mv91xx.sys (Marvell Semiconductor, Inc.)
DRV:64bit: - (JRAID) – C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (e1yexpress) Intel® – C:\Windows\SysNative\drivers\e1y62x64.sys (Intel Corporation)
DRV:64bit: - (tosrfbd) – C:\Windows\SysNative\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV:64bit: - (Tosrfusb) – C:\Windows\SysNative\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV:64bit: - (TosRfSnd) – C:\Windows\SysNative\drivers\TosRfSnd.sys (TOSHIBA Corporation)
DRV:64bit: - (Tosrfcom) – C:\Windows\SysNative\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV:64bit: - (tosrfnds) – C:\Windows\SysNative\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (Tosrfhid) – C:\Windows\SysNative\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
DRV:64bit: - (tosrfbnp) – C:\Windows\SysNative\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV:64bit: - (tosporte) – C:\Windows\SysNative\drivers\tosporte.sys (TOSHIBA Corporation)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (DSI_SiUSBXp_3_1) – C:\Windows\SysNative\drivers\DSI_SiUSBXp_3_1.sys (Silicon Laboratories)
DRV - (Lavasoft Kernexplorer) – C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys ()
DRV - (SASDIFSV) – C:\Program\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://se.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = sv
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B0 C9 36 D4 61 39 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.fraternitas-ferreus.net/forum2/index.php"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.19

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010-09-08 23:19:55 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010-09-08 23:19:55 | 000,000,000 | —D | M]

[2010-08-11 16:13:56 | 000,000,000 | —D | M] – C:\Users\Olof\AppData\Roaming\mozilla\Extensions
[2010-09-12 10:32:30 | 000,000,000 | —D | M] – C:\Users\Olof\AppData\Roaming\mozilla\Firefox\Profiles\c7rhcubc.default\extensions
[2010-08-18 18:31:28 | 000,000,000 | —D | M] – C:\Users\Olof\AppData\Roaming\mozilla\Firefox\Profiles\c7rhcubc.default\extensions\[removed]
[2010-09-06 21:08:13 | 000,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions
[2010-08-14 10:41:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010-08-14 13:10:52 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010-07-17 05:00:04 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010-07-23 02:48:26 | 000,001,470 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\allaannonser-sv-SE.xml
[2010-07-23 02:48:26 | 000,002,670 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\prisjakt-sv-SE.xml
[2010-07-23 02:48:26 | 000,000,948 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\tyda-sv-SE.xml
[2010-07-23 02:48:26 | 000,001,174 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-sv-SE.xml
[2010-07-23 02:48:26 | 000,000,951 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-sv-SE.xml

O1 HOSTS File: ([2010-09-12 10:22:09 | 000,419,251 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 14465 more lines…
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [ANT Agent] C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe (GARMIN Corp.)
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O18:64bit: - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-01-24 10:08:56 | 000,000,000 | —D | M] - F:\autorun – [ FAT32 ]
O32 - AutoRun File - [2007-05-18 10:37:12 | 000,000,069 | RH– | M] () - F:\autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2010-09-11 01:30:14 | 000,000,000 | —D | C] – C:\_OTL
[2010-09-10 18:06:02 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010-09-10 18:06:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010-09-10 16:03:00 | 000,000,000 | —D | C] – C:\Windows\pss
[2010-09-10 16:01:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\TeamSpeak 3 Client
[2010-09-09 20:08:16 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\Olof\Desktop\OTL.exe
[2010-09-09 19:54:07 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\SUPERAntiSpyware.com
[2010-09-09 19:54:01 | 000,000,000 | —D | C] – C:\Program\SUPERAntiSpyware
[2010-09-09 17:21:36 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\avg
[2010-09-08 16:33:43 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\Mumble
[2010-09-08 16:33:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mumble
[2010-09-07 22:41:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Click-N-Type
[2010-09-07 19:58:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010-09-07 17:52:09 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010-09-07 17:52:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2010-09-06 20:30:41 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\Malwarebytes
[2010-09-06 20:30:29 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010-09-06 20:30:28 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010-09-06 20:23:57 | 000,000,000 | —D | C] – C:\ProgramData\SecTaskMan
[2010-09-06 20:23:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Security Task Manager
[2010-09-06 20:04:42 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2010-09-06 20:04:39 | 000,000,000 | —D | C] – C:\ProgramData\!SASCORE
[2010-09-06 18:05:48 | 000,000,000 | -H-D | C] – C:\ProgramData\{ECC164E0-3133-4C70-A831-F08DB2940F70}
[2010-09-06 18:05:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lavasoft
[2010-09-06 17:23:25 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\Sunbelt Software
[2010-09-06 17:23:09 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2010-09-05 12:20:18 | 000,000,000 | —D | C] – C:\ProgramData\ATI
[2010-08-24 09:05:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSECache
[2010-08-16 17:32:28 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2010-08-14 13:11:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2010-08-14 11:41:24 | 000,000,000 | —D | C] – C:\ProgramData\Adobe
[2010-08-14 11:41:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe
[2010-08-14 11:41:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Adobe
[2010-08-14 11:40:56 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\Adobe
[2010-08-14 10:42:12 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2010-08-14 10:42:12 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2010-08-14 02:25:11 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\OpenOffice.org
[2010-08-14 01:55:03 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010-08-14 01:54:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Java
[2010-08-14 01:48:38 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\TS3Client
[2010-08-14 00:52:12 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\Macromedia
[2010-08-12 17:50:37 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Macromed
[2010-08-12 17:42:19 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\Deployment
[2010-08-12 17:10:00 | 000,000,000 | —D | C] – C:\Users\Olof\Documents\Mina mottagna filer
[2010-08-11 23:07:23 | 000,000,000 | —D | C] – C:\ProgramData\Blizzard Entertainment
[2010-08-11 22:41:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\CCleaner
[2010-08-11 22:33:59 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Blizzard Entertainment
[2010-08-11 22:26:33 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\GARMIN
[2010-08-11 22:25:18 | 000,000,000 | —D | C] – C:\Program\DIFX
[2010-08-11 22:25:05 | 000,024,576 | —- | C] (Silicon Laboratories) – C:\Windows\SysNative\drivers\SiLib.sys
[2010-08-11 22:25:05 | 000,016,384 | —- | C] (Silicon Laboratories) – C:\Windows\SysNative\drivers\DSI_SiUSBXp_3_1.sys
[2010-08-11 22:25:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Garmin
[2010-08-11 22:14:21 | 000,000,000 | —D | C] – C:\ProgramData\Blizzard
[2010-08-11 21:28:43 | 000,000,000 | —D | C] – C:\World of Warcraft
[2010-08-11 21:27:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\World of Warcraft
[2010-08-11 21:27:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Blizzard Entertainment
[2010-08-11 21:17:02 | 000,000,000 | R-SD | C] – C:\Users\Olof\Documents\My Stationery
[2010-08-11 21:11:19 | 000,000,000 | —D | C] – C:\Users\Olof\Tracing
[2010-08-11 21:10:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2010-08-11 21:09:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft
[2010-08-11 21:09:41 | 000,000,000 | —D | C] – C:\Users\Public\Documents\microsoft
[2010-08-11 21:09:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Live SkyDrive
[2010-08-11 21:09:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Live
[2010-08-11 21:09:18 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2010-08-11 16:13:41 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\Mozilla
[2010-08-11 16:13:41 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\Mozilla
[2010-08-11 16:13:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2010-08-11 16:08:51 | 000,013,048 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\avgrssta.dll
[2010-08-11 16:08:50 | 000,317,520 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgtdia.sys
[2010-08-11 16:08:48 | 000,269,904 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgldx64.sys
[2010-08-11 16:08:47 | 000,035,536 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgmfx64.sys
[2010-08-11 16:08:47 | 000,000,000 | —D | C] – C:\ProgramData\AVG Security Toolbar
[2010-08-11 16:08:47 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\Avg
[2010-08-11 16:06:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG
[2010-08-11 16:06:48 | 000,000,000 | —D | C] – C:\ProgramData\avg9
[2010-08-11 16:03:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Windows Live
[2010-08-11 15:51:41 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\InstallShield
[2010-08-11 15:48:48 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\Adobe
[2010-08-11 15:47:31 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Futuremark
[2010-08-11 06:40:18 | 000,000,000 | —D | C] – C:\Windows\Panther
[2010-08-11 05:49:51 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2010-08-11 05:41:29 | 000,000,000 | —D | C] – C:\Windows\Prefetch
[2010-08-11 05:41:21 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2010-08-11 00:43:42 | 000,000,000 | —D | C] – C:\Users\Olof\Documents\Bluetooth
[2010-08-11 00:43:23 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\Toshiba
[2010-08-11 00:43:23 | 000,000,000 | —D | C] – C:\ProgramData\TOSHIBA
[2010-08-11 00:36:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\ASUS
[2010-08-11 00:33:46 | 000,000,000 | —D | C] – C:\Program\Intel
[2010-08-11 00:31:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\NEC Electronics
[2010-08-11 00:31:35 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\Downloaded Installations
[2010-08-11 00:31:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Marvell
[2010-08-11 00:30:58 | 000,000,000 | —D | C] – C:\RaidTool
[2010-08-11 00:30:55 | 000,000,000 | —D | C] – C:\Windows\RaidTool
[2010-08-11 00:30:21 | 000,016,896 | —- | C] (ASUS) – C:\Windows\AsTaskSched.dll
[2010-08-11 00:30:10 | 000,000,000 | —D | C] – C:\Windows\SysWow64\RTCOM
[2010-08-11 00:30:10 | 000,000,000 | —D | C] – C:\Program\Realtek
[2010-08-11 00:30:04 | 002,719,504 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\WavesGUILib.dll
[2010-08-11 00:30:04 | 000,518,896 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSTSX64.dll
[2010-08-11 00:30:04 | 000,211,184 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSTSH64.dll
[2010-08-11 00:30:04 | 000,198,896 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSHP64.dll
[2010-08-11 00:30:04 | 000,155,888 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSWOW64.dll
[2010-08-11 00:30:02 | 000,372,936 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEP64A.dll
[2010-08-11 00:30:02 | 000,307,920 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RP3DHT64.dll
[2010-08-11 00:30:02 | 000,307,920 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RP3DAA64.dll
[2010-08-11 00:30:02 | 000,201,928 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEED64A.dll
[2010-08-11 00:30:02 | 000,099,016 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEL64A.dll
[2010-08-11 00:30:02 | 000,076,488 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEG64A.dll
[2010-08-11 00:30:01 | 002,197,264 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioEQ.dll
[2010-08-11 00:30:01 | 000,325,904 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioAPO20.dll
[2010-08-11 00:30:00 | 001,325,328 | —- | C] (DTS) – C:\Windows\SysNative\DTSS2SpeakerDLL64.dll
[2010-08-11 00:30:00 | 001,178,384 | —- | C] (DTS) – C:\Windows\SysNative\DTSS2HeadphoneDLL64.dll
[2010-08-11 00:30:00 | 001,110,800 | —- | C] (DTS) – C:\Windows\SysNative\DTSBoostDLL64.dll
[2010-08-11 00:30:00 | 000,504,592 | —- | C] (DTS) – C:\Windows\SysNative\DTSBassEnhancementDLL64.dll
[2010-08-11 00:30:00 | 000,474,896 | —- | C] (DTS) – C:\Windows\SysNative\DTSVoiceClarityDLL64.dll
[2010-08-11 00:30:00 | 000,321,440 | —- | C] (Fortemedia Corporation) – C:\Windows\SysNative\FMAPO64.dll
[2010-08-11 00:30:00 | 000,315,152 | —- | C] (DTS) – C:\Windows\SysNative\DTSNeoPCDLL64.dll
[2010-08-11 00:30:00 | 000,268,560 | —- | C] (DTS) – C:\Windows\SysNative\DTSLimiterDLL64.dll
[2010-08-11 00:30:00 | 000,265,488 | —- | C] (DTS) – C:\Windows\SysNative\DTSGainCompensatorDLL64.dll
[2010-08-11 00:30:00 | 000,123,664 | —- | C] (DTS) – C:\Windows\SysNative\DTSLFXAPO64.dll
[2010-08-11 00:30:00 | 000,123,152 | —- | C] (DTS) – C:\Windows\SysNative\DTSGFXAPO64.dll
[2010-08-11 00:30:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Realtek
[2010-08-11 00:29:59 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\InstallShield Installation Information
[2010-08-11 00:29:53 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Temp
[2010-08-11 00:29:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InstallShield
[2010-08-11 00:29:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Intel
[2010-08-11 00:28:28 | 000,000,000 | —D | C] – C:\Intel
[2010-08-11 00:15:56 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\ATI
[2010-08-11 00:15:56 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\ATI
[2010-08-11 00:14:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\ATI Technologies
[2010-08-11 00:14:20 | 000,000,000 | -HSD | C] – C:\Windows\Installer
[2010-08-11 00:14:20 | 000,000,000 | —D | C] – C:\Program\ATI
[2010-08-11 00:13:17 | 000,000,000 | —D | C] – C:\Program\ATI Technologies
[2010-08-11 00:12:35 | 000,000,000 | —D | C] – C:\ATI
[2010-08-11 00:08:56 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\Apps
[2010-08-10 23:51:21 | 000,000,000 | R–D | C] – C:\Users\Olof\Searches
[2010-08-10 23:51:16 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\Identities
[2010-08-10 23:51:15 | 000,000,000 | R–D | C] – C:\Users\Olof\Contacts
[2010-08-10 23:51:14 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\VirtualStore
[2010-08-10 23:51:12 | 000,000,000 | –SD | C] – C:\Users\Olof\AppData\Roaming\Microsoft
[2010-08-10 23:51:12 | 000,000,000 | R–D | C] – C:\Users\Olof\Videos
[2010-08-10 23:51:12 | 000,000,000 | R–D | C] – C:\Users\Olof\Saved Games
[2010-08-10 23:51:12 | 000,000,000 | R–D | C] – C:\Users\Olof\Pictures
[2010-08-10 23:51:12 | 000,000,000 | R–D | C] – C:\Users\Olof\Music
[2010-08-10 23:51:12 | 000,000,000 | R–D | C] – C:\Users\Olof\Links
[2010-08-10 23:51:12 | 000,000,000 | R–D | C] – C:\Users\Olof\Favorites
[2010-08-10 23:51:12 | 000,000,000 | R–D | C] – C:\Users\Olof\Downloads
[2010-08-10 23:51:12 | 000,000,000 | R–D | C] – C:\Users\Olof\Documents
[2010-08-10 23:51:12 | 000,000,000 | R–D | C] – C:\Users\Olof\Desktop
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\AppData\Local\Tidigare
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\AppData\Local\Temporary Internet Files
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Start-meny
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Skrivare
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\SendTo
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Recent
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Programdata
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\AppData\Local\Programdata
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Nätverket
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Documents\Mina videoklipp
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Mina dokument
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Documents\Mina bilder
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Documents\Min musik
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Mallar
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Lokala inställningar
[2010-08-10 23:51:12 | 000,000,000 | -HSD | C] – C:\Users\Olof\Cookies
[2010-08-10 23:51:12 | 000,000,000 | -H-D | C] – C:\Users\Olof\AppData
[2010-08-10 23:51:12 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\Temp
[2010-08-10 23:51:12 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Local\Microsoft
[2010-08-10 23:51:12 | 000,000,000 | —D | C] – C:\Users\Olof\AppData\Roaming\Media Center Programs
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\ProgramData\Start-meny
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\ProgramData\Skrivbord
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\Recovery
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\ProgramData\Programdata
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\Program
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\Users\Public\Documents\Mina videoklipp
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\Users\Public\Documents\Mina bilder
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\Users\Public\Documents\Min musik
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\ProgramData\Mallar
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\ProgramData\Favoriter
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\ProgramData\Dokument
[2010-08-10 23:51:09 | 000,000,000 | -HSD | C] – C:\Program\Delade filer
[2010-08-04 03:51:54 | 000,461,824 | —- | C] (AMD) – C:\Windows\SysNative\atieclxx.exe
[2010-08-04 03:51:20 | 000,203,264 | —- | C] (AMD) – C:\Windows\SysNative\atiesrxx.exe
[2010-08-04 03:50:14 | 000,120,320 | —- | C] (AMD) – C:\Windows\SysNative\atitmm64.dll
[2010-08-04 03:49:56 | 000,421,376 | —- | C] (ATI Technologies, Inc.) – C:\Windows\SysNative\atipdl64.dll
[2010-08-04 03:49:50 | 000,356,352 | —- | C] (ATI Technologies, Inc.) – C:\Windows\SysWow64\atipdlxx.dll
[2010-08-04 03:49:40 | 000,278,528 | —- | C] (ATI Technologies, Inc.) – C:\Windows\SysWow64\Oemdspif.dll
[2010-08-04 03:49:36 | 000,012,288 | —- | C] (AMD) – C:\Windows\SysNative\atimuixx.dll
[2010-08-04 03:49:32 | 000,059,392 | —- | C] (ATI Technologies, Inc.) – C:\Windows\SysNative\atiedu64.dll
[2010-08-04 03:49:26 | 000,043,520 | —- | C] (ATI Technologies, Inc.) – C:\Windows\SysWow64\ati2edxx.dll
[2010-07-15 14:47:42 | 000,116,240 | —- | C] (ATI Technologies, Inc.) – C:\Windows\SysNative\drivers\AtihdW76.sys
[2010-07-07 03:24:34 | 000,056,832 | —- | C] (AMD) – C:\Windows\SysNative\coinst.dll

========== Files - Modified Within 90 Days ==========

[2010-09-12 23:44:04 | 005,505,024 | -HS- | M] () – C:\Users\Olof\NTUSER.DAT
[2010-09-12 20:28:37 | 000,000,751 | —- | M] () – C:\Users\Public\Desktop\World of Warcraft.lnk
[2010-09-12 18:19:58 | 000,015,024 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010-09-12 18:19:58 | 000,015,024 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010-09-12 18:17:02 | 001,442,452 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010-09-12 18:17:02 | 000,617,232 | —- | M] () – C:\Windows\SysNative\perfh01D.dat
[2010-09-12 18:17:02 | 000,606,992 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010-09-12 18:17:02 | 000,120,596 | —- | M] () – C:\Windows\SysNative\perfc01D.dat
[2010-09-12 18:17:02 | 000,103,370 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010-09-12 18:16:25 | 064,557,935 | —- | M] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010-09-12 18:12:55 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010-09-12 18:12:55 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010-09-12 18:12:53 | 529,879,039 | -HS- | M] () – C:\hiberfil.sys
[2010-09-12 16:43:55 | 005,222,211 | -H– | M] () – C:\Users\Olof\AppData\Local\IconCache.db
[2010-09-12 10:22:09 | 000,419,251 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2010-09-12 10:17:52 | 000,001,254 | —- | M] () – C:\Users\Olof\Desktop\Spybot - Search & Destroy.lnk
[2010-09-10 18:06:04 | 000,001,005 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010-09-10 16:01:03 | 000,001,158 | —- | M] () – C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2010-09-09 20:08:16 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Olof\Desktop\OTL.exe
[2010-09-09 19:54:02 | 000,001,808 | —- | M] () – C:\Users\Olof\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010-09-08 17:28:51 | 000,004,813 | —- | M] () – C:\Users\Olof\Desktop\lösenord_2.odt
[2010-09-08 16:33:43 | 000,000,975 | —- | M] () – C:\Users\Public\Desktop\Mumble.lnk
[2010-09-07 22:42:41 | 000,001,063 | —- | M] () – C:\Users\Olof\Desktop\Click-N-Type Keyboard.lnk
[2010-09-07 19:32:59 | 000,005,080 | —- | M] () – C:\Users\Olof\Documents\cc_20100907_193254.reg
[2010-09-07 18:28:38 | 000,000,042 | —- | M] () – C:\Windows\SysWow64\scud.udf
[2010-09-07 18:28:00 | 000,417,891 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts.20100912-102209.backup
[2010-09-07 18:02:07 | 000,417,891 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts.20100907-182800.backup
[2010-09-06 22:15:09 | 000,013,169 | —- | M] () – C:\Users\Olof\Desktop\lösenord.odt
[2010-09-06 20:45:40 | 000,002,292 | —- | M] () – C:\Users\Olof\Documents\cc_20100906_204534.reg
[2010-09-06 18:05:47 | 000,001,148 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2010-09-05 12:14:08 | 000,000,235 | —- | M] () – C:\Users\Olof\Desktop\Options.ini
[2010-09-05 12:13:40 | 000,001,300 | —- | M] () – C:\Users\Olof\Documents\cc_20100905_121337.reg
[2010-09-05 12:13:00 | 000,001,003 | —- | M] () – C:\Users\Olof\Desktop\CCleaner.lnk
[2010-08-24 09:14:30 | 000,000,846 | —- | M] () – C:\Users\Olof\Documents\cc_20100824_091426.reg
[2010-08-18 21:34:32 | 000,011,461 | —- | M] () – C:\Users\Olof\Desktop\Träningskalender.ods
[2010-08-15 20:00:50 | 000,000,045 | —- | M] () – C:\Windows\SysWow64\initdebug.nfo
[2010-08-14 16:33:49 | 000,007,598 | —- | M] () – C:\Users\Olof\AppData\Local\Resmon.ResmonCfg
[2010-08-14 13:00:12 | 000,004,032 | —- | M] () – C:\Users\Olof\Documents\cc_20100814_130000.reg
[2010-08-14 12:59:48 | 000,008,186 | —- | M] () – C:\Users\Olof\Documents\cc_20100814_125933.reg
[2010-08-14 10:34:35 | 000,289,608 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010-08-14 02:14:07 | 000,062,952 | —- | M] () – C:\Users\Olof\AppData\Local\GDIPFONTCACHEV1.DAT
[2010-08-12 17:09:14 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010-08-12 14:15:20 | 000,015,880 | —- | M] () – C:\Windows\SysNative\lsdelete.exe
[2010-08-11 23:17:43 | 000,002,376 | —- | M] () – C:\Users\Olof\Documents\MumbleAutomaticCertificateBackup.p12
[2010-08-11 16:08:52 | 000,013,048 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\avgrssta.dll
[2010-08-11 16:08:51 | 000,317,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgtdia.sys
[2010-08-11 16:08:48 | 000,269,904 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgldx64.sys
[2010-08-11 16:08:48 | 000,035,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgmfx64.sys
[2010-08-11 16:08:47 | 000,113,461 | —- | M] () – C:\Windows\SysNative\drivers\Avg\iavichjw.avm
[2010-08-11 15:45:18 | 000,001,769 | —- | M] () – C:\Windows\Language_trs.ini
[2010-08-11 15:44:59 | 000,034,135 | —- | M] () – C:\Windows\Ascd_tmp.ini
[2010-08-11 05:43:22 | 000,046,520 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2010-08-11 05:43:22 | 000,046,520 | —- | M] () – C:\Windows\SysNative\license.rtf
[2010-08-11 00:30:21 | 000,016,896 | —- | M] (ASUS) – C:\Windows\AsTaskSched.dll
[2010-08-11 00:15:42 | 000,000,000 | —- | M] () – C:\Windows\ativpsrm.bin
[2010-08-10 23:56:55 | 000,524,288 | -HS- | M] () – C:\Users\Olof\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010-08-10 23:56:55 | 000,524,288 | -HS- | M] () – C:\Users\Olof\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010-08-10 23:56:55 | 000,065,536 | -HS- | M] () – C:\Users\Olof\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010-08-10 23:51:12 | 000,000,020 | -HS- | M] () – C:\Users\Olof\ntuser.ini
[2010-08-07 16:08:32 | 000,023,906 | —- | M] () – C:\Users\Olof\Desktop\Allmänna tips_instruktioner.odt
[2010-08-04 03:55:18 | 000,071,096 | —- | M] () – C:\Windows\SysNative\atiapfxx.blb
[2010-08-04 03:51:54 | 000,461,824 | —- | M] (AMD) – C:\Windows\SysNative\atieclxx.exe
[2010-08-04 03:51:20 | 000,203,264 | —- | M] (AMD) – C:\Windows\SysNative\atiesrxx.exe
[2010-08-04 03:50:14 | 000,120,320 | —- | M] (AMD) – C:\Windows\SysNative\atitmm64.dll
[2010-08-04 03:49:56 | 000,421,376 | —- | M] (ATI Technologies, Inc.) – C:\Windows\SysNative\atipdl64.dll
[2010-08-04 03:49:50 | 000,356,352 | —- | M] (ATI Technologies, Inc.) – C:\Windows\SysWow64\atipdlxx.dll
[2010-08-04 03:49:40 | 000,278,528 | —- | M] (ATI Technologies, Inc.) – C:\Windows\SysWow64\Oemdspif.dll
[2010-08-04 03:49:36 | 000,012,288 | —- | M] (AMD) – C:\Windows\SysNative\atimuixx.dll
[2010-08-04 03:49:32 | 000,059,392 | —- | M] (ATI Technologies, Inc.) – C:\Windows\SysNative\atiedu64.dll
[2010-08-04 03:49:26 | 000,043,520 | —- | M] (ATI Technologies, Inc.) – C:\Windows\SysWow64\ati2edxx.dll
[2010-08-04 03:25:58 | 000,523,968 | —- | M] () – C:\Windows\SysNative\atiumd6a.cap
[2010-08-04 03:23:46 | 000,056,832 | —- | M] (AMD) – C:\Windows\SysNative\coinst.dll
[2010-08-04 03:21:14 | 000,523,968 | —- | M] () – C:\Windows\SysWow64\atiumdva.cap
[2010-08-03 21:43:10 | 004,960,446 | —- | M] () – C:\Users\Olof\Desktop\WarriorDPS2.602Excel07_Oruk.xlsm
[2010-07-27 07:54:44 | 000,022,053 | —- | M] () – C:\Windows\atiogl.xml
[2010-07-15 14:47:42 | 000,116,240 | —- | M] (ATI Technologies, Inc.) – C:\Windows\SysNative\drivers\AtihdW76.sys
[2010-06-16 15:22:56 | 000,219,348 | —- | M] () – C:\Windows\SysNative\atiicdxx.dat
[2010-06-16 00:28:58 | 000,002,857 | —- | M] () – C:\Windows\SysWow64\atipblag.dat
[2010-06-16 00:28:58 | 000,002,857 | —- | M] () – C:\Windows\SysNative\atipblag.dat

========== Files Created - No Company Name ==========

[2010-09-12 10:17:52 | 000,001,254 | —- | C] () – C:\Users\Olof\Desktop\Spybot - Search & Destroy.lnk
[2010-09-10 18:06:04 | 000,001,005 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010-09-10 16:01:03 | 000,001,158 | —- | C] () – C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2010-09-09 19:54:02 | 000,001,808 | —- | C] () – C:\Users\Olof\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010-09-08 17:28:51 | 000,004,813 | —- | C] () – C:\Users\Olof\Desktop\lösenord_2.odt
[2010-09-08 16:33:43 | 000,000,975 | —- | C] () – C:\Users\Public\Desktop\Mumble.lnk
[2010-09-07 22:42:41 | 000,001,063 | —- | C] () – C:\Users\Olof\Desktop\Click-N-Type Keyboard.lnk
[2010-09-07 19:32:57 | 000,005,080 | —- | C] () – C:\Users\Olof\Documents\cc_20100907_193254.reg
[2010-09-07 18:28:38 | 000,000,042 | —- | C] () – C:\Windows\SysWow64\scud.udf
[2010-09-06 20:45:38 | 000,002,292 | —- | C] () – C:\Users\Olof\Documents\cc_20100906_204534.reg
[2010-09-06 19:32:31 | 000,015,880 | —- | C] () – C:\Windows\SysNative\lsdelete.exe
[2010-09-06 18:05:47 | 000,001,148 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2010-09-05 12:13:38 | 000,001,300 | —- | C] () – C:\Users\Olof\Documents\cc_20100905_121337.reg
[2010-08-24 09:14:28 | 000,000,846 | —- | C] () – C:\Users\Olof\Documents\cc_20100824_091426.reg
[2010-08-18 21:34:30 | 000,011,461 | —- | C] () – C:\Users\Olof\Desktop\Träningskalender.ods
[2010-08-15 20:00:50 | 000,000,045 | —- | C] () – C:\Windows\SysWow64\initdebug.nfo
[2010-08-15 10:08:31 | 000,023,906 | —- | C] () – C:\Users\Olof\Desktop\Allmänna tips_instruktioner.odt
[2010-08-14 13:00:02 | 000,004,032 | —- | C] () – C:\Users\Olof\Documents\cc_20100814_130000.reg
[2010-08-14 12:59:45 | 000,008,186 | —- | C] () – C:\Users\Olof\Documents\cc_20100814_125933.reg
[2010-08-14 11:14:15 | 000,000,235 | —- | C] () – C:\Users\Olof\Desktop\Options.ini
[2010-08-14 11:13:36 | 004,960,446 | —- | C] () – C:\Users\Olof\Desktop\WarriorDPS2.602Excel07_Oruk.xlsm
[2010-08-14 11:13:26 | 000,009,323 | —- | C] () – C:\Users\Olof\Desktop\Utgiftslogg.xlsx
[2010-08-14 11:13:15 | 000,022,528 | —- | C] () – C:\Users\Olof\Desktop\Utgifter Ö-vik.xls
[2010-08-14 11:13:07 | 000,009,264 | —- | C] () – C:\Users\Olof\Desktop\MC-logg.xlsx
[2010-08-14 11:12:50 | 000,013,169 | —- | C] () – C:\Users\Olof\Desktop\lösenord.odt
[2010-08-14 11:12:36 | 000,014,848 | —- | C] () – C:\Users\Olof\Desktop\Fridas Bank.xls
[2010-08-14 11:12:18 | 002,549,270 | —- | C] () – C:\Users\Olof\Desktop\familjen.odt
[2010-08-14 11:12:12 | 000,019,456 | —- | C] () – C:\Users\Olof\Desktop\Aktier.xls
[2010-08-12 17:09:14 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010-08-11 23:17:43 | 000,002,376 | —- | C] () – C:\Users\Olof\Documents\MumbleAutomaticCertificateBackup.p12
[2010-08-11 22:42:01 | 000,001,003 | —- | C] () – C:\Users\Olof\Desktop\CCleaner.lnk
[2010-08-11 21:45:33 | 000,000,751 | —- | C] () – C:\Users\Public\Desktop\World of Warcraft.lnk
[2010-08-11 16:08:47 | 064,557,935 | —- | C] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010-08-11 16:08:47 | 000,113,461 | —- | C] () – C:\Windows\SysNative\drivers\Avg\iavichjw.avm
[2010-08-11 05:41:21 | 529,879,039 | -HS- | C] () – C:\hiberfil.sys
[2010-08-11 00:36:40 | 000,024,576 | R— | C] () – C:\Windows\SysWow64\AsIO.dll
[2010-08-11 00:36:40 | 000,013,440 | R— | C] () – C:\Windows\SysWow64\drivers\AsIO.sys
[2010-08-11 00:36:37 | 000,011,832 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2010-08-11 00:36:37 | 000,010,216 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2010-08-11 00:33:43 | 000,001,904 | —- | C] () – C:\Windows\SysNative\SetupBD.din
[2010-08-11 00:33:18 | 000,003,315 | —- | C] () – C:\Windows\SysNative\e1y62x64.din
[2010-08-11 00:28:08 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2010-08-11 00:28:06 | 000,034,135 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2010-08-11 00:27:00 | 000,007,598 | —- | C] () – C:\Users\Olof\AppData\Local\Resmon.ResmonCfg
[2010-08-11 00:15:42 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010-08-10 23:51:12 | 005,505,024 | -HS- | C] () – C:\Users\Olof\NTUSER.DAT
[2010-08-10 23:51:12 | 000,524,288 | -HS- | C] () – C:\Users\Olof\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010-08-10 23:51:12 | 000,524,288 | -HS- | C] () – C:\Users\Olof\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010-08-10 23:51:12 | 000,262,144 | -HS- | C] () – C:\Users\Olof\ntuser.dat.LOG1
[2010-08-10 23:51:12 | 000,065,536 | -HS- | C] () – C:\Users\Olof\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010-08-10 23:51:12 | 000,000,020 | -HS- | C] () – C:\Users\Olof\ntuser.ini
[2010-08-10 23:51:12 | 000,000,000 | -HS- | C] () – C:\Users\Olof\ntuser.dat.LOG2
[2010-08-04 03:55:18 | 000,071,096 | —- | C] () – C:\Windows\SysNative\atiapfxx.blb
[2010-08-04 03:25:58 | 000,523,968 | —- | C] () – C:\Windows\SysNative\atiumd6a.cap
[2010-08-04 03:21:14 | 000,523,968 | —- | C] () – C:\Windows\SysWow64\atiumdva.cap
[2010-07-27 07:54:44 | 000,022,053 | —- | C] () – C:\Windows\atiogl.xml
[2010-06-16 15:22:56 | 000,219,348 | —- | C] () – C:\Windows\SysNative\atiicdxx.dat
[2010-06-16 00:28:58 | 000,002,857 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2010-06-16 00:28:58 | 000,002,857 | —- | C] () – C:\Windows\SysNative\atipblag.dat
[2009-07-14 01:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009-07-13 23:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009-04-02 14:30:14 | 000,010,296 | —- | C] () – C:\Windows\SysWow64\drivers\ASUSHWIO.SYS
[2008-02-05 13:28:20 | 000,000,051 | —- | C] () – C:\Users\Olof\AppData\Local\setup.txt

========== LOP Check ==========

[2010-08-11 22:26:33 | 000,000,000 | —D | M] – C:\Users\Olof\AppData\Roaming\GARMIN
[2010-09-09 23:06:36 | 000,000,000 | —D | M] – C:\Users\Olof\AppData\Roaming\Mumble
[2010-08-14 02:25:11 | 000,000,000 | —D | M] – C:\Users\Olof\AppData\Roaming\OpenOffice.org
[2010-08-14 01:50:11 | 000,000,000 | —D | M] – C:\Users\Olof\AppData\Roaming\TS3Client
[2010-09-08 19:41:38 | 000,032,634 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========


< End of report >
Hi olfie,


Apparently there's no more malware in your machine; the keylogger is gone. Let's do some cleanup:


Step 1 | Clean up with OTL

  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
  • Now, from the desktop, delete any logs that you have left over.

Last Step | Now, in order to avoid future infections, please take time to read the following articles:


Read those articles and your potential for being infected again will reduce dramatically. Avoid underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users.


Thank you for your patience, and performing all of the procedures requested. I'd be grateful if you could reply to this post so that I know you have read it and, if you've no other questions, the thread can then be closed. Posted Image

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI